✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Critical Command Injection Flaw Found in TP-Link Omada Gateways (2024)
In June 2024, TP-Link disclosed a critical security vulnerability (CVE-2024-5035) affecting several Omada gateway models. The flaw is a pre-authentication operating system command injection that could allow remote, unauthenticated attackers to execute arbitrary commands on vulnerable devices, compromising the integrity and availability of network infrastructure. TP-Link quickly released firmware patches, urging customers to update immediately. This exposure heightened the risk of unauthorized access to internal networks, potentially leading to data breaches, lateral movement, or infrastructure disruption for organizations reliant on impacted Omada devices. The incident underscores an ongoing trend of targeting network infrastructure via supply chain or firmware vulnerabilities, which have become increasingly prevalent as attackers seek to exploit core networking hardware. This highlights the need for vigilant patch management and segmentation in defense strategies, as well as resilience against emerging firmware and gateway attacks.
6 months ago
Kill Chain
Europol Busts Global SIM Farm Fueling Industrial-Scale Fake Accounts and Cybercrime
In October 2025, Europol led Operation SIMCARTEL to dismantle a sophisticated cybercrime-as-a-service (CaaS) organization running an extensive SIM farm network. This criminal service provisioned more than 49 million SIM cards to cybercriminals worldwide, enabling the rapid creation and management of fake online accounts. Threat actors leveraged the infrastructure for phishing campaigns, investment fraud, impersonation, and large-scale social engineering schemes, causing substantial financial and reputational harm to both individuals and businesses. The coordinated law enforcement operation involved 26 property searches, resulted in seven arrests, and the seizure of equipment and digital assets tied to the illicit platform. This incident highlights the growing industrialization of cybercrime, where turnkey services significantly lower the barrier to entry and accelerate threat actor operations. Law enforcement and the security industry face increasing challenges as cybercriminals exploit scalable CaaS platforms, requiring organizations to modernize their defenses and policy enforcement.
6 months ago
Kill Chain
NSA’s Multi-Tool Cyber Assault on Beijing’s National Time Service Center: Lessons for Critical Infrastructure
In October 2025, China's Ministry of State Security (MSS) accused the U.S. National Security Agency (NSA) of orchestrating a sophisticated, multi-stage cyberattack against the National Time Service Center (NTSC) in Beijing. The MSS claims that the NSA deployed at least 42 distinct cyber tools to penetrate critical national infrastructure, leveraging advanced techniques such as encrypted and east-west traffic manipulation, zero trust segmentation circumvention, and covert remote access. The compromise included strategic lateral movement and evasion of detection, reportedly leaving a significant impact on the operational integrity of NTSC, which serves as a reference point for the nation’s official timekeeping and scientific endeavors. This incident marks an escalation in cyber power projection between nation-states and spotlights the increasing use of multi-tool modular attack frameworks by advanced persistent threats (APTs). The breach underscores the urgency for critical infrastructure operators worldwide to reevaluate network segmentation, encrypted communications, and visibility gaps in light of evolving nation-state tactics.
6 months ago
Kill Chain
131 Chrome Extensions Hijack WhatsApp Web: The 2025 Brazilian Spam Campaign
In October 2025, a coordinated cyberattack was uncovered where 131 malicious Chrome browser extensions—clones of a popular WhatsApp Web automation tool—were used to hijack users’ sessions and launch an automated spam campaign targeting Brazilian users. Researchers from security company Socket found that these plugins, sharing an identical codebase and infrastructure, infected over 20,000 users by enticing them to install seemingly legitimate add-ons, enabling attackers to take control of browser sessions, inject spam messages, and exfiltrate private data at scale. The incident underscores the risks associated with browser extension supply chain threats, exposing enterprises and individuals to large-scale account compromise and privacy breaches. This breach is particularly significant as it demonstrates the adaptability and persistence of threat actors in abusing browser supply routes and leveraging rebranded extensions to evade traditional security controls. The campaign’s targeting of WhatsApp Web also signals a shift toward exploiting widely-used communication channels for coordinated spam and fraud, spotlighting the critical need for proactive browser extension vetting and user awareness.
6 months ago
Kill Chain
The F5 2025 Multi-Vector Breach: A Wake-up Call for Hybrid Cloud Defense
In October 2025, F5 Networks experienced a sophisticated multi-vector cyber breach in which attackers gained undetected foothold within its environment for a prolonged period. The adversaries reportedly exploited a combination of Linux rootkits, encrypted traffic evasion, and a new attack method known as Pixnapping to laterally move between internal workloads and exfiltrate sensitive data. Their persistence was enabled by bypassing both east-west and egress security controls, leveraging cloud-native environments and covert remote access tools, before the intrusion was detected. Business operations were disrupted, and F5 initiated incident response and regulatory disclosures. This breach underscores the urgent reality that advanced attackers employ stealthy, multi-stage tactics, exploiting visibility gaps, lateral pathways, and cloud complexity. As such, it highlights the evolving need for proactive threat detection, zero trust segmentation, and continuous monitoring in today’s hybrid enterprise landscapes.
6 months ago
Kill Chain
Salt Typhoon Breaches European Telecom via Citrix Flaw and Snappybee Malware
In July 2025, a major European telecommunications provider suffered a targeted cyber espionage breach attributed to Salt Typhoon (aka Earth Estries), a suspected China-nexus group. Attackers exploited a vulnerability in a Citrix NetScaler Gateway appliance to gain initial access, then deployed the custom Snappybee malware for persistent network infiltration and surveillance. The operation allowed lateral movement across critical systems, putting sensitive customer and infrastructure data at risk. Timely detection by Darktrace helped contain the breach, but the incident highlights the telecom industry's growing exposure to sophisticated APT tactics and advanced malware. This breach exemplifies how state-aligned actors are exploiting enterprise VPN and appliance vulnerabilities for initial access, a recurring trend influencing regulatory scrutiny and CISO priorities. Telecom providers remain high-value targets due to their access to critical national infrastructure and vast troves of sensitive data.
6 months ago
Kill Chain
PolarEdge Botnet Targets Cisco, ASUS, QNAP, Synology Routers in 2025 Operation
In February 2025, security researchers uncovered a sophisticated botnet campaign dubbed PolarEdge, targeting router devices produced by Cisco, ASUS, QNAP, and Synology. The attackers leverage a custom TLS-based ELF implant to compromise home and enterprise routers, enlisting them into an expanding botnet. Initial infection vectors are believed to exploit known and zero-day vulnerabilities in router firmware, granting the threat actors persistent access and control over thousands of devices globally. The current purpose of the PolarEdge botnet remains undetermined, but activity suggests ongoing monitoring, traffic manipulation, and possible lateral movement within affected networks. Organizations with exposed or outdated devices face heightened operational risk, including surveillance, DDoS, and data interception. This incident underscores the growing menace of router-based botnets leveraging encrypted payloads and advanced evasion techniques. With a surge in attacks on network edge hardware and the proliferation of Internet of Things (IoT) devices, organizations must prioritize firmware patching, network segmentation, and comprehensive threat detection to mitigate emerging risks.
6 months ago
Kill Chain
US Court Bars NSO Group from Targeting WhatsApp Users with Spyware
In June 2024, a U.S. federal judge issued a permanent injunction against NSO Group, prohibiting the Israeli spyware developer from targeting WhatsApp users with its surveillance products. The case originated from a 2019 incident in which NSO Group exploited flaws in WhatsApp's messaging platform to compromise user privacy, prompting Meta (WhatsApp's parent company) to launch a protracted legal battle. The court recognized the significant risk posed to Meta's business and user trust, as WhatsApp's core value proposition is secure, end-to-end encrypted communications. The injunction was coupled with a major reduction in damages, from $167.3 million to $4 million, marking a significant legal precedent in the spyware industry. This decision highlights mounting regulatory and legal scrutiny on commercial spyware vendors and underscores the increasing stakes for companies offering encrypted services. The ruling signals judicial awareness of privacy threats from advanced surveillance tools and may embolden similar litigation or policy action worldwide.
6 months ago
Kill Chain
NSA-Linked Cyberattack Highlights Risks to China’s National Time Service Center (2023–2024)
Between March 2022 and June 2024, China’s National Time Service Center reportedly fell victim to a sophisticated cyber-espionage campaign allegedly orchestrated by the U.S. National Security Agency (NSA). Attackers initially compromised employee mobile devices via a text-messaging service vulnerability, leading to credential theft and enabling unauthorized access to the Center’s internal systems by April 2023. From August 2023 onward, the NSA purportedly leveraged a suite of 42 advanced cyber tools to target sensitive infrastructure, using VPNs and forged certificates to evade detection and bypass defenses. The attack put critical services at risk, with potential consequences including network disruption, financial system instability, and interruptions to vital communications and national defense functions. This incident underscores escalating nation-state cyber competition, especially over foundational infrastructure. The methods used—mobile device exploitation, lateral movement, and evasion through encrypted channels—reflect trending Tactics, Techniques, and Procedures (TTPs) in state-sponsored attacks, raising concerns for governments and critical sectors worldwide about supply chain and timing-related risks.
6 months ago
Kill Chain
Europol Takedown of SIMCARTEL: SIM Box Fraud Network Disrupted
In October 2024, Europol led a coordinated international operation to dismantle a sophisticated cybercrime syndicate known as "SIMCARTEL". This network, spanning Austria, Estonia, and Latvia, leveraged over 1,200 SIM box devices and 40,000 active SIM cards to conduct large-scale phishing, credential theft, and financial fraud across more than 3,200 recorded cases. Authorities linked the group to $5.8 million in financial losses, the creation of 49 million fraudulent accounts, and infrastructure facilitating criminal services in over 80 countries. The takedown resulted in seven arrests, seizure of servers, SIMs, websites, luxury vehicles, and the freezing of suspect assets. This incident highlights the growing global threat posed by SIM farms and SIM box networks, which enable scammers to evade detection, commit diverse types of fraud, and undermine trust in online communications. The rapid adoption of similar tactics worldwide puts financial institutions, telecoms, and consumers increasingly at risk.
6 months ago
Kill Chain
F5 Supply Chain Breach 2025: China-Linked Attack Exposes Global BIG-IP Risk
In October 2025, F5 Networks disclosed a major cybersecurity incident involving a China-linked nation-state group (UNC5291) that gained unauthorized access to its infrastructure. Attackers reportedly maintained covert access for at least a year, stealing F5 BIG-IP source code and information on as-yet-undisclosed vulnerabilities. While F5 stated there’s no evidence of active exploitation of these flaws, the breach affects more than 266,000 exposed BIG-IP instances worldwide. The attackers leveraged advanced persistence techniques and deployed specialized malware, raising serious concerns about global supply chain integrity. This breach highlights the persistent targeting of critical infrastructure vendors by highly resourced nation-state actors. Government agencies and enterprises face heightened urgency as regulatory bodies issue emergency directives to patch devices, with compliance and operational risks elevated by the scale and sophistication of the attack.
6 months ago
Kill Chain
Europol Busts Massive SIM-Box Cybercrime Network in 2025
In October 2025, Europol led a major operation codenamed 'SIMCARTEL' that dismantled an extensive SIM-box network servicing global cybercriminals. The illicit operation spanned multiple countries, employed 1,200 SIM-box devices and 40,000 SIM cards, and provided fake phone numbers for cybercrimes such as phishing, fraud, impersonation, and extortion. Two key websites, gogetsms.com and apisim.com, were seized. Authorities arrested seven suspects, confiscated servers and luxury assets, and froze significant cryptocurrency and bank funds. Investigators linked the service to at least 3,200 fraud cases and a direct financial loss exceeding €4.5 million, with indications the service was used to create over 49 million fraudulent online accounts. This incident underscores a growing trend in Cybercrime-as-a-Service, where sophisticated tools enable large-scale identity obfuscation and fraud. The takedown reflects mounting law enforcement pressure on criminal infrastructure rentals fueling online financial crime, highlighting urgent regulatory and security challenges for organizations reliant on voice and messaging account verification.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports