The Containment Era is here. →Explore

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

747 threat reports
Page 5 of 63

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Telecommunications Threat Reports

Showing 4960 / 747 reports
Iranian Cybercriminal Arrested for $3.4 Billion in Damages
Impact· HIGH

Iranian Cybercriminal Arrested for $3.4 Billion in Damages

In June 2026, Montenegrin authorities, in collaboration with the FBI, arrested a 39-year-old dual Iranian and Turkish citizen in Kotor. The individual is accused of orchestrating mass cyberattacks since 2013, targeting over 150 U.S. universities and causing damages exceeding $3.4 billion. The stolen data reportedly benefited Iran's Islamic Revolutionary Guard Corps and various Iranian state entities. Extradition proceedings are underway in Montenegro's capital, Podgorica. This arrest underscores the persistent threat posed by state-sponsored cyber activities and highlights the importance of international cooperation in combating cybercrime. Organizations should remain vigilant and enhance their cybersecurity measures to protect against such sophisticated attacks.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
European Parliament Member Targeted with Pegasus Spyware During Investigation
Impact· HIGH

European Parliament Member Targeted with Pegasus Spyware During Investigation

In October 2022 and March 2023, former Member of the European Parliament (MEP) Stelios Kouloglou's mobile device was infiltrated with Pegasus spyware while he was serving on the PEGA committee, which was investigating the misuse of such surveillance tools within the European Union. The Citizen Lab's forensic analysis confirmed these infections, indicating that attackers potentially accessed confidential committee documents and deliberations. The specific government or entity responsible for these attacks remains unidentified. ([citizenlab.ca](https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus/?utm_source=openai)) This incident underscores the escalating threat of sophisticated spyware targeting high-profile individuals, including those involved in oversight and investigative roles. It highlights the urgent need for robust cybersecurity measures and regulatory frameworks to protect sensitive information and uphold democratic processes. ([theguardian.com](https://www.theguardian.com/world/2026/jul/03/spyware-used-against-mep-investigating-pegasus-abuses-report-finds?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Google's 2026 Takedown of NetNut Residential Proxy Network
Impact· MEDIUM

Google's 2026 Takedown of NetNut Residential Proxy Network

In July 2026, Google, in collaboration with the FBI and Lumen, significantly disrupted the NetNut residential proxy network, also known as Popa. This network, comprising at least 2 million home devices worldwide, was exploited by cybercriminals and espionage groups to mask malicious activities and conduct password-guessing attacks. Google's actions included disabling accounts and services associated with NetNut's command-and-control operations, leading to a substantial reduction in the network's operational capacity. ([thehackernews.com](https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html?utm_source=openai)) The takedown of NetNut underscores the growing threat posed by residential proxy networks, which can be co-opted by malicious actors to obscure their activities. This incident highlights the critical need for enhanced security measures and vigilance among consumers and organizations to prevent their devices from being exploited in such networks.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Vulnerabilities Discovered in ST Engineering iDirect iQ-Series Terminals
Impact· HIGH

Critical Vulnerabilities Discovered in ST Engineering iDirect iQ-Series Terminals

In July 2026, vulnerabilities were identified in ST Engineering iDirect's iQ-Series Terminals, specifically CVE-2026-38059 and CVE-2026-38057. These flaws allowed unauthenticated attackers to access sensitive device information and execute unauthorized device reboots, potentially leading to denial-of-service conditions. The affected products included Evolution iQ-Series terminals, 3315-Series terminals, and 9-Series terminals, all running firmware versions up to 4.5.2.1. The discovery of these vulnerabilities underscores the critical importance of securing networked devices in sectors such as Communications, Defense Industrial Base, Energy, Government Services, and Transportation Systems. Organizations are urged to update their devices to firmware version 4.5.2.2 or newer and implement recommended security practices to mitigate potential exploitation.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Vulnerability in CubeSpace CW0057 Reaction Wheel Firmware
Impact· LOW

Critical Vulnerability in CubeSpace CW0057 Reaction Wheel Firmware

In July 2026, CubeSpace disclosed a vulnerability (CVE-2026-13743) in its CW0057 Reaction Wheel firmware versions prior to 5.0.20. This flaw allows attackers with physical access to upload malicious firmware without authentication, potentially compromising satellite operations. The issue stems from the device's reliance on CRC-32 integrity checks, which verify data integrity but not the authenticity of the firmware source. CubeSpace has released firmware version 5.0.20, introducing cryptographically verified secure boot, though this feature is not enabled by default and requires user activation. This incident underscores the critical importance of robust firmware authentication mechanisms in aerospace components. As satellites become increasingly integral to global communications and defense, ensuring the integrity of onboard systems is paramount. Organizations must proactively implement and enable security features to mitigate risks associated with unauthorized firmware modifications.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
19-Year-Old Scattered Spider Member Extradited to U.S. for Hacking Charges
Impact· HIGH

19-Year-Old Scattered Spider Member Extradited to U.S. for Hacking Charges

On July 1, 2026, the U.S. Department of Justice announced the extradition of Peter Stokes, a 19-year-old dual U.S. and Estonian citizen, from Finland to the United States. Stokes, identified by the online handle "Bouquet," faces charges of conspiracy, computer intrusion, and fraud for his alleged involvement with the cybercriminal group Scattered Spider. This group has been linked to over 100 network intrusions, resulting in more than $100 million in ransom payments. Stokes appeared in a Chicago federal court on June 30, where he was ordered to remain in custody. The arrest underscores the persistent threat posed by Scattered Spider, known for targeting sectors such as casinos, retailers, and airlines through sophisticated social engineering tactics. Despite recent law enforcement actions, the group's methods continue to evolve, highlighting the need for organizations to bolster their cybersecurity defenses against such adaptive threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Iran-Nexus TAG-182 Deploys MarkiRAT Malware in Surveillance Campaign
Impact· HIGH

Iran-Nexus TAG-182 Deploys MarkiRAT Malware in Surveillance Campaign

In early 2026, the Iranian-linked threat group TAG-182 initiated a cyber espionage campaign deploying MarkiRAT malware via counterfeit Android applications, including fake VPNs and media tools, to surveil Iranian citizens domestically and abroad. This operation aligns with Iran's intensified digital surveillance efforts following the partial restoration of internet access on May 26, 2026, targeting perceived dissidents and foreign collaborators. The MarkiRAT samples exhibit tradecraft overlaps with previous variants used by Ferocious Kitten, suggesting a potential operational connection, though further evidence is required to confirm organizational links. ([staging.hawk-eye.io](https://staging.hawk-eye.io/iran-apt-threat-advisory/?utm_source=openai)) The resurgence of TAG-182's activities underscores the persistent threat posed by Iranian state-sponsored cyber operations, particularly in the realm of surveillance and intelligence gathering. Organizations and individuals, especially those involved in human rights advocacy or opposition activities, should remain vigilant against sophisticated social engineering tactics and ensure robust cybersecurity measures are in place to mitigate the risks associated with such targeted campaigns.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
China-Linked Group Targets Southeast Asia Critical Systems
Impact· HIGH

China-Linked Group Targets Southeast Asia Critical Systems

In mid-2025, the Chinese-speaking advanced persistent threat (APT) group CL-STA-1062 initiated a cyber espionage campaign targeting government entities and critical infrastructure in Southeast Asia. The group compromised at least 10 organizations, including state-owned enterprises in the energy and government sectors, deploying a custom backdoor named TinyRCT. This backdoor facilitated unauthorized access, data exfiltration, and system control, posing significant risks to national security and operational stability. ([thehackernews.com](https://thehackernews.com/2026/06/chinese-speaking-apt-deploys-new.html?utm_source=openai)) The emergence of TinyRCT underscores the evolving sophistication of state-sponsored cyber threats in the region. Organizations must enhance their cybersecurity measures to detect and mitigate such advanced persistent threats, ensuring the resilience of critical infrastructure against future attacks. ([thehackernews.com](https://thehackernews.com/2026/06/chinese-speaking-apt-deploys-new.html?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Urgent: CVE-2026-8037 Vulnerability in Progress Kemp LoadMaster Under Active Exploitation
Impact· CRITICAL

Urgent: CVE-2026-8037 Vulnerability in Progress Kemp LoadMaster Under Active Exploitation

In June 2026, a critical security vulnerability identified as CVE-2026-8037 was discovered in Progress Kemp LoadMaster, an application delivery controller widely used in enterprise environments. This OS command injection flaw allows unauthenticated attackers to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple API command endpoints. The vulnerability affects LoadMaster versions GA v7.2.63.1 and earlier, as well as LTSF v7.2.54.17 and earlier. Exploitation attempts were first observed on June 29, 2026, originating from specific IP addresses, though initial attempts were unsuccessful. ([thehackernews.com](https://thehackernews.com/2026/07/latest-progress-kemp-loadmaster-pre.html?utm_source=openai)) The availability of a proof-of-concept exploit and detailed technical analyses has heightened the risk of successful attacks. Organizations using affected LoadMaster versions are urged to apply the patches released by Progress Kemp immediately and restrict API access to trusted networks to mitigate potential exploitation. ([qpulse.quasarcybertech.com](https://qpulse.quasarcybertech.com/news/4414/critical-unauthenticated-rce-vulnerability-in-progress-kemp-loadmaster-cve-2026-8037?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Malicious PyPI Packages Compromise Telegram Bot Servers in 2026
Impact· MEDIUM

Malicious PyPI Packages Compromise Telegram Bot Servers in 2026

Between November 2025 and June 2026, a campaign dubbed 'Operation Navy Ghost' targeted Python developers creating Telegram bots by distributing trojanized versions of the Pyrogram library on the Python Package Index (PyPI). These malicious packages, including 'VLifeGram' and 'pyrogram-styled', contained a hidden backdoor that, upon activation, allowed attackers to execute arbitrary code and access sensitive data on compromised servers. The backdoor was designed to operate silently, suppressing errors and disabling logging, thereby granting attackers extensive control over the affected systems. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/malicious-pypi-packages-give-hackers-control-of-telegram-bot-servers/?utm_source=openai)) This incident underscores the persistent threat of supply chain attacks in open-source ecosystems. The exploitation of widely-used libraries like Pyrogram highlights the need for developers to exercise caution when integrating third-party packages. Ensuring the integrity of software dependencies is crucial to prevent unauthorized access and data breaches.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
RustDuck Botnet's Evolution: A New Era of DDoS Threats
Impact· CRITICAL

RustDuck Botnet's Evolution: A New Era of DDoS Threats

Since February 2026, the RustDuck botnet has been actively compromising home routers, IP cameras, Android devices, and poorly secured servers to orchestrate large-scale Distributed Denial-of-Service (DDoS) attacks. Researchers at QiAnXin's XLab have observed its rapid evolution, notably transitioning its core codebase from C to Rust, enhancing its adaptability and resistance to analysis. The malware propagates through weak password brute-forcing on Telnet/SSH services and exploits various remote code execution vulnerabilities in devices from manufacturers like TVT, Ruijie, TP-Link, and ZTE, as well as web applications such as ThinkPHP, Jenkins, and Hadoop YARN. ([thehackernews.com](https://thehackernews.com/2026/06/rustduck-botnet-rebuilds-in-rust-to.html?utm_source=openai)) The emergence of RustDuck underscores a concerning trend in botnet development, where threat actors adopt modern programming languages like Rust to create more resilient and evasive malware. This shift complicates detection and mitigation efforts, highlighting the need for continuous adaptation in cybersecurity defenses. ([thehackernews.com](https://thehackernews.com/2026/06/rustduck-botnet-rebuilds-in-rust-to.html?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical Vulnerability in Progress Kemp LoadMaster: CVE-2026-8037
Impact· CRITICAL

Critical Vulnerability in Progress Kemp LoadMaster: CVE-2026-8037

In June 2026, a critical vulnerability (CVE-2026-8037) was identified in Progress Kemp LoadMaster, an application delivery controller and load balancer. This flaw allows unauthenticated attackers to execute arbitrary commands as root by sending crafted requests to the API, due to improper input sanitization in the escape_quotes() function. The vulnerability affects LoadMaster GA v7.2.63.1 and earlier, and LTSF v7.2.54.17 and earlier. Progress released patches (GA v7.2.63.2 and LTSF v7.2.54.18) to address this issue. ([thehackernews.com](https://thehackernews.com/2026/06/progress-kemp-loadmaster-flaw-could-let.html?utm_source=openai)) The discovery of this vulnerability underscores the ongoing risks associated with API security and input validation flaws. Organizations are urged to promptly apply the provided patches and review their API security measures to prevent potential exploitation. ([thehackernews.com](https://thehackernews.com/2026/06/progress-kemp-loadmaster-flaw-could-let.html?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports