✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Telegram 'tdata' Folder Exploited in Credential Harvesting Attack - April 2026
In April 2026, a sophisticated cyberattack was observed targeting Telegram Desktop users through the exploitation of the 'tdata' folder, which stores session data. Attackers gained initial access via weak SSH credentials, conducted system reconnaissance, and specifically sought out the 'tdata' directory to harvest Telegram session tokens. This method allowed them to bypass two-factor authentication and gain unauthorized access to users' Telegram accounts, leading to potential data exfiltration and account misuse. The incident underscores the evolving tactics of threat actors who are now combining resource hijacking with credential harvesting to establish persistent access and exploit digital identities. This trend highlights the critical need for robust SSH configurations, vigilant monitoring of sensitive directories, and comprehensive session management practices to mitigate such multifaceted threats.
3 months ago
Kill Chain
NGate Malware Variant Exploits HandyPay App to Steal NFC Data
In November 2025, ESET researchers identified a new variant of the NGate malware family targeting Android users in Brazil. This variant exploits a legitimate NFC payment application called HandyPay by embedding malicious code, likely generated with the assistance of AI. The malware captures NFC data and payment card PINs from victims, enabling attackers to perform unauthorized contactless ATM withdrawals and payments. Distribution methods include fake lottery websites and counterfeit Google Play pages, indicating a coordinated effort by a single threat actor. This incident underscores the evolving sophistication of cyber threats, particularly the integration of AI in malware development. The use of legitimate applications as vectors for malware distribution highlights the need for heightened vigilance and robust security measures to protect sensitive financial information.
3 months ago
Kill Chain
Scattered Spider Leader Pleads Guilty to Multi-Million Dollar Cyber Attacks
Between September 2021 and April 2023, Tyler Robert Buchanan, a 24-year-old from Dundee, Scotland, orchestrated a series of high-profile phishing attacks and cryptocurrency thefts as a core member of the cybercriminal group Scattered Spider. Utilizing sophisticated social engineering techniques, Buchanan and his co-conspirators harvested thousands of credentials, leading to the theft of over $8 million in cryptocurrency from U.S. residents. Their victims included high-net-worth individuals and businesses across sectors such as entertainment, telecommunications, technology, and virtual currency. ([cyberscoop.com](https://cyberscoop.com/the-com-scattered-spider-hacker-tyler-robert-buchanan-guilty-plea/?utm_source=openai)) Buchanan's recent guilty plea underscores the persistent threat posed by cybercriminal groups employing advanced social engineering tactics. This case highlights the critical need for organizations to bolster their cybersecurity defenses, particularly in safeguarding against phishing and credential theft, to mitigate the risk of significant financial and reputational damage.
3 months ago
Kill Chain
Urgent Alert: Active Exploitation of Cisco SD-WAN Vulnerability CVE-2026-20133
In April 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) identified active exploitation of a critical vulnerability (CVE-2026-20133) in Cisco Catalyst SD-WAN Manager. This flaw, stemming from insufficient file system access restrictions, allows unauthenticated remote attackers to access sensitive information on affected systems. Cisco had patched this vulnerability in February 2026, but unpatched systems remain at risk. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-flags-new-sd-wan-flaw-as-actively-exploited-in-attacks/?utm_source=openai)) The exploitation of CVE-2026-20133 underscores the persistent threat posed by unpatched vulnerabilities in critical network infrastructure. Organizations are urged to prioritize timely patching and adhere to CISA's directives to mitigate potential breaches and safeguard sensitive data.
3 months ago
Kill Chain
Scattered Spider's Tylerb Pleads Guilty to Cybercrime Charges
In April 2026, Tyler Robert Buchanan, a 24-year-old British national and senior member of the cybercrime group 'Scattered Spider,' pleaded guilty to wire fraud conspiracy and aggravated identity theft. Buchanan admitted to orchestrating a series of SMS-based phishing attacks in 2022, targeting major technology companies such as Twilio, LastPass, DoorDash, and Mailchimp. These attacks facilitated unauthorized access to corporate systems, leading to the theft of sensitive data and over $8 million in cryptocurrency from investors. This case underscores the persistent threat posed by sophisticated social engineering tactics employed by cybercriminal groups like Scattered Spider. Organizations must remain vigilant, as such groups continue to exploit human vulnerabilities to infiltrate systems and exfiltrate valuable data, emphasizing the need for robust security measures and employee training.
3 months ago
Kill Chain
CISA Adds 8 Exploited Flaws to KEV Catalog
In April 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added eight vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation. Notably, CVE-2023-27351, an improper authentication flaw in PaperCut NG/MF, allows attackers to bypass authentication via the SecurityRequestFilter class. Other vulnerabilities affect JetBrains TeamCity, Kentico Xperience, Quest KACE SMA, Synacor Zimbra, and Cisco Catalyst SD-WAN Manager. ([thehackernews.com](https://thehackernews.com/2026/04/cisa-adds-8-exploited-flaws-to-kev-sets.html?utm_source=openai)) The inclusion of these vulnerabilities underscores the persistent threat posed by both new and longstanding security flaws. Organizations are urged to promptly apply patches to mitigate risks associated with these actively exploited vulnerabilities.
3 months ago
Kill Chain
NGate Malware Exploits HandyPay App to Steal NFC Data in Brazil
In April 2026, ESET researchers identified a new variant of the NGate Android malware targeting users in Brazil. This malware abuses a legitimate application called HandyPay by injecting malicious code, likely generated with AI assistance. The campaign, active since November 2025, distributes the trojanized app through fake lottery websites and counterfeit Google Play pages. Once installed, the app prompts users to set it as the default NFC payment application, enter their payment card PIN, and tap their card against the device. The malware then relays the NFC data and PIN to attacker-controlled devices, enabling unauthorized contactless transactions and ATM withdrawals. ([globenewswire.com](https://www.globenewswire.com/news-release/2026/04/21/3277653/0/en/eset-research-new-ngate-hides-in-nfc-payment-app-possibly-built-with-ai.html?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals, who are now leveraging AI-generated code to enhance malware capabilities and employing sophisticated social engineering techniques to distribute malicious applications. The focus on NFC payment data highlights the increasing targeting of mobile payment systems, necessitating heightened vigilance and security measures for both users and financial institutions. ([globenewswire.com](https://www.globenewswire.com/news-release/2026/04/21/3277653/0/en/eset-research-new-ngate-hides-in-nfc-payment-app-possibly-built-with-ai.html?utm_source=openai))
3 months ago
Kill Chain
Scattered Spider Leader Pleads Guilty to Multi-Million Dollar Crypto Theft
In April 2026, Tyler Robert Buchanan, a British national and alleged leader of the Scattered Spider cybercrime group, pleaded guilty in the United States to charges of wire fraud and aggravated identity theft. Between September 2021 and April 2023, Buchanan and his co-conspirators executed SMS phishing attacks targeting employees of various companies across industries such as entertainment, telecommunications, and technology. By impersonating legitimate entities, they obtained confidential information, enabling them to hijack email accounts through SIM swapping and steal over $8 million in cryptocurrency. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/british-scattered-spider-hacker-pleads-guilty-to-crypto-theft-charges/?utm_source=openai)) This case underscores the persistent threat posed by sophisticated social engineering tactics employed by cybercriminal groups like Scattered Spider. Organizations must remain vigilant against such methods, as the group's activities have led to significant financial losses and operational disruptions across multiple sectors. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/fbi-shares-tactics-of-notorious-scattered-spider-hacker-collective/?utm_source=openai))
3 months ago
Kill Chain
WhatsApp Metadata Leak Raises Privacy Concerns
In early 2026, security researcher Tal Be'ery uncovered vulnerabilities in WhatsApp's multi-device encryption protocol that allowed attackers to infer user metadata, including device operating systems and online status, without user interaction. This flaw enabled potential adversaries to perform device fingerprinting, facilitating targeted malware attacks. Meta, WhatsApp's parent company, began rolling out fixes in January 2026 to address these issues, but challenges in fully masking device signatures persist. ([darkreading.com](https://www.darkreading.com/endpoint-security/whatsapp-leaks-user-metadata?utm_source=openai)) This incident underscores the critical importance of securing metadata in encrypted communications. As messaging platforms expand their features, ensuring comprehensive privacy protections becomes increasingly complex, highlighting the need for continuous security assessments and prompt remediation of identified vulnerabilities.
3 months ago
Kill Chain
GreyNoise Uncovers Early Indicators of Edge Device Vulnerabilities
In early 2026, GreyNoise Intelligence identified a pattern where spikes in network traffic targeting specific vendors' edge devices often preceded public vulnerability disclosures. Over a 103-day study, 50% of these traffic surges were followed by a vulnerability disclosure from the same vendor within three weeks, with a median lead time of nine days. This suggests that attackers conduct reconnaissance on edge devices before exploiting newly discovered vulnerabilities, providing a potential early-warning system for defenders. ([cyberscoop.com](https://cyberscoop.com/greynoise-traffic-surge-early-warning-system-network-edge-device-vulnerabilities/?utm_source=openai)) This finding underscores the critical need for organizations to monitor unusual network activity as a proactive measure. By detecting these reconnaissance patterns, security teams can implement mitigations ahead of public vulnerability disclosures, reducing the window of exposure to potential attacks.
3 months ago
Kill Chain
Apple Account Change Alerts Abused in Sophisticated Phishing Scheme
In April 2026, cybercriminals exploited Apple's account change notification system to distribute phishing emails that appeared to originate from Apple's legitimate servers. These emails falsely informed recipients of an $899 iPhone purchase via PayPal and provided a phone number to cancel the transaction. The attackers manipulated the account's personal information fields to embed the phishing message, leading to the dispatch of authentic-looking emails from Apple. This tactic increased the credibility of the scam and enhanced its chances of bypassing spam filters. Victims who called the provided number were at risk of being deceived into installing remote access software or divulging sensitive financial information, potentially resulting in financial theft or data breaches. This incident underscores the evolving sophistication of phishing attacks, where threat actors leverage legitimate system features to enhance the authenticity of their scams. Organizations and individuals must remain vigilant against such tactics, as similar methods have been observed in other platforms, including Microsoft Azure Monitor alerts being abused for callback phishing attacks.
3 months ago
Kill Chain
Critical Protobuf.js Vulnerability Exposes Systems to Remote Code Execution
In April 2026, a critical remote code execution (RCE) vulnerability was discovered in protobuf.js, a widely used JavaScript implementation of Google's Protocol Buffers. The flaw, identified as GHSA-xq3m-2v4x-88gg, arises from unsafe dynamic code generation within the library, allowing attackers to inject and execute arbitrary JavaScript code by supplying malicious schemas. This vulnerability affects versions 8.0.0/7.5.4 and lower, potentially enabling unauthorized access to environment variables, credentials, databases, and internal systems, and facilitating lateral movement within infrastructures. The release of proof-of-concept exploit code underscores the urgency for organizations to address this issue promptly. Given the extensive use of protobuf.js in inter-service communication and real-time applications, the potential for widespread exploitation is significant.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports