✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Cisco Firewalls Under Siege: 2024 Zero-Day Flaws Trigger DoS Attacks on ASA & FTD
In June 2024, Cisco disclosed that two actively exploited zero-day vulnerabilities in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) firewalls were being weaponized in the wild. Attackers leveraged these flaws (CVE-2024-20353 and CVE-2024-20359) to trigger repeated reboot loops, effectively causing Denial-of-Service (DoS) on critical network perimeter defenses. Initial exploitation began as targeted zero-days, but attackers quickly adopted the flaws in larger campaigns, dramatically impacting the availability and security of organizations relying on Cisco ASA or FTD devices. The incident underscores a growing trend of targeting infrastructure security devices as a primary attack vector, especially given the rise of ransomware actors and APT groups seeking disruption over data theft. Exploitation of device vulnerabilities for DoS attacks highlights the heightened urgency for rapid patching and robust segmentation in modern enterprise environments.
6 months ago
Kill Chain
LandFall Spyware: Samsung Zero-Day Exploited Through WhatsApp (2024 Attack Insights)
In early 2024, cybersecurity researchers identified that a sophisticated threat actor exploited a zero-day vulnerability in Samsung’s Android image processing library to deploy a previously unknown spyware, dubbed 'LandFall.' The attackers delivered malicious images via WhatsApp messages, abusing the image parsing process to gain device access without user interaction. Once installed, LandFall enabled covert surveillance, exfiltration of private data, and remote control capabilities, putting millions of Samsung devices at risk globally—especially given the attack’s stealthy, user-independent execution method. The breach demonstrates a significant advancement in mobile spyware delivery and a major supply chain risk for mobile OS providers. This incident is highly relevant as attackers increasingly leverage messaging platforms and zero-click vulnerabilities to distribute advanced spyware. The weaponization of zero-days against widespread consumer hardware underscores the urgent need for rapid vulnerability detection and robust response protocols across the mobile ecosystem.
6 months ago
Kill Chain
Samsung 2025: LANDFALL Zero-Day Spyware Breach Exposes Enterprise Mobile Risks
In October 2025, a critical zero-day vulnerability (CVE-2025-21042) in Samsung Galaxy Android devices was actively exploited in the wild to deploy commercial-grade Android spyware known as LANDFALL. Attackers leveraged an out-of-bounds write flaw in the 'libimagecodec.quram.so' component through remote zero-click techniques, enabling arbitrary code execution without user interaction. Targeted campaigns, primarily in the Middle East, allowed adversaries to gain full device access and conduct covert surveillance until Samsung issued an urgent patch. The attacks highlight the sophistication and stealth of modern mobile threat actors and the increasing use of zero-day exploits to compromise mobile endpoints. This incident exemplifies the rise of highly targeted mobile spyware attacks leveraging zero-day vulnerabilities in globally popular hardware. It signals a broader trend in which commercial surveillance tools are abused by both state and non-state actors, driving greater urgency around mobile threat detection, zero-trust controls, and rapid patch management in enterprise environments.
6 months ago
Kill Chain
Chinese Nation-State Hackers Breach U.S. Non-Profit Using Legacy Bugs
In early 2025, a China-linked advanced persistent threat (APT) group carried out a sophisticated cyber espionage campaign targeting a prominent U.S. non-profit focused on policy issues. Leveraging legacy vulnerabilities such as Log4j and Microsoft IIS flaws, the attackers gained initial access, established persistent footholds, and conducted covert data exfiltration operations while remaining undetected for several months. According to detailed analyses by Symantec and Carbon Black, the group focused on harvesting sensitive documents related to U.S. government policy and influencing discussions through clandestine activity within compromised systems, amplifying strategic risk to both the organization and its stakeholders. This incident exemplifies a broader trend of nation-state actors weaponizing unpatched, well-known vulnerabilities for long-term espionage. Organizations with legacy infrastructure are increasingly attractive targets, underscoring the urgent need for proactive vulnerability management, encrypted traffic controls, and robust east-west security to counter evolving, identity-driven threats.
6 months ago
Kill Chain
LANDFALL Spyware: Exploiting CVE-2025-21042 Against Samsung Android Devices
In early 2025, the commercial-grade spyware known as LANDFALL was discovered targeting Samsung Android devices. Leveraging the newly identified CVE-2025-21042, attackers embedded the spyware in specially crafted malicious DNG image files. When unsuspecting users opened these images, the exploit chain compromised the underlying image processing library, granting attackers unauthorized access to device data, communications, and possibly real-time surveillance capabilities. This incident highlights yet another example of sophisticated supply chain exploitation aimed at high-value mobile assets, resulting in potential data exposure, loss of privacy, and reputational damage for affected organizations and individuals. LANDFALL’s attack chain signals an alarming new era for mobile threats, emphasizing the rapid weaponization of zero-days on widely deployed platforms. With growing regulatory scrutiny, businesses must closely examine mobile security controls and incident response readiness given the increasing complexity of modern spyware campaigns.
6 months ago
Kill Chain
Cisco's 2024 Critical UCCX Flaw Exposes Root-Level Risks
In June 2024, Cisco disclosed a critical vulnerability (CVE-2024-20253) in its Unified Contact Center Express (UCCX) software, which could allow remote attackers to execute arbitrary commands with root privileges on affected systems. The flaw, which is due to improper validation of user-supplied input, does not require user authentication and is rated 9.9 out of 10 in severity. Malicious actors exploiting this vulnerability could gain full control over the underlying infrastructure, potentially leading to data breaches, service interruptions, or lateral movement within an organization's network. Cisco has issued security patches, and there are currently no reports of exploitation in the wild. The incident underscores the urgent need for prompt patch management and reinforces the trend of attackers rapidly leveraging zero-day and critical vulnerabilities in widely deployed enterprise platforms. Organizations must prioritize vulnerability management and maintain strict network segmentation to contain similar risks in their environments.
6 months ago
Kill Chain
Cisco Firewall DoS Attack: How CVE-2025-20333 & CVE-2025-20362 Disrupted Critical Networks
In November 2025, Cisco disclosed a vulnerability exploitation campaign targeting its Secure Firewall ASA and Threat Defense (FTD) devices. Threat actors actively weaponized two zero-day vulnerabilities, CVE-2025-20333 and CVE-2025-20362, to force vulnerable appliances to unexpectedly reload, resulting in denial-of-service (DoS) conditions that disrupted network operations. Affected organizations saw service disruptions, increased operational risk, and potential visibility gaps, especially where patch management or segmentation was lacking. Cisco responded by recommending immediate updates, enhanced monitoring, and deployment of compensating security controls until all devices are patched. This incident underscores a continuing trend of attackers rapidly exploiting unpatched firewall vulnerabilities, threatening the network perimeter’s reliability. The rise in sophisticated DoS tactics against infrastructure devices points to an urgent need for proactive patching, segmentation, and visibility into both perimeter and east-west traffic.
6 months ago
Kill Chain
Cloudflare Top Domain Rankings Compromised by Aisuru Botnet in 2025
In October 2025, Cloudflare faced an unprecedented attack by the Aisuru botnet, a rapidly scaling network of compromised IoT devices. The botnet leveraged its vast fleet to overwhelm Cloudflare's public DNS resolver (1.1.1.1) with massive volumes of automated queries, propelling its malicious command-and-control domains to the top ranks of Cloudflare's most-queried website list. This manipulation triggered widespread concern over data integrity and brand confusion, as Aisuru domains temporarily displaced legitimate top domains like Google and Apple. In response, Cloudflare resorted to redacting and eventually removing suspicious domains from its ranking list, highlighting significant security gaps in popular trust datasets. This incident underscores the mounting risk posed by large IoT botnets to critical internet infrastructure, including DNS reliability and reputation-based services. It reveals how attackers exploit both technical and social trust mechanisms, with potential downstream effects on security decisions that leverage third-party domain rankings.
6 months ago
Kill Chain
Bronze Butler Exploits Zero-Day to Breach Japanese Enterprise Networks
In early 2025, Chinese state-sponsored APT group 'Bronze Butler' exploited a zero-day vulnerability (CVE-2025-61932) in a widely used endpoint management platform to penetrate several Japanese organizations. The attackers gained privileged access by leveraging the flaw for initial compromise, then established persistence and moved laterally across victims’ networks. Exfiltrated data included sensitive business documents and internal communications. The coordinated campaign went undetected for weeks, resulting in significant operational disruption and exposure of confidential assets, raising alarms about cyber-espionage threats facing Japan’s critical industries. This breach highlights the intensifying use of zero-day vulnerabilities by advanced threat actors for targeting supply chain software and trusted management tools. Similar recent attacks signal a broader trend of sophisticated, nation-state-driven intrusions against key sectors in Asia, and reinforce the urgent need for proactive patch management and stronger east-west network segmentation.
6 months ago
Kill Chain
Kimsuky Unleashes HTTPTroy Backdoor in Targeted Attack on South Korea
In early 2024, the North Korean state-sponsored group Kimsuky launched a targeted cyberespionage campaign using a new backdoor called HTTPTroy, aimed at South Korean users. Leveraging sophisticated obfuscation and advanced anti-analysis features, Kimsuky distributed the malware primarily via phishing emails containing malicious attachments. Once installed, HTTPTroy enabled the attackers to execute commands remotely and exfiltrate sensitive data while evading detection. The campaign underscores the increasing technical capabilities of North Korean APT groups and their persistent focus on South Korean government, critical infrastructure, and research sectors. This incident highlights an accelerating trend of advanced persistent threats deploying stealthy, resilient malware to bypass traditional defenses. As attackers evolve their toolchains, organizations—especially in frequently targeted regions—face heightened risk from espionage operations that blend social engineering, evasion tactics, and custom malware.
6 months ago
Kill Chain
Inside the 2025 Cybercrime Merger: Scattered Spider, LAPSUS$, and ShinyHunters Unite
In August 2025, a powerful new cybercrime collective emerged from the merger of Scattered Spider, LAPSUS$, and ShinyHunters—three of the most notorious threat groups involved in high-profile data theft, ransomware, and extortion. This unified entity quickly established 16 Telegram channels to coordinate attacks, evade platform moderation, and amplify operations. Leveraging advanced social engineering and data exfiltration techniques, the collective launched a string of multinational breaches targeting enterprises, exposing sensitive information and causing significant financial and reputational harm to victims. Security teams observed an uptick in lateral movement, exploitation of hybrid/cloud environments, and sophisticated policy evasion tied to these actors. This incident exemplifies a growing trend where cybercriminal syndicates combine resources and expertise, accelerating the pace and scale of attacks. The merger highlights the urgent need for organizations to adapt to evolving threat actor alliances and reinforces the importance of advanced segmentation, zero trust, and robust monitoring frameworks.
6 months ago
Kill Chain
IDIS ICM Viewer 2025: Critical Application Vulnerability Risk Exposed
In November 2025, IDIS disclosed a critical vulnerability (CVE-2025-12556) in its ICM Viewer application, enabling remote attackers to execute arbitrary code via improper neutralization of argument delimiters—a classic argument injection flaw. The vulnerability, scored CVSS v4 8.7, affected version 1.6.0.10 and allowed exploitation through low-complexity attacks requiring only limited privileges. The flaw could provide adversaries with broad control over vulnerable systems, directly impacting critical communications infrastructure deployed worldwide and potentially undermining operational continuity and data integrity. This incident highlights the growing risk posed by supply chain and application-layer vulnerabilities in industrial and communications networks. The prevalence of remote, low-complexity exploits underscores the urgent need for robust patch management and defense-in-depth approaches, especially as regulators intensify scrutiny of critical infrastructure cybersecurity.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports