The Containment Era is here. →Explore

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

751 threat reports
Page 41 of 63

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Telecommunications Threat Reports

Showing 481492 / 751 reports
D-Link Legacy Router Flaw Exploited: CVE-2026-0625 Zero-Day Endangers Networks
Impact· medium

D-Link Legacy Router Flaw Exploited: CVE-2026-0625 Zero-Day Endangers Networks

In early January 2026, a critical security incident involving D-Link legacy DSL routers came to light as attackers actively exploited a command injection vulnerability tracked as CVE-2026-0625. The flaw, caused by improper input sanitization in the dnscfg.cgi endpoint of several out-of-support D-Link DSL gateway models, allowed unauthenticated remote attackers to execute arbitrary shell commands and potentially gain full control over affected devices. Although the exploit was first detected by Shadowserver Foundation honeypots, the method was not previously public, raising the risk of widespread attacks on consumer and small business network infrastructure. Impacted routers—including the DSL-526B, DSL-2640B, DSL-2740R, and DSL-2780B—are end-of-life and will not receive security updates, leaving users exposed unless devices are decommissioned or isolated. This incident highlights the persistent risks associated with legacy, unsupported network hardware across both consumer and SMB environments, particularly as attackers increasingly exploit unpatched, remotely accessible routers. It underscores the urgent importance of retiring end-of-life devices or segmenting critical networks, as well as the need for improved asset management strategies in the face of rising supply-chain and infrastructure vulnerabilities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Kimwolf Botnet’s 2024 Assault: How Residential Proxies Fueled Widespread Android Device Infections
Impact· medium

Kimwolf Botnet’s 2024 Assault: How Residential Proxies Fueled Widespread Android Device Infections

In 2024, the Kimwolf Android botnet rapidly expanded to over two million infected hosts by exploiting vulnerabilities in residential proxy networks to penetrate internal devices. This botnet, an evolution of Aisuru malware, leverages residential IP addresses to mask malicious activity and facilitate lateral movement inside targeted networks. By abusing these proxies, Kimwolf can bypass perimeter defenses, execute command-and-control operations, and enable wide-scale internal compromise of Android and IoT devices, causing extensive disruption and exposing organizations to data theft, downtime, and potential extortion. Kimwolf highlights a growing threat: attackers are increasingly leveraging residential proxies and internal lateral movement tactics to amplify reach and evade detection. Its success underscores the need for improved egress filtering, network segmentation, and east-west traffic monitoring as threat actors adopt more sophisticated methods to breach internal assets.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Tenfold Spike: Chinese State Cyberattacks on Taiwan’s Energy Sector in 2025
Impact· medium

Tenfold Spike: Chinese State Cyberattacks on Taiwan’s Energy Sector in 2025

In 2025, Taiwan experienced a dramatic surge in cyberattacks against its energy sector, with incidents increasing tenfold compared to the previous year, as reported by the country's National Security Bureau. Chinese nation-state groups, such as BlackTech, Flax Typhoon, Mustang Panda, APT41, and UNC3886, orchestrated targeted campaigns that leveraged hardware and software vulnerabilities, DDoS, social engineering, and supply-chain tactics. These attacks predominantly focused on industrial control systems and aimed to implant malware during key software upgrade windows, affecting vital infrastructure in petroleum, electricity, and natural gas domains and raising geopolitical and operational security concerns. This incident highlights the persistent threat of coordinated nation-state cyber activity against critical infrastructure, especially during politically sensitive periods. The tactics and techniques observed reflect global trends in the exploitation of operational technology and underscore the increasing need for advanced defense and cross-border intelligence sharing.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
TOTOLINK EX200 Unpatched Flaw Enables Remote Takeover in 2026
Impact· medium

TOTOLINK EX200 Unpatched Flaw Enables Remote Takeover in 2026

In January 2026, a critical unpatched firmware vulnerability (CVE-2025-65606) was disclosed by CERT/CC affecting TOTOLINK EX200 wireless range extenders. This flaw resides in the device’s firmware-upload error-handling logic, allowing a remote authenticated attacker to trigger processes leading to full device compromise. Successful exploitation provides total administrative control, enabling attackers to alter configurations, secretly listen to traffic, or pivot to other devices on the network. TOTOLINK has not released an update, leaving vulnerable devices exposed in both home and enterprise environments. This breach highlights the ongoing threat posed by IoT device vulnerabilities—especially as attackers increasingly exploit authentication-bypass flaws and manufacturer patch delays. The incident underscores the importance of swift vulnerability management and robust network segmentation in mitigating the risk from unpatched IoT endpoints.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
NordVPN 2026: False Data Breach Claim Traced to Vendor Test Environment
Impact· high

NordVPN 2026: False Data Breach Claim Traced to Vendor Test Environment

In January 2026, a threat actor claimed to have breached NordVPN's internal Salesforce development servers, alleging access to over ten databases containing sensitive Salesforce API keys and Jira tokens. The attacker purportedly leveraged brute-force tactics against a misconfigured server; however, NordVPN clarified that the data originated from a vendor's temporary test environment used months prior for automated testing. The breached environment contained only non-sensitive, dummy data, was never linked to NordVPN's production infrastructure, and did not expose customer information or production credentials. The company immediately investigated, engaged with the affected vendor, and publicly denied any compromise of its operational assets. This incident highlights how false breach claims—when amplified by threat actors and forums—can impact enterprise reputation, erode trust, and distract security teams. The event also spotlights the importance of robust controls and clear communication regarding third-party environments, even those used only for testing, as threat actors increasingly seek to exploit every operational touchpoint.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Brightspeed Hit by Crimson Collective: Major 2026 Data Breach Exposes Customer PII
Impact· high

Brightspeed Hit by Crimson Collective: Major 2026 Data Breach Exposes Customer PII

In January 2026, Brightspeed, one of the largest fiber broadband providers in the United States, launched an investigation after the Crimson Collective extortion gang claimed to have breached the company’s networks and stolen sensitive data. The group asserted they had accessed personal and account-related information of over 1 million customers, including names, addresses, emails, phone numbers, payment histories, and some payment card details. The threat actors reportedly targeted user account systems and exfiltrated personally identifiable information (PII), subsequently pressuring Brightspeed to respond to their extortion demands by threatening to publish samples of the stolen data. This attack underscores the persistent risk posed by targeted data breaches in the telecom sector, where expansive networks and large customer bases make attractive targets for financially motivated threat actors. The incident further highlights a concerning trend: extortion groups are increasingly leveraging cloud misconfigurations, stolen credentials, and lateral movement within corporate environments to maximize data theft and pressure on organizations.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Kimwolf Botnet Compromises 2 Million+ Android Devices via Exposed ADB in 2026
Impact· high

Kimwolf Botnet Compromises 2 Million+ Android Devices via Exposed ADB in 2026

In early 2026, the Kimwolf botnet orchestrated one of the largest Android targeting campaigns to date, infecting over 2 million devices. Attackers exploited exposed Android Debug Bridge (ADB) interfaces and abused residential proxy networks to establish persistent control and monetize the compromised devices. Synthient researchers revealed that Kimwolf operators maintained access for lateral movement, facilitated app installations, sold network bandwidth, and weaponized infected endpoints for DDoS attacks. The attack chain emphasized exploiting weak or default security configurations on Android devices, allowing broad propagation and quick monetization at scale. The Kimwolf botnet illustrates the evolving risk landscape for mobile endpoints and the increasing use of cloud or residential proxy infrastructure by cybercriminals. Given the speed and scale of infection, this case underscores the urgent need for stronger defense-in-depth strategies and highlights regulatory scrutiny on IoT and mobile security postures.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Russia-Aligned Group UAC-0184 Breaches Ukrainian Government via Viber Attack
Impact· low

Russia-Aligned Group UAC-0184 Breaches Ukrainian Government via Viber Attack

In early 2025, the Russia-aligned cyber-espionage group UAC-0184 undertook a targeted campaign against Ukrainian military and government organizations. Leveraging the popular Viber messaging platform, the threat actors distributed malicious ZIP archives to infiltrate sensitive networks. Security researchers from the 360 Threat Intelligence Center noted that these operations demonstrated continued intelligence-gathering efforts, employing social engineering tactics and the abuse of trusted communication channels. The attack resulted in the unauthorized access and potential exposure of confidential government and defense information, further escalating the cyber hostilities related to the conflict in Ukraine. This incident highlights a growing trend in the weaponization of encrypted messaging apps for cyber-espionage, as nation-state actors increasingly exploit trusted consumer platforms to bypass traditional enterprise security controls. The breach underscores the urgency for robust east-west traffic monitoring, zero trust segmentation, and advanced detection capabilities across critical sectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
How Telegram Became the World's Largest Darknet Market Platform in 2026
Impact· medium

How Telegram Became the World's Largest Darknet Market Platform in 2026

In early 2026, major Chinese-speaking darknet markets known as Tudou Guarantee and Xinbi Guarantee emerged on the encrypted messaging platform Telegram, quickly becoming the world’s largest such entities. Following enforcement action and the banning of two prior networks, these new markets enabled an illicit ecosystem reportedly handling nearly $2 billion each month in laundering, sale of scamware, stolen data, deepfake technologies, and a disturbing array of black-market services. Their operations fuel high-volume crypto investment and romance scams, including the so-called 'pig butchering' schemes, which exploit trafficked labor and result in billions in global losses—with US victims alone losing around $10 billion a year. This incident illustrates the adaptability of cybercriminal infrastructure, highlighting Telegram’s evolving role as a trusted communications and trading platform for serious organized cyber threats. The surge in Telegram-based darknet activity coincides with increased regulatory scrutiny, growing law enforcement action, and a shift toward encrypted, resilient, and cross-border cybercrime tactics.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Kimwolf Botnet: When Residential Proxies Turn Your LAN Into a Global Attack Platform
Impact· medium

Kimwolf Botnet: When Residential Proxies Turn Your LAN Into a Global Attack Platform

In late 2025, a rapidly growing botnet called Kimwolf infected over two million devices worldwide, primarily through compromised Android TV boxes and digital photo frames lacking basic security controls or authentication. Attackers abused vulnerabilities in residential proxy networks—particularly via IPIDEA—to tunnel through external firewalls, gaining direct access to devices inside private networks. Kimwolf malware leveraged DNS tricks and default-enabled Android Debug Bridge (ADB) to enable lateral movement, turning victim devices into nodes for ad fraud, account takeovers, content scraping, and high-volume DDoS attacks, demonstrating unprecedented attacker reach into home and small business LANs. Kimwolf's swift expansion and post-takedown resilience reveal a new class of threats exploiting insecure IoT and overlooked network entry points inside residential and SMB environments. The incident highlights emerging risks from mass-produced, inadequately secured consumer tech and proxy networks, urging organizations to reconsider internal network trust assumptions and prioritize visibility, segmentation, and policy-driven controls to stop lateral movement and botnet proliferation.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Kimwolf Botnet 2025: The Largest IoT Attack Forces Rethink of DDoS and Proxy Security
Impact· medium

Kimwolf Botnet 2025: The Largest IoT Attack Forces Rethink of DDoS and Proxy Security

In 2025, a record-shattering wave of distributed denial-of-service (DDoS) and proxy attacks targeted high-profile websites including KrebsOnSecurity.com, Google, and Cloudflare. Initial attribution pointed to the Aisuru botnet, but subsequent investigation by XLab and others revealed the underlying infrastructure was largely driven by the Kimwolf botnet, comprising over 1.8 million compromised Internet-of-Things (IoT) devices. The attackers leveraged vulnerable connected devices worldwide, harnessing them not only for disruptive DDoS campaigns but also for proxy rental services that enabled cybercriminal anonymity, exposing widespread insecurity in IoT ecosystems. This incident underscores a concerning shift: major botnets are evolving from sporadic attacks to persistent, multi-purpose criminal platforms. It highlights the urgent need for enterprises to address IoT security gaps and for cloud providers to enforce robust countermeasures against residential proxy abuse and large-scale botnet activity.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
HoneyMyte APT Unleashes Kernel-Mode Rootkit with ToneShell Backdoor in Southeast Asia
Impact· high

HoneyMyte APT Unleashes Kernel-Mode Rootkit with ToneShell Backdoor in Southeast Asia

In early 2025, the HoneyMyte APT group launched a targeted cyberespionage campaign against government organizations in Southeast and East Asia, primarily Myanmar and Thailand. Leveraging a stolen digital certificate, HoneyMyte deployed a malicious kernel-mode rootkit disguised as a signed driver to inject the advanced ToneShell backdoor into high-privilege system processes. The attack chain delivered full process, registry, and file protection for malicious activity, making removal and detection by security tools exceedingly challenging. The backdoor enabled covert remote access, data exfiltration, and command execution via communications camouflaged to resemble legitimate encrypted TLS traffic. This incident is a stark example of modern APT evolution, showcasing new levels of stealth and persistence through kernel-level threats and advanced obfuscation. It highlights a broader shift towards supply-chain and trusted-cert abuse, increasing risk for public sector and critical infrastructure targets in the Asia-Pacific region.

6 months ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports