✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Nexcorium Botnet's Exploitation of CVE-2024-3721 in TBK DVRs
In April 2026, cybersecurity researchers identified a new variant of the Mirai botnet, named Nexcorium, actively exploiting CVE-2024-3721—a command injection vulnerability in TBK DVR-4104 and DVR-4216 devices. By sending specially crafted HTTP POST requests to the vulnerable endpoint, attackers gained remote control over these devices, integrating them into a botnet used for large-scale Distributed Denial-of-Service (DDoS) attacks. The campaign, attributed to a group known as 'Nexus Team,' highlights the persistent threat posed by unpatched IoT devices in critical environments. ([fortinet.com](https://www.fortinet.com/blog/threat-research/tracking-mirai-variant-nexcorium-a-vulnerability-driven-iot-botnet-campaign?utm_source=openai)) This incident underscores the ongoing risks associated with IoT vulnerabilities, particularly in devices that are often overlooked in security protocols. The exploitation of CVE-2024-3721 by Nexcorium serves as a stark reminder of the importance of timely patching and robust security measures to protect against evolving botnet threats.
3 months ago
Kill Chain
CISA Alerts on Active Exploitation of Apache ActiveMQ Vulnerability CVE-2026-34197
In April 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) identified active exploitation of a critical vulnerability in Apache ActiveMQ, designated as CVE-2026-34197. This flaw, present for 13 years, allows authenticated attackers to execute arbitrary code via the Jolokia JMX-HTTP bridge. The vulnerability was discovered by Horizon3 researcher Naveen Sunkavally using the Claude AI assistant and has been patched in ActiveMQ Classic versions 6.2.3 and 5.19.4. The exploitation of this long-standing vulnerability underscores the persistent risks associated with unpatched software and the importance of proactive vulnerability management. Organizations using Apache ActiveMQ are urged to update their systems promptly to mitigate potential threats.
3 months ago
Kill Chain
Operation PowerOFF Dismantles 53 DDoS-for-Hire Domains, Exposes 3 Million Criminal Accounts
In April 2026, an international law enforcement operation known as Operation PowerOFF targeted the DDoS-for-hire ecosystem across 21 countries. Authorities seized 53 domains, arrested four individuals, and identified over 75,000 users involved in launching DDoS attacks. The operation disrupted booter services and dismantled infrastructure, including servers and databases, that supported these illicit activities. ([cyberscoop.com](https://cyberscoop.com/ddos-for-hire-takedowns-operation-poweroff/?utm_source=openai)) This crackdown underscores the persistent threat posed by DDoS-for-hire services, which enable individuals with minimal technical expertise to launch significant cyberattacks. The operation highlights the necessity for continuous vigilance and international cooperation to combat evolving cyber threats. ([cyberscoop.com](https://cyberscoop.com/ddos-for-hire-takedowns-operation-poweroff/?utm_source=openai))
3 months ago
Kill Chain
Apache ActiveMQ CVE-2026-34197: Critical RCE Vulnerability Under Active Exploitation
In April 2026, a critical remote code execution (RCE) vulnerability, CVE-2026-34197, was identified in Apache ActiveMQ Classic. This flaw resides in the Jolokia JMX-HTTP bridge, which, due to an overly permissive default access policy, allows authenticated attackers to execute arbitrary code on the broker's JVM. Exploitation involves invoking specific MBeans operations with crafted discovery URIs that load malicious Spring XML configurations, leading to full system compromise. Affected versions include Apache ActiveMQ Broker before 5.19.4 and from 6.0.0 before 6.2.3. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-34197/?utm_source=openai)) The urgency to address this vulnerability is heightened by its addition to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. Organizations using affected versions should prioritize upgrading to patched releases and review access controls to mitigate potential threats. ([securityonline.info](https://securityonline.info/apache-activemq-rce-jolokia-cve-2026-34197/?utm_source=openai))
3 months ago
Kill Chain
North Korea's Sapphire Sleet Exploits ClickFix to Target macOS Users
In April 2026, the North Korean state-sponsored group Sapphire Sleet launched a sophisticated cyber campaign targeting macOS users. Utilizing the 'ClickFix' social engineering technique, attackers posed as recruiters on professional networking platforms, engaging victims with fake job offers. They directed targets to install a malicious 'Zoom SDK Update.scpt' file, which, when executed, initiated a multi-stage payload chain. This chain included credential harvesters, data stealers targeting wallets and keychains, and backdoors for persistence. Notably, the malware bypassed Apple's Transparency, Consent, and Control (TCC) security framework, allowing unauthorized actions without user prompts. The campaign resulted in significant data exfiltration and potential financial losses for affected individuals and organizations. ([darkreading.com](https://www.darkreading.com/application-security/north-korea-clickfix-target-macos-users-data/?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors in targeting macOS platforms, highlighting the need for heightened vigilance against social engineering attacks and the importance of robust endpoint security measures.
3 months ago
Kill Chain
Critical RCE Vulnerability in Apache ActiveMQ: CVE-2026-34197
In April 2026, a critical remote code execution (RCE) vulnerability, designated CVE-2026-34197, was identified in Apache ActiveMQ Classic. This flaw resides in the Jolokia JMX-HTTP bridge exposed at /api/jolokia/ on the web console. Due to an overly permissive default Jolokia access policy, authenticated attackers can invoke sensitive operations, such as BrokerService.addNetworkConnector(String), with crafted discovery URIs. This exploitation allows the loading of a remote Spring XML application context, leading to arbitrary code execution on the broker's JVM through methods like Runtime.exec(). The vulnerability affects Apache ActiveMQ Broker versions before 5.19.4 and from 6.0.0 before 6.2.3. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-34197/?utm_source=openai)) The discovery of this vulnerability underscores the importance of rigorous input validation and access control in software components. Organizations utilizing affected versions of Apache ActiveMQ are urged to upgrade to version 5.19.5 or 6.2.3 to mitigate this risk. ([rapid7.com](https://www.rapid7.com/db/vulnerabilities/apache-activemq-cve-2026-34197/?utm_source=openai))
3 months ago
Kill Chain
Operation PowerOFF 2026: A Major Blow to DDoS-for-Hire Services
In April 2026, a coordinated international law enforcement effort known as Operation PowerOFF led to the seizure of 53 domains associated with DDoS-for-hire services and the arrest of four individuals allegedly involved in these operations. Authorities from 21 countries, including the United States, United Kingdom, and Germany, dismantled infrastructure supporting these services, which had been utilized by over 75,000 cybercriminals to launch distributed denial-of-service (DDoS) attacks. The operation also resulted in the identification of more than 3 million user accounts linked to these illegal activities. ([cyberscoop.com](https://cyberscoop.com/ddos-for-hire-takedowns-operation-poweroff/?utm_source=openai)) This crackdown underscores the persistent threat posed by DDoS-for-hire services, which enable individuals with minimal technical expertise to disrupt online services across various sectors. The operation highlights the necessity for organizations to bolster their cybersecurity defenses against such attacks and the importance of international collaboration in combating cybercrime.
3 months ago
Kill Chain
Operation PowerOFF 2026: A Landmark in Combating IoT Botnets
In March 2026, an international law enforcement operation known as Operation PowerOFF successfully dismantled the command-and-control infrastructure of four major IoT botnets—Aisuru, KimWolf, JackSkid, and Mossad. These botnets had collectively infected over three million devices worldwide, including digital video recorders, web cameras, and WiFi routers, and were responsible for launching distributed denial-of-service (DDoS) attacks reaching up to 31.4 terabits per second, setting new records for attack scale and impact. The coordinated effort involved authorities from the United States, Canada, and Germany, leading to the seizure of multiple domains and virtual servers associated with these botnets. ([justice.gov](https://www.justice.gov/usao-ak/pr/authorities-disrupt-worlds-largest-iot-ddos-botnets-responsible-record-breaking-attacks?utm_source=openai)) This takedown underscores the escalating threat posed by IoT-based botnets and the critical need for robust cybersecurity measures. Despite this significant disruption, security experts caution that DDoS threats persist, emphasizing the importance of continued vigilance and proactive defense strategies to protect against evolving cyber threats. ([securityboulevard.com](https://securityboulevard.com/2026/03/doj-disrupts-botnets-but-ddos-threats-remain-security-pros-warn/?utm_source=openai))
3 months ago
Kill Chain
PowMix Botnet: A New Threat to Czech Organizations in 2025
In December 2025, Cisco Talos identified a new botnet named PowMix targeting the workforce in the Czech Republic. The attackers distributed malicious documents impersonating legitimate brands and regulatory frameworks to lure victims, particularly those in human resources, legal, and recruitment sectors. PowMix employs randomized command-and-control (C2) beaconing intervals and embeds encrypted heartbeat data into C2 URL paths that mimic legitimate REST API URLs, making detection challenging. Additionally, it can dynamically update its C2 domain within the botnet configuration file. Notably, PowMix shares tactical similarities with the earlier ZipLine campaign, including payload delivery mechanisms and misuse of cloud platforms like Heroku for C2 operations. ([blog.talosintelligence.com](https://blog.talosintelligence.com/powmix-botnet-targets-czech-workforce/?utm_source=openai)) This incident underscores the evolving sophistication of botnets, highlighting the need for organizations to enhance their cybersecurity measures. The use of randomized C2 intervals and legitimate-looking URLs indicates a trend towards more evasive malware, emphasizing the importance of advanced detection techniques and continuous monitoring to mitigate such threats.
3 months ago
Kill Chain
Mirax Android RAT: A New Era of Mobile Malware Threats
In April 2026, a sophisticated Android remote access trojan (RAT) named Mirax was identified targeting Spanish-speaking countries. Distributed through Meta advertisements, Mirax infected over 220,000 devices by masquerading as legitimate streaming applications. Once installed, it granted attackers full control over compromised devices, enabling real-time interaction, keystroke logging, and the deployment of dynamic overlays to steal sensitive information. Notably, Mirax transformed infected devices into residential proxy nodes using the SOCKS5 protocol, allowing cybercriminals to route malicious traffic through victims' IP addresses, thereby evading detection systems and facilitating fraudulent activities. This incident underscores a concerning evolution in mobile malware, where traditional RAT functionalities are augmented with proxy capabilities, expanding the operational scope of cybercriminals. The use of social media platforms for widespread distribution highlights the need for enhanced vigilance and security measures among users and organizations to mitigate such threats.
3 months ago
Kill Chain
Oracle WebLogic Server 2026 Authentication Bypass Vulnerability: What You Need to Know
In January 2026, a critical vulnerability (CVE-2026-21962) was identified in Oracle's WebLogic Server Proxy Plug-in, affecting versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. This flaw allows unauthenticated attackers with network access via HTTP to bypass authentication mechanisms, potentially leading to unauthorized access and modification of critical data. The vulnerability has a CVSS score of 10.0, indicating its severity and the urgency for remediation. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-21962?utm_source=openai)) The exploitation of this vulnerability underscores the increasing sophistication of cyber threats targeting middleware components. Organizations relying on Oracle's WebLogic Server are urged to apply the latest patches promptly to mitigate potential risks associated with this authentication bypass flaw.
3 months ago
Kill Chain
Fiber Optic Cables: The New Frontier in Covert Eavesdropping
In April 2026, researchers from The Hong Kong Polytechnic University, The Chinese University of Hong Kong, and the Technological and Higher Education Institute of Hong Kong unveiled a novel side-channel attack that transforms standard fiber optic internet cables into covert listening devices. Presented at the Network and Distributed System Security (NDSS) Symposium 2026, the study demonstrated that by exploiting the physical properties of fiber optic cables, attackers can capture and reconstruct ambient sounds without the need for traditional microphones. This method leverages the cables' sensitivity to acoustic vibrations, enabling unauthorized eavesdropping on private conversations. ([cryptika.com](https://www.cryptika.com/fiber-optic-cables-turned-into-hidden-microphones-to-secretly-spy-on-your-conversations/?utm_source=openai)) The significance of this discovery lies in its potential to compromise the confidentiality of communications transmitted over fiber optic networks. As these cables are widely used in telecommunications infrastructure, the attack underscores the need for enhanced security measures to protect against such unconventional eavesdropping techniques. Organizations must reassess the physical security of their network components and consider implementing countermeasures to mitigate the risk of acoustic side-channel attacks.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports