The Containment Era is here. →Explore

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

747 threat reports
Page 2 of 63

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Telecommunications Threat Reports

Showing 1324 / 747 reports
Daxin and Stupig Malware Resurface in Taiwan Manufacturing Firm
Impact· HIGH

Daxin and Stupig Malware Resurface in Taiwan Manufacturing Firm

In May 2026, Symantec's Threat Hunter Team identified the re-emergence of Backdoor.Daxin, a sophisticated kernel-mode rootkit previously linked to China-based threat actors, on a compromised host within a Taiwan-based subsidiary of a multinational high-tech manufacturer. Alongside Daxin, researchers discovered a novel backdoor named Stupig, which exploits a trojanized keyboard-layout DLL to execute commands with SYSTEM privileges directly from the Windows logon screen, bypassing standard authentication mechanisms. Both malware samples carry compile timestamps from early 2013, suggesting a prolonged undetected presence of up to 13 years within the victim's network. This incident underscores the persistent and evolving nature of cyber threats targeting critical infrastructure and high-tech industries. The discovery of Stupig's unique pre-authentication execution method highlights the need for continuous vigilance and advanced detection capabilities to identify and mitigate such stealthy intrusions.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
US Indicts Russian Nationals for Bulletproof Hosting Services in 2026
Impact· CRITICAL

US Indicts Russian Nationals for Bulletproof Hosting Services in 2026

In July 2026, U.S. federal prosecutors unsealed charges against three Russian nationals—Aleksandr Volosovik, Yulia Pankova, and Kirill Zatolokin—for operating bulletproof hosting services, Media Land and ML.Cloud. These services provided infrastructure to ransomware gangs, facilitating over $62 million in damages globally. The hosting services were designed to resist law enforcement takedown efforts, supporting activities such as malware distribution, command-and-control operations, and phishing attacks. The infrastructure spanned multiple countries, including China, Finland, the Netherlands, and the United States. This incident underscores the persistent threat posed by bulletproof hosting services in the cybercrime ecosystem. The U.S. Department of State has offered a $10 million reward for information on these individuals, highlighting the international commitment to dismantling such networks. Organizations are urged to enhance their cybersecurity measures to mitigate risks associated with these resilient infrastructures.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Dutch Authorities Dismantle €100 Million Investment Fraud Network
Impact· HIGH

Dutch Authorities Dismantle €100 Million Investment Fraud Network

In July 2026, Dutch authorities dismantled a sophisticated international investment fraud scheme that operated 20 call centers across multiple countries, employing over 700 individuals posing as financial advisors. The organization is estimated to have defrauded tens of thousands of victims, amassing over €100 million per month at its peak. The fraudsters built trust with victims over extended periods, introducing them to realistic-looking investment platforms that displayed fictitious profits. Victims were persuaded to increase their investments, often through cryptocurrency transfers, while the criminals siphoned the funds and presented fake dashboards showing inflated returns. This incident underscores the evolving complexity and scale of cyber-enabled financial fraud, highlighting the need for enhanced vigilance and regulatory measures in the financial sector. The use of sophisticated social engineering tactics and the exploitation of cryptocurrency platforms for illicit gains reflect broader trends in cybercrime, necessitating continuous adaptation of security strategies by organizations and individuals alike.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
TuxBot v3 Evolution: Unveiling the AI-Assisted IoT Botnet Threat
Impact· CRITICAL

TuxBot v3 Evolution: Unveiling the AI-Assisted IoT Botnet Threat

In early 2026, cybersecurity researchers uncovered TuxBot v3 Evolution, a sophisticated modular IoT botnet framework. This malware targets a wide range of IoT devices by exploiting known vulnerabilities and employing extensive Telnet brute-force attacks. Notably, the development of TuxBot v3 Evolution involved assistance from a large language model (LLM), resulting in both functional components and critical errors due to unreviewed AI-generated code. The botnet's capabilities include multi-architecture support, encrypted command-and-control communications, and a variety of fallback mechanisms, posing a significant threat to IoT security. The discovery of TuxBot v3 Evolution underscores the evolving landscape of cyber threats, where adversaries leverage AI technologies to enhance malware development. This trend highlights the urgent need for robust security measures and continuous monitoring to protect IoT ecosystems from increasingly sophisticated attacks.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical Vulnerabilities in 6 GHz Wi-Fi AFC Systems Uncovered
Impact· HIGH

Critical Vulnerabilities in 6 GHz Wi-Fi AFC Systems Uncovered

In July 2026, researchers from Pennsylvania State University and Idaho National Laboratory identified significant security vulnerabilities in Automated Frequency Coordination (AFC) systems, which manage the 6 GHz Wi-Fi spectrum to prevent interference with critical infrastructure. The study revealed that AFC systems inherently trust client-side data, such as GPS coordinates and time synchronization inputs, without adequate verification. This trust model exposes the systems to potential attacks where adversaries could spoof location data or manipulate time synchronization, leading to unauthorized spectrum access, harmful interference with incumbent services, or denial-of-service conditions for legitimate 6 GHz Wi-Fi users. ([darkreading.com](https://www.darkreading.com/perimeter/6-ghz-wi-fi-flaws-disrupt-critical-systems?utm_source=openai)) The findings underscore the urgent need for enhanced security measures in AFC systems, especially as the adoption of 6 GHz Wi-Fi expands. Without addressing these vulnerabilities, critical communication infrastructures remain at risk of disruption, highlighting the importance of implementing robust authentication and validation mechanisms within AFC architectures to safeguard against potential exploits.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Unveiling TuxBot v3 Evolution: The AI-Assisted IoT Botnet Threat
Impact· HIGH

Unveiling TuxBot v3 Evolution: The AI-Assisted IoT Botnet Threat

In early 2026, security researchers identified TuxBot v3 Evolution, a sophisticated modular IoT botnet framework. This malware targets a wide range of IoT devices by exploiting known vulnerabilities and employing extensive Telnet brute-force attacks. Notably, the developers utilized large language models (LLMs) to assist in code development, resulting in a mix of functional and flawed components. The botnet's capabilities include cross-compilation for multiple architectures, encrypted command-and-control (C2) communications, and a DDoS-for-hire panel. Despite some non-functional features due to development oversights, the framework's modularity and adaptability pose a significant threat to IoT security. The emergence of TuxBot v3 Evolution underscores a concerning trend: the integration of AI tools in malware development, which can accelerate the creation of complex and adaptable threats. This incident highlights the urgent need for enhanced security measures in IoT devices and the importance of monitoring AI-assisted developments in the cyber threat landscape.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Strengthening Router Security Against State-Sponsored Cyber Threats
Impact· CRITICAL

Strengthening Router Security Against State-Sponsored Cyber Threats

In July 2026, a joint advisory from the NSA, CISA, FBI, and international partners highlighted that Russian FSB Center 16 cyber actors, also known as Berserk Bear and Dragonfly, have been exploiting poorly configured and vulnerable networking devices worldwide. These actors primarily target critical infrastructure sectors such as communications, energy, defense, financial services, government facilities, and healthcare. Their tactics include scanning for devices with default or weak SNMP credentials and exploiting known vulnerabilities in Cisco devices and protocols, enabling unauthorized access and potential disruption of essential services. This incident underscores the persistent threat posed by state-sponsored cyber actors targeting critical infrastructure through common vulnerabilities. Organizations are urged to enhance their network security by updating device configurations, disabling legacy protocols, and implementing strong authentication measures to mitigate such risks.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CISA Adds CVE-2008-4128 to Known Exploited Vulnerabilities Catalog
Impact· MEDIUM

CISA Adds CVE-2008-4128 to Known Exploited Vulnerabilities Catalog

On July 13, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2008-4128 to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability, a Cross-Site Request Forgery (CSRF) flaw in the HTTP Administration component of Cisco IOS 12.4 running on 871 Integrated Services Routers, allows remote attackers to execute arbitrary commands. Despite being disclosed in 2008, recent evidence indicates active exploitation, prompting CISA to mandate federal agencies to apply mitigations by July 16, 2026. The resurgence of exploitation of this 17-year-old vulnerability underscores the persistent risk posed by unpatched legacy systems. Organizations are urged to reassess their network infrastructure, prioritize the remediation of known vulnerabilities, and implement robust patch management practices to mitigate potential threats.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical RabbitMQ Vulnerabilities Expose OAuth Secrets - CVE-2026-57219
Impact· HIGH

Critical RabbitMQ Vulnerabilities Expose OAuth Secrets - CVE-2026-57219

In July 2026, two critical vulnerabilities were identified in RabbitMQ, a widely used open-source message broker. The most severe, CVE-2026-57219, allowed unauthenticated attackers to access the broker's OAuth client secret via an obsolete management API endpoint, potentially enabling full control over the messaging infrastructure. The second flaw, CVE-2026-57221, permitted authenticated users with no privileges to view metadata of other tenants' queues and exchanges, risking exposure of sensitive business information. Both vulnerabilities have been patched in RabbitMQ versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6. Organizations are urged to update their systems and rotate any exposed OAuth secrets to mitigate potential risks. ([scworld.com](https://www.scworld.com/news/rabbitmq-fixes-flaw-that-allowed-broker-takeover-via-oauth-secret-disclosure?utm_source=openai)) These incidents underscore the critical importance of securing management interfaces and promptly addressing deprecated endpoints to prevent unauthorized access and data exposure. The widespread use of RabbitMQ amplifies the potential impact, highlighting the need for vigilant security practices in managing messaging infrastructures.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Russian FSB Exploits Cisco Vulnerabilities in Critical Infrastructure Attacks
Impact· CRITICAL

Russian FSB Exploits Cisco Vulnerabilities in Critical Infrastructure Attacks

In July 2026, a joint cybersecurity advisory from the United States and 12 other nations highlighted ongoing cyber intrusions by Russian state-sponsored hackers, specifically the FSB's Center 16, also known as Berserk Bear and Static Tundra. These actors have been exploiting vulnerabilities in Cisco networking devices, notably CVE-2008-4128 and CVE-2018-0171, to infiltrate critical infrastructure sectors such as defense, communications, energy, finance, government, and healthcare. The attackers leverage default or weak passwords and unpatched systems to gain unauthorized access, conduct reconnaissance, and potentially disrupt operations. This incident underscores the persistent threat posed by nation-state actors targeting outdated and misconfigured network devices. Organizations are urged to implement robust security measures, including disabling vulnerable features like Cisco's Smart Install, enforcing strong authentication protocols, and regularly updating systems to mitigate such risks.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
EU and UK Sanction Russian Entities Over Cyberespionage Campaign
Impact· HIGH

EU and UK Sanction Russian Entities Over Cyberespionage Campaign

In July 2026, the European Union and the United Kingdom imposed coordinated sanctions on Russian military intelligence officers, hackers, and private companies in response to a prolonged cyberespionage campaign attributed to Russian actors. The EU targeted nine individuals and four entities, while the UK sanctioned 24 individuals and organizations. These sanctions, including asset freezes and travel bans, were directed at actors linked to Russia's FSB and GRU intelligence agencies, accused of conducting cyber operations targeting governments and critical infrastructure since 2010. Key affected countries include France, Germany, Poland, the Netherlands, and Finland, with specific incidents such as the sabotage of Polish railway infrastructure highlighted. ([apnews.com](https://apnews.com/article/1d3c542e1409b54a10856eacad18b7ca?utm_source=openai)) This incident underscores the escalating threat of state-sponsored cyberattacks on critical infrastructure and governmental networks. The coordinated response by the EU and UK reflects a growing recognition of the need for unified action against cyber threats, emphasizing the importance of robust cybersecurity measures and international cooperation to safeguard national security and public services.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
US and Allies Issue Joint Advisory on Russian Cyber Threats to Critical Infrastructure
Impact· CRITICAL

US and Allies Issue Joint Advisory on Russian Cyber Threats to Critical Infrastructure

In July 2026, cybersecurity agencies from the United States and eight allied nations issued a joint advisory warning that Russian state-sponsored hackers, specifically FSB Center 16 (also known as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra), are actively targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks. These actors exploit default or weak SNMP authentication strings and known vulnerabilities, such as CVE-2018-0171 in Cisco's Smart Install feature, to gain unauthorized access, exfiltrate configuration files, and conduct reconnaissance within victim networks. The sectors most at risk include energy, communications, defense industrial base, healthcare, financial services, and government services. This incident underscores the persistent threat posed by nation-state actors to critical infrastructure, highlighting the importance of proactive cybersecurity measures. Organizations are urged to upgrade to SNMPv3, disable unnecessary services like Cisco Smart Install, enforce strong unique passwords, block TFTP and SNMP traffic at edge firewalls, update software and firmware, and replace end-of-life devices to mitigate such risks.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports