The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

943 threat reports
Page 29 of 79

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Telecommunications Threat Reports

Showing 337–348 / 943 reports
Europol's Operation Kratos 2: A Major Blow to Digital Piracy
Impact· LOW

Europol's Operation Kratos 2: A Major Blow to Digital Piracy

Between September 2025 and April 2026, European authorities conducted Operation Kratos 2, a coordinated effort led by Bulgaria and supported by Europol, targeting illegal streaming networks. This seven-month operation resulted in 29 arrests, the dismantling of nine organized crime groups, and the removal of over 27,000 illegal streaming URLs that infringed on nearly 850,000 media assets across 169 domains. The operation also involved 148 house searches, identification of 86 suspects, and referral of 59 cases for criminal proceedings. Investigators collaborated with private-sector partners to identify nearly 4,400 new domains and more than 18,000 IP addresses linked to piracy and other illegal activities, leading to the reporting of almost 400,000 additional URLs for suspension or removal. ([europol.europa.eu](https://www.europol.europa.eu/media-press/newsroom/news/29-arrested-law-enforcement-strikes-criminal-networks-behind-illegal-streaming?utm_source=openai)) This operation underscores the persistent threat posed by sophisticated criminal enterprises exploiting digital platforms for illegal content distribution. The success of Operation Kratos 2 highlights the importance of international collaboration in combating digital piracy and protecting intellectual property rights.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerabilities in Acer Wave 7 Routers: CVE-2026-49200 and CVE-2026-49201
Impact· CRITICAL

Critical Vulnerabilities in Acer Wave 7 Routers: CVE-2026-49200 and CVE-2026-49201

In May 2026, security researcher Gergo Pap identified two critical vulnerabilities in Acer's Wave 7 mesh routers running firmware version T7c_GBL_1.01.000055 or earlier. The first vulnerability (CVE-2026-49200) allows unauthenticated remote access to the 'acer_cgi.log' file via the web interface, exposing cleartext login credentials and enabling unauthorized system access. The second vulnerability (CVE-2026-49201) involves a hardcoded AES encryption key in the 'upload.cgi' binary, permitting attackers to decrypt, modify, and re-encrypt system backups, potentially injecting persistent backdoors into the router. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/acer-warns-of-max-severity-zero-days-affecting-wave-7-routers/?utm_source=openai)) These vulnerabilities underscore the critical importance of securing network infrastructure devices, as they can serve as entry points for attackers to infiltrate organizational networks. The incident highlights the necessity for manufacturers to implement robust security measures, including proper access controls and secure cryptographic practices, to prevent such exposures.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CISA Alerts on Active Exploitation of Android and Linux Vulnerabilities
Impact· HIGH

CISA Alerts on Active Exploitation of Android and Linux Vulnerabilities

In June 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2025-48595 and CVE-2022-0492. CVE-2025-48595 is a high-severity integer overflow vulnerability in the Android Framework affecting versions 14 through 16, allowing local privilege escalation without user interaction. CVE-2022-0492 is a privilege escalation flaw in the Linux kernel's cgroups v1 subsystem, enabling attackers to bypass namespace isolation and potentially gain root access on host systems. Both vulnerabilities have been actively exploited in the wild, prompting immediate patching and mitigation efforts. The inclusion of these vulnerabilities in the KEV catalog underscores the persistent threat posed by privilege escalation flaws in widely used operating systems. Organizations are urged to prioritize the application of security updates to mitigate potential exploitation risks and protect their systems from unauthorized access and control.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Exploiting Google Gemini: The Rise of Prompt Injection Attacks
Impact· MEDIUM

Exploiting Google Gemini: The Rise of Prompt Injection Attacks

In June 2026, a security vulnerability was discovered in Google Gemini's voice assistant, allowing attackers to exploit its notification summarization feature through prompt injection techniques. By embedding malicious commands within message notifications, adversaries could manipulate the assistant to perform unauthorized actions such as controlling smart home devices, initiating video streams, conducting social engineering attacks, and compromising the integrity of large language model (LLM) memory. This flaw was identified and responsibly disclosed by SafeBreach, leading Google to implement content classifier updates to mitigate the issue. This incident underscores the evolving threat landscape associated with AI-powered assistants and the critical need for robust security measures to prevent prompt injection attacks. As AI integration in daily applications increases, ensuring the integrity and security of these systems becomes paramount to protect users from sophisticated exploitation methods.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Impact· HIGH

CISA Adds Two Known Exploited Vulnerabilities to Catalog

On June 2, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2022-0492, a Linux Kernel Improper Authentication Vulnerability, and CVE-2025-48595, an Android Framework Integer Overflow Vulnerability. Both vulnerabilities are actively exploited, posing significant risks to federal enterprises. CVE-2022-0492 allows unauthorized access to Linux systems, while CVE-2025-48595 enables local privilege escalation on Android devices without user interaction. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-48595?utm_source=openai)) The inclusion of these vulnerabilities in the KEV Catalog underscores the critical need for organizations to promptly address known security flaws. With active exploitation in the wild, timely remediation is essential to mitigate potential threats and protect sensitive information.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Google Addresses Actively Exploited Android Zero-Day CVE-2025-48595 in June 2026 Security Update
Impact· HIGH

Google Addresses Actively Exploited Android Zero-Day CVE-2025-48595 in June 2026 Security Update

In June 2026, Google released security patches addressing 124 vulnerabilities in the Android operating system, notably including CVE-2025-48595. This high-severity zero-day flaw in the Android Framework allows local attackers to execute code and escalate privileges on devices running Android 14 and later. Exploitation does not require user interaction, suggesting potential use of malicious applications to gain unauthorized access. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/google-fixes-one-actively-exploited-android-zero-day-124-flaws/?utm_source=openai)) The active exploitation of CVE-2025-48595 underscores the persistent threat posed by zero-day vulnerabilities in widely used platforms. Organizations must prioritize timely application of security updates to mitigate risks associated with such flaws, especially given the increasing sophistication of targeted attacks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/google-fixes-one-actively-exploited-android-zero-day-124-flaws/?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Google's June 2026 Android Security Update: Addressing 124 Vulnerabilities, Including Actively Exploited CVE-2025-48595
Impact· HIGH

Google's June 2026 Android Security Update: Addressing 124 Vulnerabilities, Including Actively Exploited CVE-2025-48595

In June 2026, Google released security updates addressing 124 vulnerabilities in the Android operating system, notably including CVE-2025-48595—a high-severity privilege escalation flaw in the Framework component. This vulnerability affects Android versions 14 through 16 QPR2 and allows attackers to gain elevated privileges without user interaction, potentially leading to full device compromise. Google has acknowledged indications of limited, targeted exploitation of this flaw in the wild. The active exploitation of CVE-2025-48595 underscores the persistent threat posed by privilege escalation vulnerabilities in widely used mobile platforms. Organizations and individuals are urged to promptly apply the June 2026 security patches to mitigate potential risks associated with this and other addressed vulnerabilities.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Dutch Authorities Dismantle Massive 17 Million-Device Botnet
Impact· HIGH

Dutch Authorities Dismantle Massive 17 Million-Device Botnet

In May 2026, Dutch authorities dismantled a massive botnet comprising over 17 million infected devices, including computers, smartphones, and IoT devices. The operation, conducted by the Dutch National Police and the National Cyber Security Centre (NCSC), involved seizing more than 200 servers located in the Netherlands that controlled the botnet's infrastructure. The botnet was reportedly linked to Asocks, a company offering residential proxy services, which had been exploited for various cybercriminal activities such as DDoS attacks, phishing, and malware distribution. ([arstechnica.com](https://arstechnica.com/security/2026/05/botnet-of-more-than-17-million-devices-dismantled/?utm_source=openai)) This incident underscores the growing threat posed by large-scale botnets leveraging residential proxy networks to mask malicious activities. The takedown highlights the importance of international cooperation in combating cybercrime and the need for robust security measures to protect consumer devices from being co-opted into such networks.

3 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Charter Communications Data Breach 2026: A Case Study in Social Engineering Attacks
Impact· HIGH

Charter Communications Data Breach 2026: A Case Study in Social Engineering Attacks

In early April 2026, Charter Communications, a major U.S. telecommunications provider, experienced a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers gained access through a voice phishing (vishing) attack that compromised an employee's Microsoft Entra account, allowing them to infiltrate Charter's Salesforce system. This breach resulted in the exfiltration of personal information from approximately 4.9 million accounts, including names, email addresses, physical addresses, phone numbers, phone types, plan information, support ticket data, and some Customer Proprietary Network Information (CPNI). Charter confirmed the breach but stated that no sensitive personal or CPNI data was exfiltrated. After the company refused to pay the ransom demanded by ShinyHunters, the stolen data was leaked on the dark web. This incident underscores the growing threat posed by sophisticated social engineering attacks targeting employee credentials to access sensitive corporate systems. The breach highlights the critical need for robust security measures, including comprehensive employee training on phishing tactics and the implementation of multi-factor authentication, to prevent unauthorized access and protect customer data.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Dutch Authorities Dismantle Massive 17 Million-Device Botnet
Impact· HIGH

Dutch Authorities Dismantle Massive 17 Million-Device Botnet

In May 2026, Dutch authorities dismantled a massive botnet comprising 17 million infected devices, including computers, tablets, and smartphones. The operation involved seizing over 200 servers located in the Netherlands that controlled the botnet's infrastructure. This network was utilized for various cyberattacks, such as distributed denial-of-service (DDoS) attacks and malicious traffic proxying. The botnet was linked to a service called Asocks, which offered proxy services using compromised devices without the owners' knowledge. This incident underscores the growing threat posed by botnets leveraging residential devices, highlighting the need for enhanced security measures to protect consumer hardware from unauthorized exploitation.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
GREYVIBE's AI-Powered Cyberattacks on Ukraine: A 2025 Case Study
Impact· HIGH

GREYVIBE's AI-Powered Cyberattacks on Ukraine: A 2025 Case Study

In August 2025, a previously undocumented threat actor named GREYVIBE initiated a series of cyberattacks targeting Ukrainian military, government, civilian, and business entities. Operating from the Russian time zone and aligning with Kremlin state interests, GREYVIBE employed multiple attack vectors, including spear-phishing emails, fake CAPTCHA pages, and fraudulent websites, to deliver custom-developed malware such as PhantomRelay and LegionRelay. Notably, the group leveraged generative artificial intelligence (GenAI) and large language models (LLMs) to enhance their operations, facilitating rapid development of obfuscators, loaders, and malware. ([thehackernews.com](https://thehackernews.com/2026/05/new-russian-linked-greyvibe-targets.html?utm_source=openai)) The integration of AI technologies in cyberattacks signifies a concerning evolution in threat actor capabilities, enabling even low-to-moderately sophisticated groups to execute complex operations. This trend underscores the urgent need for organizations to adopt advanced cybersecurity measures to detect and mitigate AI-assisted threats. ([t.co](https://t.co/WAHU7GJnZC?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
BTMOB: The No-Code Android Malware Service Empowering Cybercriminals
Impact· HIGH

BTMOB: The No-Code Android Malware Service Empowering Cybercriminals

In May 2026, cybersecurity researchers identified BTMOB, an Android remote access trojan (RAT) offered as a malware-as-a-service (MaaS) platform. BTMOB provides cybercriminals with a no-code APK builder, enabling the creation of customized phishing payloads without programming expertise. The malware grants attackers extensive control over infected devices, including data exfiltration, financial transaction interception, screenshot capture, and remote operation. Distributed primarily through phishing websites impersonating legitimate services, BTMOB has been notably active in Brazil and Latin America. Its accessibility and comprehensive feature set pose a significant threat to Android users globally. The emergence of BTMOB underscores a concerning trend in the cyber threat landscape: the commoditization of sophisticated malware through MaaS platforms. This development lowers the barrier to entry for cybercriminals, facilitating the rapid proliferation of advanced threats. Organizations must remain vigilant, as the ease of deploying such malware increases the risk of widespread attacks targeting mobile devices.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports