The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
APT36 Evolves Tactics with Rust Malware and GitHub Infrastructure in Operation RapidRust
In September 2026, the Pakistan-aligned threat group Transparent Tribe (APT36) launched Operation RapidRust, targeting government and defense entities in India and Afghanistan with four new malware families: RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The campaign utilized innovative command-and-control infrastructure through private GitHub repositories and typosquatted domains mimicking Indian news organizations. The sophisticated attack chain involved a Rust-based backdoor for encrypted communications, USB propagation tools, and cross-platform file stealers capable of exfiltrating up to 5GB of sensitive data per execution. This incident highlights the evolving threat landscape where nation-state actors increasingly leverage legitimate cloud services for malicious infrastructure while expanding their technical capabilities across multiple operating systems and attack vectors.
6 days ago
Kill Chain
MikroTrick Attack Chain: How Attackers Gained Full Control of RouterOS Devices
In September 2026, security researchers discovered MikroTrick, a sophisticated attack chain targeting MikroTik RouterOS devices that allowed attackers to gain administrative access without authentication. The vulnerability chain combined CVE-2026-67279 (SSH authentication bypass via rekeying) and CVE-2026-86060 (privilege escalation through username manipulation) to achieve complete router takeover. Evidence indicates active exploitation occurred before public disclosure, with compromised devices found containing persistent backdoors including unauthorized administrative accounts and scheduled scripts designed to maintain persistence. The attack affected RouterOS versions 6.x and 7.x, with internet-facing routers being primary targets. This incident highlights the critical evolution of network infrastructure attacks, where threat actors are increasingly targeting edge devices that sit between organizations and the internet, providing unprecedented access to monitor traffic, steal credentials, and establish persistent footholds for lateral movement into internal networks.
6 days ago
Kill Chain
Critical BIND 9 Update Patches 14 DNS Vulnerabilities Including Unauthenticated DoH Crash
The Internet Systems Consortium (ISC) released BIND 9.20.29 and 9.21.26 in September 2026 to address fourteen critical security vulnerabilities in its open-source DNS server software. The most severe flaw (CVE-2026-77692) allows unauthenticated attackers to crash DNS-over-HTTPS servers with a single malformed request containing an invalid SIG(0) signature. Seven vulnerabilities received High CVSS ratings of 7.5, including multiple denial-of-service attacks, cache poisoning vulnerabilities, and resource exhaustion flaws affecting recursive resolvers and authoritative servers. This vulnerability disclosure highlights the increasing sophistication of DNS-targeted attacks and the critical importance of maintaining updated DNS infrastructure. As organizations increasingly rely on DNS-over-HTTPS for secure name resolution and adopt zero-trust architectures, vulnerabilities in core DNS services represent significant attack vectors for threat actors seeking initial compromise or lateral movement capabilities.
1 week ago
Kill Chain
Chinese APT FamousSparrow Targets Latin America with Advanced SparroWocky Backdoor
In August 2025, the China-aligned state-sponsored threat actor FamousSparrow began deploying a new backdoor called SparroWocky across multiple Latin American countries including Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The modular C++ backdoor replaced their previous SparrowDoor implant and targeted governmental entities through DLL sideloading techniques. SparroWocky features advanced capabilities including file execution, TCP proxy functionality, command execution, data exfiltration, screenshot capture, and self-deletion mechanisms while leveraging open-source tools like Mbed TLS for secure C2 communications. This campaign represents the evolving sophistication of Chinese APT groups who are increasingly integrating open-source offensive tools directly into custom malware rather than using them as separate utilities. The geographic focus on Latin America suggests either a formal mandate or opportunistic targeting based on current geopolitical circumstances, highlighting the global reach of state-sponsored cyber espionage operations.
1 week ago
Kill Chain
Hospitality Under Fire: PBX System Reconnaissance Reveals Critical Security Gaps
In September 2020, SANS Internet Storm Center detected targeted reconnaissance scans against hospitality industry applications, specifically focusing on the abandoned PIAF-HMS (PBX in a Flash Hospitality Management System) project. The scans originated from IP address 94.102.49.125, associated with bulletproof hosting provider IP Volume (AS202425), and targeted multiple hospitality-related endpoints including /admin/, /ucp/, /hms/, and /hotel/. The attackers used a distinctive user agent 'Farez-Sorter/1.0' and appeared to be exploiting recently disclosed SQL injection vulnerabilities in the decade-old, unpatched system that lacks proper input validation and authentication controls. This incident highlights the persistent targeting of hospitality infrastructure, where attackers seek to steal valuable guest personal data and potentially launch man-in-the-middle attacks. The focus on PBX systems suggests sophisticated attack vectors that could allow threat actors to impersonate internal hotel communications and manipulate guest interactions through compromised telephony infrastructure.
1 week ago
Kill Chain
Critical Unbound DNS Vulnerability Exposes Organizations to Remote Code Execution
A critical heap overflow vulnerability (CVE-2026-81642) was discovered in the Unbound DNS resolver's DNSSEC validator, affecting all versions before 1.26.1. The flaw allows remote code execution when an attacker controls a malicious DNS zone and queries a vulnerable resolver. NLnet Labs released Unbound 1.26.1 on September 17, 2026, patching this critical vulnerability along with eight other security flaws. The vulnerability has a CVSS score of 9.1 and requires no user interaction or privileges to exploit. This incident highlights the growing sophistication of DNS-based attacks and the critical importance of maintaining up-to-date DNS infrastructure components. With DNS being foundational to internet operations, vulnerabilities in widely-deployed resolvers like Unbound pose significant risks to organizational security postures and can serve as initial compromise vectors for advanced persistent threats.
1 week ago
Kill Chain
FBI Disrupts NightmareStresser: Major DDoS-for-Hire Takedown Exposes Cybercrime-as-a-Service Threats
In December 2024, the FBI and Royal Canadian Mounted Police seized the primary domain and associated websites of NightmareStresser, one of the longest-running and most popular DDoS-for-hire services used by cybercriminals globally. Operating since at least 2022, the service facilitated hundreds of thousands of DDoS attacks against educational institutions, government agencies, gaming platforms, and millions of individuals worldwide. The takedown was part of Operation PowerOFF, an ongoing international effort targeting IP stressers and booter services that make DDoS attacks accessible to non-technical users through user-friendly interfaces and tutorials. This incident highlights the persistent threat of commoditized cyber attack services that democratize sophisticated attack capabilities, enabling script kiddies and low-skilled threat actors to launch disruptive campaigns against critical infrastructure and services with minimal technical expertise required.
1 week ago
Kill Chain
Google Patches Actively Exploited Android Zero-Day CVE-2026-58704 on Pixel Devices
In September 2026, Google addressed CVE-2026-58704, a high-severity zero-day vulnerability in Android Pixel devices that was actively exploited in targeted attacks. The flaw stems from improper authorization and protection mechanism failures in the Modem subcomponent, allowing attackers with adjacent network access to escalate privileges without user interaction. Google's security update patched this vulnerability along with 109 other security issues, including 12 remote code execution and 89 privilege escalation flaws rated critical or high severity. This incident highlights the growing sophistication of mobile device attacks and the critical importance of rapid patch deployment in enterprise environments where mobile devices access corporate networks and sensitive data.
1 week ago
Kill Chain
Issabel Framework Under Attack: CVE-2026-89026 Enables Unauthenticated Remote Code Execution
In September 2026, attackers began actively exploiting CVE-2026-89026, a critical vulnerability in the Issabel Framework affecting open-source unified communications PBX systems. The flaw stems from a hard-coded JWT signing key that allows unauthenticated remote attackers to forge valid bearer tokens and execute arbitrary operating system commands through the /pbxapi/manager/originate endpoint. While a patch was released on August 1, 2026, the Shadowserver Foundation detected active exploitation beginning September 9, 2026, putting thousands of installations at risk of complete system compromise. This incident highlights the growing threat landscape targeting VoIP and unified communications infrastructure, which has become increasingly critical for remote work operations. The vulnerability demonstrates how authentication bypass flaws in telecommunications systems can provide attackers with direct pathways to enterprise networks and sensitive communications data.
1 week ago
Kill Chain
APT37 Embeds Malware in Load Balancers to Spy on South Korean Industries
A North Korean advanced persistent threat group, likely APT37, conducted sophisticated espionage operations against South Korean media and automotive companies throughout 2025-2026. The attackers compromised HAProxy load balancers to deploy a custom Linux toolkit called 'TED', gaining access to decrypted communications and conducting long-term surveillance operations. The group harvested credentials, modified log files to hide their tracks, and maintained persistent access to target networks for intelligence collection on media sources and manufacturing technology. This incident represents a significant evolution in APT tactics, demonstrating how threat actors are embedding malicious code directly into production infrastructure rather than deploying traditional malware. The targeting of critical industrial sectors and the sophisticated load balancer compromise technique highlight the growing threat to network appliances and the need for enhanced infrastructure security.
1 week ago
Kill Chain
Active Exploitation of WSO2 API Manager JWT Bypass Highlights Critical API Security Gaps
In September 2026, watchTowr researchers detected active exploitation of CVE-2026-5430, a critical JWT authentication bypass vulnerability in WSO2 API Manager products. The flaw allows attackers to forge JWT tokens with administrative privileges by using unsupported cryptographic algorithms that the system incorrectly validates. Threat actors are leveraging this vulnerability to gain unauthorized access to API backends, extract consumer keys and secrets, and potentially compromise entire API ecosystems. The vulnerability affects multiple WSO2 products including API Manager versions 4.1.0 through 4.6.0, with exploitation attempts captured in honeypot networks showing forged admin tokens being used for lateral movement. This incident highlights the growing sophistication of API-targeted attacks as organizations increasingly rely on API-first architectures. The vulnerability demonstrates how improper cryptographic validation can lead to complete administrative takeover, emphasizing the urgent need for robust API security controls and zero-trust verification mechanisms.
1 week ago
Kill Chain
Critical Google Pixel Modem Flaw CVE-2026-58704 Exploited in Zero-Click Attacks
In September 2026, Google disclosed that CVE-2026-58704, a high-severity privilege escalation vulnerability in Pixel Cellular Modem components, was being exploited in the wild through limited, targeted attacks. The flaw allows remote attackers to bypass permission checks and escalate privileges without user interaction, making it exploitable as a zero-click attack. Google patched the vulnerability alongside 109 other security flaws in the September 2026 Pixel security update, with CISA adding it to the Known Exploited Vulnerabilities catalog and mandating federal agency remediation by September 19, 2026. This incident highlights the growing sophistication of mobile device attacks and the critical importance of securing cellular modem components that were previously considered peripheral attack surfaces. The zero-click nature of this exploit represents an evolution in mobile threat tactics, emphasizing the need for comprehensive mobile security strategies that extend beyond traditional application-layer protections.
1 week ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports