✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Texas Sues TP-Link Over Chinese Hacking Risks
In February 2026, the Texas Attorney General filed a lawsuit against TP-Link Systems Inc., alleging deceptive marketing practices and security vulnerabilities in their networking devices. The suit claims that TP-Link misled consumers by labeling products as 'Made in Vietnam' while sourcing components from China, potentially exposing users to Chinese state-sponsored cyberattacks. The lawsuit highlights instances where TP-Link routers were exploited by Chinese hacking groups, such as the Quad7 botnet, to conduct credential-theft operations targeting U.S. entities. This legal action underscores the growing concern over supply chain security and the integrity of networking equipment used by consumers and businesses. As cyber threats evolve, ensuring transparency in product sourcing and robust security measures in networking devices becomes increasingly critical to protect against state-sponsored cyber espionage and attacks.
5 months ago
Kill Chain
Massiv Android Trojan Exploits IPTV Apps for Device Takeover Attacks in 2026
In early 2026, cybersecurity researchers identified a new Android trojan named Massiv, which masquerades as IPTV applications to infiltrate devices. Once installed, Massiv enables attackers to remotely control infected devices, facilitating device takeover attacks that lead to unauthorized financial transactions from victims' banking accounts. The malware employs techniques such as screen streaming, keylogging, SMS interception, and fake overlays to steal sensitive information. Notably, it has targeted applications like Portugal's gov.pt, exploiting digital identity systems to bypass Know Your Customer (KYC) verifications and open fraudulent accounts in victims' names. This incident underscores the evolving tactics of cybercriminals who exploit popular app themes to distribute malware, highlighting the need for heightened vigilance among mobile banking users. The use of IPTV app disguises reflects a broader trend of leveraging entertainment-related applications to deceive users, emphasizing the importance of downloading apps only from trusted sources and maintaining robust security practices.
5 months ago
Kill Chain
PromptSpy: AI-Enhanced Android Malware Redefines Mobile Threats
In February 2026, cybersecurity researchers identified PromptSpy, the first known Android malware to exploit Google's Gemini AI for persistence. Disguised as a banking app targeting users in Argentina, PromptSpy uses Gemini to analyze on-screen elements and execute gestures that keep it active in the device's recent apps list, preventing easy termination. Beyond persistence, it deploys a VNC module granting attackers remote access to the device, enabling actions like capturing lockscreen data, taking screenshots, and recording screen activity. The malware also employs Android's accessibility services to block uninstallation attempts by overlaying invisible elements on critical buttons. Distribution occurred through dedicated phishing websites impersonating JPMorgan Chase Bank, with evidence suggesting development in a Chinese-speaking environment. ([eset.com](https://www.eset.com/us/about/newsroom/research/eset-research-discovers-promptspy-first-android-threat-using-genai/?utm_source=openai)) This incident underscores the evolving threat landscape where adversaries integrate generative AI into malware, enhancing adaptability across various devices and operating system versions. The use of AI in malware execution flows signifies a shift towards more dynamic and resilient attack methods, posing challenges for traditional detection and mitigation strategies. ([computerweekly.com](https://www.computerweekly.com/news/366639201/PromptSpy-Android-malware-may-exploit-Gemini-AI?utm_source=openai))
5 months ago
Kill Chain
Salt Typhoon 2026 Telecom Breach: A Wake-Up Call for Cybersecurity
In early 2026, the Chinese state-sponsored hacking group known as Salt Typhoon executed a sophisticated cyber espionage campaign targeting major telecommunications providers, including AT&T and Verizon. The attackers exploited vulnerabilities in network devices to gain unauthorized access, allowing them to intercept private communications and exfiltrate sensitive data over an extended period. This breach compromised the personal information of millions of users and raised significant concerns about the security of critical infrastructure. The incident underscores the escalating threat posed by nation-state actors to global telecommunications networks. Despite previous sanctions and heightened security measures, Salt Typhoon's continued success highlights the need for more robust defenses and international cooperation to protect against such advanced persistent threats.
5 months ago
Kill Chain
Critical Vulnerability in Grandstream VoIP Phones Exposes Networks to Attack
In February 2026, a critical vulnerability (CVE-2026-2329) was discovered in Grandstream's GXP1600 series VoIP phones, allowing unauthenticated remote code execution with root privileges. The flaw, present in the devices' web-based API service, could be exploited by sending specially crafted HTTP requests to the /cgi-bin/api.values.get endpoint, enabling attackers to intercept calls, extract credentials, and potentially pivot into internal networks. Grandstream released firmware version 1.0.7.81 to address this issue. This incident underscores the importance of securing VoIP infrastructure, especially as such devices are often overlooked in security assessments. The availability of exploit code and the widespread use of these devices make immediate patching and network segmentation critical to prevent potential breaches.
5 months ago
Kill Chain
Critical Vulnerability in Grandstream GXP1600 VoIP Phones: CVE-2026-2329
In February 2026, a critical vulnerability (CVE-2026-2329) was discovered in Grandstream's GXP1600 series VoIP phones, affecting models GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630. This unauthenticated stack-based buffer overflow in the HTTP API endpoint "/cgi-bin/api.values.get" allows remote attackers to execute arbitrary code with root privileges. Exploitation could lead to unauthorized access, interception of VoIP communications, and potential eavesdropping on sensitive conversations. ([rapid7.com](https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/?utm_source=openai)) The incident underscores the importance of promptly applying security patches and monitoring VoIP infrastructure for vulnerabilities. Organizations using these devices should update to firmware version 1.0.7.81 to mitigate the risk. ([rapid7.com](https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/?utm_source=openai))
5 months ago
Kill Chain
Keenadu Malware: A 2026 Android Supply Chain Attack
In early 2026, security researchers discovered 'Keenadu,' a sophisticated malware embedded within the firmware of various Android devices. This malware, introduced through a supply chain attack, integrates into the Android 'Zygote' process, allowing it to infect every application on the device. Once active, Keenadu grants attackers extensive control, enabling actions such as hijacking browser searches, committing ad fraud, and potentially accessing sensitive user data. The malware was found pre-installed on devices from multiple manufacturers, including the Alldocube iPlay 50 mini Pro tablet, and was also distributed through compromised applications on official app stores. As of February 2026, approximately 13,000 devices across countries like Russia, Japan, Germany, Brazil, and the Netherlands have been affected. ([darkreading.com](https://www.darkreading.com/mobile-security/supply-chain-attack-embeds-malware-android-devices?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting firmware, highlighting the need for rigorous security measures throughout the manufacturing and software development processes. The ability of Keenadu to operate at the firmware level makes detection and removal particularly challenging, emphasizing the importance of proactive security practices and the use of trusted devices and software sources.
5 months ago
Kill Chain
UNC3886's 2025 Cyber Attack on Singapore's Telecom Sector
In July 2025, Singapore's four major telecommunications providers—Singtel, StarHub, M1, and SIMBA Telecom—were targeted by the Chinese state-sponsored cyber espionage group UNC3886. The attackers employed sophisticated techniques, including rootkits and zero-day exploits in firewalls, to gain unauthorized access to parts of the telecom networks. Despite these efforts, the intrusion did not disrupt services or result in the exfiltration of sensitive customer data. The Singaporean government, in collaboration with the affected telcos, launched Operation Cyber Guardian, a coordinated response involving over 100 personnel from various agencies, to contain and mitigate the threat. ([channelnewsasia.com](https://www.channelnewsasia.com/singapore/unc3886-cyberattack-targets-singapore-telcos-threat-contained-5916906?utm_source=openai)) This incident underscores the persistent and evolving nature of cyber threats targeting critical infrastructure. The use of advanced tools and tactics by UNC3886 highlights the need for continuous vigilance and robust cybersecurity measures within the telecommunications sector to safeguard against potential future attacks.
5 months ago
Kill Chain
Critical Vulnerability in Cryptographic Libraries Exposes Sensitive Data
In February 2026, a critical vulnerability was identified in widely-used JavaScript and Python cryptographic libraries, aes-js and pyaes, respectively. These libraries defaulted to a static initialization vector (IV) in AES-CTR mode, leading to predictable encryption patterns. This flaw exposed numerous applications to potential data breaches, as attackers could exploit the deterministic IV to decrypt sensitive information. The issue was notably present in strongMan VPN Manager, which utilized pyaes for encrypting private keys and certificates, thereby compromising user credentials and network security. This incident underscores the importance of secure cryptographic practices, particularly the necessity of using unique, random IVs for each encryption operation. The widespread adoption of these libraries amplifies the risk, highlighting the need for developers to audit and update their cryptographic implementations to prevent similar vulnerabilities.
5 months ago
Kill Chain
AI Discovers Critical OpenSSL Vulnerabilities in 2026
In January 2026, the AI-assisted cybersecurity firm Aisle identified twelve previously undisclosed vulnerabilities in OpenSSL, a widely used cryptographic library essential for secure internet communications. These vulnerabilities, some dating back to 1998, included critical issues like CVE-2025-15467, a stack buffer overflow in CMS message parsing that could lead to remote code execution. OpenSSL rated this vulnerability as HIGH severity, with a CVSS v3 score of 9.8 out of 10. The discovery underscores the potential of AI in enhancing cybersecurity measures by identifying complex vulnerabilities that have eluded traditional detection methods. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/ai-assisted-cybersecurity-team-discovers-12-openssl-vulnerabilities-claims-humans-are-the-limiting-factor-some-vulnerabilities-have-been-around-for-decades?utm_source=openai)) The findings highlight the evolving landscape of cybersecurity, where AI tools are becoming instrumental in proactively identifying and mitigating risks. This shift emphasizes the need for organizations to integrate AI-driven solutions into their security protocols to stay ahead of sophisticated cyber threats.
5 months ago
Kill Chain
Keenadu Backdoor: A Deep Dive into the 2026 Android Firmware Compromise
In February 2026, Kaspersky researchers uncovered a firmware-level backdoor named Keenadu embedded in Android tablets from multiple manufacturers, including Alldocube. This malware, integrated during the firmware build process, injects itself into the Zygote process, granting attackers extensive control over the device. Keenadu enables remote execution of malicious payloads, such as hijacking browser searches, monetizing app installations, and interacting with advertising elements. The backdoor has been detected in firmware dating back to August 2023, affecting over 13,700 users worldwide, with significant concentrations in Russia, Japan, Germany, Brazil, and the Netherlands. The discovery of Keenadu underscores the escalating threat of supply chain attacks targeting device firmware. This incident highlights the critical need for manufacturers to secure their development processes and for consumers to remain vigilant about device integrity. The integration of malware at such a fundamental level poses significant challenges for detection and removal, emphasizing the importance of robust security measures throughout the supply chain.
5 months ago
Kill Chain
DKnife: The Linux Toolkit Hijacking Router Traffic for Espionage
In February 2026, cybersecurity researchers uncovered 'DKnife,' a sophisticated Linux-based toolkit active since 2019, designed to hijack router traffic for espionage and malware delivery. DKnife comprises seven modules enabling deep packet inspection, traffic manipulation, credential harvesting, and malware deployment, including the ShadowPad and DarkNimbus backdoors. The toolkit specifically targets Chinese services and exhibits Simplified Chinese language artifacts, indicating a China-nexus threat actor. DKnife's capabilities include DNS hijacking, intercepting Android app updates, and monitoring user activities on platforms like WeChat and Signal. As of January 2026, its command-and-control servers remain active. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/dknife-linux-toolkit-hijacks-router-traffic-to-spy-deliver-malware/?utm_source=openai))
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports