The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
ThreatsDay August 2026: Critical RCE Vulnerabilities and State-Sponsored Campaigns Reshape Cybersecurity Landscape
August 2026 witnessed a significant surge in critical remote code execution vulnerabilities across multiple platforms, highlighting the evolving threat landscape. Key incidents included a maximum-severity CVE-2026-52813 flaw in Gogs version 10.0 allowing RCE through Git hooks, a prototype pollution vulnerability in n8n workflow automation (CVE-2026-33696), and an unauthenticated RCE in CircleCI's MCP server. Additionally, the U.S. Department of Justice charged 17 Iranian nationals from the Mabna Institute for a massive cyber theft campaign targeting universities and organizations, stealing over 31TB of academic data on behalf of Iran's IRGC. These incidents reflect the current trend of attackers exploiting trusted components and legitimate applications to bypass security controls. The emergence of AI-powered exploitation tools like China's GLM-5.3 model, which discovered 2,436 vulnerabilities across 269 projects, demonstrates how artificial intelligence is accelerating vulnerability discovery and exploitation capabilities, making rapid patch management and zero-trust architectures more critical than ever.
1 month ago
Kill Chain
How Pakistan's Transparent Tribe Exploited Cybersecurity Gaps in Afghan Infrastructure
Pakistan's Transparent Tribe (APT36) conducted an active cyber espionage campaign against Afghan government and telecommunications organizations from December 2025 through August 2026, deploying new malware variants including Patchcord and Sheetcord backdoors. The threat actor successfully compromised an Afghan Telecom IT officer and an international company's Afghan subsidiary, stealing sensitive data and WhatsApp communications for further social engineering attacks. While attacks against Indian government agencies including the Ministries of Defense and Foreign Affairs were attempted, these were unsuccessful due to India's superior cybersecurity defenses and proactive blocking by CERT-In. This incident highlights the growing sophistication of regional APT groups targeting countries with immature cybersecurity infrastructures, particularly in the context of heightened geopolitical tensions in South Asia and the Taliban's governance challenges in Afghanistan.
1 month ago
Kill Chain
Grandoreiro Banking Trojan Returns: Advanced Evasion Campaign Targets Mexico
The Grandoreiro banking Trojan has resurfaced in a sophisticated campaign targeting users in Mexico, demonstrating significant operational evolution despite law enforcement disruption in 2024. Operators are leveraging DLL sideloading techniques and legitimate file-management applications to deliver the malware, with telemetry showing additional victims across North America and Europe. The campaign employs extensive anti-analysis and anti-forensics capabilities, including sandbox evasion checks for system uptime, application combinations, memory configurations, and nearly 50 security monitoring tools. This represents a deliberate shift toward separating initial access from long-term payload capabilities, indicating the malware's adaptation to modern security environments. This incident highlights the persistent threat of banking Trojans in Latin America and their continued evolution post-takedown, with Grandoreiro operators demonstrating enhanced stealth capabilities that challenge traditional detection mechanisms.
1 month ago
Kill Chain
Advanced Android Banking Malware: ToxicPanda 2.0 and GoldDigger Threaten Global Financial Security
ToxicPanda 2.0 represents a significant evolution in Android banking malware, expanding from targeting 16 banking applications to 349 financial institutions across 16 countries. The malware leverages Android accessibility services to steal UI elements, deploy overlay-based credential theft, and abuse Android Wireless Debugging for privilege escalation. Concurrently, GoldDigger banking trojan has launched massive infection campaigns in South Africa and the U.K., impersonating airline companies and retailers while performing sophisticated on-device fraud through real-time screen access and automated transaction manipulation. These incidents highlight the rapidly evolving landscape of mobile banking threats, where attackers are leveraging cloud infrastructure for distribution and implementing advanced evasion techniques. The shift toward on-device fraud capabilities and expanded targeting scope reflects the growing sophistication of mobile threat actors and their ability to adapt to modern security measures.
1 month ago
Kill Chain
Manic Malware Breaks the Air Gap: How Wi-Fi Mesh Networks Enable Data Theft from Offline Devices
The Manic Android malware campaign emerged in February 2026, targeting Ukrainian banks, government services, and Russian financial institutions through sophisticated phishing sites and dropper applications. This hybrid banking malware and spyware employs a novel Wi-Fi mesh technique that enables infected devices to relay stolen data through nearby compromised devices with internet access, allowing data exfiltration even when the primary device is offline. The malware monitors 169 package IDs across financial, government, and messaging applications, utilizing accessibility services abuse and transparent overlays to capture sensitive data including PIN codes, authentication credentials, and location information. This incident represents a significant evolution in mobile threats, demonstrating how attackers are adapting to air-gapped security measures and developing mesh-based exfiltration techniques. The campaign's timing amid ongoing geopolitical tensions and its focus on Ukrainian infrastructure highlights the intersection of cybercrime and nation-state activities, making mobile device security and network segmentation increasingly critical for organizational defense strategies.
1 month ago
Kill Chain
SilkParasite APT's Advanced RATs Target Central Asian Governments
In late 2025, the Chinese-nexus advanced persistent threat (APT) group known as SilkParasite initiated a cyber-espionage campaign targeting government organizations across Central Asia, including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. Utilizing spear-phishing emails with regionally tailored Office documents, often within password-protected RAR archives, the attackers deployed a suite of seven remote access Trojans (RATs), five of which were previously undocumented. These RATs enabled long-term access to sensitive governmental systems, facilitating intelligence gathering and potential disruption of critical operations. This incident underscores the evolving sophistication of state-sponsored cyber threats, particularly the use of modular and AI-assisted malware designed to evade detection. The strategic focus on Central Asian governments highlights a shift in geopolitical cyber-espionage activities, emphasizing the need for enhanced cybersecurity measures and international cooperation to mitigate such threats.
1 month ago
Kill Chain
China-Linked AI Cyberattack Targets Taiwan Government in 2026
In early July 2026, a sophisticated cyberattack targeted Taiwan's government agencies and critical infrastructure. Over four days, attackers employed autonomous AI agents to compromise 85 government accounts, exfiltrate over 2,500 personnel records, and infiltrate the nuclear safety agency and multiple energy companies. The AI-driven system utilized open-source frameworks like Hermes and OpenClaw to autonomously map networks, identify vulnerabilities, and adapt strategies in real-time, all while masquerading as legitimate penetration tests. The attack did not rely on zero-day exploits but exploited existing security weaknesses such as exposed APIs and weak authentication mechanisms. Internal communications in Simplified Chinese suggest a high probability of Chinese state-sponsored involvement. This incident underscores the escalating threat of AI-driven cyberattacks, highlighting the need for enhanced identity management and advanced behavioral monitoring to counteract machine-driven intrusions with human-like coordination and minimal oversight.
1 month ago
Kill Chain
SilkParasite: Unveiling a Sophisticated Cyber Espionage Threat in Central Asia
In late 2025, a cyber espionage operation named SilkParasite was identified targeting Central Asian government entities. The campaign utilized seven remote access tools (RATs), including five previously undocumented variants: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. Attackers employed AI-assisted development techniques and spear-phishing emails with malicious Microsoft Office documents to infiltrate systems. The operation is linked to Chinese state-sponsored actors, evidenced by the use of backdoors like BLOODALCHEMY and SpiceRAT, both associated with Chinese hacking groups. This incident underscores the evolving sophistication of cyber threats, particularly the integration of AI in malware development. Organizations must enhance their cybersecurity measures to detect and mitigate such advanced persistent threats.
1 month ago
Kill Chain
Unisoc Modem Vulnerability: Millions of Android Devices at Risk
In August 2026, researchers at SSD Secure Disclosure identified a critical security vulnerability in Unisoc's T612 modem firmware. By chaining a previously disclosed remote code execution (RCE) flaw with a newly discovered memory isolation weakness, attackers can gain privileged access to the Android kernel on affected devices. The exploit involves delivering a malicious payload to the modem and then initiating a video call, which the victim must answer to trigger the attack. This vulnerability impacts devices from manufacturers such as Realme, Xiaomi, and Motorola, leaving millions of users at risk. The significance of this discovery lies in the increasing prevalence of sophisticated attack chains targeting mobile devices. As threat actors continue to exploit firmware-level vulnerabilities, it underscores the necessity for robust security measures and timely firmware updates to protect user data and device integrity.
1 month ago
Kill Chain
City Forum Campaign: Unveiling the Salesforce and ServiceNow Data Breach
Since March 2025, a single attacker has systematically scraped data from Salesforce and ServiceNow customer portals across various industries, including telecommunications, financial services, and public sector organizations. The attacker utilized a server (IP: 158.220.87.79) hosted by Contabo, employing a custom tool identified by the Go net/http library's default user agent. This tool exploited misconfigured guest user profiles, allowing unauthorized access to sensitive records without authentication. The campaign, dubbed 'City Forum,' highlights the critical need for organizations to review and tighten guest user permissions to prevent unauthorized data access. ([reco.ai](https://www.reco.ai/blog/inside-the-shinyhunters-experience-cloud-campaign-iocs-detection-logic-and-whats-at-risk?utm_source=openai)) This incident underscores a growing trend of attackers targeting misconfigured SaaS platforms to exfiltrate data. As organizations increasingly rely on cloud-based services, ensuring proper configuration and access controls becomes paramount to safeguard sensitive information.
1 month ago
Kill Chain
Massive Azure Data Breach: 3.6 Million Records Allegedly Stolen
In August 2026, a threat actor known as "TheHatman" claimed to have stolen 3.64 million employee records from multiple Fortune 500 companies by exploiting compromised credentials to access their Microsoft Azure infrastructures. The stolen data reportedly includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts, and other tenant account records. Companies allegedly affected include McDonald's, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels, and Kyndryl. Some organizations have disputed the claims, stating that the data appears outdated and that no credible evidence of a breach was found. This incident underscores the persistent threat posed by credential-based attacks and highlights the importance of robust authentication mechanisms. The use of techniques such as password spraying and Multi-Factor Authentication (MFA) fatigue attacks demonstrates the evolving tactics of cybercriminals targeting cloud infrastructures.
1 month ago
Kill Chain
Evooo1Bot: A New Era of Botnet Threats Targeting IoT Devices
In August 2026, security researchers identified a new Linux-based botnet named Evooo1Bot, which extends the capabilities of the infamous Mirai malware beyond traditional Distributed Denial of Service (DDoS) attacks. Evooo1Bot exploits vulnerabilities in various Internet-facing devices, including those from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link, some dating back to 2007. Once compromised, these devices are utilized for credential theft, establishing encrypted command-and-control communications, and setting up reverse SOCKS proxies, effectively transforming them into persistent attacker infrastructure. ([arstechnica.com](https://arstechnica.com/security/2026/03/14000-routers-are-infected-by-malware-thats-highly-resistant-to-takedowns/?utm_source=openai)) The emergence of Evooo1Bot underscores the evolving threat landscape where botnets are increasingly used for multifaceted cyberattacks beyond DDoS. This development highlights the critical need for organizations to secure Internet of Things (IoT) devices, promptly apply security patches, and implement robust network monitoring to detect and mitigate such sophisticated threats.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports