The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

943 threat reports
Page 2 of 79

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Telecommunications Threat Reports

Showing 13–24 / 943 reports
Critical D-Link Router Zero-Day Exposes Network Infrastructure to Immediate Exploitation
Impact· CRITICAL

Critical D-Link Router Zero-Day Exposes Network Infrastructure to Immediate Exploitation

D-Link disclosed a critical zero-day vulnerability (CVE-2026-86296) affecting DIR-822A dual-band Wi-Fi routers in September 2026. The maximum-severity flaw stems from a stack-based buffer overflow in the DHCP server component, allowing unauthenticated attackers on the local network to send crafted DHCP packets and potentially achieve remote code execution. With public proof-of-concept exploit code available and no patch currently released, affected devices face immediate exploitation risk for botnet recruitment and DDoS attacks. This incident highlights the persistent threat landscape targeting legacy network infrastructure, particularly as threat actors increasingly weaponize published exploits to rapidly compromise unpatched devices for large-scale cybercriminal operations.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
ClosedQuorum Malware: The Dawn of Fully Autonomous AI-Driven Cyber Attacks
Impact· MEDIUM

ClosedQuorum Malware: The Dawn of Fully Autonomous AI-Driven Cyber Attacks

ClosedQuorum represents a significant evolution in malware automation, utilizing multiple AI models including Google Gemini, DeepSeek, Qwen, and Mistral to make autonomous tactical decisions during post-compromise operations. Discovered by Cisco Talos researchers in September 2026, this Go-based Windows malware operates without human operator commands, using AI voting systems to determine actions like credential theft, process injection, and persistence mechanisms. The malware demonstrates complete attack chain automation, exfiltrating stolen credentials through Discord webhooks while eliminating the need for real-time human oversight. This incident marks the emergence of AI-driven autonomous malware operations, coinciding with increasing concerns about AI integration in cybercriminal activities and the need for enhanced detection capabilities against machine-speed attacks that can operate continuously without human intervention.

2 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Malicious npm Package Impersonates Twilio Security Research to Steal Developer Credentials
Impact· MEDIUM

Malicious npm Package Impersonates Twilio Security Research to Steal Developer Credentials

In August 2026, cybersecurity researchers discovered a sophisticated supply chain attack involving the malicious npm package "tw-pkgprobe-7731" that masqueraded as an authorized Twilio bug bounty research tool. The package, published by the user "twdepprobe7731," specifically targeted developers integrating Twilio APIs into their applications. Across 11 versions released within 45 minutes, the malware evolved to collect environment variables, system configurations, and critically, Twilio authentication credentials including ACCOUNT_SID and AUTH_TOKEN values, enabling potential unauthorized billing and communication services abuse. This incident highlights the growing sophistication of supply chain attacks targeting developer ecosystems, particularly as organizations increasingly rely on third-party packages and cloud-based communication services for critical business operations.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Zyxel Switch Vulnerability CVE-2026-7273 Added to CISA KEV Catalog
Impact· HIGH

Critical Zyxel Switch Vulnerability CVE-2026-7273 Added to CISA KEV Catalog

CISA has added CVE-2026-7273, a critical stack-based buffer overflow vulnerability in Zyxel GS1900 Series switches, to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation in the wild. This vulnerability allows attackers to potentially achieve remote code execution on affected network infrastructure devices, posing significant risks to federal and enterprise networks. The addition coincides with the enforcement of Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize rapid remediation of high-risk vulnerabilities that grant total system control post-exploitation. This incident highlights the growing trend of threat actors targeting network infrastructure devices as initial compromise vectors, leveraging unpatched vulnerabilities in edge devices to establish persistent footholds in enterprise environments and facilitate lateral movement across segmented networks.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical VeloCloud Orchestrator Flaw Exposes SD-WAN Infrastructure to Remote Compromise
Impact· CRITICAL

Critical VeloCloud Orchestrator Flaw Exposes SD-WAN Infrastructure to Remote Compromise

Attackers are actively exploiting a critical CVSS 10.0 vulnerability (CVE-2026-93952) in Arista's VeloCloud Orchestrator that affects certificate-based SD-WAN deployments. The flaw allows remote attackers with no authentication to execute privileged functions and compromise the orchestrator host, potentially gaining access to all managed Edge devices and their data. Arista confirmed external discovery and active exploitation, with fixes available for some release trains but not others, leaving many enterprise SD-WAN infrastructures exposed. This incident highlights the critical security risks in SD-WAN infrastructure as organizations increasingly rely on these solutions for hybrid connectivity, making orchestrator security paramount for preventing network-wide compromises.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Three Critical Linux Kernel Vulnerabilities Added to CISA's Active Exploit List
Impact· HIGH

Three Critical Linux Kernel Vulnerabilities Added to CISA's Active Exploit List

In September 2026, CISA added three critical Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation in the wild. The vulnerabilities affect core kernel components including TLS processing, ebtables networking, and cryptographic operations, with CVSS scores ranging from 7.8 to 9.8. Red Hat acknowledged active exploitation and classified these as high-priority risks requiring immediate patching. Federal agencies were given until September 21, 2026, to apply fixes under BOD 26-04. This incident highlights the growing threat landscape targeting foundational Linux infrastructure, with attackers increasingly exploiting kernel-level vulnerabilities for privilege escalation and system compromise. The timing coincides with broader campaigns targeting Linux systems in enterprise and cloud environments.

5 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
CISA Adds Critical Linux Kernel Vulnerability CVE-2025-39682 to KEV Catalog
Impact· HIGH

CISA Adds Critical Linux Kernel Vulnerability CVE-2025-39682 to KEV Catalog

CISA added CVE-2025-39682, a Linux Kernel vulnerability involving improper check for unusual or exceptional conditions, to its Known Exploited Vulnerabilities (KEV) Catalog on September 18, 2026, based on evidence of active exploitation. The vulnerability poses significant risks to federal enterprises and represents a frequent attack vector for malicious cyber actors. Under the new Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch agencies must prioritize rapid remediation of high-risk vulnerabilities listed in the KEV Catalog, particularly those on publicly exposed assets that grant total control post-exploitation. This incident highlights the evolving threat landscape where kernel-level vulnerabilities are increasingly targeted by sophisticated threat actors for initial access and privilege escalation. The timing coincides with heightened federal cybersecurity requirements and demonstrates the critical need for organizations to implement risk-based vulnerability management approaches that prioritize actively exploited vulnerabilities over theoretical risks.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Scattered Spider Core Member Pleads Guilty to Multi-Million Dollar Cryptocurrency Theft Spree
Impact· HIGH

Scattered Spider Core Member Pleads Guilty to Multi-Million Dollar Cryptocurrency Theft Spree

Ahmed Hossam Eldin Elbadawy, a 24-year-old Texas resident and core member of the Scattered Spider cybercrime group, pleaded guilty to wire fraud conspiracy and aggravated identity theft charges in December 2023. Operating from 2021 to 2023, Elbadawy and his co-conspirators used social engineering tactics to compromise credentials at major companies across entertainment, telecom, technology, and cryptocurrency sectors. The group targeted high net worth individuals with virtual currency accounts, successfully stealing over $8.6 million in cryptocurrency, including individual thefts of $6.35 million, $571,000, and $1.7 million. Prosecutors are seeking forfeiture of over $17.6 million in Bitcoin and Ethereum, plus luxury assets including vehicles, watches, and designer goods. This case highlights the continued evolution of financially motivated cybercrime groups like Scattered Spider, which has grown to thousands of members despite law enforcement actions against early leaders. The group's sophisticated social engineering techniques and focus on cryptocurrency theft represent a persistent threat to organizations holding digital assets.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Four Linux Kernel Flaws Enable Root Access: The AI-Assisted Vulnerability Era Begins
Impact· MEDIUM

Four Linux Kernel Flaws Enable Root Access: The AI-Assisted Vulnerability Era Begins

In September 2026, security researcher Asim Manizada disclosed four Linux kernel vulnerabilities that enable local privilege escalation to root access. The flaws, dubbed DirtyAH6, TUNderflow, PPPoEject, and DiagSpill, affect various networking components and were discovered using AI-assisted vulnerability research techniques. While kernel maintainers have patched all vulnerabilities, the public release of working exploit code significantly raises the risk for systems running outdated kernels, particularly in multi-user environments where attackers seek to escalate from limited user accounts to full administrative control. This disclosure represents a concerning trend of AI-accelerated vulnerability discovery in critical infrastructure components. As threat actors increasingly adopt similar AI-assisted techniques for offensive purposes, the time between vulnerability discovery and exploitation continues to shrink, demanding faster patch deployment cycles and enhanced kernel hardening strategies across enterprise environments.

6 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
FamousSparrow's Latin America Campaign: When Cyber Espionage Meets Geopolitical Competition
Impact· HIGH

FamousSparrow's Latin America Campaign: When Cyber Espionage Meets Geopolitical Competition

In July 2025, the Chinese APT group FamousSparrow pivoted to exclusively target Latin American government organizations using a new custom backdoor called SparroWocky. The campaign focuses on countries with significant Chinese Belt and Road Initiative investments including Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group deployed sophisticated evasion techniques including stack spoofing, in-memory execution, encrypted C2 communications, and Beacon Object File compatibility to maintain persistent access while monitoring government responses to US pressure on Chinese regional influence. This incident represents the new reality of cyber espionage in geopolitical competition, as nation-state actors increasingly use targeted surveillance to gain strategic intelligence about economic and political developments that affect their global investments and sphere of influence.

6 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Bransys ELD Vulnerabilities Expose Transportation Fleet Data Through Hardcoded Credentials
Impact· HIGH

Critical Bransys ELD Vulnerabilities Expose Transportation Fleet Data Through Hardcoded Credentials

In September 2026, CISA disclosed critical vulnerabilities in Bransys Electronic Logging Device (ELD) systems affecting both Android and iOS versions. The vulnerabilities included hardcoded MQTT and FTP credentials (CVE-2026-86520, CVE-2026-77960) and cleartext transmission of sensitive information (CVE-2026-86689). These flaws could allow unauthorized attackers to access real-time telemetry data from active devices across multiple transportation carriers, potentially compromising driver location data, vehicle diagnostics, and compliance records. The vendor has released patches requiring users to update to Android version 11.00.00 or iOS version 1.1.54. This incident highlights the growing security risks in critical transportation infrastructure as IoT devices become more interconnected. With increasing regulatory scrutiny on supply chain security and the recent focus on transportation system vulnerabilities following nation-state attacks on critical infrastructure, organizations must prioritize secure development practices and regular security assessments of embedded systems.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
September 2026: When AI Became Both Weapon and Target in Massive Multi-Vector Campaign
Impact· CRITICAL

September 2026: When AI Became Both Weapon and Target in Massive Multi-Vector Campaign

September 2026 witnessed an unprecedented surge in multi-vector cyberattacks, with threat actors exploiting everything from AI agent vulnerabilities to traditional infrastructure weaknesses. Notable incidents included the CL-CRI-1171 pay-per-install operation distributing malware through YouTube channels, large-scale attacks on exposed LocalAI instances compromising 230 systems including Thai military infrastructure, and the emergence of AI agents capable of rewriting their own models mid-task. Additional threats ranged from insider SIM swap operations netting $600,000 in losses to new ransomware families like Settra claiming 70 victims globally. The campaign demonstrates how attackers are successfully combining traditional attack vectors with emerging AI-powered techniques to maximize impact across diverse targets. This surge reflects the growing sophistication of cybercriminal ecosystems that are rapidly adapting to exploit both legacy vulnerabilities and cutting-edge AI technologies, creating a perfect storm of traditional and next-generation threats.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports