The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Iranian Hackers Deploy Cavern C2 Framework Against Israeli Sectors
In early 2026, an Iranian state-sponsored hacking group known as Cavern Manticore targeted Israeli government and IT sectors using a sophisticated modular command-and-control (C2) framework called Cavern. This framework, built on a .NET foundation with multiple compilation formats, enabled the attackers to execute DLL side-loading through SysAid's software update feature, leading to the deployment of various modules for reconnaissance, data theft, and lateral movement. The attack chain involved the execution of a trojanized DLL ('uxtheme.dll') containing the Cavern Agent, which then loaded additional modules to contact the C2 server and fetch further post-exploitation tools. ([research.checkpoint.com](https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/?utm_source=openai)) The incident underscores the evolving tactics of Iranian threat actors, who are increasingly leveraging modular and adaptable toolsets to enhance their cyber espionage capabilities. The use of such frameworks allows for tailored deployments based on victim profiles, reducing forensic visibility and ensuring persistent access. Organizations must remain vigilant and implement robust security measures to defend against these sophisticated threats.
2 months ago
Kill Chain
Disruption of NetNut Residential Proxy Network in 2026
In July 2026, Google, in collaboration with the U.S. Federal Bureau of Investigation (FBI), Lumen, and other partners, dismantled the NetNut residential proxy network, also known as Popa. This network, comprising over 2 million devices globally, exploited home devices like smart TVs and streaming boxes by distributing SDKs that transformed them into proxies for malicious traffic. The compromised devices were either pre-installed with malware before purchase or infected through user-downloaded applications containing hidden proxy code. This operation built upon a previous takedown of IPIDEA in January 2026. The disruption of NetNut underscores the escalating threat posed by botnets leveraging residential devices to mask malicious activities. Such networks not only compromise individual privacy but also facilitate large-scale cyberattacks, making their neutralization a priority for global cybersecurity efforts.
2 months ago
Kill Chain
Unprivileged Users Can Gain Root Access via 'Bad Epoll' Vulnerability in Linux Kernel
In July 2026, a critical vulnerability known as 'Bad Epoll' (CVE-2026-46242) was disclosed in the Linux kernel's eventpoll subsystem. This use-after-free flaw allows unprivileged users to escalate their privileges to root, affecting Linux desktops, servers, and Android devices. The vulnerability arises from a race condition where two kernel components attempt to free the same memory object simultaneously, leading to memory corruption and potential system compromise. A proof-of-concept exploit demonstrates a high success rate in achieving root access, even from within restrictive environments like Chrome's renderer sandbox. The discovery of 'Bad Epoll' underscores the challenges in detecting complex race-condition vulnerabilities within critical system components. Despite prior identification of similar flaws by advanced AI models, this particular issue remained undetected, highlighting the need for continuous and comprehensive security assessments. Organizations are urged to apply the available patches promptly to mitigate potential exploitation risks.
2 months ago
Kill Chain
FBI Dismantles NetNut Proxy Network and Popa Botnet in 2026
In July 2026, the FBI, in collaboration with industry partners including Google and Lumen Technologies, seized hundreds of domains associated with NetNut, a residential proxy service operated by Alarum Technologies. This action disrupted the Popa botnet, which had compromised over two million devices, such as smart TVs and streaming boxes, turning them into proxy nodes for cybercriminal activities like content scraping, advertising fraud, and account takeovers. The takedown significantly degraded NetNut's proxy network and business operations, reducing the pool of compromised devices by millions. This incident underscores the persistent threat posed by residential proxy networks exploited by cybercriminals to mask malicious activities. The collaboration between law enforcement and industry partners highlights the importance of coordinated efforts in combating such threats. Organizations should remain vigilant and implement robust security measures to protect against similar vulnerabilities.
2 months ago
Kill Chain
Iranian Cybercriminal Arrested for $3.4 Billion in Damages
In June 2026, Montenegrin authorities, in collaboration with the FBI, arrested a 39-year-old dual Iranian and Turkish citizen in Kotor. The individual is accused of orchestrating mass cyberattacks since 2013, targeting over 150 U.S. universities and causing damages exceeding $3.4 billion. The stolen data reportedly benefited Iran's Islamic Revolutionary Guard Corps and various Iranian state entities. Extradition proceedings are underway in Montenegro's capital, Podgorica. This arrest underscores the persistent threat posed by state-sponsored cyber activities and highlights the importance of international cooperation in combating cybercrime. Organizations should remain vigilant and enhance their cybersecurity measures to protect against such sophisticated attacks.
2 months ago
Kill Chain
European Parliament Member Targeted with Pegasus Spyware During Investigation
In October 2022 and March 2023, former Member of the European Parliament (MEP) Stelios Kouloglou's mobile device was infiltrated with Pegasus spyware while he was serving on the PEGA committee, which was investigating the misuse of such surveillance tools within the European Union. The Citizen Lab's forensic analysis confirmed these infections, indicating that attackers potentially accessed confidential committee documents and deliberations. The specific government or entity responsible for these attacks remains unidentified. ([citizenlab.ca](https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus/?utm_source=openai)) This incident underscores the escalating threat of sophisticated spyware targeting high-profile individuals, including those involved in oversight and investigative roles. It highlights the urgent need for robust cybersecurity measures and regulatory frameworks to protect sensitive information and uphold democratic processes. ([theguardian.com](https://www.theguardian.com/world/2026/jul/03/spyware-used-against-mep-investigating-pegasus-abuses-report-finds?utm_source=openai))
2 months ago
Kill Chain
Google's 2026 Takedown of NetNut Residential Proxy Network
In July 2026, Google, in collaboration with the FBI and Lumen, significantly disrupted the NetNut residential proxy network, also known as Popa. This network, comprising at least 2 million home devices worldwide, was exploited by cybercriminals and espionage groups to mask malicious activities and conduct password-guessing attacks. Google's actions included disabling accounts and services associated with NetNut's command-and-control operations, leading to a substantial reduction in the network's operational capacity. ([thehackernews.com](https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html?utm_source=openai)) The takedown of NetNut underscores the growing threat posed by residential proxy networks, which can be co-opted by malicious actors to obscure their activities. This incident highlights the critical need for enhanced security measures and vigilance among consumers and organizations to prevent their devices from being exploited in such networks.
2 months ago
Kill Chain
Critical Vulnerabilities Discovered in ST Engineering iDirect iQ-Series Terminals
In July 2026, vulnerabilities were identified in ST Engineering iDirect's iQ-Series Terminals, specifically CVE-2026-38059 and CVE-2026-38057. These flaws allowed unauthenticated attackers to access sensitive device information and execute unauthorized device reboots, potentially leading to denial-of-service conditions. The affected products included Evolution iQ-Series terminals, 3315-Series terminals, and 9-Series terminals, all running firmware versions up to 4.5.2.1. The discovery of these vulnerabilities underscores the critical importance of securing networked devices in sectors such as Communications, Defense Industrial Base, Energy, Government Services, and Transportation Systems. Organizations are urged to update their devices to firmware version 4.5.2.2 or newer and implement recommended security practices to mitigate potential exploitation.
2 months ago
Kill Chain
Critical Vulnerability in CubeSpace CW0057 Reaction Wheel Firmware
In July 2026, CubeSpace disclosed a vulnerability (CVE-2026-13743) in its CW0057 Reaction Wheel firmware versions prior to 5.0.20. This flaw allows attackers with physical access to upload malicious firmware without authentication, potentially compromising satellite operations. The issue stems from the device's reliance on CRC-32 integrity checks, which verify data integrity but not the authenticity of the firmware source. CubeSpace has released firmware version 5.0.20, introducing cryptographically verified secure boot, though this feature is not enabled by default and requires user activation. This incident underscores the critical importance of robust firmware authentication mechanisms in aerospace components. As satellites become increasingly integral to global communications and defense, ensuring the integrity of onboard systems is paramount. Organizations must proactively implement and enable security features to mitigate risks associated with unauthorized firmware modifications.
2 months ago
Kill Chain
19-Year-Old Scattered Spider Member Extradited to U.S. for Hacking Charges
On July 1, 2026, the U.S. Department of Justice announced the extradition of Peter Stokes, a 19-year-old dual U.S. and Estonian citizen, from Finland to the United States. Stokes, identified by the online handle "Bouquet," faces charges of conspiracy, computer intrusion, and fraud for his alleged involvement with the cybercriminal group Scattered Spider. This group has been linked to over 100 network intrusions, resulting in more than $100 million in ransom payments. Stokes appeared in a Chicago federal court on June 30, where he was ordered to remain in custody. The arrest underscores the persistent threat posed by Scattered Spider, known for targeting sectors such as casinos, retailers, and airlines through sophisticated social engineering tactics. Despite recent law enforcement actions, the group's methods continue to evolve, highlighting the need for organizations to bolster their cybersecurity defenses against such adaptive threats.
2 months ago
Kill Chain
Iran-Nexus TAG-182 Deploys MarkiRAT Malware in Surveillance Campaign
In early 2026, the Iranian-linked threat group TAG-182 initiated a cyber espionage campaign deploying MarkiRAT malware via counterfeit Android applications, including fake VPNs and media tools, to surveil Iranian citizens domestically and abroad. This operation aligns with Iran's intensified digital surveillance efforts following the partial restoration of internet access on May 26, 2026, targeting perceived dissidents and foreign collaborators. The MarkiRAT samples exhibit tradecraft overlaps with previous variants used by Ferocious Kitten, suggesting a potential operational connection, though further evidence is required to confirm organizational links. ([staging.hawk-eye.io](https://staging.hawk-eye.io/iran-apt-threat-advisory/?utm_source=openai)) The resurgence of TAG-182's activities underscores the persistent threat posed by Iranian state-sponsored cyber operations, particularly in the realm of surveillance and intelligence gathering. Organizations and individuals, especially those involved in human rights advocacy or opposition activities, should remain vigilant against sophisticated social engineering tactics and ensure robust cybersecurity measures are in place to mitigate the risks associated with such targeted campaigns.
2 months ago
Kill Chain
China-Linked Group Targets Southeast Asia Critical Systems
In mid-2025, the Chinese-speaking advanced persistent threat (APT) group CL-STA-1062 initiated a cyber espionage campaign targeting government entities and critical infrastructure in Southeast Asia. The group compromised at least 10 organizations, including state-owned enterprises in the energy and government sectors, deploying a custom backdoor named TinyRCT. This backdoor facilitated unauthorized access, data exfiltration, and system control, posing significant risks to national security and operational stability. ([thehackernews.com](https://thehackernews.com/2026/06/chinese-speaking-apt-deploys-new.html?utm_source=openai)) The emergence of TinyRCT underscores the evolving sophistication of state-sponsored cyber threats in the region. Organizations must enhance their cybersecurity measures to detect and mitigate such advanced persistent threats, ensuring the resilience of critical infrastructure against future attacks. ([thehackernews.com](https://thehackernews.com/2026/06/chinese-speaking-apt-deploys-new.html?utm_source=openai))
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports