The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

943 threat reports
Page 10 of 79

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Telecommunications Threat Reports

Showing 109–120 / 943 reports
ThreatsDay August 2026: Critical RCE Vulnerabilities and State-Sponsored Campaigns Reshape Cybersecurity Landscape
Impact· CRITICAL

ThreatsDay August 2026: Critical RCE Vulnerabilities and State-Sponsored Campaigns Reshape Cybersecurity Landscape

August 2026 witnessed a significant surge in critical remote code execution vulnerabilities across multiple platforms, highlighting the evolving threat landscape. Key incidents included a maximum-severity CVE-2026-52813 flaw in Gogs version 10.0 allowing RCE through Git hooks, a prototype pollution vulnerability in n8n workflow automation (CVE-2026-33696), and an unauthenticated RCE in CircleCI's MCP server. Additionally, the U.S. Department of Justice charged 17 Iranian nationals from the Mabna Institute for a massive cyber theft campaign targeting universities and organizations, stealing over 31TB of academic data on behalf of Iran's IRGC. These incidents reflect the current trend of attackers exploiting trusted components and legitimate applications to bypass security controls. The emergence of AI-powered exploitation tools like China's GLM-5.3 model, which discovered 2,436 vulnerabilities across 269 projects, demonstrates how artificial intelligence is accelerating vulnerability discovery and exploitation capabilities, making rapid patch management and zero-trust architectures more critical than ever.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
How Pakistan's Transparent Tribe Exploited Cybersecurity Gaps in Afghan Infrastructure
Impact· HIGH

How Pakistan's Transparent Tribe Exploited Cybersecurity Gaps in Afghan Infrastructure

Pakistan's Transparent Tribe (APT36) conducted an active cyber espionage campaign against Afghan government and telecommunications organizations from December 2025 through August 2026, deploying new malware variants including Patchcord and Sheetcord backdoors. The threat actor successfully compromised an Afghan Telecom IT officer and an international company's Afghan subsidiary, stealing sensitive data and WhatsApp communications for further social engineering attacks. While attacks against Indian government agencies including the Ministries of Defense and Foreign Affairs were attempted, these were unsuccessful due to India's superior cybersecurity defenses and proactive blocking by CERT-In. This incident highlights the growing sophistication of regional APT groups targeting countries with immature cybersecurity infrastructures, particularly in the context of heightened geopolitical tensions in South Asia and the Taliban's governance challenges in Afghanistan.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Grandoreiro Banking Trojan Returns: Advanced Evasion Campaign Targets Mexico
Impact· HIGH

Grandoreiro Banking Trojan Returns: Advanced Evasion Campaign Targets Mexico

The Grandoreiro banking Trojan has resurfaced in a sophisticated campaign targeting users in Mexico, demonstrating significant operational evolution despite law enforcement disruption in 2024. Operators are leveraging DLL sideloading techniques and legitimate file-management applications to deliver the malware, with telemetry showing additional victims across North America and Europe. The campaign employs extensive anti-analysis and anti-forensics capabilities, including sandbox evasion checks for system uptime, application combinations, memory configurations, and nearly 50 security monitoring tools. This represents a deliberate shift toward separating initial access from long-term payload capabilities, indicating the malware's adaptation to modern security environments. This incident highlights the persistent threat of banking Trojans in Latin America and their continued evolution post-takedown, with Grandoreiro operators demonstrating enhanced stealth capabilities that challenge traditional detection mechanisms.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Advanced Android Banking Malware: ToxicPanda 2.0 and GoldDigger Threaten Global Financial Security
Impact· HIGH

Advanced Android Banking Malware: ToxicPanda 2.0 and GoldDigger Threaten Global Financial Security

ToxicPanda 2.0 represents a significant evolution in Android banking malware, expanding from targeting 16 banking applications to 349 financial institutions across 16 countries. The malware leverages Android accessibility services to steal UI elements, deploy overlay-based credential theft, and abuse Android Wireless Debugging for privilege escalation. Concurrently, GoldDigger banking trojan has launched massive infection campaigns in South Africa and the U.K., impersonating airline companies and retailers while performing sophisticated on-device fraud through real-time screen access and automated transaction manipulation. These incidents highlight the rapidly evolving landscape of mobile banking threats, where attackers are leveraging cloud infrastructure for distribution and implementing advanced evasion techniques. The shift toward on-device fraud capabilities and expanded targeting scope reflects the growing sophistication of mobile threat actors and their ability to adapt to modern security measures.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Manic Malware Breaks the Air Gap: How Wi-Fi Mesh Networks Enable Data Theft from Offline Devices
Impact· HIGH

Manic Malware Breaks the Air Gap: How Wi-Fi Mesh Networks Enable Data Theft from Offline Devices

The Manic Android malware campaign emerged in February 2026, targeting Ukrainian banks, government services, and Russian financial institutions through sophisticated phishing sites and dropper applications. This hybrid banking malware and spyware employs a novel Wi-Fi mesh technique that enables infected devices to relay stolen data through nearby compromised devices with internet access, allowing data exfiltration even when the primary device is offline. The malware monitors 169 package IDs across financial, government, and messaging applications, utilizing accessibility services abuse and transparent overlays to capture sensitive data including PIN codes, authentication credentials, and location information. This incident represents a significant evolution in mobile threats, demonstrating how attackers are adapting to air-gapped security measures and developing mesh-based exfiltration techniques. The campaign's timing amid ongoing geopolitical tensions and its focus on Ukrainian infrastructure highlights the intersection of cybercrime and nation-state activities, making mobile device security and network segmentation increasingly critical for organizational defense strategies.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
SilkParasite APT's Advanced RATs Target Central Asian Governments
Impact· HIGH

SilkParasite APT's Advanced RATs Target Central Asian Governments

In late 2025, the Chinese-nexus advanced persistent threat (APT) group known as SilkParasite initiated a cyber-espionage campaign targeting government organizations across Central Asia, including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. Utilizing spear-phishing emails with regionally tailored Office documents, often within password-protected RAR archives, the attackers deployed a suite of seven remote access Trojans (RATs), five of which were previously undocumented. These RATs enabled long-term access to sensitive governmental systems, facilitating intelligence gathering and potential disruption of critical operations. This incident underscores the evolving sophistication of state-sponsored cyber threats, particularly the use of modular and AI-assisted malware designed to evade detection. The strategic focus on Central Asian governments highlights a shift in geopolitical cyber-espionage activities, emphasizing the need for enhanced cybersecurity measures and international cooperation to mitigate such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
China-Linked AI Cyberattack Targets Taiwan Government in 2026
Impact· HIGH

China-Linked AI Cyberattack Targets Taiwan Government in 2026

In early July 2026, a sophisticated cyberattack targeted Taiwan's government agencies and critical infrastructure. Over four days, attackers employed autonomous AI agents to compromise 85 government accounts, exfiltrate over 2,500 personnel records, and infiltrate the nuclear safety agency and multiple energy companies. The AI-driven system utilized open-source frameworks like Hermes and OpenClaw to autonomously map networks, identify vulnerabilities, and adapt strategies in real-time, all while masquerading as legitimate penetration tests. The attack did not rely on zero-day exploits but exploited existing security weaknesses such as exposed APIs and weak authentication mechanisms. Internal communications in Simplified Chinese suggest a high probability of Chinese state-sponsored involvement. This incident underscores the escalating threat of AI-driven cyberattacks, highlighting the need for enhanced identity management and advanced behavioral monitoring to counteract machine-driven intrusions with human-like coordination and minimal oversight.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
SilkParasite: Unveiling a Sophisticated Cyber Espionage Threat in Central Asia
Impact· HIGH

SilkParasite: Unveiling a Sophisticated Cyber Espionage Threat in Central Asia

In late 2025, a cyber espionage operation named SilkParasite was identified targeting Central Asian government entities. The campaign utilized seven remote access tools (RATs), including five previously undocumented variants: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. Attackers employed AI-assisted development techniques and spear-phishing emails with malicious Microsoft Office documents to infiltrate systems. The operation is linked to Chinese state-sponsored actors, evidenced by the use of backdoors like BLOODALCHEMY and SpiceRAT, both associated with Chinese hacking groups. This incident underscores the evolving sophistication of cyber threats, particularly the integration of AI in malware development. Organizations must enhance their cybersecurity measures to detect and mitigate such advanced persistent threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Unisoc Modem Vulnerability: Millions of Android Devices at Risk
Impact· HIGH

Unisoc Modem Vulnerability: Millions of Android Devices at Risk

In August 2026, researchers at SSD Secure Disclosure identified a critical security vulnerability in Unisoc's T612 modem firmware. By chaining a previously disclosed remote code execution (RCE) flaw with a newly discovered memory isolation weakness, attackers can gain privileged access to the Android kernel on affected devices. The exploit involves delivering a malicious payload to the modem and then initiating a video call, which the victim must answer to trigger the attack. This vulnerability impacts devices from manufacturers such as Realme, Xiaomi, and Motorola, leaving millions of users at risk. The significance of this discovery lies in the increasing prevalence of sophisticated attack chains targeting mobile devices. As threat actors continue to exploit firmware-level vulnerabilities, it underscores the necessity for robust security measures and timely firmware updates to protect user data and device integrity.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
City Forum Campaign: Unveiling the Salesforce and ServiceNow Data Breach
Impact· HIGH

City Forum Campaign: Unveiling the Salesforce and ServiceNow Data Breach

Since March 2025, a single attacker has systematically scraped data from Salesforce and ServiceNow customer portals across various industries, including telecommunications, financial services, and public sector organizations. The attacker utilized a server (IP: 158.220.87.79) hosted by Contabo, employing a custom tool identified by the Go net/http library's default user agent. This tool exploited misconfigured guest user profiles, allowing unauthorized access to sensitive records without authentication. The campaign, dubbed 'City Forum,' highlights the critical need for organizations to review and tighten guest user permissions to prevent unauthorized data access. ([reco.ai](https://www.reco.ai/blog/inside-the-shinyhunters-experience-cloud-campaign-iocs-detection-logic-and-whats-at-risk?utm_source=openai)) This incident underscores a growing trend of attackers targeting misconfigured SaaS platforms to exfiltrate data. As organizations increasingly rely on cloud-based services, ensuring proper configuration and access controls becomes paramount to safeguard sensitive information.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Massive Azure Data Breach: 3.6 Million Records Allegedly Stolen
Impact· MEDIUM

Massive Azure Data Breach: 3.6 Million Records Allegedly Stolen

In August 2026, a threat actor known as "TheHatman" claimed to have stolen 3.64 million employee records from multiple Fortune 500 companies by exploiting compromised credentials to access their Microsoft Azure infrastructures. The stolen data reportedly includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts, and other tenant account records. Companies allegedly affected include McDonald's, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels, and Kyndryl. Some organizations have disputed the claims, stating that the data appears outdated and that no credible evidence of a breach was found. This incident underscores the persistent threat posed by credential-based attacks and highlights the importance of robust authentication mechanisms. The use of techniques such as password spraying and Multi-Factor Authentication (MFA) fatigue attacks demonstrates the evolving tactics of cybercriminals targeting cloud infrastructures.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Evooo1Bot: A New Era of Botnet Threats Targeting IoT Devices
Impact· CRITICAL

Evooo1Bot: A New Era of Botnet Threats Targeting IoT Devices

In August 2026, security researchers identified a new Linux-based botnet named Evooo1Bot, which extends the capabilities of the infamous Mirai malware beyond traditional Distributed Denial of Service (DDoS) attacks. Evooo1Bot exploits vulnerabilities in various Internet-facing devices, including those from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link, some dating back to 2007. Once compromised, these devices are utilized for credential theft, establishing encrypted command-and-control communications, and setting up reverse SOCKS proxies, effectively transforming them into persistent attacker infrastructure. ([arstechnica.com](https://arstechnica.com/security/2026/03/14000-routers-are-infected-by-malware-thats-highly-resistant-to-takedowns/?utm_source=openai)) The emergence of Evooo1Bot underscores the evolving threat landscape where botnets are increasingly used for multifaceted cyberattacks beyond DDoS. This development highlights the critical need for organizations to secure Internet of Things (IoT) devices, promptly apply security patches, and implement robust network monitoring to detect and mitigate such sophisticated threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports