The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

943 threat reports
Page 38 of 79

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Telecommunications Threat Reports

Showing 445–456 / 943 reports
GreyNoise Uncovers Early Indicators of Edge Device Vulnerabilities
Impact· CRITICAL

GreyNoise Uncovers Early Indicators of Edge Device Vulnerabilities

In early 2026, GreyNoise Intelligence identified a pattern where spikes in network traffic targeting specific vendors' edge devices often preceded public vulnerability disclosures. Over a 103-day study, 50% of these traffic surges were followed by a vulnerability disclosure from the same vendor within three weeks, with a median lead time of nine days. This suggests that attackers conduct reconnaissance on edge devices before exploiting newly discovered vulnerabilities, providing a potential early-warning system for defenders. ([cyberscoop.com](https://cyberscoop.com/greynoise-traffic-surge-early-warning-system-network-edge-device-vulnerabilities/?utm_source=openai)) This finding underscores the critical need for organizations to monitor unusual network activity as a proactive measure. By detecting these reconnaissance patterns, security teams can implement mitigations ahead of public vulnerability disclosures, reducing the window of exposure to potential attacks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Apple Account Change Alerts Abused in Sophisticated Phishing Scheme
Impact· MEDIUM

Apple Account Change Alerts Abused in Sophisticated Phishing Scheme

In April 2026, cybercriminals exploited Apple's account change notification system to distribute phishing emails that appeared to originate from Apple's legitimate servers. These emails falsely informed recipients of an $899 iPhone purchase via PayPal and provided a phone number to cancel the transaction. The attackers manipulated the account's personal information fields to embed the phishing message, leading to the dispatch of authentic-looking emails from Apple. This tactic increased the credibility of the scam and enhanced its chances of bypassing spam filters. Victims who called the provided number were at risk of being deceived into installing remote access software or divulging sensitive financial information, potentially resulting in financial theft or data breaches. This incident underscores the evolving sophistication of phishing attacks, where threat actors leverage legitimate system features to enhance the authenticity of their scams. Organizations and individuals must remain vigilant against such tactics, as similar methods have been observed in other platforms, including Microsoft Azure Monitor alerts being abused for callback phishing attacks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Protobuf.js Vulnerability Exposes Systems to Remote Code Execution
Impact· HIGH

Critical Protobuf.js Vulnerability Exposes Systems to Remote Code Execution

In April 2026, a critical remote code execution (RCE) vulnerability was discovered in protobuf.js, a widely used JavaScript implementation of Google's Protocol Buffers. The flaw, identified as GHSA-xq3m-2v4x-88gg, arises from unsafe dynamic code generation within the library, allowing attackers to inject and execute arbitrary JavaScript code by supplying malicious schemas. This vulnerability affects versions 8.0.0/7.5.4 and lower, potentially enabling unauthorized access to environment variables, credentials, databases, and internal systems, and facilitating lateral movement within infrastructures. The release of proof-of-concept exploit code underscores the urgency for organizations to address this issue promptly. Given the extensive use of protobuf.js in inter-service communication and real-time applications, the potential for widespread exploitation is significant.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Nexcorium Botnet's Exploitation of CVE-2024-3721 in TBK DVRs
Impact· MEDIUM

Nexcorium Botnet's Exploitation of CVE-2024-3721 in TBK DVRs

In April 2026, cybersecurity researchers identified a new variant of the Mirai botnet, named Nexcorium, actively exploiting CVE-2024-3721—a command injection vulnerability in TBK DVR-4104 and DVR-4216 devices. By sending specially crafted HTTP POST requests to the vulnerable endpoint, attackers gained remote control over these devices, integrating them into a botnet used for large-scale Distributed Denial-of-Service (DDoS) attacks. The campaign, attributed to a group known as 'Nexus Team,' highlights the persistent threat posed by unpatched IoT devices in critical environments. ([fortinet.com](https://www.fortinet.com/blog/threat-research/tracking-mirai-variant-nexcorium-a-vulnerability-driven-iot-botnet-campaign?utm_source=openai)) This incident underscores the ongoing risks associated with IoT vulnerabilities, particularly in devices that are often overlooked in security protocols. The exploitation of CVE-2024-3721 by Nexcorium serves as a stark reminder of the importance of timely patching and robust security measures to protect against evolving botnet threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
CISA Alerts on Active Exploitation of Apache ActiveMQ Vulnerability CVE-2026-34197
Impact· HIGH

CISA Alerts on Active Exploitation of Apache ActiveMQ Vulnerability CVE-2026-34197

In April 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) identified active exploitation of a critical vulnerability in Apache ActiveMQ, designated as CVE-2026-34197. This flaw, present for 13 years, allows authenticated attackers to execute arbitrary code via the Jolokia JMX-HTTP bridge. The vulnerability was discovered by Horizon3 researcher Naveen Sunkavally using the Claude AI assistant and has been patched in ActiveMQ Classic versions 6.2.3 and 5.19.4. The exploitation of this long-standing vulnerability underscores the persistent risks associated with unpatched software and the importance of proactive vulnerability management. Organizations using Apache ActiveMQ are urged to update their systems promptly to mitigate potential threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Operation PowerOFF Dismantles 53 DDoS-for-Hire Domains, Exposes 3 Million Criminal Accounts
Impact· LOW

Operation PowerOFF Dismantles 53 DDoS-for-Hire Domains, Exposes 3 Million Criminal Accounts

In April 2026, an international law enforcement operation known as Operation PowerOFF targeted the DDoS-for-hire ecosystem across 21 countries. Authorities seized 53 domains, arrested four individuals, and identified over 75,000 users involved in launching DDoS attacks. The operation disrupted booter services and dismantled infrastructure, including servers and databases, that supported these illicit activities. ([cyberscoop.com](https://cyberscoop.com/ddos-for-hire-takedowns-operation-poweroff/?utm_source=openai)) This crackdown underscores the persistent threat posed by DDoS-for-hire services, which enable individuals with minimal technical expertise to launch significant cyberattacks. The operation highlights the necessity for continuous vigilance and international cooperation to combat evolving cyber threats. ([cyberscoop.com](https://cyberscoop.com/ddos-for-hire-takedowns-operation-poweroff/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Apache ActiveMQ CVE-2026-34197: Critical RCE Vulnerability Under Active Exploitation
Impact· HIGH

Apache ActiveMQ CVE-2026-34197: Critical RCE Vulnerability Under Active Exploitation

In April 2026, a critical remote code execution (RCE) vulnerability, CVE-2026-34197, was identified in Apache ActiveMQ Classic. This flaw resides in the Jolokia JMX-HTTP bridge, which, due to an overly permissive default access policy, allows authenticated attackers to execute arbitrary code on the broker's JVM. Exploitation involves invoking specific MBeans operations with crafted discovery URIs that load malicious Spring XML configurations, leading to full system compromise. Affected versions include Apache ActiveMQ Broker before 5.19.4 and from 6.0.0 before 6.2.3. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-34197/?utm_source=openai)) The urgency to address this vulnerability is heightened by its addition to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. Organizations using affected versions should prioritize upgrading to patched releases and review access controls to mitigate potential threats. ([securityonline.info](https://securityonline.info/apache-activemq-rce-jolokia-cve-2026-34197/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
North Korea's Sapphire Sleet Exploits ClickFix to Target macOS Users
Impact· HIGH

North Korea's Sapphire Sleet Exploits ClickFix to Target macOS Users

In April 2026, the North Korean state-sponsored group Sapphire Sleet launched a sophisticated cyber campaign targeting macOS users. Utilizing the 'ClickFix' social engineering technique, attackers posed as recruiters on professional networking platforms, engaging victims with fake job offers. They directed targets to install a malicious 'Zoom SDK Update.scpt' file, which, when executed, initiated a multi-stage payload chain. This chain included credential harvesters, data stealers targeting wallets and keychains, and backdoors for persistence. Notably, the malware bypassed Apple's Transparency, Consent, and Control (TCC) security framework, allowing unauthorized actions without user prompts. The campaign resulted in significant data exfiltration and potential financial losses for affected individuals and organizations. ([darkreading.com](https://www.darkreading.com/application-security/north-korea-clickfix-target-macos-users-data/?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors in targeting macOS platforms, highlighting the need for heightened vigilance against social engineering attacks and the importance of robust endpoint security measures.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical RCE Vulnerability in Apache ActiveMQ: CVE-2026-34197
Impact· HIGH

Critical RCE Vulnerability in Apache ActiveMQ: CVE-2026-34197

In April 2026, a critical remote code execution (RCE) vulnerability, designated CVE-2026-34197, was identified in Apache ActiveMQ Classic. This flaw resides in the Jolokia JMX-HTTP bridge exposed at /api/jolokia/ on the web console. Due to an overly permissive default Jolokia access policy, authenticated attackers can invoke sensitive operations, such as BrokerService.addNetworkConnector(String), with crafted discovery URIs. This exploitation allows the loading of a remote Spring XML application context, leading to arbitrary code execution on the broker's JVM through methods like Runtime.exec(). The vulnerability affects Apache ActiveMQ Broker versions before 5.19.4 and from 6.0.0 before 6.2.3. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-34197/?utm_source=openai)) The discovery of this vulnerability underscores the importance of rigorous input validation and access control in software components. Organizations utilizing affected versions of Apache ActiveMQ are urged to upgrade to version 5.19.5 or 6.2.3 to mitigate this risk. ([rapid7.com](https://www.rapid7.com/db/vulnerabilities/apache-activemq-cve-2026-34197/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Operation PowerOFF 2026: A Major Blow to DDoS-for-Hire Services
Impact· LOW

Operation PowerOFF 2026: A Major Blow to DDoS-for-Hire Services

In April 2026, a coordinated international law enforcement effort known as Operation PowerOFF led to the seizure of 53 domains associated with DDoS-for-hire services and the arrest of four individuals allegedly involved in these operations. Authorities from 21 countries, including the United States, United Kingdom, and Germany, dismantled infrastructure supporting these services, which had been utilized by over 75,000 cybercriminals to launch distributed denial-of-service (DDoS) attacks. The operation also resulted in the identification of more than 3 million user accounts linked to these illegal activities. ([cyberscoop.com](https://cyberscoop.com/ddos-for-hire-takedowns-operation-poweroff/?utm_source=openai)) This crackdown underscores the persistent threat posed by DDoS-for-hire services, which enable individuals with minimal technical expertise to disrupt online services across various sectors. The operation highlights the necessity for organizations to bolster their cybersecurity defenses against such attacks and the importance of international collaboration in combating cybercrime.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Operation PowerOFF 2026: A Landmark in Combating IoT Botnets
Impact· MEDIUM

Operation PowerOFF 2026: A Landmark in Combating IoT Botnets

In March 2026, an international law enforcement operation known as Operation PowerOFF successfully dismantled the command-and-control infrastructure of four major IoT botnets—Aisuru, KimWolf, JackSkid, and Mossad. These botnets had collectively infected over three million devices worldwide, including digital video recorders, web cameras, and WiFi routers, and were responsible for launching distributed denial-of-service (DDoS) attacks reaching up to 31.4 terabits per second, setting new records for attack scale and impact. The coordinated effort involved authorities from the United States, Canada, and Germany, leading to the seizure of multiple domains and virtual servers associated with these botnets. ([justice.gov](https://www.justice.gov/usao-ak/pr/authorities-disrupt-worlds-largest-iot-ddos-botnets-responsible-record-breaking-attacks?utm_source=openai)) This takedown underscores the escalating threat posed by IoT-based botnets and the critical need for robust cybersecurity measures. Despite this significant disruption, security experts caution that DDoS threats persist, emphasizing the importance of continued vigilance and proactive defense strategies to protect against evolving cyber threats. ([securityboulevard.com](https://securityboulevard.com/2026/03/doj-disrupts-botnets-but-ddos-threats-remain-security-pros-warn/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
PowMix Botnet: A New Threat to Czech Organizations in 2025
Impact· MEDIUM

PowMix Botnet: A New Threat to Czech Organizations in 2025

In December 2025, Cisco Talos identified a new botnet named PowMix targeting the workforce in the Czech Republic. The attackers distributed malicious documents impersonating legitimate brands and regulatory frameworks to lure victims, particularly those in human resources, legal, and recruitment sectors. PowMix employs randomized command-and-control (C2) beaconing intervals and embeds encrypted heartbeat data into C2 URL paths that mimic legitimate REST API URLs, making detection challenging. Additionally, it can dynamically update its C2 domain within the botnet configuration file. Notably, PowMix shares tactical similarities with the earlier ZipLine campaign, including payload delivery mechanisms and misuse of cloud platforms like Heroku for C2 operations. ([blog.talosintelligence.com](https://blog.talosintelligence.com/powmix-botnet-targets-czech-workforce/?utm_source=openai)) This incident underscores the evolving sophistication of botnets, highlighting the need for organizations to enhance their cybersecurity measures. The use of randomized C2 intervals and legitimate-looking URLs indicates a trend towards more evasive malware, emphasizing the importance of advanced detection techniques and continuous monitoring to mitigate such threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports