The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Critical RabbitMQ Vulnerabilities Expose OAuth Secrets - CVE-2026-57219
In July 2026, two critical vulnerabilities were identified in RabbitMQ, a widely used open-source message broker. The most severe, CVE-2026-57219, allowed unauthenticated attackers to access the broker's OAuth client secret via an obsolete management API endpoint, potentially enabling full control over the messaging infrastructure. The second flaw, CVE-2026-57221, permitted authenticated users with no privileges to view metadata of other tenants' queues and exchanges, risking exposure of sensitive business information. Both vulnerabilities have been patched in RabbitMQ versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6. Organizations are urged to update their systems and rotate any exposed OAuth secrets to mitigate potential risks. ([scworld.com](https://www.scworld.com/news/rabbitmq-fixes-flaw-that-allowed-broker-takeover-via-oauth-secret-disclosure?utm_source=openai)) These incidents underscore the critical importance of securing management interfaces and promptly addressing deprecated endpoints to prevent unauthorized access and data exposure. The widespread use of RabbitMQ amplifies the potential impact, highlighting the need for vigilant security practices in managing messaging infrastructures.
2 months ago
Kill Chain
Russian FSB Exploits Cisco Vulnerabilities in Critical Infrastructure Attacks
In July 2026, a joint cybersecurity advisory from the United States and 12 other nations highlighted ongoing cyber intrusions by Russian state-sponsored hackers, specifically the FSB's Center 16, also known as Berserk Bear and Static Tundra. These actors have been exploiting vulnerabilities in Cisco networking devices, notably CVE-2008-4128 and CVE-2018-0171, to infiltrate critical infrastructure sectors such as defense, communications, energy, finance, government, and healthcare. The attackers leverage default or weak passwords and unpatched systems to gain unauthorized access, conduct reconnaissance, and potentially disrupt operations. This incident underscores the persistent threat posed by nation-state actors targeting outdated and misconfigured network devices. Organizations are urged to implement robust security measures, including disabling vulnerable features like Cisco's Smart Install, enforcing strong authentication protocols, and regularly updating systems to mitigate such risks.
2 months ago
Kill Chain
EU and UK Sanction Russian Entities Over Cyberespionage Campaign
In July 2026, the European Union and the United Kingdom imposed coordinated sanctions on Russian military intelligence officers, hackers, and private companies in response to a prolonged cyberespionage campaign attributed to Russian actors. The EU targeted nine individuals and four entities, while the UK sanctioned 24 individuals and organizations. These sanctions, including asset freezes and travel bans, were directed at actors linked to Russia's FSB and GRU intelligence agencies, accused of conducting cyber operations targeting governments and critical infrastructure since 2010. Key affected countries include France, Germany, Poland, the Netherlands, and Finland, with specific incidents such as the sabotage of Polish railway infrastructure highlighted. ([apnews.com](https://apnews.com/article/1d3c542e1409b54a10856eacad18b7ca?utm_source=openai)) This incident underscores the escalating threat of state-sponsored cyberattacks on critical infrastructure and governmental networks. The coordinated response by the EU and UK reflects a growing recognition of the need for unified action against cyber threats, emphasizing the importance of robust cybersecurity measures and international cooperation to safeguard national security and public services.
2 months ago
Kill Chain
US and Allies Issue Joint Advisory on Russian Cyber Threats to Critical Infrastructure
In July 2026, cybersecurity agencies from the United States and eight allied nations issued a joint advisory warning that Russian state-sponsored hackers, specifically FSB Center 16 (also known as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra), are actively targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks. These actors exploit default or weak SNMP authentication strings and known vulnerabilities, such as CVE-2018-0171 in Cisco's Smart Install feature, to gain unauthorized access, exfiltrate configuration files, and conduct reconnaissance within victim networks. The sectors most at risk include energy, communications, defense industrial base, healthcare, financial services, and government services. This incident underscores the persistent threat posed by nation-state actors to critical infrastructure, highlighting the importance of proactive cybersecurity measures. Organizations are urged to upgrade to SNMPv3, disable unnecessary services like Cisco Smart Install, enforce strong unique passwords, block TFTP and SNMP traffic at edge firewalls, update software and firmware, and replace end-of-life devices to mitigate such risks.
2 months ago
Kill Chain
UK Authorities Charge Five in Russian Coms Caller ID Spoofing Case
In July 2026, UK authorities charged five individuals in connection with Russian Coms, a caller ID spoofing platform implicated in over 1.8 million scam calls since its inception in 2020. The platform enabled criminals to impersonate trusted entities, leading to financial losses estimated in the tens of millions and affecting approximately 170,000 victims. The National Crime Agency (NCA) had previously dismantled Russian Coms in March 2024, arresting key figures believed to be its developers and administrators. The recent charges underscore the ongoing efforts to hold accountable those involved in facilitating large-scale fraud operations. This incident highlights the persistent threat posed by sophisticated social engineering tactics and the critical need for robust cybersecurity measures to protect individuals and organizations from such fraudulent schemes.
2 months ago
Kill Chain
Cyberattack on Nihon Kotsu Disrupts Taxi Services Across Japan
In July 2026, Nihon Kotsu, Japan's largest taxi operator, experienced a cyberattack that compromised its internal systems, leading to the shutdown of critical infrastructure, including the taxi dispatch system. The attack occurred early Saturday morning, prompting the company to implement emergency measures to prevent further damage. As a result, services such as car hire, web booking, reservation management, and telephone dispatch remain unavailable. The company has engaged external cybersecurity experts to investigate the incident and assess potential data leaks. Customers are advised to use the 'GO' taxi app or visit nearby taxi stands for services. This incident underscores the escalating threat of cyberattacks targeting critical infrastructure and essential services. Organizations must prioritize robust cybersecurity measures and incident response plans to mitigate operational disruptions and protect sensitive data.
2 months ago
Kill Chain
New U-Boot Vulnerabilities Expose Devices to Stealthy Firmware Attacks
In July 2026, six critical vulnerabilities were discovered in the U-Boot bootloader, a widely used open-source component in embedded Linux devices such as enterprise servers, networking equipment, and IoT devices. These flaws, identified by the Binarly Research team, affect the FIT (Flattened Image Tree) signature verification process, potentially allowing attackers to execute malicious code during the device boot sequence. This could lead to stealthy firmware attacks that bypass security protections and install persistent malware, compromising devices before the operating system and its security software are initiated. The discovery underscores the increasing focus on firmware security, highlighting the need for robust verification mechanisms in bootloaders. As attackers continue to exploit vulnerabilities at the firmware level, organizations must prioritize securing their supply chains and implementing comprehensive security measures to protect against such sophisticated threats.
2 months ago
Kill Chain
Odido Data Breach 2026: A Wake-Up Call for Telecom Security
In February 2026, Dutch telecommunications provider Odido experienced a significant data breach when attackers accessed its customer contact system, compromising personal data of approximately 6.2 million customers. The exposed information included full names, addresses, mobile numbers, customer numbers, email addresses, IBANs, dates of birth, and identification details such as passport or driver's license numbers. The breach was executed through a phishing attack where a Dutch-speaking individual impersonated an Odido IT employee to deceive customer service representatives. The cybercriminal group ShinyHunters claimed responsibility for the attack, releasing an 88GB archive containing over 15 million records on the dark web. This incident underscores the escalating threat of sophisticated phishing and social engineering attacks targeting large organizations. The involvement of ShinyHunters, known for high-profile data breaches, highlights the need for enhanced cybersecurity measures and employee training to prevent similar incidents in the future.
2 months ago
Kill Chain
Critical U-Boot Vulnerabilities Expose Devices to Crashes and Code Execution
In July 2026, firmware security firm Binarly disclosed six vulnerabilities in U-Boot, a widely used bootloader for devices such as home routers, smart cameras, and data-center servers. Four of these flaws can cause device crashes, while the remaining two allow attackers to execute arbitrary code during the boot process by presenting malicious images. These vulnerabilities have existed since U-Boot version 2013.07 and affect numerous vendor firmware built upon U-Boot. Exploitation requires delivering a crafted image to the boot path, potentially through physical access or a privileged foothold. The discovery underscores the critical importance of securing bootloaders, as vulnerabilities at this level can compromise the entire system's integrity. Organizations utilizing U-Boot should prioritize applying patches and reviewing their firmware update processes to mitigate potential exploitation risks.
2 months ago
Kill Chain
June 2026 CVE Landscape: A 49% Surge in High-Impact Vulnerabilities
In June 2026, Insikt Group identified 60 high-impact vulnerabilities, marking a 49% increase from the previous month. Notably, 23 of these vulnerabilities were included in the US Cybersecurity and Infrastructure Security Agency (CISA)'s Known Exploited Vulnerabilities (KEV) catalog. The vulnerabilities affected products from 36 vendors, with Microsoft accounting for approximately 18%. ([vulnerability-lookup.org](https://www.vulnerability-lookup.org/2026/07/02/vulnerability-report-june-2026/?utm_source=openai)) This surge underscores the escalating threat landscape, emphasizing the need for organizations to prioritize vulnerability management and remediation efforts to mitigate potential exploits.
2 months ago
Kill Chain
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
In July 2026, a critical vulnerability named XRING was disclosed in XQUIC, Alibaba's QUIC and HTTP/3 library. This flaw allows remote clients to crash HTTP/3 servers by sending approximately 260 bytes of standard QPACK traffic, without requiring authentication or malformed packets. The issue stems from improper handling of the dynamic table resizing in QPACK, leading to memory corruption and server crashes. All versions up to v1.9.4 are affected, and as of July 10, no patch has been released. This incident underscores the importance of rigorous input validation and memory management in protocol implementations. The lack of a current patch necessitates immediate mitigation measures, such as disabling QPACK's dynamic table or HTTP/3 support, to prevent potential denial-of-service attacks.
2 months ago
Kill Chain
Fake 7-Zip Installers Compromise Devices as Residential Proxy Nodes
In early 2026, cybersecurity researchers uncovered a campaign by the threat actor 'Lurking Lizard,' which distributed trojanized 7-Zip installers via the domain '7zip[.]com.' These malicious installers covertly transformed compromised devices into nodes within a residential proxy network, allowing attackers to route illicit traffic through unsuspecting users' IP addresses. The operation, dating back to at least August 2022, involved over 230 lookalike domains and impersonated major proxy providers to expand its reach. This incident highlights the growing trend of cybercriminals exploiting legitimate software and services to build extensive proxy networks, complicating detection and mitigation efforts. The use of residential proxies enables threat actors to mask their activities, posing significant challenges for cybersecurity defenses and emphasizing the need for heightened vigilance against such deceptive tactics. ([fbi.gov](https://www.fbi.gov/investigate/cyber/alerts/2026/evading-residential-proxy-networks-protecting-your-devices-from-becoming-a-tool-for-criminals?utm_source=openai))
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports