The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

943 threat reports
Page 32 of 79

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Telecommunications Threat Reports

Showing 373–384 / 943 reports
INTERPOL's Operation Ramz: A Major Cybercrime Crackdown in the MENA Region
Impact· HIGH

INTERPOL's Operation Ramz: A Major Cybercrime Crackdown in the MENA Region

Between October 2025 and February 2026, INTERPOL coordinated Operation Ramz, a large-scale cybercrime crackdown across 13 Middle Eastern and North African countries. The operation led to the arrest of 201 individuals and the identification of 382 additional suspects involved in phishing, malware distribution, and online fraud. Authorities seized 53 servers and identified 3,867 victims, disrupting significant malicious infrastructure and preventing further cyber threats. ([interpol.int](https://www.interpol.int/News-and-Events/News/2026/201-arrests-in-first-of-its-kind-cybercrime-operation-in-MENA-region?utm_source=openai)) This operation underscores the escalating threat of cybercrime in the MENA region and highlights the effectiveness of international collaboration in combating such activities. The involvement of private cybersecurity firms like Kaspersky and Group-IB demonstrates the critical role of public-private partnerships in enhancing global cybersecurity efforts. ([kaspersky.co.za](https://www.kaspersky.co.za/about/press-releases/kaspersky-supports-interpols-operation-ramz-in-mena-region-resulting-in-over-200-arrests?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
INTERPOL's Operation Ramz: A Landmark Cybercrime Crackdown in MENA
Impact· HIGH

INTERPOL's Operation Ramz: A Landmark Cybercrime Crackdown in MENA

Between October 2025 and February 2026, INTERPOL coordinated Operation Ramz, a significant cybercrime crackdown across 13 Middle East and North Africa (MENA) countries. This operation led to the arrest of 201 individuals and the identification of 382 additional suspects involved in various cybercrimes, including phishing, malware distribution, and financial fraud. Authorities seized 53 servers and identified 3,867 victims, highlighting the extensive impact of these cybercriminal activities. ([interpol.int](https://www.interpol.int/News-and-Events/News/2026/201-arrests-in-first-of-its-kind-cybercrime-operation-in-MENA-region?utm_source=openai)) The success of Operation Ramz underscores the effectiveness of international collaboration in combating cybercrime. As cyber threats continue to evolve and proliferate, such coordinated efforts are crucial in disrupting malicious networks and protecting potential victims from emerging cyber scams and attacks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Mamont Banking Trojan: A Rising Threat in Q1 2026
Impact· MEDIUM

Mamont Banking Trojan: A Rising Threat in Q1 2026

In Q1 2026, the Mamont banking Trojan emerged as a significant threat to Android users, accounting for 73.5% of banking Trojan detections. This malware family, including variants like Mamont.jo and Mamont.jx, primarily targets users' financial credentials by masquerading as legitimate applications. The surge in Mamont-related incidents underscores the evolving tactics of cybercriminals in exploiting mobile platforms for financial gain. The proliferation of Mamont banking Trojans highlights the critical need for enhanced mobile security measures. As cyber threats become more sophisticated, users and organizations must adopt proactive strategies to safeguard sensitive financial information from such pervasive malware.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
Impact· CRITICAL

CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits

In May 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical vulnerability, CVE-2026-20182, affecting Cisco Catalyst SD-WAN Controllers and Managers, to its Known Exploited Vulnerabilities (KEV) catalog. This authentication bypass flaw allows unauthenticated remote attackers to gain administrative privileges on affected systems. Exploitation has been linked to the threat actor cluster UAT-8616, which has previously targeted similar vulnerabilities to gain unauthorized access to SD-WAN systems. The attackers have been observed adding SSH keys, modifying NETCONF configurations, and escalating privileges to root. ([thehackernews.com](https://thehackernews.com/2026/05/cisa-adds-cisco-sd-wan-cve-2026-20182.html?utm_source=openai)) The inclusion of CVE-2026-20182 in the KEV catalog underscores the ongoing threat posed by sophisticated actors targeting critical infrastructure. Organizations utilizing Cisco SD-WAN solutions must prioritize patching and implementing recommended mitigations to prevent potential breaches and maintain network security.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
FrostyNeighbor's 2026 Cyberattack on Ukrainian Government: A Detailed Analysis
Impact· HIGH

FrostyNeighbor's 2026 Cyberattack on Ukrainian Government: A Detailed Analysis

In March 2026, the Belarus-aligned cyberespionage group FrostyNeighbor launched a sophisticated spear-phishing campaign targeting Ukrainian governmental organizations. The attackers distributed malicious PDF documents impersonating the Ukrainian telecommunications company Ukrtelecom. These PDFs contained links that, upon clicking, led to a multi-stage infection chain. If the victim's IP address was identified as Ukrainian, the server delivered a malicious RAR archive containing a JavaScript-based downloader known as PicassoLoader. This downloader collected system information and, upon validation, deployed a Cobalt Strike beacon, granting the attackers remote control over the compromised systems. ([welivesecurity.com](https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors in Eastern Europe, highlighting the increasing sophistication of phishing campaigns and the use of geofencing to target specific regions. Organizations must remain vigilant against such targeted attacks, especially those employing multi-stage infection chains and advanced payloads like Cobalt Strike.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(low)
Read Report
Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files
Impact· HIGH

Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files

In May 2026, Palo Alto Networks' Unit 42 identified a new variant of the Gremlin Stealer malware, which has evolved from a basic credential harvester into a sophisticated modular toolkit. This variant employs advanced obfuscation techniques, including concealing malicious payloads within embedded resource files and utilizing instruction virtualization to evade detection. Gremlin Stealer targets sensitive information such as payment card details, browser cookies, session tokens, cryptocurrency wallet data, and FTP and VPN credentials, exfiltrating this data to attacker-controlled servers for potential exploitation. The rapid evolution of Gremlin Stealer underscores a broader trend in the cyber threat landscape, where infostealers are becoming more sophisticated and harder to detect. This development highlights the urgent need for organizations to enhance their cybersecurity measures, particularly in monitoring and defending against advanced malware that employs complex evasion tactics.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Cisco SD-WAN Zero-Day CVE-2026-20182 Exploited by UAT-8616
Impact· CRITICAL

Cisco SD-WAN Zero-Day CVE-2026-20182 Exploited by UAT-8616

In May 2026, Cisco disclosed a critical authentication bypass vulnerability (CVE-2026-20182) in its Catalyst SD-WAN Controller and Manager platforms. This flaw allows unauthenticated remote attackers to gain administrative access by exploiting weaknesses in the peering authentication mechanism. The threat group UAT-8616 has been actively exploiting this vulnerability, leading to unauthorized control over affected systems. Cisco has released patches to address this issue and urges immediate application to prevent further exploitation. This incident underscores the persistent targeting of network infrastructure by advanced threat actors. Organizations must prioritize timely patch management and enhance monitoring to detect and mitigate such sophisticated attacks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Cisco CVE-2026-20182: Critical SD-WAN Zero-Day Exploited in the Wild
Impact· CRITICAL

Cisco CVE-2026-20182: Critical SD-WAN Zero-Day Exploited in the Wild

In May 2026, Cisco disclosed a critical authentication bypass vulnerability (CVE-2026-20182) in its Catalyst SD-WAN Controller and Manager, which was actively exploited in zero-day attacks. This flaw allowed unauthenticated remote attackers to gain administrative privileges by sending crafted requests, potentially enabling them to manipulate network configurations and insert rogue devices into the SD-WAN fabric. The vulnerability affected both on-premises and cloud deployments, posing significant risks to organizations relying on Cisco's SD-WAN solutions. The discovery of CVE-2026-20182 underscores the persistent targeting of network infrastructure by sophisticated threat actors. This incident highlights the critical need for organizations to promptly apply security patches, monitor for unauthorized access, and implement robust network segmentation to mitigate the impact of such vulnerabilities.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Authentication Bypass Vulnerability in Cisco Catalyst SD-WAN Controller (CVE-2026-20182)
Impact· CRITICAL

Critical Authentication Bypass Vulnerability in Cisco Catalyst SD-WAN Controller (CVE-2026-20182)

In May 2026, Cisco disclosed a critical authentication bypass vulnerability (CVE-2026-20182) in its Catalyst SD-WAN Controller and Manager, formerly known as vSmart and vManage. This flaw allows unauthenticated, remote attackers to gain administrative privileges by exploiting weaknesses in the peering authentication mechanism. Successful exploitation enables attackers to access NETCONF, facilitating unauthorized manipulation of network configurations. Cisco has released software updates to address this issue, emphasizing the absence of viable workarounds. Organizations are urged to apply these patches promptly to mitigate potential risks. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW?utm_source=openai)) The exploitation of CVE-2026-20182 underscores a concerning trend of attackers targeting critical network infrastructure components. This incident highlights the necessity for organizations to maintain rigorous patch management practices and to monitor for unauthorized access attempts. The ongoing exploitation of such vulnerabilities emphasizes the importance of proactive security measures to protect against evolving threats. ([news.backbox.org](https://news.backbox.org/2026/05/14/ongoing-exploitation-of-cisco-catalyst-sd-wan-vulnerabilities/?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
FrostyNeighbor APT's Targeted Cyberespionage Campaign in Poland and Ukraine
Impact· HIGH

FrostyNeighbor APT's Targeted Cyberespionage Campaign in Poland and Ukraine

In March 2026, the Belarus-aligned advanced persistent threat (APT) group known as FrostyNeighbor launched a targeted cyberespionage campaign against government organizations in Poland and Ukraine. The attackers employed spear-phishing emails containing blurred PDF attachments that impersonated legitimate entities, such as Ukrainian telecom provider Ukrtelecom. These PDFs included malicious links leading to a multi-stage infection chain, culminating in the deployment of Cobalt Strike for post-compromise operations. Notably, the group implemented server-side victim validation, delivering payloads only to users from specific geographic locations, thereby enhancing the precision and effectiveness of their attacks. This incident underscores the evolving sophistication of nation-state cyber threats, particularly in Eastern Europe. The use of geofencing and advanced spear-phishing techniques highlights the need for organizations to bolster their cybersecurity defenses, especially against highly targeted and adaptive adversaries.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
AI-Assisted Zero-Day Exploit: A New Era in Cyber Threats
Impact· HIGH

AI-Assisted Zero-Day Exploit: A New Era in Cyber Threats

In May 2026, Google's Threat Intelligence Group identified the first documented instance of cybercriminals utilizing artificial intelligence to develop a zero-day exploit. The attackers employed AI to discover a flaw in a Python script, enabling them to bypass two-factor authentication on a widely-used open-source system. The exploit code exhibited characteristics indicative of AI assistance, such as explanatory comments and an invented severity rating. This incident underscores a significant shift in cyber threat dynamics, as AI begins to play an active role in enhancing the capabilities of cyberattacks. The discovery highlights the growing reliance of both state-sponsored and criminal cyber threat actors on AI across various stages of attack, from exploit development to social engineering. As AI models become increasingly adept at uncovering subtle software vulnerabilities, the cybersecurity landscape faces new challenges in defending against these sophisticated, AI-driven threats.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
FamousSparrow APT's Persistent Attacks on Azerbaijani Energy Sector in 2026
Impact· CRITICAL

FamousSparrow APT's Persistent Attacks on Azerbaijani Energy Sector in 2026

In late December 2025 through February 2026, the China-linked Advanced Persistent Threat (APT) group known as FamousSparrow targeted an Azerbaijani oil and gas company. The attackers exploited a vulnerable Microsoft Exchange server to gain initial access, deploying sophisticated techniques such as a two-stage DLL sideloading mechanism to evade detection and install remote access tools like Deed RAT and Terndoor. Despite remediation efforts, the group conducted multiple attack waves, indicating a persistent and strategic cyber espionage campaign. ([bitdefender.com](https://www.bitdefender.com/en-us/blog/businessinsights/famoussparrow-apt-targets-azerbaijani-oil-gas-industry?utm_source=openai)) This incident underscores a significant shift in cyber threat landscapes, with Chinese APTs expanding their focus to regions traditionally influenced by other state actors. The use of advanced evasion techniques highlights the evolving sophistication of cyber adversaries, emphasizing the need for robust and proactive cybersecurity measures in critical infrastructure sectors. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/china-famoussparrow-apt-south-caucasus-energy-firm?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports