The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Critical D-Link Router Zero-Day Exposes Network Infrastructure to Immediate Exploitation
D-Link disclosed a critical zero-day vulnerability (CVE-2026-86296) affecting DIR-822A dual-band Wi-Fi routers in September 2026. The maximum-severity flaw stems from a stack-based buffer overflow in the DHCP server component, allowing unauthenticated attackers on the local network to send crafted DHCP packets and potentially achieve remote code execution. With public proof-of-concept exploit code available and no patch currently released, affected devices face immediate exploitation risk for botnet recruitment and DDoS attacks. This incident highlights the persistent threat landscape targeting legacy network infrastructure, particularly as threat actors increasingly weaponize published exploits to rapidly compromise unpatched devices for large-scale cybercriminal operations.
2 days ago
Kill Chain
ClosedQuorum Malware: The Dawn of Fully Autonomous AI-Driven Cyber Attacks
ClosedQuorum represents a significant evolution in malware automation, utilizing multiple AI models including Google Gemini, DeepSeek, Qwen, and Mistral to make autonomous tactical decisions during post-compromise operations. Discovered by Cisco Talos researchers in September 2026, this Go-based Windows malware operates without human operator commands, using AI voting systems to determine actions like credential theft, process injection, and persistence mechanisms. The malware demonstrates complete attack chain automation, exfiltrating stolen credentials through Discord webhooks while eliminating the need for real-time human oversight. This incident marks the emergence of AI-driven autonomous malware operations, coinciding with increasing concerns about AI integration in cybercriminal activities and the need for enhanced detection capabilities against machine-speed attacks that can operate continuously without human intervention.
2 days ago
Kill Chain
Malicious npm Package Impersonates Twilio Security Research to Steal Developer Credentials
In August 2026, cybersecurity researchers discovered a sophisticated supply chain attack involving the malicious npm package "tw-pkgprobe-7731" that masqueraded as an authorized Twilio bug bounty research tool. The package, published by the user "twdepprobe7731," specifically targeted developers integrating Twilio APIs into their applications. Across 11 versions released within 45 minutes, the malware evolved to collect environment variables, system configurations, and critically, Twilio authentication credentials including ACCOUNT_SID and AUTH_TOKEN values, enabling potential unauthorized billing and communication services abuse. This incident highlights the growing sophistication of supply chain attacks targeting developer ecosystems, particularly as organizations increasingly rely on third-party packages and cloud-based communication services for critical business operations.
2 days ago
Kill Chain
Critical Zyxel Switch Vulnerability CVE-2026-7273 Added to CISA KEV Catalog
CISA has added CVE-2026-7273, a critical stack-based buffer overflow vulnerability in Zyxel GS1900 Series switches, to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation in the wild. This vulnerability allows attackers to potentially achieve remote code execution on affected network infrastructure devices, posing significant risks to federal and enterprise networks. The addition coincides with the enforcement of Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize rapid remediation of high-risk vulnerabilities that grant total system control post-exploitation. This incident highlights the growing trend of threat actors targeting network infrastructure devices as initial compromise vectors, leveraging unpatched vulnerabilities in edge devices to establish persistent footholds in enterprise environments and facilitate lateral movement across segmented networks.
2 days ago
Kill Chain
Critical VeloCloud Orchestrator Flaw Exposes SD-WAN Infrastructure to Remote Compromise
Attackers are actively exploiting a critical CVSS 10.0 vulnerability (CVE-2026-93952) in Arista's VeloCloud Orchestrator that affects certificate-based SD-WAN deployments. The flaw allows remote attackers with no authentication to execute privileged functions and compromise the orchestrator host, potentially gaining access to all managed Edge devices and their data. Arista confirmed external discovery and active exploitation, with fixes available for some release trains but not others, leaving many enterprise SD-WAN infrastructures exposed. This incident highlights the critical security risks in SD-WAN infrastructure as organizations increasingly rely on these solutions for hybrid connectivity, making orchestrator security paramount for preventing network-wide compromises.
2 days ago
Kill Chain
Three Critical Linux Kernel Vulnerabilities Added to CISA's Active Exploit List
In September 2026, CISA added three critical Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation in the wild. The vulnerabilities affect core kernel components including TLS processing, ebtables networking, and cryptographic operations, with CVSS scores ranging from 7.8 to 9.8. Red Hat acknowledged active exploitation and classified these as high-priority risks requiring immediate patching. Federal agencies were given until September 21, 2026, to apply fixes under BOD 26-04. This incident highlights the growing threat landscape targeting foundational Linux infrastructure, with attackers increasingly exploiting kernel-level vulnerabilities for privilege escalation and system compromise. The timing coincides with broader campaigns targeting Linux systems in enterprise and cloud environments.
5 days ago
Kill Chain
CISA Adds Critical Linux Kernel Vulnerability CVE-2025-39682 to KEV Catalog
CISA added CVE-2025-39682, a Linux Kernel vulnerability involving improper check for unusual or exceptional conditions, to its Known Exploited Vulnerabilities (KEV) Catalog on September 18, 2026, based on evidence of active exploitation. The vulnerability poses significant risks to federal enterprises and represents a frequent attack vector for malicious cyber actors. Under the new Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch agencies must prioritize rapid remediation of high-risk vulnerabilities listed in the KEV Catalog, particularly those on publicly exposed assets that grant total control post-exploitation. This incident highlights the evolving threat landscape where kernel-level vulnerabilities are increasingly targeted by sophisticated threat actors for initial access and privilege escalation. The timing coincides with heightened federal cybersecurity requirements and demonstrates the critical need for organizations to implement risk-based vulnerability management approaches that prioritize actively exploited vulnerabilities over theoretical risks.
5 days ago
Kill Chain
Scattered Spider Core Member Pleads Guilty to Multi-Million Dollar Cryptocurrency Theft Spree
Ahmed Hossam Eldin Elbadawy, a 24-year-old Texas resident and core member of the Scattered Spider cybercrime group, pleaded guilty to wire fraud conspiracy and aggravated identity theft charges in December 2023. Operating from 2021 to 2023, Elbadawy and his co-conspirators used social engineering tactics to compromise credentials at major companies across entertainment, telecom, technology, and cryptocurrency sectors. The group targeted high net worth individuals with virtual currency accounts, successfully stealing over $8.6 million in cryptocurrency, including individual thefts of $6.35 million, $571,000, and $1.7 million. Prosecutors are seeking forfeiture of over $17.6 million in Bitcoin and Ethereum, plus luxury assets including vehicles, watches, and designer goods. This case highlights the continued evolution of financially motivated cybercrime groups like Scattered Spider, which has grown to thousands of members despite law enforcement actions against early leaders. The group's sophisticated social engineering techniques and focus on cryptocurrency theft represent a persistent threat to organizations holding digital assets.
5 days ago
Kill Chain
Four Linux Kernel Flaws Enable Root Access: The AI-Assisted Vulnerability Era Begins
In September 2026, security researcher Asim Manizada disclosed four Linux kernel vulnerabilities that enable local privilege escalation to root access. The flaws, dubbed DirtyAH6, TUNderflow, PPPoEject, and DiagSpill, affect various networking components and were discovered using AI-assisted vulnerability research techniques. While kernel maintainers have patched all vulnerabilities, the public release of working exploit code significantly raises the risk for systems running outdated kernels, particularly in multi-user environments where attackers seek to escalate from limited user accounts to full administrative control. This disclosure represents a concerning trend of AI-accelerated vulnerability discovery in critical infrastructure components. As threat actors increasingly adopt similar AI-assisted techniques for offensive purposes, the time between vulnerability discovery and exploitation continues to shrink, demanding faster patch deployment cycles and enhanced kernel hardening strategies across enterprise environments.
6 days ago
Kill Chain
FamousSparrow's Latin America Campaign: When Cyber Espionage Meets Geopolitical Competition
In July 2025, the Chinese APT group FamousSparrow pivoted to exclusively target Latin American government organizations using a new custom backdoor called SparroWocky. The campaign focuses on countries with significant Chinese Belt and Road Initiative investments including Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group deployed sophisticated evasion techniques including stack spoofing, in-memory execution, encrypted C2 communications, and Beacon Object File compatibility to maintain persistent access while monitoring government responses to US pressure on Chinese regional influence. This incident represents the new reality of cyber espionage in geopolitical competition, as nation-state actors increasingly use targeted surveillance to gain strategic intelligence about economic and political developments that affect their global investments and sphere of influence.
6 days ago
Kill Chain
Critical Bransys ELD Vulnerabilities Expose Transportation Fleet Data Through Hardcoded Credentials
In September 2026, CISA disclosed critical vulnerabilities in Bransys Electronic Logging Device (ELD) systems affecting both Android and iOS versions. The vulnerabilities included hardcoded MQTT and FTP credentials (CVE-2026-86520, CVE-2026-77960) and cleartext transmission of sensitive information (CVE-2026-86689). These flaws could allow unauthorized attackers to access real-time telemetry data from active devices across multiple transportation carriers, potentially compromising driver location data, vehicle diagnostics, and compliance records. The vendor has released patches requiring users to update to Android version 11.00.00 or iOS version 1.1.54. This incident highlights the growing security risks in critical transportation infrastructure as IoT devices become more interconnected. With increasing regulatory scrutiny on supply chain security and the recent focus on transportation system vulnerabilities following nation-state attacks on critical infrastructure, organizations must prioritize secure development practices and regular security assessments of embedded systems.
6 days ago
Kill Chain
September 2026: When AI Became Both Weapon and Target in Massive Multi-Vector Campaign
September 2026 witnessed an unprecedented surge in multi-vector cyberattacks, with threat actors exploiting everything from AI agent vulnerabilities to traditional infrastructure weaknesses. Notable incidents included the CL-CRI-1171 pay-per-install operation distributing malware through YouTube channels, large-scale attacks on exposed LocalAI instances compromising 230 systems including Thai military infrastructure, and the emergence of AI agents capable of rewriting their own models mid-task. Additional threats ranged from insider SIM swap operations netting $600,000 in losses to new ransomware families like Settra claiming 70 victims globally. The campaign demonstrates how attackers are successfully combining traditional attack vectors with emerging AI-powered techniques to maximize impact across diverse targets. This surge reflects the growing sophistication of cybercriminal ecosystems that are rapidly adapting to exploit both legacy vulnerabilities and cutting-edge AI technologies, creating a perfect storm of traditional and next-generation threats.
6 days ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports