✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Cisco Zero-Day Flaw Sparks Mass Exploitation of Unified Communications Platforms
In early June 2026, Cisco disclosed a critical zero-day vulnerability (CVE-2026-20045) impacting its Unified Communications (UC) suite, which quickly became the target of mass automated exploitation. Threat actors leveraged the flaw to gain remote code execution, potentially allowing them to fully compromise UC servers and pivot into broader enterprise networks. The scale of the vulnerability—affecting millions of devices worldwide—prompted urgent alerts from security agencies and rapid patching actions by global organizations. Successful intrusions could enable attackers to intercept sensitive communications, exfiltrate data, and disrupt business operations. This incident is especially notable as zero-day attacks against high-availability collaboration infrastructure have surged, reflecting a broader trend in targeting business-critical communication platforms. The Cisco exploitation underscores the speed at which adversaries now weaponize new flaws, and the risks posed to organizations lacking robust patch and segmentation defenses.
6 months ago
Kill Chain
Attackers Exploit GNU InetUtils Telnetd Flaw for Root Access in 2026
In January 2026, researchers discovered active exploitation of a critical eleven-year-old authentication bypass vulnerability (CVE-2026-24061) in the GNU InetUtils telnetd server, affecting versions 1.9.3 through 2.7. Attackers leveraged unsanitized environment variable handling to pass 'USER=-f root' via Telnet connections, trivially gaining root shell access without authentication. While identified exploitation was limited—18 unique IPs targeting 60 sessions over two days—many affected systems are legacy or embedded industrial and IoT devices, complicating patching or replacement and increasing exposure risk in Operational Technology (OT) environments. This incident highlights how long-standing vulnerabilities in rarely updated legacy software can be weaponized by both automated and hands-on attackers. The persistence of Telnet in OT, IoT, and embedded sectors, combined with publicly available exploits, underscores increased urgency for organizations to identify, mitigate, or segment such outdated services before broader exploitation occurs.
6 months ago
Kill Chain
SmarterMail Auth Bypass Allows Attackers to Reset Admin Accounts in Live Exploits
In January 2026, attackers began exploiting an authentication bypass vulnerability in SmarterTools’ SmarterMail email server platform, which enabled unauthenticated users to reset admin account passwords and seize full system control. The flaw, residing in a publicly-exposed API endpoint allowing forced resets with attacker-supplied JSON, let threat actors escalate privileges by resetting admin credentials, paving the way to remote code execution. The vulnerability was disclosed in early January, patched on January 15, and observed in active exploitation just days later as attackers reverse-engineered the fix to target unpatched servers globally. This incident draws attention to the criticality of prompt patch management and highlights the ongoing risk of API flaws being rapidly weaponized post-disclosure. It underscores a broader trend of attackers targeting authentication controls in business-critical SaaS and infrastructure applications, raising regulatory and operational pressure for stronger access security and rapid response procedures.
6 months ago
Kill Chain
Cisco Zero-Day Exploited: Critical Remote Code Execution in Unified Communications (2026)
In January 2026, Cisco disclosed and patched CVE-2026-20045, a critical zero-day vulnerability affecting Unified Communications Manager, Unity Connection, and Webex Calling Dedicated Instance platforms. The flaw, arising from improper validation of user-supplied input via HTTP requests, allowed unauthenticated attackers to execute arbitrary code and escalate privileges to root on impacted servers. Cisco’s Product Security Incident Response Team (PSIRT) confirmed in-the-wild exploitation prior to patch release and issued urgent guidance for customers to update, as no workarounds exist. The U.S. CISA swiftly added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating timely remediation for federal agencies. This incident highlights a broader trend of sophisticated zero-day attacks targeting enterprise communications infrastructure. As attackers increasingly focus on supply chain and collaboration platforms, organizations must maintain rapid patching practices and improve segmentation and detection mechanisms against privilege escalation and remote code execution threats.
6 months ago
Kill Chain
CVE-2026-20045: Active Code Injection Exploit Strikes Cisco Unified Communications
In January 2026, CISA added CVE-2026-20045 to its Known Exploited Vulnerabilities Catalog following reports of active exploitation targeting Cisco Unified Communications products. Attackers exploited a code injection vulnerability that allowed remote, unauthenticated threat actors to execute arbitrary code on affected devices, potentially compromising sensitive communications and opening access for further malicious activity within targeted federal civilian executive branch (FCEB) networks. This rapid addition of CVE-2026-20045 prompted urgent federal action to remediate impacted systems and reduce the risk of lateral movement and data exfiltration. The incident highlights a persistent threat vector facing organizations reliant on unified communications infrastructure. With attackers increasingly exploiting unpatched vulnerabilities and leveraging code injection to bypass security controls, the importance of timely patch management and network segmentation continues to grow amid tightening regulatory standards and intensifying audit scrutiny.
6 months ago
Kill Chain
Tudou Guarantee Shuts Down Telegram Transactions After $12B Crypto Fraud Wave
In January 2026, Tudou Guarantee Marketplace, a major Telegram-based platform known for facilitating illicit services and cryptocurrency fraud, halted its public Telegram transactions after processing over $12 billion in suspicious activity. This dramatic step followed the arrest of Chen Zhi, CEO of Prince Group, whose organization was linked to large-scale scam operations including forced labor, romance scams, and investment fraud. The sudden drop in wallet activity suggests a direct link to recent law enforcement action targeting Southeast Asian scam networks. This incident highlights the persistent risks of unregulated messaging platforms in enabling transnational cybercrime and the growing technological sophistication behind crypto-related fraud. With law enforcement crackdowns intensifying and marketplaces shifting tactics, organizations must update controls against social engineering, identity abuse, and crypto laundering.
6 months ago
Kill Chain
Ingram Micro 2025 Ransomware Breach: Over 42,000 Impacted in Supply Chain Attack
In July 2025, information technology distributor Ingram Micro experienced a significant ransomware attack that compromised its internal systems and resulted in the unauthorized access and potential theft of sensitive personal information for over 42,000 individuals. Attackers infiltrated the company’s network, deployed ransomware, and encrypted critical data, causing temporary disruption to business operations. Ingram Micro responded by shutting down affected systems, launching an investigation, and notifying impacted individuals, highlighting gaps in east-west traffic security and incident detection. This breach underscores the ongoing resurgence of ransomware attacks targeting supply chain companies and IT providers. With attackers refining lateral movement techniques, organizations face mounting pressure to adopt robust segmentation, real-time anomaly detection, and comprehensive data protection strategies in compliance with evolving regulatory expectations.
6 months ago
Kill Chain
UK Under Siege: NoName057(16) DDoS Attacks Target Critical Infrastructure in 2026
In January 2026, the UK's National Cyber Security Centre (NCSC) issued a warning about ongoing DDoS attacks targeting critical infrastructure and local government organizations across the United Kingdom. These attacks are attributed to the pro-Russian hacktivist group NoName057(16), known for leveraging their crowdsourced DDoSia platform to coordinate massive denial-of-service campaigns. Despite an international law enforcement operation in mid-2025 that resulted in arrests and the takedown of supporting servers, the core operators evaded capture and resumed disruptive activities. The attacks, while technically unsophisticated, resulted in interruptions of public-facing services, forced organizations to invest in defensive measures, and threatened operational resilience. This incident underscores a broader trend of ideologically motivated hacktivism targeting Western critical infrastructure, amplified by evolving techniques and persistent threat actors. As geopolitical tensions rise and hacktivists increasingly collaborate via decentralized platforms, DDoS threats have become a significant operational risk for organizations across the public and private sectors.
6 months ago
Kill Chain
Google Pixel 9 (2026): Zero-Click BigWave Driver Breach Exposes Kernel Vulnerabilities
In January 2026, Google Pixel 9 devices were found vulnerable to a sophisticated zero-click exploit chain targeting the Android BigWave hardware driver. Attackers combined a remote code execution exploit affecting a Dolby decoder with a privilege escalation flaw in the /dev/bigwave device, accessible from the mediacodec SELinux sandbox. The chain allowed attackers to escape the sandbox, bypass SELinux protections, and achieve kernel-level arbitrary read/write, essentially gaining full device control. This exploit enabled unauthorized access to sensitive data and even allowed remote data exfiltration by attackers, severely compromising device security. This incident highlights the increasing sophistication of exploit chains leveraging hardware-specific drivers and sandbox escape techniques in mobile ecosystems. With the rise in supply chain threats, use of AI to automate exploit engineering, and growing pressure from privacy regulators, organizations face escalating risks from zero-day attacks targeting embedded devices.
6 months ago
Kill Chain
Google Pixel 9's 2025 Zero-Click Exploit Chain: Lessons in Mobile Supply Chain Security
In 2025, security researchers demonstrated a critical 0-click exploit chain targeting Google Pixel 9 and other Android devices, leveraging vulnerabilities in the Dolby UDC audio codec and the BigWave driver. Attackers could remotely execute code without user interaction by exploiting flaws in audio file processing and privilege escalation within device drivers. Despite early reporting and clear exploitability, it took vendors up to 139 days to release patches, leaving millions of Android users at risk. Gaps in patch management, inconsistent security controls, and delayed vulnerability classification contributed to prolonged exposure and a significant operational risk. This incident underscores the urgency of promptly addressing zero-click vulnerabilities and supply chain security issues in mobile ecosystems. As attackers increasingly exploit overlooked decoders, device drivers, and rapidly introduced AI features, coordinated patching and proactive privilege reduction remain essential to counter evolving mobile threats.
6 months ago
Kill Chain
Black Basta Ransomware Boss Named, Placed on Interpol Red Notice in Major 2026 Crackdown
In January 2026, international law enforcement, led by Ukraine and Germany, identified Oleg Evgenievich Nefedov as the leader of the Black Basta ransomware-as-a-service (RaaS) gang. Authorities added Nefedov to Interpol's 'Red Notice' and Europol's 'Most Wanted' lists, following coordinated raids that apprehended affiliates specializing in breaching corporate systems, cracking passwords, and escalating privileges to facilitate attacks. Black Basta has been attributed to over 600 global cyber incidents targeting enterprises in sectors from defense to healthcare, employing ransomware and data extortion to extract payments and exfiltrate sensitive information. This incident is significant as it marks one of the first times a major ransomware operation's leadership was officially unmasked and targeted with international warrants. The Black Basta takedown reflects increasing sophistication and coordination in responses to organized cybercrime, underscoring the persistent threat posed by ransomware groups and their rapid evolution post-Conti.
6 months ago
Kill Chain
Sitecore 2025: China-Linked APT UAT-8837’s Zero-Day Attack Reveals Modern Espionage Tactics
In early September 2025, an advanced persistent threat group known as UAT-8837, believed to be linked to China, exploited a zero-day vulnerability (CVE-2025-53690) in Sitecore products to gain initial access to critical infrastructure targets in North America. The attackers obtained credentials and leveraged living-off-the-land tools, open-source utilities, and custom backdoors—including 'WeepSteel'—to conduct deep reconnaissance, move laterally, and collect sensitive data such as credentials and Active Directory configurations. Post-exploitation activity also included disabling security controls and exfiltrating internal DLLs, which could be leveraged for future supply chain attacks. This incident spotlights a surge in targeted espionage exploiting both zero-day and known software vulnerabilities, with an emphasis on credential compromise and lateral movement. Growing overlap in TTPs among China-nexus actors and continued attack innovation reinforce the importance of modernizing defenses against sophisticated identity- and supply-chain-driven attacks.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports