The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

943 threat reports
Page 17 of 79

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Telecommunications Threat Reports

Showing 193–204 / 943 reports
Dysphoria Botnet's Global Impact in 2026
Impact· HIGH

Dysphoria Botnet's Global Impact in 2026

In July 2026, cybersecurity researchers identified a botnet named Dysphoria that had compromised approximately 200,000 devices globally. The botnet evolved from previous malware strains like 'jackskid' and 'fbot', incorporating a covert blockchain-based command-and-control mechanism using Ethereum ENS and Solana SNS domains. Dysphoria exploited weak Telnet and SSH credentials, as well as known vulnerabilities in routers, cameras, and IoT devices, to conduct distributed denial-of-service (DDoS) attacks and traffic relay operations. The botnet's operators claimed a maximum DDoS capacity of 4 Tbps, posing significant disruption risks. The emergence of Dysphoria underscores the increasing sophistication of botnets leveraging blockchain technology for resilient command-and-control infrastructures. This trend highlights the urgent need for organizations to strengthen device security, regularly update firmware, and implement robust access controls to mitigate the risk of such advanced threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
Dysphoria IoT Botnet: A New Era of Resilient Cyber Threats
Impact· CRITICAL

Dysphoria IoT Botnet: A New Era of Resilient Cyber Threats

In July 2026, cybersecurity researchers identified a new IoT botnet named Dysphoria, which has infected approximately 200,000 devices globally. Following the March 2026 law enforcement takedown of the JackSkid botnet, Dysphoria emerged with enhanced resilience by integrating blockchain-based command-and-control (C2) mechanisms and utilizing infected devices as relays to obscure its infrastructure. This evolution complicates traditional disruption methods and poses significant challenges to cybersecurity defenses. The adoption of blockchain name services for C2 resolution and the use of victim devices as relays represent a concerning trend in botnet development. These tactics not only enhance the botnet's resilience against takedown efforts but also indicate a shift towards more sophisticated and decentralized control structures in cyber threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Zero-Day Vulnerability in Arista VeloCloud Orchestrator Exploited
Impact· CRITICAL

Critical Zero-Day Vulnerability in Arista VeloCloud Orchestrator Exploited

In July 2026, Arista Networks disclosed a critical command injection vulnerability (CVE-2026-16812) in its on-premises VeloCloud Orchestrator (VCO) deployments. This unauthenticated OS command injection flaw, with a CVSS score of 10.0, allows remote attackers to access privileged internal functionalities, potentially compromising the confidentiality, integrity, and availability of the orchestrator and the data it manages. The vulnerability affects VCO versions 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. Hosted and Dedicated VCO deployments were patched prior to the advisory and are not affected. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/?utm_source=openai)) The exploitation of this zero-day vulnerability underscores the increasing sophistication of cyber threats targeting network management systems. Organizations are urged to promptly apply the provided patches, restrict access to the VCO web interface to administrative networks, and monitor for indicators of compromise, including connections from known malicious IP addresses and unauthorized configuration changes. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
TELESHIM: Exploiting Telegram for Covert C2 in Middle East Government Attacks
Impact· HIGH

TELESHIM: Exploiting Telegram for Covert C2 in Middle East Government Attacks

In July 2026, cybersecurity researchers identified a sophisticated cyber-espionage campaign targeting government entities in the Middle East. The campaign, attributed to a threat actor with ties to East Asia, deployed previously undocumented malware families named TELESHIM, MIXEDKEY, and BINDCLOAK. The attack chain began with the use of ISO image files containing a legitimate ASUSTek executable, which sideloaded a malicious DLL to deploy the TELESHIM backdoor. TELESHIM notably abused the Telegram API for command-and-control (C2) communications, allowing the attackers to blend malicious traffic with legitimate network activity. The operation demonstrated advanced techniques, including DLL sideloading, environmental keying, and heavy code obfuscation, indicating a high level of operational security and a focus on long-term espionage and data exfiltration. ([zscaler.com](https://www.zscaler.com/blogs/security-research/targeted-attack-government-entities-middle-east-part-1?utm_source=openai)) This incident underscores a growing trend of threat actors leveraging popular communication platforms like Telegram for covert C2 channels, complicating detection and mitigation efforts. The use of such legitimate services for malicious purposes highlights the need for organizations to enhance their monitoring capabilities and adopt more sophisticated threat detection mechanisms to identify and respond to these evolving tactics.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Origin Energy Data Breach 2026: A Wake-Up Call for Critical Infrastructure Security
Impact· MEDIUM

Origin Energy Data Breach 2026: A Wake-Up Call for Critical Infrastructure Security

In July 2026, Origin Energy, Australia's largest energy retailer, confirmed unauthorized access to and disclosure of customer data. The compromised information includes names, addresses, dates of birth, contact numbers, account details, and partial financial data such as the last four digits of credit cards and the last three digits of bank accounts. The exact number of affected customers remains under investigation. Origin Energy has engaged with the Australian Cyber Security Centre and the Australian Federal Police to address the breach and is working to secure its systems to prevent further unauthorized access. This incident underscores the escalating threat of cyberattacks targeting critical infrastructure sectors. The exposure of personal and partial financial data heightens the risk of identity theft and sophisticated phishing scams, especially with the increasing use of AI by cybercriminals to craft convincing fraudulent communications.

2 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
The Rise of Residential Proxy Botnets: A New Cybersecurity Challenge
Impact· HIGH

The Rise of Residential Proxy Botnets: A New Cybersecurity Challenge

In July 2026, Lumen Technologies' Black Lotus Labs reported a significant surge in botnets utilizing residential proxy networks, with nearly 60 million compromised IP addresses globally. Approximately 25% of these infected IPs are located in the United States. Notably, the IPIDEA botnet, after a coordinated takedown in January, rebounded to half its size within hours and has since expanded to about 10 million IPs. This rapid recovery underscores the resilience and adaptability of such botnets. ([cyberscoop.com](https://cyberscoop.com/botnets-residential-proxy-networks-proliferate-lumen-black-lotus-labs/?utm_source=openai)) The proliferation of these botnets is driven by a growing market demand for residential IPs, enabling cybercriminals to mask malicious activities within legitimate traffic. The increasing availability of vulnerable devices, coupled with the cessation of security updates for older products, exacerbates the issue. ([cyberscoop.com](https://cyberscoop.com/botnets-residential-proxy-networks-proliferate-lumen-black-lotus-labs/?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
BlueNoroff's 2026 Zoom Phishing Campaign: A Wake-Up Call for Crypto Firms
Impact· HIGH

BlueNoroff's 2026 Zoom Phishing Campaign: A Wake-Up Call for Crypto Firms

In July 2026, the North Korean state-sponsored group BlueNoroff launched a sophisticated phishing campaign targeting cryptocurrency organizations. The attackers utilized typosquatted Zoom and Microsoft Teams domains to impersonate legitimate videoconferencing platforms. By hijacking trusted Telegram accounts, they invited high-ranking employees to fake meetings, where victims were prompted to grant webcam access. This access allowed the attackers to profile victims' cryptocurrency wallets before delivering malware, enabling selective targeting of high-value individuals. This incident underscores the evolving tactics of threat actors who exploit trust in widely used communication platforms. The integration of social engineering with advanced reconnaissance techniques highlights the need for heightened vigilance and robust security measures within the cryptocurrency sector.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Emerging Cyber Threats: Android Spyware, PLC Attacks, and AI Image Prompt Injections
Impact· HIGH

Emerging Cyber Threats: Android Spyware, PLC Attacks, and AI Image Prompt Injections

In July 2026, a series of sophisticated cyber threats emerged, including Android spyware, PLC attacks, and AI image prompt injections. These incidents involved malicious packages stealing data, counterfeit extensions enabling remote access, and images embedding hidden commands to manipulate AI agents. Such attacks exploited vulnerabilities in open systems, weak code, and standard network traffic, posing significant risks to both individual users and organizations. The current relevance of these incidents lies in the evolving nature of cyber threats, where attackers increasingly leverage advanced techniques to infiltrate systems. The rise in AI-driven attacks and the exploitation of everyday applications underscore the need for heightened vigilance and robust security measures to protect against such multifaceted threats.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Origin Energy Data Breach: A Wake-Up Call for Critical Infrastructure Security
Impact· HIGH

Origin Energy Data Breach: A Wake-Up Call for Critical Infrastructure Security

In July 2026, Origin Energy, Australia's largest energy retailer, confirmed a data breach involving unauthorized access to customer information. The compromised data includes names, addresses, dates of birth, contact numbers, account details, and partial financial information (last four digits of credit cards or last three digits of bank accounts). The company is working to determine the total number of affected customers and has engaged with the Australian Cyber Security Centre, the Australian Federal Police, and the Office of the Australian Information Commissioner to investigate the incident. ([originenergy.com.au](https://www.originenergy.com.au/about/investors-media/update-on-data-security-incident/?utm_source=openai)) This breach underscores the escalating threat of cyberattacks targeting critical infrastructure sectors. The exposure of personal information increases the risk of identity theft and sophisticated phishing scams, particularly with the rise of AI-driven cybercrime. Organizations must enhance their cybersecurity measures to protect sensitive customer data and maintain public trust. ([abc.net.au](https://www.abc.net.au/news/2026-07-24/origin-breach-could-fuel-wave-of-ai-powered-scams/106951588?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Fake Bahrain Alert App Exploits Crisis to Deploy Android Spyware
Impact· HIGH

Fake Bahrain Alert App Exploits Crisis to Deploy Android Spyware

In July 2026, a malicious Android application named "BH Alert" emerged, masquerading as Bahrain's official civil-defense emergency alert app. Distributed through counterfeit Google Play Store and Bahraini government websites, the app exploited heightened public concern during Iranian missile strikes. Once installed, it deployed a sophisticated four-stage surveillance platform capable of harvesting lockscreen credentials, SMS messages, contacts, and screenshots, running banking-app overlays, and granting attackers full remote control over the device. This campaign underscores the increasing trend of threat actors leveraging trusted government applications during crises to disseminate advanced spyware. Organizations should be vigilant about such tactics, as similar methods have been observed in previous incidents, including a Trojanized version of Israel's "Red Alert" app distributed via phishing campaigns earlier this year.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
LG Takes Action Against Residential Proxy Apps on Smart TVs
Impact· MEDIUM

LG Takes Action Against Residential Proxy Apps on Smart TVs

In July 2026, LG Electronics USA announced plans to suspend smart TV applications that transform televisions into residential proxy nodes. This decision followed research indicating that over 42% of apps available on LG's webOS store incorporated software development kits (SDKs) enabling third parties to route internet traffic through users' TVs. Such practices raised significant privacy and security concerns, as they allowed external entities to utilize home networks without explicit user consent. LG's proactive stance aims to eliminate these unauthorized proxy functionalities and enhance user trust in their smart TV ecosystem. This incident underscores the growing trend of embedding residential proxy capabilities into consumer devices, often without transparent disclosure. The prevalence of such practices highlights the need for stringent app review processes and increased consumer awareness regarding the potential misuse of household devices for unauthorized network activities.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
AI's Role in Accelerating Exploit Development: A Call for Immediate Action
Impact· LOW

AI's Role in Accelerating Exploit Development: A Call for Immediate Action

In July 2026, cybersecurity experts highlighted a critical shift in vulnerability exploitation dynamics. Traditionally, organizations had weeks to patch known vulnerabilities before attackers could develop exploits. However, advancements in AI have drastically reduced this window. For instance, AI systems like Claude Mythos Preview have demonstrated the capability to reverse-engineer patches into working exploits within an hour of a patch's release. This rapid turnaround means that unpatched systems are at immediate risk, as attackers can weaponize vulnerabilities almost as soon as they are disclosed. This development underscores the urgent need for organizations to rethink their vulnerability management strategies. The traditional approach of patching within weeks is no longer sufficient. Organizations must adopt proactive measures, such as continuous monitoring, real-time threat intelligence, and automated patch management, to stay ahead of rapidly evolving threats.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports