✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Fortinet's 2026 Authentication Bypass Vulnerability: A Critical Security Alert
In January 2026, Fortinet disclosed a critical authentication bypass vulnerability (CVE-2026-24858) affecting multiple products, including FortiOS, FortiManager, FortiAnalyzer, FortiProxy, and FortiWeb. This flaw allowed attackers with a FortiCloud account and a registered device to gain unauthorized access to other devices registered to different accounts, provided FortiCloud SSO authentication was enabled. Exploitation of this vulnerability led to unauthorized firewall configuration changes, creation of rogue administrator accounts, and potential data exfiltration. Fortinet responded by disabling FortiCloud SSO on January 26, 2026, and subsequently released patches to address the issue. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, urging immediate remediation. This incident underscores the critical importance of timely patch management and vigilant monitoring of authentication mechanisms to prevent unauthorized access and potential data breaches.
5 months ago
Kill Chain
Critical Vulnerability in KiloView Encoder Series: Unauthenticated Admin Account Takeover
In January 2026, a critical vulnerability (CVE-2026-1453) was identified in KiloView Encoder Series devices, allowing unauthenticated attackers to create or delete administrator accounts, thereby gaining full administrative control. This flaw, stemming from missing authentication checks on critical functions, affects multiple versions across the E1, E1-s, E2, G1, P1, P2, and RE1 hardware series. The vulnerability has a CVSS score of 9.8, indicating its severity. ([thehackerwire.com](https://www.thehackerwire.com/vulnerability/CVE-2026-1453/?utm_source=openai)) The absence of authentication mechanisms in these devices underscores the importance of implementing robust security measures in critical infrastructure components. Organizations utilizing KiloView Encoder Series devices should prioritize immediate mitigation strategies to prevent potential exploitation. ([isssource.com](https://www.isssource.com/no-fix-for-kiloview-encoder-series/?utm_source=openai))
5 months ago
Kill Chain
Google's 2026 Disruption of IPIDEA Proxy Network
In January 2026, Google’s Threat Intelligence Group (GTIG) disrupted IPIDEA, a China-based residential proxy network that covertly enrolled millions of consumer devices into its infrastructure. By embedding malicious software development kits (SDKs) into various applications, IPIDEA transformed devices into proxy nodes without user consent, facilitating cybercriminal activities such as password spraying and unauthorized access to cloud environments. Google’s intervention, which included legal actions to seize control domains and collaboration with partners like Cloudflare and Lumen’s Black Lotus Labs, resulted in a significant reduction of IPIDEA’s operational capacity, removing millions of devices from the network. ([blog.google](https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/gtig-ipidea-disrupted/?utm_source=openai)) This incident underscores the escalating misuse of residential proxy networks by cybercriminals and state-sponsored actors. The proliferation of such networks highlights the urgent need for enhanced vigilance among developers and consumers regarding the integration and use of third-party SDKs, as well as the importance of industry-wide collaboration to dismantle malicious infrastructures.
5 months ago
Kill Chain
UAT-8099's Exploitation of IIS Servers in Asia Using BadIIS Malware
Between late 2025 and early 2026, the China-linked threat actor UAT-8099 launched a campaign targeting vulnerable Internet Information Services (IIS) servers across Asia, with a particular focus on Thailand and Vietnam. The attackers exploited security vulnerabilities to gain initial access, deploying web shells and leveraging tools like GotoHTTP for remote control. They installed customized variants of the BadIIS malware to manipulate search engine optimization (SEO) rankings, redirecting users to malicious sites and exfiltrating sensitive data. This operation underscores the evolving tactics of cybercriminals in exploiting web server vulnerabilities for financial gain and data theft. Organizations are urged to strengthen their server defenses and monitor for signs of such sophisticated intrusions. ([thehackernews.com](https://thehackernews.com/2026/01/china-linked-uat-8099-targets-iis.html?utm_source=openai))
5 months ago
Kill Chain
Chinese APTs Target ASEAN Entities with Advanced Malware
In early 2024, Chinese state-sponsored Advanced Persistent Threat (APT) groups, notably Stately Taurus (also known as Mustang Panda), launched sophisticated cyber-espionage campaigns targeting entities across ASEAN countries, including Myanmar, the Philippines, Japan, and Singapore. These operations coincided with the ASEAN-Australia Special Summit in March 2024, suggesting a strategic intent to gather intelligence during significant diplomatic events. The attackers employed advanced malware packages, such as PUBLOAD downloader, delivered through phishing emails containing malicious ZIP archives and screensaver executables. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/chinese-apts-target-asean-entities/?utm_source=openai)) This incident underscores the escalating cyber threats posed by state-sponsored actors in the Asia-Pacific region. The use of sophisticated malware and targeted phishing campaigns highlights the need for heightened cybersecurity measures, especially during high-profile events that may attract espionage activities.
5 months ago
Kill Chain
Salt Typhoon's 2024 Breach of U.S. Telecom Networks: A Wake-Up Call for Cybersecurity
In 2024, the Chinese state-sponsored hacking group known as Salt Typhoon orchestrated a sophisticated cyber espionage campaign targeting major U.S. telecommunications companies, including AT&T, Verizon, and T-Mobile. By exploiting vulnerabilities in network devices and systems, the group gained unauthorized access to sensitive data such as call logs, text messages, and, in some instances, audio recordings. Notably, they infiltrated systems used for lawful wiretapping, posing significant national security concerns. The attackers employed advanced techniques, including 'living off the land' tactics, utilizing legitimate administrative tools to evade detection and maintain persistent access. This incident underscores the escalating threat posed by state-sponsored cyber actors to critical infrastructure. The breach highlights the necessity for robust cybersecurity measures and continuous monitoring to detect and mitigate such sophisticated intrusions. Organizations must prioritize the security of their network devices and systems to prevent similar attacks in the future.
5 months ago
Kill Chain
2024 Critical Telnet Flaw: How Legacy Protocols Created a Global Attack Surface
In early 2024, security researchers uncovered a critical vulnerability affecting widely used Telnet server software running on hundreds of thousands of legacy and IoT devices worldwide. Attackers exploited the bug, which allowed unauthenticated remote access using unencrypted Telnet sessions, to compromise network and industrial systems, bypass access controls, and rapidly pivot laterally. Many affected devices remained unpatched due to lack of vendor support, making remediation difficult and exposing organizations in healthcare, manufacturing, and critical infrastructure to potential downtime and data theft. This incident highlights the enduring risk of forgotten, legacy protocols like Telnet persisting in enterprise environments. Attackers increasingly scan for and exploit such overlooked attack surfaces, emphasizing the need for proactive inventory, segmentation, and the retirement of obsolete network services to defend against emergent threats.
5 months ago
Kill Chain
China-Backed PeckBirdy APT Orchestrates Cross-Platform Attacks in 2024
In early 2024, the China-linked threat group dubbed 'PeckBirdy' orchestrated sophisticated cross-platform cyberattacks against Asian government entities and gambling platforms. Utilizing the JScript C2 framework, the attackers deployed new backdoors to penetrate both Windows and Linux systems, enabling remote command execution and persistent access. The dual-campaign approach demonstrated PeckBirdy's flexibility, targeting sectors with rich data and financial value. The initial compromise was achieved via spear-phishing emails and exploit delivery, followed by lateral movement to critical systems. Exfiltration of sensitive data and ongoing espionage activities resulted in operational disruptions and an increased risk of regulatory exposure for targeted organizations. This incident underscores the evolving nature of state-sponsored APT operations, notably the growing crossover between espionage and financially-motivated attacks. PeckBirdy's toolset and cross-platform reach reflect a trend where threat actors innovate rapidly, blending custom malware with proven C2 tactics, raising the stakes for defenders in Asia and beyond.
5 months ago
Kill Chain
Fake Dating App Used to Deliver Android Spyware in Pakistan
In early 2024, an Android spyware campaign was uncovered by ESET researchers targeting users in Pakistan via a fraudulent dating app masquerading as a legitimate platform. The attackers lured victims using romance scam tactics, convincing users to download the malicious app outside of trusted marketplaces. Once installed, the spyware harvested sensitive data including call logs, messages, and device information, forwarding it to remote command-and-control servers linked to an ongoing espionage operation. The threat actors exhibited targeted behavior, indicating a capability for victim profiling and data exfiltration on mobile devices. This incident underscores a broader cybersecurity trend: growing use of socially engineered lures and repurposed surveillance tooling in region-specific espionage. Mobile attack vectors are increasingly leveraged for targeted intelligence gathering, amplifying urgency for robust defenses and heightened awareness of app distribution risks.
5 months ago
Kill Chain
HoneyMyte 2025 Cyberespionage Hits: Updated CoolClient and Credential Theft Campaigns
Between 2024 and 2025, the advanced persistent threat group HoneyMyte (aka Mustang Panda, Bronze President) orchestrated advanced espionage campaigns targeting government entities across Southeast Asia, Mongolia, Malaysia, Myanmar, and Europe. Using updated CoolClient backdoors, custom browser credential stealers, and sophisticated prying scripts, HoneyMyte achieved persistent access, broad network infiltration, and the theft of sensitive documents, credentials, and operational intelligence. Attackers exploited signed DLL sideloading, launched post-exploitation scripts, and used public file-sharing services for covert exfiltration, successfully bypassing traditional defense layers and maintaining long-term surveillance on official targets. This incident highlights the evolving techniques of APT campaigns with growing reliance on multi-stage malware, encrypted traffic, and cloud-based exfiltration channels. The sophistication and persistence demonstrated by HoneyMyte reflect a broader rise in state-sponsored cyber espionage, posing continuing challenges for organizations' detection and regulatory compliance efforts in 2025.
6 months ago
Kill Chain
Mustang Panda’s CoolClient Infostealer: 2026 Global Espionage Campaign Unveiled
In January 2026, Chinese state-sponsored group Mustang Panda leveraged an updated version of its CoolClient backdoor to conduct targeted espionage campaigns against government organizations in Myanmar, Mongolia, Malaysia, Russia, and Pakistan. The attackers used legitimate Sangfor software for initial infection and subsequently deployed tailored infostealers that extracted login credentials from major browsers, monitored clipboard data, and profiled compromised systems. The operation featured advanced tactics such as DLL side-loading, remote shell plugins, encrypted multi-stage payloads, and the use of public cloud services (via hardcoded tokens) for stealthy data exfiltration. This breach highlights the rapid advancement and operational innovation among state-backed APT actors, particularly regarding infostealer deployment and C2 evasion using legitimate cloud infrastructure. Organizations in APAC, government, and critical infrastructure sectors remain top targets as attacker toolsets evolve to bypass both endpoint and network security controls.
6 months ago
Kill Chain
How 2024 Romance Scams Use WhatsApp Social Engineering: An Inside Look
In early 2024, security researchers investigated the initial phases of romance scams conducted over WhatsApp, where attackers use social engineering tactics to engage targets. Scammers made initial contact using 'wrong number' messages, then rapidly built rapport through flattering responses and fabricated personal stories. Over the span of several weeks, operators established credibility by sharing career details, transitioning conversations to new phone numbers, and sharing lifestyle photos to lay groundwork for future financial scams. The observed campaigns were early-stage but designed to emotionally manipulate victims for eventual financial exploitation. This incident spotlights the refined playbooks, multi-operator approaches, and psychological grooming now typical in romance scams. With surges in digital-first communication and persistent threat actor innovation, such social engineering exploits pose a significant and evolving risk to individuals and businesses alike.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports