The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Critical MikroTik RouterOS Vulnerabilities Added to CISA KEV Catalog: Immediate Action Required
CISA added two critical MikroTik RouterOS vulnerabilities (CVE-2026-67277 and CVE-2026-86060) to its Known Exploited Vulnerabilities (KEV) Catalog in September 2026 following evidence of active exploitation. CVE-2026-67277 involves missing authentication for critical functions, while CVE-2026-86060 relates to improper neutralization of argument delimiters in commands. These vulnerabilities affect network infrastructure devices and allow attackers to gain total control of compromised systems, posing significant risks to federal and enterprise networks. This addition reinforces the critical importance of rapid vulnerability remediation as network infrastructure attacks continue to surge, with threat actors increasingly targeting edge devices and routers to establish persistent footholds for lateral movement and data exfiltration campaigns.
1 week ago
Kill Chain
Surfshark VPN Breach Exposes Critical Cloud Security Gaps in Development Environments
In August 2026, Surfshark VPN disclosed that hackers accessed internal test servers after a configuration error exposed them to the internet. The breach occurred due to human error in server configuration, allowing unauthorized access to system binaries, code history, build credentials, and a separate proxy server used for content optimization. While no customer data, VPN traffic, or encryption keys were compromised, the incident exposed internal development infrastructure and service configurations. Surfshark detected the breach on August 31, contained it by September 2, and completed remediation within three days. This incident highlights the growing trend of cloud misconfigurations becoming primary attack vectors, particularly as organizations rapidly expand their cloud infrastructure without implementing consistent security controls across development and production environments.
2 weeks ago
Kill Chain
Critical Infrastructure Under Siege: CISA's September 2026 Emergency Patch Alert
CISA added three critical vulnerabilities to its Known Exploited Vulnerabilities catalog on September 10, 2026, affecting Cisco Secure Firewall Management Center (CVE-2026-20079), Citrix NetScaler ADC/Gateway (CVE-2026-19490), and Fortinet products (CVE-2025-25249). The Cisco flaw allows unauthenticated attackers to bypass authentication and gain root access, while active exploitation was detected in August 2026. The Fortinet vulnerability has been weaponized by Russian-speaking threat actors to deploy PivotC2 malware, compromising over 178 devices across 3,000+ targeted IP addresses since July 2026. This incident highlights the accelerating exploitation of network infrastructure devices as primary attack vectors, with threat actors increasingly targeting edge devices that lack robust monitoring capabilities. The multi-vendor nature of these simultaneous exploits demonstrates the coordinated scanning and opportunistic targeting of perimeter security appliances by sophisticated threat groups.
2 weeks ago
Kill Chain
Gigabud Banking Trojan Weaponizes Android Work Profiles in Advanced Evasion Campaign
The Gigabud banking trojan has evolved its attack methodology by leveraging Android work profiles to evade detection by banking applications' security checks. Active since 2022 and attributed to the GoldFactory threat group, this remote access trojan now deploys a secondary app called Vwork that creates isolated work profiles on infected devices and installs tampered banking applications within them. By operating from within these separated environments, the trojan can conduct fraudulent transactions while remaining hidden from malware detection systems that scan the device's personal space. Group-IB confirmed active infections across Indonesia with estimated losses of $960,000 between February and July 2026, though the technique has been observed targeting multiple countries including Brazil, Colombia, Egypt, Mexico, and several Southeast Asian nations. This incident represents a significant evolution in mobile banking malware, demonstrating how threat actors are adapting legitimate Android enterprise features for malicious purposes. As organizations increasingly rely on mobile banking and BYOD policies, understanding these sophisticated evasion techniques becomes critical for developing effective mobile security strategies.
2 weeks ago
Kill Chain
RedTail Linux Malware: Advanced Evasion Techniques Target Cloud Infrastructure
In September 2024, security researchers documented the RedTail Linux malware family through dynamic analysis of samples captured from DShield honeypots. The malware demonstrated sophisticated evasion techniques including process masquerading as legitimate services like php-fpm and PostgreSQL, extensive host profiling capabilities, and active interference with security monitoring tools. RedTail established persistence through cron jobs, created dynamic TCP listeners on high-numbered ports, attempted firewall manipulation, and initiated DNS-over-TLS connections to multiple resolver services, showcasing a multi-faceted approach to maintaining access and evading detection on compromised Linux systems. This analysis highlights the evolving sophistication of Linux-targeted malware as threat actors increasingly focus on cloud and virtualized environments where Linux systems are prevalent, making comprehensive endpoint security and behavioral monitoring critical for modern infrastructure protection.
2 weeks ago
Kill Chain
How U.S. Authorities Dismantled a $30 Billion Romance Scam Empire
In September 2026, the U.S. Department of Justice dismantled Xinbi Guarantee, a Chinese-operated Telegram marketplace facilitating pig butchering romance scams and cryptocurrency money laundering. The coordinated operation seized Telegram channels, froze $52.8 million in cryptocurrency across 52 wallets, and disrupted 13 scam compounds in Madagascar operated by Chinese organized crime syndicates. Xinbi served as an escrow service connecting scammers with vendors offering fraudulent investment websites, money laundering services, and human trafficking for scam operations, processing approximately $30 billion in transactions since 2022. This disruption highlights the escalating threat of Southeast Asian scam centers that steal billions annually from American victims, with criminal organizations increasingly leveraging cryptocurrency and messaging platforms to operate sophisticated fraud-as-a-service ecosystems beyond traditional law enforcement reach.
2 weeks ago
Kill Chain
F5 BIG-IP Under Attack: Memory-Resident Web Shell Evades Traditional Detection
A sophisticated malware campaign targeting F5 BIG-IP Access Policy Manager appliances exploits CVE-2025-53521 to inject PHP web shells directly into memory rather than storing them on disk. The malware, tracked as c05d5254 and PoisonedRefresh, hooks Apache functions to modify three specific PHP scripts in memory when loaded, enabling command execution through normal web requests while evading traditional file-based detection. The attack chain begins with exploitation of the critical remote code execution vulnerability (CVSS 9.8) and establishes persistence through infected system binaries and installation media. This incident highlights the evolution of fileless malware techniques and the growing sophistication of infrastructure-focused attacks. As organizations increasingly rely on application delivery controllers and load balancers for critical services, attackers are developing advanced evasion techniques that challenge traditional security monitoring approaches, making network-level visibility and behavioral analysis essential for detection.
2 weeks ago
Kill Chain
PoisonedRefresh Rootkit: Advanced Threat Targets F5 BIG-IP Infrastructure
In September 2026, security researchers discovered a sophisticated Linux rootkit campaign targeting F5 BIG-IP APM devices. Attackers exploited CVE-2025-53521, a critical remote code execution vulnerability, to deploy the 'PoisonedRefresh' rootkit that injects fileless web shells directly into memory. The malware intercepts PHP file operations, modifies scripts in memory without altering disk files, and creates password-protected backdoors while maintaining persistence across system upgrades. This advanced attack demonstrates the evolution of infrastructure targeting, as threat actors increasingly focus on critical network appliances that provide extensive access to organizational traffic and systems. With 795 vulnerable endpoints still exposed online, this incident highlights the urgent need for robust patch management and enhanced monitoring of network infrastructure devices.
2 weeks ago
Kill Chain
WeChat Zero-Click Worm: How 1.4 Billion Users Were at Risk from Incoming Calls
In July 2026, security researchers at Calif discovered a critical zero-click vulnerability in WeChat that allowed attackers to take complete control of user accounts through incoming calls without any user interaction. The exploit worked by leveraging WeChat's contact trust system, enabling worm-like propagation where compromised accounts could automatically infect other contacts. Affecting WeChat's 1.4 billion user base across iPhone and Android platforms, the vulnerability granted attackers full access to messages, payments, and WeChat's extensive ecosystem of mini-programs and services. Tencent patched the flaw in August 2026 versions 8.0.77 for Android and 8.0.76 for iOS. This incident highlights the growing sophistication of mobile application attacks and the critical importance of securing communication platforms that serve as digital wallets and business ecosystems, particularly as zero-click exploits become increasingly weaponized against high-value messaging applications.
2 weeks ago
Kill Chain
MikroTik SSH Authentication Bypass: Critical RouterOS Vulnerability Demands Immediate Zero Trust Response
In September 2024, MikroTik released an emergency patch for a critical SSH authentication bypass vulnerability affecting RouterOS devices that was already being actively exploited in the wild. The vulnerability allows attackers to completely bypass SSH authentication mechanisms, gaining unauthorized administrative access to network infrastructure devices. Threat actors have been leveraging this flaw to create persistent backdoor accounts on compromised devices, ensuring continued access even after patches are applied. The exploitation campaign has resulted in widespread compromise of MikroTik devices globally, with attackers targeting both enterprise and service provider networks. This incident highlights the critical importance of network infrastructure security and the devastating impact of authentication bypass vulnerabilities on organizational networks and internet infrastructure stability.
2 weeks ago
Kill Chain
REVSTEALER's Four-Module Attack: How Infostealers Are Evolving Beyond Credential Theft
In September 2026, Elastic Security Labs documented four previously unreported modules associated with REVSTEALER, a commercial Windows information stealer active since February 2026. The malware initially operates as a traditional infostealer, harvesting browser credentials, cryptocurrency wallets, gaming accounts, and messaging data before deleting itself. However, four persistent modules remain on infected systems: ProManager (wallet overlay attacks), WinUpdate (clipboard cryptocurrency address replacement), SoftManager (reverse proxy), and LockAppHost (disables Windows Update and Defender to run cryptocurrency miners). The malware spreads primarily through game cheat lures on compromised YouTube channels and fake AI applications. This incident highlights the evolution of infostealers beyond simple credential theft toward persistent system compromise and resource abuse. As threat actors increasingly combine multiple attack vectors in single campaigns, organizations face compound risks from credential harvesting, system weakening, and unauthorized resource consumption that can persist long after the initial infection appears resolved.
2 weeks ago
Kill Chain
MikroTik RouterOS SSH Authentication Bypass: Critical Infrastructure Attack Analysis
In September 2026, attackers exploited MikroTik RouterOS devices through internet-exposed SSH services, gaining full administrative control without authentication. CERT Polska reported active exploitation beginning September 2, targeting RouterOS versions 6.0.0-6.49.21, 7.0.0-7.23.4, and 7.24-7.24.2 through a vulnerability combination dubbed 'MikroTrick.' The attacks allowed unauthorized configuration changes and complete device compromise, prompting immediate security updates from MikroTik across multiple RouterOS channels. Network infrastructure attacks like this highlight the critical importance of securing remote access services and implementing proper network segmentation. The incident demonstrates how exposed management interfaces continue to be prime targets for threat actors seeking to establish persistent network footholds and lateral movement capabilities.
2 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports