The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
GhostJacking: Unveiling AI Agent Security Vulnerabilities
In August 2026, Tenet Security unveiled 'GhostJacking,' a sophisticated attack technique exploiting AI agents' reliance on trusted data sources. By embedding malicious instructions into security alerts, logs, and error reports, attackers can manipulate AI agents to execute unauthorized actions, including code execution, credential theft, and infrastructure takeover. Demonstrations highlighted vulnerabilities in platforms like Cloudflare, Datadog, and Sentry, where AI agents misinterpreted poisoned data as legitimate commands, leading to significant security breaches. This incident underscores the critical need for robust identity governance and operational safeguards in AI agent deployments. As AI systems become integral to organizational operations, ensuring they can discern and resist malicious manipulations is paramount to maintaining security and trust.
1 month ago
Kill Chain
Cyberattack on Polish Power Plant via Private Cellular Network - 2025
In December 2025, a coordinated cyberattack targeted Poland's energy infrastructure, including over 30 renewable energy farms and a major combined heat and power (CHP) plant supplying heat to nearly 500,000 residents. Attackers exploited vulnerabilities in private cellular networks, gaining unauthorized access to industrial control systems (ICS) and deploying wiper malware aimed at sabotaging operations. Despite the sophisticated nature of the attack, prompt response measures prevented significant service disruptions. This incident underscores the escalating threat landscape facing critical infrastructure, highlighting the need for robust cybersecurity measures in industrial environments. The attack's timing, during severe winter conditions, emphasizes the potential human and economic impact of such cyber threats.
1 month ago
Kill Chain
Malicious SIM Cards Exploit IoT Device Modems - August 2026
In August 2026, researchers from the University of Birmingham and security firm Fuzzware discovered that malicious SIM cards can execute attacker-controlled commands within the modems of cellular IoT devices, such as electric vehicle chargers, industrial routers, and car telematics units. Testing 26 devices, they found that 9 were vulnerable, including certain models from OPPO and ASUS. The vulnerability stems from the 'RUN AT' proactive command, which allows a SIM card to instruct the modem to execute AT commands, potentially leading to full device compromise. This issue predominantly affects machine-to-machine hardware, with several Quectel modules identified as susceptible. The researchers recommend disabling or hardening the 'RUN AT' interface to mitigate this risk. This discovery underscores the critical need for robust security measures in IoT devices, especially as they become more integrated into essential infrastructure. The ability for a SIM card to control device modems highlights a significant attack vector that could be exploited if not properly addressed.
1 month ago
Kill Chain
Cyberattack on Polish Energy Plant via Private APN Highlights Infrastructure Vulnerabilities
In December 2025, a coordinated cyberattack targeted Poland's energy infrastructure, including a small combined heat and power (CHP) plant supplying heat to approximately 50,000 residents. The attackers exploited a misconfigured private Access Point Name (APN) to access the plant's operational technology (OT) network. By compromising a WAGO PFC200 programmable logic controller (PLC) with default credentials, they gained control over the plant's systems, leading to the shutdown of the steam turbine and water treatment system. The plant's staff managed to restore operations swiftly, preventing significant disruption to the population. This incident underscores the evolving tactics of nation-state actors in targeting critical infrastructure. The use of private APNs as attack vectors highlights the necessity for robust network segmentation, stringent access controls, and regular security assessments to mitigate such threats.
1 month ago
Kill Chain
Critical Metabase Vulnerability Exposes Sensitive Data
In February 2026, a critical vulnerability was discovered in Metabase, an open-source business intelligence tool. This flaw allowed authenticated users, including those with embedding permissions, to craft specially formatted notification templates to extract sensitive information, such as database connection details and credentials, and send them via outbound email. Metabase promptly addressed the issue by releasing security advisories and urging all self-hosted users to upgrade to the latest versions to mitigate potential exploitation. ([metabase.com](https://www.metabase.com/blog/security-vulnerability?utm_source=openai)) This incident underscores the importance of timely software updates and vigilant monitoring of open-source tools. As organizations increasingly rely on such platforms, ensuring their security becomes paramount to prevent unauthorized data access and potential breaches.
1 month ago
Kill Chain
Urgent: Patch Critical Vulnerability in Progress Kemp LoadMaster Now
In June 2026, a critical vulnerability (CVE-2026-8037) was identified in Progress Kemp LoadMaster appliances, allowing unauthenticated attackers to execute arbitrary commands remotely. This command injection flaw, present in the 'escape_quotes()' function, enables attackers to gain root access without valid credentials. ([hackerposts.org](https://www.hackerposts.org/en/blog/progress-kemp-loadmaster-cve-2026-8037-preauth-rce?utm_source=openai)) Exploitation attempts began on June 29, 2026, following the public release of a proof-of-concept exploit. ([esentire.com](https://www.esentire.com/security-advisories/progress-kemp-loadmaster-vulnerability-targeted-cve-2026-8037?utm_source=openai)) The inclusion of this vulnerability in CISA's Known Exploited Vulnerabilities catalog underscores the urgency for organizations to apply the necessary patches promptly to mitigate potential threats. ([aha.org](https://www.aha.org/h-isac-white-reports/2026-07-01-h-isac-tlp-white-threat-bulletin-observed-exploitation-attempts-targeting-critical-progress?utm_source=openai))
1 month ago
Kill Chain
CISA Highlights Critical Vulnerability in Progress LoadMaster: CVE-2026-8037
In August 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-8037 to its Known Exploited Vulnerabilities (KEV) Catalog, highlighting active exploitation of this critical command injection vulnerability in Progress Software's LoadMaster appliance. This flaw allows unauthenticated attackers to execute arbitrary commands via unsanitized input in multiple API endpoints, potentially leading to full system compromise. Organizations utilizing affected versions are urged to apply patches immediately to mitigate the risk of unauthorized access and data breaches. The inclusion of CVE-2026-8037 in the KEV Catalog underscores the persistent threat posed by command injection vulnerabilities, which remain a favored attack vector for cyber adversaries. This incident serves as a critical reminder for organizations to prioritize timely remediation of known vulnerabilities and to implement robust input validation mechanisms to prevent similar exploits.
1 month ago
Kill Chain
NatJack Attack: Exploiting NAT Vulnerabilities in Windows and Linux
In August 2026, security researcher Malcolm Stagg unveiled 'NatJack,' a novel attack class that exploits vulnerabilities in Network Address Translation (NAT) implementations to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. The research identified two critical vulnerabilities: CVE-2026-56181 in Windows NAT used by Hyper-V and CVE-2026-63913 in Linux Netfilter conntrack. These flaws allow attackers with privileged access to a system behind the same NAT as the victim to manipulate connection states, leading to potential data interception and service disruptions. Organizations are advised to apply the latest patches and implement network segmentation to mitigate these risks. The NatJack disclosure underscores the evolving threat landscape targeting network infrastructure. As attackers continue to find and exploit design assumptions in widely used technologies, it is imperative for organizations to reassess their network security postures, prioritize internal traffic encryption, and adopt zero-trust principles to safeguard against such sophisticated attacks.
1 month ago
Kill Chain
Critical Linux Kernel Vulnerability (CVE-2026-64564) Exposes Systems to Root Access and Container Escapes
An 18-year-old use-after-free vulnerability in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation, identified as CVE-2026-64564 and dubbed 'SCTPhantom,' has been discovered. This flaw allows local users to escalate privileges to root and potentially escape containerized environments. The vulnerability has existed since 2008 and affects all kernel versions from 2.6.25 onwards. Tencent's Zhuque Lab demonstrated successful exploitation on distributions including Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9, and OpenCloudOS. The issue arises from improper handling of delete requests in SCTP's dynamic address reconfiguration feature, leading to use-after-free conditions. The vulnerability was publicly disclosed on August 6, 2026, with patches released in stable kernel versions 7.1.6, 6.18.42, 6.12.101, and 6.6.148 on August 3, 2026. Organizations are urged to update their systems promptly to mitigate potential exploitation risks.
1 month ago
Kill Chain
Canadian Hacker Convicted in Massive Snowflake Data Breach Extortions
Between February and October 2024, Connor Riley Moucka, a 26-year-old Canadian, orchestrated unauthorized access to at least 165 organizations utilizing Snowflake's cloud data services. Exploiting stolen credentials from accounts lacking multi-factor authentication, Moucka and his co-conspirators exfiltrated sensitive data, including personal information and call records of over 100 million AT&T customers. The stolen data was used to extort victims by threatening public disclosure. This incident underscores the critical importance of implementing robust security measures, such as multi-factor authentication, to protect cloud-based data. Organizations must remain vigilant against credential-based attacks, as threat actors continue to exploit such vulnerabilities for financial gain and data theft.
1 month ago
Kill Chain
15 TP-Link Vulnerabilities Unveil Critical Zero-Touch Provisioning Risks
In August 2026, researchers at Black Hat USA disclosed 15 vulnerabilities in TP-Link's Omada software-defined networking ecosystem, highlighting significant security risks associated with zero-touch provisioning (ZTP). These vulnerabilities, affecting routers, switches, gateways, and Wi-Fi access points, could be exploited to hijack devices, execute client-side code, disclose sensitive information, and compromise encryption protocols. The findings underscore the potential for large-scale network intrusions facilitated by automated provisioning processes. The incident serves as a critical reminder of the inherent risks in ZTP implementations, emphasizing the need for organizations to scrutinize and secure their provisioning workflows. As ZTP adoption grows, ensuring robust security measures during device onboarding becomes paramount to prevent exploitation by threat actors.
1 month ago
Kill Chain
Snowflake Data Breach: Lessons in Credential Security
In 2024, threat actor UNC5537 exploited stolen credentials to access Snowflake customer accounts lacking multi-factor authentication (MFA), compromising at least 165 organizations and exposing data of over 100 million individuals. The attackers utilized infostealer malware to harvest credentials, some dating back to 2020, leading to significant data breaches affecting companies like AT&T and Ticketmaster. This incident underscores the critical importance of implementing robust security measures, such as MFA and regular credential rotation, to protect against credential-based attacks. Organizations must remain vigilant as similar tactics continue to pose significant threats to data security.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports