The Containment Era is here. →Explore

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

747 threat reports
Page 6 of 63

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Telecommunications Threat Reports

Showing 6172 / 747 reports
Discovery of 'Short-Sleeve' RSA Keys Poses Significant Security Risk
Impact· HIGH

Discovery of 'Short-Sleeve' RSA Keys Poses Significant Security Risk

In June 2026, researchers from Trail of Bits and the badkeys project identified a critical vulnerability in RSA keys characterized by patterns of zeros, termed "short-sleeve" RSA keys. These keys, found in public sources like Certificate Transparency logs and SSH hosts, were associated with major organizations such as Yahoo and Verizon, as well as devices running NetApp software and CompleteFTP software from EnterpriseDT. The vulnerability, stemming from improper key generation processes, allows attackers to factor the public modulus and derive private keys, compromising encrypted communications and data integrity. ([blog.trailofbits.com](https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/?utm_source=openai)) This discovery underscores the persistent risks associated with flawed cryptographic implementations. Organizations must prioritize regular audits of cryptographic keys and ensure adherence to secure key generation practices to mitigate potential breaches.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
KDDI Data Breach Exposes 14.2 Million Email Logins Across Six ISPs
Impact· HIGH

KDDI Data Breach Exposes 14.2 Million Email Logins Across Six ISPs

In June 2026, KDDI Corporation, a major Japanese telecommunications operator, disclosed a data breach affecting its email systems used by six internet service providers (ISPs). The breach, discovered on June 17, resulted from attackers exploiting a vulnerability in third-party software, potentially exposing up to 14.2 million email addresses and passwords. The affected ISPs include STNet, JCOM, Chubu Telecommunications, NIFTY, BIGLOBE, and KDDI Web Communications. KDDI promptly blocked the attacker and implemented defensive measures upon detection. This incident underscores the critical importance of securing third-party software components within shared infrastructure environments. As cyber threats continue to evolve, organizations must rigorously assess and monitor the security of all integrated software solutions to prevent similar breaches.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
U.S. Offers $10 Million Reward for Information on Russian Hackers Targeting Encrypted Messaging Apps
Impact· HIGH

U.S. Offers $10 Million Reward for Information on Russian Hackers Targeting Encrypted Messaging Apps

In June 2026, the U.S. Department of State announced a reward of up to $10 million for information leading to the identification or location of members of the Russian-linked cyber groups UNC5792 and UNC4221. These groups have been implicated in extensive phishing campaigns targeting Signal and WhatsApp accounts of U.S. government officials, military leaders, and allied personnel. The attackers employed social engineering tactics, impersonating support agents to deceive users into revealing their backup recovery keys, thereby gaining access to their encrypted communications. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/us-offers-10-million-for-hackers-targeting-whatsapp-signal-users/?utm_source=openai)) This incident underscores the evolving nature of cyber threats, particularly the sophisticated use of social engineering to bypass encryption safeguards. It highlights the critical need for heightened vigilance and robust security protocols to protect sensitive communications, especially for individuals in positions of authority or influence.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Gamaredon's 2025 Cyber Offensive: Unveiling New Malware and Tactics
Impact· HIGH

Gamaredon's 2025 Cyber Offensive: Unveiling New Malware and Tactics

In 2025, the Russian-aligned APT group Gamaredon intensified its cyber operations against Ukrainian governmental and military institutions. ESET observed 35 distinct spear-phishing campaigns, primarily in the latter half of the year, utilizing archive attachments and XHTML files with HTML smuggling to deploy malicious HTA downloaders. These campaigns aimed to exfiltrate sensitive information to support Russian interests in the ongoing conflict. Gamaredon also exploited a WinRAR vulnerability (CVE-2025-8088) to achieve persistence by placing malicious files in the Windows Startup folder. Additionally, the group introduced six new PowerShell tools, including PteroDee and PteroCache, to enhance their malware arsenal. ([thehackernews.com](https://thehackernews.com/2026/06/gamaredon-expands-ukraine-attacks-with.html?utm_source=openai)) The group's reliance on third-party services grew significantly, employing tunnel services and serverless platforms to conceal their infrastructure. This evolution underscores the increasing sophistication of state-sponsored cyber threats and the necessity for robust cybersecurity measures to protect sensitive governmental data. ([thehackernews.com](https://thehackernews.com/2026/06/gamaredon-expands-ukraine-attacks-with.html?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Massive Crypto Scam Operation Exploits DCloud Uni-App Framework
Impact· HIGH

Massive Crypto Scam Operation Exploits DCloud Uni-App Framework

In June 2026, cybersecurity firm Infoblox uncovered that over 236,000 websites were utilizing investment scam templates built with the DCloud Uni-App framework. These sites facilitated a range of fraudulent activities, including fake cryptocurrency exchanges, phishing schemes, and crypto wallet drainers. The malicious domains spanned multiple continents and languages, indicating a coordinated effort by various threat actors. Notably, the RainbowEx platform, implicated in a Ponzi scheme affecting thousands in Argentina in late 2024, was among the identified domains. ([thehackernews.com](https://thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html?utm_source=openai)) The exploitation of legitimate development frameworks like DCloud Uni-App underscores the evolving tactics of cybercriminals. This incident highlights the critical need for organizations to implement robust security measures, including thorough vetting of third-party tools and continuous monitoring for suspicious activities. ([thehackernews.com](https://thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Russian Intelligence Exploits Fake Support Texts to Breach Messaging Accounts
Impact· HIGH

Russian Intelligence Exploits Fake Support Texts to Breach Messaging Accounts

In June 2026, the Security Service of Ukraine (SSU), in collaboration with the U.S. Federal Bureau of Investigation (FBI), uncovered a prolonged cyber espionage campaign orchestrated by Russian intelligence services. This operation targeted government officials, military personnel, politicians, and activists across Ukraine, Europe, and the United States. The attackers employed social engineering tactics, sending SMS messages that impersonated messaging platform support services to deceive recipients into divulging their account credentials. The primary objective was to access sensitive military, political, and economic information, as well as personal data. ([thehackernews.com](https://thehackernews.com/2026/06/ukraine-says-russian-intelligence-used.html?utm_source=openai)) This incident underscores the escalating sophistication of state-sponsored cyber threats, particularly those leveraging social engineering to exploit human vulnerabilities. Organizations and individuals must remain vigilant, adopting robust security measures such as two-factor authentication and regular monitoring of account activities to mitigate the risks posed by such targeted attacks.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Impact· CRITICAL

CISA Adds Two Known Exploited Vulnerabilities to Catalog

On June 25, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-12569, an improper input validation vulnerability in PTC Windchill and FlexPLM, and CVE-2026-20230, a server-side request forgery (SSRF) vulnerability in Cisco Unified Communications Manager. These vulnerabilities are actively exploited by malicious actors, posing significant risks to federal enterprises. CISA's Binding Operational Directive (BOD) 26-04 mandates federal agencies to prioritize remediation of such high-risk vulnerabilities to protect their networks against active threats. While BOD 26-04 applies to Federal Civilian Executive Branch (FCEB) agencies, CISA encourages all organizations to adopt risk-based vulnerability management practices and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to update the catalog as new vulnerabilities are identified.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Russian Intelligence Services' Phishing Campaigns Targeting Messaging Apps in 2026
Impact· HIGH

Russian Intelligence Services' Phishing Campaigns Targeting Messaging Apps in 2026

In March 2026, the FBI and CISA issued a Public Service Announcement warning of ongoing phishing campaigns by Russian Intelligence Services (RIS) targeting commercial messaging applications (CMAs) such as Signal and WhatsApp. These campaigns aim to compromise individual user accounts by impersonating official support channels and tricking users into sharing verification codes or personal information. High-value targets include U.S. government officials, military personnel, political figures, and journalists. Once access is gained, attackers can view messages, contact lists, and conduct further phishing attacks. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260626?utm_source=openai)) This incident underscores the persistent threat posed by nation-state actors employing social engineering tactics to bypass encryption and gain unauthorized access to sensitive communications. The rise in such targeted phishing campaigns highlights the need for heightened vigilance and robust security practices among users of CMAs.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Urgent Patching Required for Exploited Cisco and PTC Vulnerabilities
Impact· CRITICAL

Urgent Patching Required for Exploited Cisco and PTC Vulnerabilities

In June 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) mandated federal agencies to urgently patch two critical vulnerabilities: CVE-2026-20230 in Cisco Unified Communications Manager (Unified CM) and CVE-2026-12569 in PTC's Windchill and FlexPLM products. CVE-2026-20230 is a server-side request forgery (SSRF) flaw that allows unauthenticated remote attackers to write files to the operating system, potentially leading to root privilege escalation. CVE-2026-12569 is a remote code execution (RCE) vulnerability arising from the deserialization of untrusted data, affecting multiple versions of Windchill and FlexPLM. Both vulnerabilities were actively exploited, prompting CISA to set a remediation deadline of June 28, 2026. The urgency of these patches underscores the increasing sophistication and frequency of cyberattacks targeting critical infrastructure. Organizations must prioritize timely vulnerability management and adopt proactive security measures to mitigate risks associated with such exploits.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Chinese APT CL-STA-1062's Deployment of TinyRCT Backdoor in Southeast Asia
Impact· HIGH

Chinese APT CL-STA-1062's Deployment of TinyRCT Backdoor in Southeast Asia

In 2025, the Chinese-speaking advanced persistent threat (APT) group CL-STA-1062 targeted government entities and critical infrastructure in Southeast Asia, focusing on state-owned enterprises in the energy and government sectors. The attackers employed a hybrid toolkit, including common open-source tools like SoftEther VPN and Mimikatz, alongside a newly developed backdoor named TinyRCT. This backdoor facilitated arbitrary command execution, file exfiltration, screen capture, and included a self-destruct mechanism to erase forensic evidence. The campaign involved initial access through web application exploitation, deployment of ASPX web shells, and subsequent reconnaissance and lateral movement within the compromised networks. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/?utm_source=openai)) This incident underscores the evolving sophistication of APT groups in developing custom malware to infiltrate critical infrastructure. The use of TinyRCT highlights the need for organizations to enhance their detection capabilities and implement robust security measures to defend against such advanced threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Operation Endgame: A Landmark Blow to Cybercriminal Networks in 2026
Impact· HIGH

Operation Endgame: A Landmark Blow to Cybercriminal Networks in 2026

In June 2026, Europol, in collaboration with international law enforcement agencies and private sector partners, executed Operation Endgame, a coordinated effort targeting the infrastructure supporting the SocGholish, Amadey, and StealC malware networks. This operation led to the dismantling of 326 servers and 142 domains, the recovery of 27 million stolen login credentials, and the seizure of over €41 million in cryptocurrency assets. The SocGholish malware, linked to the Russian cybercriminal group Evil Corp, had compromised nearly 15,000 legitimate websites to distribute malicious software. Amadey and StealC were utilized to gain initial access to systems and exfiltrate sensitive data, respectively. ([europol.europa.eu](https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks?utm_source=openai)) This operation signifies a strategic shift in combating cybercrime by disrupting entire malware ecosystems rather than focusing on individual threats. The success of Operation Endgame underscores the effectiveness of international cooperation and public-private partnerships in addressing large-scale cyber threats. ([europol.europa.eu](https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Poland's Crackdown on SIM-Swap Crypto Theft: A 2026 Case Study
Impact· HIGH

Poland's Crackdown on SIM-Swap Crypto Theft: A 2026 Case Study

In June 2026, Polish authorities, with support from the FBI and Homeland Security Investigations, arrested four individuals involved in a sophisticated SIM-swapping scheme targeting cryptocurrency exchanges. The perpetrators breached IT systems of entities collaborating with telecom operators, using specialized software and social engineering to access employee email accounts. This enabled them to hijack victims' phone numbers, intercept SMS messages, and gain control over cryptocurrency exchange accounts, resulting in the theft and laundering of digital assets exceeding tens of millions of Polish zloty. ([thecoinomist.com](https://thecoinomist.com/news/poland-detains-four-sim-swap-crypto-heist-merry-linked/?utm_source=openai)) This incident underscores the escalating threat of SIM-swapping attacks in the cryptocurrency sector, highlighting the need for enhanced security measures beyond SMS-based two-factor authentication. The collaboration between Polish authorities and U.S. agencies reflects the global nature of cybercrime and the importance of international cooperation in combating such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports