The Containment Era is here. →Explore

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

751 threat reports
Page 39 of 63

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Telecommunications Threat Reports

Showing 457468 / 751 reports
China-Linked APT Leverages Sitecore Zero-Day to Target Critical Infrastructure (2025)
Impact· medium

China-Linked APT Leverages Sitecore Zero-Day to Target Critical Infrastructure (2025)

In late 2025, a China-nexus advanced persistent threat group tracked as UAT-8837 exploited a critical Sitecore zero-day vulnerability (CVE-2025-53690, CVSS 9.0) to compromise multiple critical infrastructure organizations in North America. Following initial access through vulnerable servers or compromised credentials, the threat actor leveraged open-source post-exploitation tools to steal sensitive credentials, manipulate Active Directory, and establish multiple persistent access channels. Attackers disabled security features like RestrictedAdmin for RDP and exfiltrated confidential assets, including proprietary DLL libraries, potentially setting the stage for future supply chain attacks or further reverse engineering efforts. This incident reflects a broader trend of sophisticated, state-linked attackers increasingly targeting operational technology environments and critical infrastructure, exploiting unpatched vulnerabilities and adopting living-off-the-land techniques. The ongoing relevance is underscored by heightened governmental warnings and the urgent need for robust vulnerability management, segmentation, and monitoring in high-value environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Predator Spyware: Inside Intellexa’s Vendor-Controlled C2 Attack Tactics (2024)
Impact· medium

Predator Spyware: Inside Intellexa’s Vendor-Controlled C2 Attack Tactics (2024)

In early 2024, cybersecurity researchers uncovered evidence of Predator, a commercial spyware platform developed by Intellexa, leveraging a vendor-controlled command-and-control (C2) infrastructure to improve attack precision. Failed and thwarted infection attempts were systematically analyzed by the vendor to refine future attack methods, highlighting a professionalized feedback loop in commercial spyware campaigns. The attack vectors included advanced mobile device exploits, with malicious payloads deployed on targeted mobile devices through phishing or exploit links. The incident underscores how commercial spyware vendors adapt rapidly by learning from failed compromises, posing significant operational risk to both individuals and organizations globally. The exposure of Predator's vendor-controlled C2 approach signals a broader industry shift toward more dynamic, resilient spyware operations, complicating detection and defense for enterprises. This incident exemplifies the rise of highly adaptive, commercially-driven attack infrastructure, intensifying regulatory, technical, and reputational challenges for security leaders and organizations handling sensitive data.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Salt Typhoon Exploits Redis Unauthenticated RCE: 2026 Lessons for Zero Trust
Impact· low

Salt Typhoon Exploits Redis Unauthenticated RCE: 2026 Lessons for Zero Trust

In early January 2026, a critical security flaw was discovered in Redis servers that allowed unauthenticated remote code execution (RCE). Exploited by a new threat group dubbed Salt Typhoon, the attackers leveraged unencrypted traffic and lack of east-west network controls to gain foothold via exposed Redis instances. The operation enabled lateral movement within affected organizations’ environments, resulting in rapid credential access and potential data exfiltration. Numerous enterprises faced service disruptions and urgent patching efforts, as exploitation spread quickly amidst widespread cloud and on-prem deployments. This incident highlights the resurgence of unauthenticated RCE exploits targeting core data store infrastructure, particularly where zero trust segmentation and encrypted traffic policies are not rigorously applied. Growing attacker interest in lateral movement, compounded by hybrid cloud complexity, has made traditional perimeter defenses insufficient.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Kimwolf Botnet’s 2025 DDoS Blitz: 2M Devices, Unprecedented Risk
Impact· high

Kimwolf Botnet’s 2025 DDoS Blitz: 2M Devices, Unprecedented Risk

In October 2025, the Kimwolf botnet—an offshoot of the notorious Aisuru DDoS network—rapidly infected over 2 million unofficial Android TV devices by exploiting weaknesses in residential proxy networks. The operators, believed to be financially motivated cybercriminals, orchestrated large-scale distributed denial-of-service (DDoS) attacks affecting gaming communities, notably targeting Minecraft servers, and leveraged fast-evolving infrastructure to evade detection. Industry players, including Lumen’s Black Lotus Labs, responded by null-routing botnet-linked IP addresses and blocking command-and-control infrastructure, significantly diminishing Kimwolf’s operational bandwidth and disrupting its growth trajectory. Kimwolf’s meteoric rise highlights the growing threat posed by botnets that co-opt consumer devices and abuse proxy services for stealth and scale. The incident demonstrates the urgent need for robust internal network controls, real-time anomaly response, and resilient segmentation, as attackers escalate their tactics and DDoS attacks hit record-breaking volumes.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
Ukraine’s Army Compromised by Void Blizzard in Charity-Themed Malware Campaign
Impact· medium

Ukraine’s Army Compromised by Void Blizzard in Charity-Themed Malware Campaign

Between October and December 2025, Ukraine's Defense Forces were targeted by a sophisticated malware campaign attributed to the Russian-linked threat group 'Void Blizzard' (also known as 'Laundry Bear'). Attackers leveraged instant messaging apps like Signal and WhatsApp, using compelling charity-themed lures to trick recipients into downloading a password-protected archive. Inside, the PluggyApe backdoor—bundled as disguised executables—provided remote access to compromised hosts, stealing sensitive data and awaiting additional commands. The malware's second-generation included enhanced obfuscation, anti-analysis techniques, and a novel approach to fetching command-and-control addresses from public services like Pastebin. This campaign reflects the escalating use of social engineering, mobile device targeting, and supply chain tactics by state-aligned groups in espionage operations. It highlights the urgent need for stronger endpoint protection, policy enforcement, and continuous monitoring across both traditional and mobile attack surfaces.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How the Free Mobile 2024 Data Breach Exposed Millions: Lessons in Telecom Security
Impact· high

How the Free Mobile 2024 Data Breach Exposed Millions: Lessons in Telecom Security

In October 2024, Free Mobile—France's second-largest ISP—suffered a significant data breach when hackers compromised its management tool, exposing information of up to 23 million current and former subscribers. Attackers leveraged weak VPN authentication and exploited inadequate detection controls to exfiltrate sensitive customer data, including banking details (IBANs). The breach then led to data being offered for sale on a hacker forum, with later regulatory investigations confirming extensive security lapses, leading to a €42 million fine by CNIL for violations of GDPR related to security, breach notification, and data retention. This incident highlights the growing risk facing telecom providers from targeted attacks utilizing credential compromise and weak internal controls. It underscores regulatory attention and penalties for organizations that fail to meet cybersecurity and data protection obligations, particularly under GDPR.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
PLUGGYAPE Malware Campaign Exposes Messenger Security Gaps in Ukraine’s Defense Sector
Impact· medium

PLUGGYAPE Malware Campaign Exposes Messenger Security Gaps in Ukraine’s Defense Sector

Between October and December 2025, Ukrainian defense forces were targeted by cyber espionage campaigns conducted by the Russian-linked group known as Void Blizzard (aka Laundry Bear or UAC-0190). Using popular messaging platforms Signal and WhatsApp, attackers posed as charity organizations and tricked victims into downloading password-protected archives containing a Python-based backdoor, PLUGGYAPE. The malware, distributed through well-crafted social engineering and employing techniques such as obfuscated payloads and anti-analysis, enabled remote command execution and data theft. Attackers further enhanced operational security using external paste services for command-and-control server updates, rendering infrastructure takedowns less effective while maintaining persistent access on compromised hosts. This breach underscores the growing sophistication of social engineering and the exploitation of widely trusted communication platforms for initial access. The incident highlights not only ongoing threat activity against critical state functions but also the evolving nature of cyber threats adapting to countermeasures, necessitating enhanced vigilance and reformulated defense postures across the public and private sectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Unpacking the Kimwolf & AISURU Botnet: How 2 Million Android Devices Became a DDoS Army
Impact· high

Unpacking the Kimwolf & AISURU Botnet: How 2 Million Android Devices Became a DDoS Army

In late 2025, security researchers at Lumen’s Black Lotus Labs null-routed traffic to over 550 command-and-control (C2) servers associated with the rapidly expanding Kimwolf and AISURU botnets. These botnets primarily targeted Android TV streaming devices—especially those with exposed ADB services—and used a malicious SDK (ByteConnect) to conscript over two million devices into a powerful residential proxy network. Threat actors leveraged this massive bot army to launch distributed denial-of-service (DDoS) attacks and facilitate malicious relay of internet traffic, further monetizing access via underground proxy services marketed on Discord and other platforms. The botnets exhibited rapid growth, exploiting security flaws in both consumer hardware and third-party proxy services for propagation. This incident highlights a shift in cybercriminal tactics toward wielding residential IP addresses for nefarious activity, circumventing traditional detection and blocking mechanisms. The scale and sophistication of these campaigns underscore escalating risks to organizations relying on residential endpoints and underscore the urgency for improved segmentation, anomaly detection, and real-time response.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
YoSmart YoLink 2026: IoT Flaws Enable Remote Takeover and Data Exposure
Impact· medium

YoSmart YoLink 2026: IoT Flaws Enable Remote Takeover and Data Exposure

In January 2026, YoSmart's YoLink Smart Hub platform was found vulnerable to a series of security flaws that placed smart home users at risk worldwide. Discovered and reported by Bishop Fox and disclosed via CISA, these issues included insufficient authorization in device communication, the use of predictable device identifiers, cleartext transmission of sensitive information over MQTT, and excessive session token lifetimes. Attackers could remotely control users' smart devices, intercept data, and hijack sessions without physical access, affecting both the hub and its mobile app ecosystem. The vulnerabilities were present in core server infrastructure, device APIs, and user-facing applications. While YoSmart resolved the vulnerabilities through server-side and over-the-air updates, this incident highlights critical and ongoing risks in the IoT and smart device sector. The attack methods exploited insecure-by-design communication and poor identity management—trends increasingly scrutinized by regulators and targeted by sophisticated threat actors worldwide.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Apex Legends Live Character Hijack: 2026 Gaming Platform Breach Explained
Impact· high

Apex Legends Live Character Hijack: 2026 Gaming Platform Breach Explained

In January 2026, Apex Legends players experienced a major security incident where an external threat actor gained unauthorized control over live player characters during matches. The attacker remotely hijacked user avatars, disconnected players from servers, and manipulated in-game identities, temporarily disrupting the gaming experience for tens of thousands. Respawn Entertainment, the game's publisher, confirmed the attack but stated there was no evidence of remote code execution or malware. Investigation pointed to exploitation of privileged backend debugging or admin interfaces, rather than a software vulnerability affecting all client machines. This incident underscores escalating threats targeting large-scale gaming platforms, where privilege escalation and endpoint attacks now rival phishing or malware techniques in their sophistication. With gaming ecosystems becoming lucrative and complex, attackers continue to innovate, highlighting the urgent need for improved internal traffic security and continuous monitoring.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Pig Butchering Fraud: Service Providers Power the Next Wave of Industrial-Scale Online Scams
Impact· high

Pig Butchering Fraud: Service Providers Power the Next Wave of Industrial-Scale Online Scams

In early 2026, cybersecurity researchers revealed that two specialized service providers are supplying criminal networks with infrastructure and scalable toolkits to support industrial-scale pig butchering fraud, primarily across Southeast Asia. These providers lower the barrier to entry for fraudsters by offering turnkey scam platforms, stolen identity data, and payments solutions designed to evade law enforcement. The so-called PBaaS (Pig-Butchering-as-a-Service) ecosystem enables rapid creation of scam campaigns leveraging advanced CRM platforms, phishing tactics, and laundering tools, impacting individuals and financial institutions globally. This incident underscores the evolution of cyber-enabled fraud into a scalable, service-driven shadow industry, exploiting technology and industrial organization for criminal gain. The widespread adoption of such "fraud-as-a-service" business models reflects a broader trend in cybercrime, making advanced threat tactics more accessible to a wider range of malicious actors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
US Gray Zone Cyber Operations Disrupt Venezuela’s Oil Sector in 2020
Impact· medium

US Gray Zone Cyber Operations Disrupt Venezuela’s Oil Sector in 2020

In early 2020, cyber-enabled disruptions targeted Venezuela’s state-owned oil sector amidst political upheaval and mounting international pressure. While formal attribution remains disputed, sources suggest that US-affiliated actors leveraged advanced cyber techniques—such as persistent access, supply chain vulnerabilities, and mapped system dependencies—to intermittently degrade operational capabilities and exports. The campaign unfolded as ongoing, reversible disruptions aimed at eroding economic resilience and regime stability without triggering overt conflict. These actions exemplified nation-state 'gray zone' operations, leveraging cyber tools for sustained coercion rather than momentary effect. This incident marked a shift in statecraft, signaling the integration of cyber-enabled economic interference with traditional levers like sanctions and diplomacy. It reflects a broader, rising trend of major powers using deniable, persistent cyber operations to exert pressure on adversarial infrastructure while remaining below the threshold of conventional military escalation.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports