The Containment Era is here. →Explore

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

757 threat reports
Page 45 of 64

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Telecommunications Threat Reports

Showing 529540 / 757 reports
U-Boot Bootloader Flaw Threatens Global Manufacturing and Critical Infrastructure
Impact· low

U-Boot Bootloader Flaw Threatens Global Manufacturing and Critical Infrastructure

In December 2025, a critical vulnerability (CVE-2025-24857) was disclosed in U-Boot, a widely-used bootloader for embedded systems, impacting all versions prior to 2017.11 and several Qualcomm chipsets. The flaw—improper access control for volatile memory containing boot code—allowed an attacker with local access to execute arbitrary code at boot, posing significant risk to devices across essential sectors including energy, communications, manufacturing, healthcare, and more. No active exploitation has been reported, but the vulnerability could undermine device integrity and operational security in globally deployed critical infrastructure systems. Mitigations include upgrading to the latest U-Boot version and implementing strict physical and network isolation measures. This incident underlines the persistent risk posed by supply chain and firmware vulnerabilities in critical infrastructure. With IoT and embedded device ubiquity rising, attackers are increasingly targeting low-level firmware to achieve persistence or bypass security, heightening regulatory scrutiny and emphasizing the need for proactive vulnerability management and secure device lifecycle practices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Nation-State Cyber Espionage: Iran’s Shahid Shushtari Unit and the $10M Bounty
Impact· medium

Nation-State Cyber Espionage: Iran’s Shahid Shushtari Unit and the $10M Bounty

In late 2024, security authorities announced a $10 million reward for information regarding the whereabouts of Mohammad Bagher Shirinkar and Fatemeh Sedighian Kashi, key leaders of Shahid Shushtari — a cyber unit operating under Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command. Known by threat intelligence analysts as UNC5866, Cotton Sandstorm, and Haywire Kitten, the group targets critical infrastructure sectors, including news, shipping, travel, energy, financial services, and telecom across the U.S., Europe, and the Middle East. Their operations span spear-phishing, malware campaign delivery, and cyberespionage, with significant disruptions and financial damages reported. Notably, the group attempted to influence the 2020 U.S. presidential election and continues its multi-pronged attacks using evolving techniques and new tradecraft. This incident underscores the persistent and evolving threat posed by nation-state actors targeting both public and private institutions globally. Increased vigilance, timely intelligence sharing, and robust controls around east-west network traffic and encrypted communications are now critical countermeasures as similar attacks escalate.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Poland Arrests Ukrainians in 2024 Espionage Cyber Incident
Impact· low

Poland Arrests Ukrainians in 2024 Espionage Cyber Incident

In June 2024, Polish authorities arrested three Ukrainian nationals accused of using sophisticated hacking equipment to carry out cyberattacks targeting Polish IT systems, with particular emphasis on the theft of 'computer data of particular importance to national defense.' The suspects were apprehended while allegedly attempting to damage government information technology infrastructure, utilizing encrypted communications and advanced attack tools likely designed to evade monitoring and facilitate data exfiltration. The incident underscores heightened tensions in the region and reveals vulnerabilities within national networks, with Polish law enforcement quickly intervening to mitigate further impact. This breach is emblematic of a broader escalation in nation-state cyber operations across Europe, featuring cross-border actors relying on advanced techniques to infiltrate sensitive targets. The event highlights the urgent need for robust east-west traffic security, encrypted communications, and real-time anomaly detection controls to guard national interests and critical IT environments.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(low)
Read Report
Iranian APT 'MuddyWater' Launches UDPGangster Backdoor in Multi-Nation Espionage Campaign
Impact· low

Iranian APT 'MuddyWater' Launches UDPGangster Backdoor in Multi-Nation Espionage Campaign

In late 2025, the Iranian cyber espionage group MuddyWater launched a targeted campaign against organizations in Turkey, Israel, and Azerbaijan using a novel backdoor dubbed UDPGangster. The malware leveraged UDP-based command-and-control channels to enable remote management of infected systems while evading traditional network detection techniques. Attacks typically began via spear-phishing emails containing malicious attachments or links, granting the attackers a foothold in victim environments and facilitating lateral movement and data exfiltration. Fortinet FortiGuard Labs was among the first to document the malware and its unique communication characteristics. The campaign highlighted substantial risks to critical sectors and national security in the affected countries. This incident exemplifies rising threat actor sophistication—specifically, abuse of obscure protocols like UDP for covert C2—and underscores the strategic evolution of Iranian groups. Its tactics reflect broader cyber espionage trends across the Middle East and signal urgent needs for advanced lateral movement detection and zero trust controls.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
2025 Cyberattack Wave: USB Malware, React2Shell & AI Tool Exploits Expose Security Gaps
Impact· medium

2025 Cyberattack Wave: USB Malware, React2Shell & AI Tool Exploits Expose Security Gaps

In December 2025, organizations worldwide faced a surge of multi-vector cyberattacks exploiting recent vulnerabilities in USB devices, popular developer frameworks like React (notably the React2Shell bug), and emerging AI-powered coding environments. Attackers leveraged unpatched software, social engineering, and compromised USB devices to distribute malware and establish lateral movement within networks. The campaign capitalized on the rapid deployment of new technologies and lagging security controls, resulting in data breaches, financial theft via sophisticated WhatsApp worms, and the infiltration of development pipelines. This spate of incidents underscores the escalating convergence of traditional malware vectors and AI-driven exploits, exposing significant gaps in current security postures. As organizations accelerate digital transformation and adopt generative AI tools, adversaries are rapidly evolving, testing defenses across cloud, hybrid, and on-premises ecosystems.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Wave of Android Malware Hits Polish Bank Customers—FvncBot, SeedSnatcher & ClayRat Evolve
Impact· medium

Wave of Android Malware Hits Polish Bank Customers—FvncBot, SeedSnatcher & ClayRat Evolve

In late 2025, security researchers from Intel 471, CYFIRMA, and Zimperium uncovered two new Android malware families—FvncBot and SeedSnatcher—alongside an upgraded ClayRat variant. FvncBot, disguised as a banking security app targeting mBank customers in Poland, used sophisticated credential theft and evasive techniques to breach users’ devices, while SeedSnatcher enabled wide-scale stealth data exfiltration. ClayRat, already known in cybercriminal circles, has evolved to feature enhanced capabilities for data theft and persistence. These malware strains are distributed through phishing campaigns and malicious app stores targeting finance sector customers and exploiting gaps in mobile device controls and user awareness. The campaigns resulted in substantial risk of unauthorized transactions, identity theft, and broader exposure of banking and personal data. The coordinated discovery highlights a dramatic escalation in the capabilities of mobile-targeted malware, especially those aimed at financial institutions in Eastern Europe. The incident exemplifies the rapid, continuous innovation by threat actors seeking to monetize weaknesses in endpoint security and exploit unsuspecting app users, raising the urgency for organizations to modernize mobile and app-layer security postures.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Flags Active D-Link & Array Networks Vulnerabilities in 2025 KEV Catalog
Impact· low

CISA Flags Active D-Link & Array Networks Vulnerabilities in 2025 KEV Catalog

In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) expanded its Known Exploited Vulnerabilities (KEV) Catalog to include two actively exploited vulnerabilities: CVE-2022-37055, a buffer overflow in D-Link routers, and CVE-2025-66644, an OS command injection flaw impacting Array Networks ArrayOS AG. These vulnerabilities provide attack vectors for cybercriminals to gain unauthorized access, conduct lateral movement, or exfiltrate sensitive data within federal and private sector networks. The directive mandates that all Federal Civilian Executive Branch (FCEB) agencies address these threats promptly to reduce risk exposure and protect operational integrity. This update underscores the persistent threat posed by unpatched network infrastructure vulnerabilities, which remain prime targets for attackers. Timely remediation of KEV-listed vulnerabilities is increasingly critical for all organizations amid a rising trend of targeted attacks against widely deployed network devices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Holiday Season Phishing Surge: Fake Rewards, Tax Refunds, and Retail Scams Hit US Consumers
Impact· medium

Holiday Season Phishing Surge: Fake Rewards, Tax Refunds, and Retail Scams Hit US Consumers

In late 2025, a surge of SMS phishing campaigns originating from China-based threat actors targeted US consumers, leveraging fake rewards, tax refund lures, and convincing e-commerce storefronts. Attackers registered thousands of new phishing domains, deploying convincing T-Mobile and AT&T spoof sites promoted via iMessage and RCS. Victims, enticed to enter payment card data and one-time codes, unknowingly enabled attackers to enroll their cards into Apple or Google mobile wallets under fraudster control, facilitating rapid monetization of stolen credentials. These operations exploited seasonal shopping urgency and sophisticated phishing kits to evade detection, causing widespread financial fraud, identity theft, and downstream losses for individuals and financial institutions. The incident highlights a global shift in phishing techniques, with threat actors now employing advanced, rapidly deployable kits and mobile wallet fraud vectors. The proliferation of fake e-commerce and tax-refund scams demonstrates increased operational agility and a focus on bypassing traditional browser-based defenses, raising urgent concerns for both consumer security and enterprise payment protection.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Predator Spyware 2024: Zero-Click Ad Delivery Redefines Stealth Attacks
Impact· high

Predator Spyware 2024: Zero-Click Ad Delivery Redefines Stealth Attacks

Between late 2023 and early 2024, the Predator spyware—developed by surveillance tech company Intellexa—was deployed via a novel zero-click attack vector known as "Aladdin." This technique exploited malicious ads to automatically compromise targeted devices as soon as they displayed the booby-trapped advertisement, without requiring any user interaction. Elite threat actors leveraged this method to implant sophisticated spyware capable of exfiltrating sensitive data and monitoring victim activity. The campaign’s covert nature enabled infections to go undetected, raising the risk for organizations and individuals exposed to this advanced surveillance toolset. This incident highlights the rapid evolution of zero-click infection strategies, especially those exploiting web advertising ecosystems. Security teams must double down on threat detection, anomaly response, and zero trust frameworks to counter increasingly stealthy surveillance tools used by both commercial operators and nation-state clients.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Cloudflare Defeats Record 29.7 Tbps DDoS Attack Attributable to AISURU Botnet
Impact· high

Cloudflare Defeats Record 29.7 Tbps DDoS Attack Attributable to AISURU Botnet

In December 2025, Cloudflare successfully detected and mitigated the largest recorded distributed denial-of-service (DDoS) attack, peaking at 29.7 terabits per second. The attack was orchestrated by the AISURU botnet, leveraging up to four million infected hosts to launch a hyper-volumetric assault. The malicious traffic targeted Cloudflare’s infrastructure, testing the limits of web security and putting critical online services at risk of disruption during the 69-second onslaught. This incident illustrates the increasing scale and sophistication of botnet-driven DDoS attacks, forcing organizations to reassess their mitigation strategies. The AISURU attack underscores a troubling trend in the growth of for-hire botnets and record-breaking DDoS volumes seen in 2025. These evolving threats continue to challenge traditional perimeter defenses, making advanced detection, automated response, and robust network segmentation more critical than ever.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
GoldFactory Trojan Infects 11,000+ Mobile Users in Southeast Asia through Fake Banking Apps
Impact· medium

GoldFactory Trojan Infects 11,000+ Mobile Users in Southeast Asia through Fake Banking Apps

Between October and December 2024, a financially motivated threat group known as GoldFactory orchestrated an extensive campaign targeting mobile users across Indonesia, Thailand, and Vietnam. By impersonating trusted government services, the attackers distributed modified Android banking apps laced with malware, resulting in over 11,000 infections. Once installed, these malicious applications harvested sensitive financial data and enabled unauthorized transactions, posing significant financial risks to individual users and undermining trust in mobile banking channels. The campaign used phishing techniques and social engineering, making detection challenging for average users. This incident illustrates the growing trend of cybercriminals leveraging mobile channels and government impersonation to amplify reach and lower the barrier for monetization in emerging markets. It also highlights the urgent need for stronger mobile security controls, user education, and regulatory vigilance to mitigate evolving threats targeting digital financial services.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Intellexa 2024: Spyware Supply Chains Now Targeting Executives Worldwide
Impact· medium

Intellexa 2024: Spyware Supply Chains Now Targeting Executives Worldwide

In 2024, investigators identified a sprawling global network linked to Intellexa, a major commercial spyware developer behind the Predator malware platform. Entities across multiple countries—including the Czech Republic, Kazakhstan, and the Philippines—were found facilitating the shipment and deployment of Intellexa’s surveillance products to government and private sector customers. Notably, targeting expanded beyond civil society to include executives and high-value private sector individuals, with infection vectors leveraging ad-based mechanisms such as the 'Aladdin' platform. This growing balkanized ecosystem enables strategic intelligence gathering, while obfuscating operator and client identities. This incident reflects intensifying arms-race dynamics in the mercenary spyware market, characterized by increased secrecy, proliferation to jurisdictions with weak oversight, and exposure of private sector leaders. The expanding reach and impact have raised urgent concerns over regulatory gaps, legal liability, and escalating risks to both individual privacy and organizational resilience.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports