The Containment Era is here. →Explore

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

748 threat reports
Page 26 of 63

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Telecommunications Threat Reports

Showing 301312 / 748 reports
Silver Fox's 2026 AtlasCross RAT Campaign Exploits Trusted Software Brands
Impact· HIGH

Silver Fox's 2026 AtlasCross RAT Campaign Exploits Trusted Software Brands

In March 2026, the Chinese state-sponsored threat actor Silver Fox, also known as Void Arachne, launched a sophisticated cyber campaign targeting Chinese-speaking users. The attackers employed typosquatted domains that impersonated trusted software brands, including Surfshark, Signal, and Zoom, to distribute a previously undocumented remote access trojan (RAT) named AtlasCross. By leveraging stolen Extended Validation (EV) code-signing certificates, Silver Fox was able to bypass security checks and establish deep persistence within enterprise networks. The campaign utilized polished landing pages that mimicked legitimate application vendors, leading victims to download malicious installers. These installers deployed trojanized components alongside legitimate decoy applications, effectively evading detection mechanisms. The AtlasCross RAT, central to this operation, featured a custom PowerShell execution engine named PowerChell, which disabled host defenses and maintained encrypted communication with command-and-control servers. This campaign underscores the evolving tactics of threat actors in exploiting trusted software brands and advanced evasion techniques to infiltrate target systems. Organizations are advised to enhance their security posture by verifying software sources, monitoring for typosquatted domains, and implementing robust endpoint detection and response solutions to mitigate such sophisticated threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Operation TrueChaos: Exploiting Trust in Software Updates
Impact· HIGH

Operation TrueChaos: Exploiting Trust in Software Updates

In early 2026, a sophisticated cyber espionage campaign, dubbed Operation TrueChaos, targeted government entities in Southeast Asia by exploiting a zero-day vulnerability (CVE-2026-3502) in the TrueConf video conferencing software. Attackers compromised the software's update mechanism, allowing them to distribute malicious updates that facilitated malware deployment across multiple agencies. This method enabled the attackers to bypass traditional security measures, leading to unauthorized access and potential data exfiltration. This incident underscores a growing trend where threat actors exploit trusted software supply chains to infiltrate secure environments. Organizations must reassess and fortify their internal trust mechanisms, especially concerning software updates, to mitigate such sophisticated attack vectors.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical RCE Vulnerability in F5 BIG-IP APM: Immediate Action Required
Impact· CRITICAL

Critical RCE Vulnerability in F5 BIG-IP APM: Immediate Action Required

In October 2025, F5 disclosed CVE-2025-53521, initially identified as a high-severity denial-of-service (DoS) vulnerability in its BIG-IP Access Policy Manager (APM). However, in March 2026, the vulnerability was reclassified as a critical remote code execution (RCE) flaw with a CVSS score of 9.8, following new information and active exploitation in the wild. Attackers can exploit this vulnerability by sending specific malicious traffic to virtual servers configured with BIG-IP APM, potentially leading to full system compromise. Affected versions include 17.5.0 to 17.5.1, 17.1.0 to 17.1.2, 16.1.0 to 16.1.6, and 15.1.0 to 15.1.10. F5 has released patches and urges customers to upgrade to fixed versions immediately. ([darkreading.com](https://www.darkreading.com/application-security/fortinet-big-ip-vulnerability-reclassified-rce-exploitation/?utm_source=openai)) The reclassification and active exploitation of CVE-2025-53521 underscore the evolving nature of cybersecurity threats and the importance of continuous monitoring and timely patching. Organizations using F5 BIG-IP APM should assess their systems for indicators of compromise and apply the necessary updates to mitigate potential risks. ([darkreading.com](https://www.darkreading.com/application-security/fortinet-big-ip-vulnerability-reclassified-rce-exploitation/?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in Citrix NetScaler: CVE-2026-3055 Memory Overread
Impact· CRITICAL

Critical Vulnerability in Citrix NetScaler: CVE-2026-3055 Memory Overread

In March 2026, Citrix disclosed a critical vulnerability (CVE-2026-3055) in its NetScaler ADC and NetScaler Gateway products. This out-of-bounds read flaw allows unauthenticated remote attackers to access sensitive information from the appliance's memory when configured as a SAML Identity Provider (IdP). Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-66.59, and 13.1 before 13.1-62.23. Citrix has released patches to address this issue, and organizations are urged to update their systems promptly to mitigate potential risks. ([censys.com](https://censys.com/advisory/cve-2026-3055/?utm_source=openai)) The disclosure of CVE-2026-3055 underscores the ongoing threat posed by vulnerabilities in widely used network appliances. Similar past vulnerabilities, such as CVE-2023-4966 ("CitrixBleed"), have been rapidly exploited in the wild, highlighting the importance of timely patching and vigilant system configuration reviews to prevent unauthorized access and data breaches. ([cycognito.com](https://www.cycognito.com/blog/citrix-netscaler-adc-and-gateway-vulnerabilities-cve-2026-3055-cve-2026-4368/?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Critical Fortinet FortiClientEMS Vulnerability Exploited in the Wild
Impact· CRITICAL

Critical Fortinet FortiClientEMS Vulnerability Exploited in the Wild

In February 2026, a critical SQL injection vulnerability, CVE-2026-21643, was identified in Fortinet's FortiClientEMS version 7.4.4. This flaw allows unauthenticated attackers to execute arbitrary code via specially crafted HTTP requests, potentially leading to full system compromise. Fortinet released a patch in version 7.4.5 to address this issue. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-21643/?utm_source=openai)) As of March 2026, reports indicate active exploitation of this vulnerability in the wild, underscoring the urgency for organizations to apply the available patch promptly.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical Zero-Click Vulnerability Reported in Telegram Messenger
Impact· HIGH

Critical Zero-Click Vulnerability Reported in Telegram Messenger

In March 2026, a critical zero-click vulnerability was reported in Telegram Messenger, potentially affecting approximately 1 billion users. Discovered by researcher Michael DePlante of the Trend Micro Zero Day Initiative (ZDI), the flaw, designated as ZDI-CAN-30207, allows remote code execution on Android and Linux versions of the app through the reception of a corrupted animated sticker. This vulnerability could enable attackers to access private communications, conduct surveillance, steal sensitive data, and disrupt device functionality. Telegram has publicly denied the existence of this flaw, asserting that all stickers are validated by its servers before being played by the app. ([darkreading.com](https://www.darkreading.com/application-security/storm-brews-critical-no-click-telegram-flaw?utm_source=openai)) The controversy surrounding this vulnerability underscores the ongoing challenges in securing widely-used communication platforms. As messaging apps become integral to personal and professional communication, ensuring their security against sophisticated attack vectors remains paramount. This incident highlights the need for continuous vigilance and prompt response to potential threats in the digital communication landscape.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Critical Denial of Service Vulnerability in F5 BIG-IP APM: CVE-2025-53521
Impact· CRITICAL

Critical Denial of Service Vulnerability in F5 BIG-IP APM: CVE-2025-53521

In October 2025, a critical vulnerability identified as CVE-2025-53521 was discovered in F5 BIG-IP Access Policy Manager (APM). This flaw allows unauthenticated attackers to remotely trigger a denial of service (DoS) by sending specially crafted traffic to a virtual server configured with an APM access policy. Exploitation results in the termination and restart of the Traffic Management Microkernel (TMM) process, causing temporary disruption of all traffic handled by the BIG-IP device. Affected versions include BIG-IP APM 17.5.0 through 17.5.1, 17.1.0 through 17.1.2, 16.1.0 through 16.1.5, and 15.1.0 through 15.1.10. F5 has released patches in versions 17.5.1.3, 17.1.3, 16.1.6.1, and 15.1.10.8 to address this issue. The inclusion of CVE-2025-53521 in CISA's Known Exploited Vulnerabilities (KEV) catalog underscores the active exploitation of this vulnerability in the wild. Organizations utilizing affected versions of F5 BIG-IP APM are urged to apply the recommended patches promptly to mitigate potential service disruptions and maintain the integrity of their network infrastructure.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
TA446's Deployment of DarkSword iOS Exploit Kit in 2026
Impact· HIGH

TA446's Deployment of DarkSword iOS Exploit Kit in 2026

In March 2026, the Russian state-sponsored threat group TA446, also known as Callisto Group, SEABORGIUM, and COLDRIVER, launched a targeted spear-phishing campaign deploying the DarkSword iOS exploit kit. This sophisticated exploit chain targeted iPhones running iOS versions 18.4 through 18.7, enabling full device compromise and exfiltration of sensitive data, including credentials and cryptocurrency wallets. The campaign primarily targeted individuals and organizations in Ukraine, aligning with Russian strategic interests. ([thehackernews.com](https://thehackernews.com/2026/03/darksword-ios-exploit-kit-uses-6-flaws.html?utm_source=openai)) The public release of the DarkSword exploit kit has significantly increased the risk to iOS users worldwide. Multiple threat actors, including commercial spyware vendors and other state-sponsored groups, have adopted the exploit, leading to a surge in attacks. This incident underscores the critical importance of timely software updates and robust cybersecurity measures to protect against rapidly evolving threats. ([lookout.com](https://www.lookout.com/news-release/lookout-uncovers-darksword-ios-exploit-chain?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(low)
Read Report
F5 BIG-IP 2025 Remote Code Execution Vulnerability
Impact· CRITICAL

F5 BIG-IP 2025 Remote Code Execution Vulnerability

In October 2025, a critical vulnerability identified as CVE-2025-53521 was discovered in F5 Networks' BIG-IP Access Policy Manager (APM). This flaw allows specific, undisclosed traffic to cause the Traffic Management Microkernel (TMM) to terminate unexpectedly, leading to a denial-of-service (DoS) condition. The vulnerability affects multiple versions of BIG-IP, including 17.5.0, 17.1.0, 16.1.0, and 15.1.0, and has been assigned a CVSS v3.1 score of 7.5, indicating high severity. ([wiz.io](https://www.wiz.io/vulnerability-database/cve/cve-2025-53521?utm_source=openai)) The exploitation of this vulnerability can disrupt critical services relying on BIG-IP systems, posing significant risks to organizations. Given the widespread deployment of BIG-IP devices in enterprise environments, timely remediation is essential to prevent potential service outages and maintain operational continuity.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Telnyx PyPI Supply Chain Attack: A 2026 Case Study
Impact· HIGH

Telnyx PyPI Supply Chain Attack: A 2026 Case Study

In March 2026, the Telnyx Python package on the Python Package Index (PyPI) was compromised by the threat actor TeamPCP. Malicious versions 4.87.1 and 4.87.2 were uploaded, embedding malware that exfiltrated sensitive data such as SSH keys, cloud tokens, and cryptocurrency wallets. The attack utilized steganography, hiding the payload within WAV audio files, and affected both Linux/macOS and Windows systems. This incident underscores the escalating threat of supply chain attacks targeting widely used open-source packages, emphasizing the need for enhanced security measures in software development pipelines.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Bearlyfy's 2025 Ransomware Campaign Against Russian Companies
Impact· HIGH

Bearlyfy's 2025 Ransomware Campaign Against Russian Companies

In early 2025, the pro-Ukrainian cyber group Bearlyfy initiated a series of over 70 ransomware attacks targeting Russian companies. Employing custom strains like GenieLocker, Bearlyfy exploited vulnerabilities in public-facing applications to gain initial access, subsequently encrypting critical data and demanding ransoms. The group's operations have caused significant disruptions across various sectors in Russia. This incident underscores a growing trend of politically motivated cyberattacks, where hacktivist groups leverage ransomware to inflict economic damage. The Bearlyfy attacks highlight the evolving landscape of cyber threats, emphasizing the need for robust security measures to protect against both financially and ideologically driven adversaries.

4 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Coruna Exploit Kit: A Case Study in the Commercialization of Nation-State Cyber Tools
Impact· HIGH

Coruna Exploit Kit: A Case Study in the Commercialization of Nation-State Cyber Tools

In February 2025, Google's Threat Intelligence Group (GTIG) identified 'Coruna,' a sophisticated iOS exploit kit comprising 23 vulnerabilities across five exploit chains, targeting devices running iOS 13 through 17.2.1. Initially deployed by a surveillance vendor for government clients, Coruna was later utilized by Russian state actors in espionage campaigns against Ukrainian users. By December 2025, the exploit kit had proliferated to financially motivated Chinese cybercriminals, who employed it to steal cryptocurrency from over 42,000 iOS devices via malicious websites. This rapid transition from state-sponsored espionage to widespread financial crime underscores the growing commercialization and accessibility of nation-state-level cyber tools. The Coruna incident highlights the urgent need for organizations to stay vigilant against advanced threats, as sophisticated exploit kits once exclusive to government entities are increasingly available to cybercriminals, posing significant risks to both individuals and enterprises.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports