The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

943 threat reports
Page 62 of 79

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Telecommunications Threat Reports

Showing 733–744 / 943 reports
CISA Flags Critical Android Framework Flaws in 2025: Urgent Action Required
Impact· low

CISA Flags Critical Android Framework Flaws in 2025: Urgent Action Required

In December 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two newly discovered Android Framework vulnerabilities—CVE-2025-48572 (Privilege Escalation) and CVE-2025-48633 (Information Disclosure)—to its Known Exploited Vulnerabilities Catalog. These flaws, which have already been actively exploited in the wild, allow malicious actors to escalate privileges and potentially access sensitive data on affected Android devices. The vulnerabilities create substantial risk, particularly for federal agencies and enterprises relying on Android in their operations, prompting CISA to mandate urgent remediation under Binding Operational Directive 22-01. This incident highlights the persistent targeting of mobile platforms and increased sophistication in privilege escalation techniques observed by threat actors. Organizations are urged to prioritize patching and reinforce security monitoring, as the exploitation of unpatched Android vulnerabilities continues to fuel regulatory and cyber risk concerns in both public and private sectors.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Ransomware Halts CodeRED Emergency Alert System in 2024
Impact· high

Ransomware Halts CodeRED Emergency Alert System in 2024

In June 2024, the CodeRED emergency alert platform experienced a major operational disruption after being targeted by the Inc ransomware gang. Attackers infiltrated the organization's systems, encrypted critical servers, and exfiltrated sensitive subscriber data, causing CodeRED to take its emergency alert services offline. Initial entry occurred through a phishing campaign, allowing lateral movement and the deployment of ransomware across east-west traffic. The attack compromised both the confidentiality and availability of data, significantly impacting public safety communication in affected regions. This incident highlights the escalating threat ransomware groups pose to critical infrastructure and public safety technology providers. As attackers target essential services with increasingly sophisticated methods, robust east-west security controls, zero trust segmentation, and real-time threat detection have become urgent priorities for organizations in all sectors.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Google Issues Urgent Patch for 107 Android Vulnerabilities, Two Actively Exploited Zero-Days
Impact· high

Google Issues Urgent Patch for 107 Android Vulnerabilities, Two Actively Exploited Zero-Days

In December 2025, Google released a significant Android security update that addressed 107 vulnerabilities, including two zero-day flaws (CVE-2025-48633 and CVE-2025-48572) already being actively exploited in the wild. These high-severity issues in the Android framework allowed threat actors to access sensitive information and escalate privileges, posing a substantial threat to user data and device functionality. The update also remedied several critical vulnerabilities impacting the kernel, system, and multiple vendor components such as MediaTek, Unisoc, and Qualcomm. This incident highlights the intricate security landscape of mobile operating systems and the evolving tactics of cyber adversaries in exploiting vendor fragmentation and delayed patch cycles. The breadth and urgency of this patch reflects growing concerns around mobile platform vulnerabilities, especially as targeted exploitation of zero-days intensifies. With attackers rapidly leveraging gaps before they’re widely recognized or patched, organizations face increased pressure to maintain real-time vulnerability management and swift patch deployment to minimize exposure.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Tomiris Leverages Public-Service Implants for Stealthy Government Attacks
Impact· low

Tomiris Leverages Public-Service Implants for Stealthy Government Attacks

In late 2025, the state-sponsored threat actor Tomiris escalated its attacks against government entities and intergovernmental organizations, primarily in Russia and neighboring regions. The group notably shifted its tactics by deploying custom remote access implants that leveraged public cloud services, such as Telegram and Discord, as command-and-control (C2) channels. This allowed Tomiris to disguise their network traffic among legitimate service use, evading conventional perimeter defenses and security controls. The compromise enabled attackers to maintain persistent access, deploy additional payloads, and potentially exfiltrate sensitive diplomatic and policy data. This incident is significant due to its demonstration of the evolving sophistication in APT tactics: the use of ubiquitous public platforms for C2, making detection and attribution harder. It also highlights the urgency for zero trust architectures, enhanced traffic monitoring, and cloud-centric security controls as industries face an increase in nation-state and intelligence-motivated threats.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Multi-Vector Breach: npm Worm, Firefox RCE, and M365 Email Raids Rock 2025
Impact· high

Multi-Vector Breach: npm Worm, Firefox RCE, and M365 Email Raids Rock 2025

In December 2025, a coordinated multi-vector cyberattack was observed targeting organizations through the exploitation of critical zero-day vulnerabilities (CVEs), a resurgence of the npm InfoStealer Worm, a remote code execution flaw in Mozilla Firefox, and widespread credential compromise leading to Microsoft 365 email account takeovers. Attackers leveraged a blend of social engineering, poisoned open-source packages, and malicious links to infiltrate developer environments, gain access to corporate cloud accounts, and spread laterally via trusted supply chains. Impacted organizations faced the risk of sensitive data exfiltration, widespread internal compromise, and disruption of core IT services across software development and communications. This incident underscores the growing sophistication and scale of modern attack campaigns that blend supply chain, RCE, SaaS compromise, and worm tactics. The convergence of these vectors highlights the urgent need for zero trust segmentation, continuous threat detection, and cloud-specific defenses as attackers increasingly target developer and business collaboration tools.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Australia 2024 Airport Evil Twin WiFi Attack: Network Intrusion Threat Exposed
Impact· low

Australia 2024 Airport Evil Twin WiFi Attack: Network Intrusion Threat Exposed

In 2024, Australian authorities sentenced a 44-year-old man to over seven years in prison for orchestrating a series of 'evil twin' WiFi attacks at major Australian airports. The perpetrator set up rogue wireless networks mimicking legitimate airport WiFi, luring unsuspecting travelers into connecting and unknowingly handing over sensitive data, including credentials and personal information. Over a prolonged period, these attacks evaded detection due to the sophistication of the deceptive access points and inherent insecurity of public wireless networks. The incident highlighted significant risks for both individuals and organizations, demonstrating effective tactics for harvesting credentials in the wild. This case exemplifies a broader trend of attackers exploiting public and unsecured networks to launch network intrusion campaigns, especially as remote work and mobile connectivity surge. Such methods bypass conventional perimeter defenses and increase compliance and regulatory pressures for organizations to protect data in transit.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Tomiris APT 2025: Abuse of Telegram, Discord & Multi-Language Toolkit in Advanced Government Attacks
Impact· low

Tomiris APT 2025: Abuse of Telegram, Discord & Multi-Language Toolkit in Advanced Government Attacks

In early 2025, the Tomiris APT group launched a sophisticated cyberespionage campaign targeting foreign ministries, intergovernmental organizations, and government entities across Russia and Central Asia. Using spear-phishing emails with password-protected malicious archives, Tomiris delivered a diverse toolkit of implants written in C/C++, Rust, Go, C#, and Python. Their malware leveraged public services like Telegram and Discord for command-and-control (C2), employed open-source frameworks such as Havoc and AdaptixC2, and enabled attackers to perform reconnaissance, maintain persistence, and exfiltrate sensitive data, while evading traditional network defenses by blending illicit traffic with legitimate channels. This incident highlights a clear evolution in APT tradecraft: rapid adoption of multi-language toolchains, creative lateral movement, and the abuse of popular cloud-based services for covert operations. With the continued rise of lawful-shadow C2 channels and open-source post-exploitation kits, organizations face heightened risks from identity-driven, stealthy attacks that challenge conventional segmentation and anomaly detection strategies.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
2025 Multi-Vector Attack: AI Malware, Voice Bots, Crypto Laundering & IoT Breach
Impact· medium

2025 Multi-Vector Attack: AI Malware, Voice Bots, Crypto Laundering & IoT Breach

In November 2025, threat analysts observed a coordinated, multi-vector cyberattack campaign targeting enterprises across finance, healthcare, and IoT-heavy sectors. Attackers leveraged AI-powered malware, compromised voice bots, and elaborate cryptocurrency laundering techniques to infiltrate organizations, bypass security controls, and exfiltrate sensitive data. Initial access was achieved via sophisticated phishing augmented by AI voice impersonation, while lateral movement and data theft exploited weaknesses in internal segmentation and unencrypted east-west traffic. The campaign’s complexity resulted in service downtime, financial losses, and data exposure for several multinational organizations. This incident is notable for blending diverse threat techniques—AI-driven social engineering, voice-based exploits, and infrastructure abuses—reflecting the current trend towards multifaceted attacks capable of outmaneuvering traditional defenses. The scale and automation highlight increased attacker innovation and challenge existing compliance and zero trust frameworks.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Bloody Wolf's NetSupport RAT Campaign Breaches Kyrgyzstan and Uzbekistan: 2025 Analysis
Impact· medium

Bloody Wolf's NetSupport RAT Campaign Breaches Kyrgyzstan and Uzbekistan: 2025 Analysis

In mid-2025, the threat actor known as Bloody Wolf launched a targeted cyber campaign against government and enterprise entities in Kyrgyzstan, later expanding its operations to Uzbekistan by October 2025. Utilizing sophisticated phishing lures, attackers delivered Java-based loaders that deployed the NetSupport Remote Access Trojan (RAT), allowing persistent access and potential data exfiltration. The campaign featured advanced evasion tactics, encrypted command-and-control traffic, and was attributed by Group-IB and local cybersecurity agencies. Affected organizations faced risks of unauthorized network access and potential compromise of sensitive information. This incident highlights ongoing regional cybercrime escalation, especially the trend of weaponizing legitimate tools like NetSupport RAT through creative malware loaders. With cross-border expansion and zero-day techniques, the event exemplifies how remote access trojans are reshaping threat landscapes and driving demand for advanced network and east-west traffic controls.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ASUS Issues Urgent Patch for Critical AiCloud Authentication Bypass Flaw in Routers
Impact· medium

ASUS Issues Urgent Patch for Critical AiCloud Authentication Bypass Flaw in Routers

In June 2024, ASUS disclosed a critical authentication bypass vulnerability (CVE-2024-3080) affecting several router models running AiCloud. Attackers could exploit this flaw remotely, without authentication, to gain administrative access and potentially control router functions—enabling unauthorized changes, interception of network traffic, and further lateral movement within home or small business networks. The flaw was one of nine vulnerabilities addressed by an urgent firmware patch released by ASUS, after receiving responsible disclosure and industry warnings. Although there are no major reports of exploitation in the wild yet, affected users were strongly urged to update immediately to prevent potential compromise. This incident highlights the increasing targeting of network infrastructure and IoT devices by attackers seeking easy entry points into corporate and personal environments. With a surge in authentication bypasses and router-based exploits, organizations and individuals must prioritize timely patching and implement additional network segmentation and anomaly detection controls.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ShadowV2 Botnet Turns AWS Outage into Opportunity: 2024 IoT and Hybrid Cloud Attacks Surge
Impact· medium

ShadowV2 Botnet Turns AWS Outage into Opportunity: 2024 IoT and Hybrid Cloud Attacks Surge

In June 2024, a new botnet malware known as ShadowV2 emerged, leveraging Mirai source code to target IoT devices, particularly from D-Link and TP-Link, exploiting known vulnerabilities for large-scale infection. Security researchers observed the malware operators using the widespread AWS outage as an opportunity to test command and control resilience, evade detection, and enhance lateral spread across hybrid and cloud networks. Initial access occurred via unpatched vulnerabilities in internet-facing devices, leading to rapid compromise and recruitment of thousands of endpoints, posing heightened risks to corporate and critical infrastructure systems. Detection was challenged by the use of encrypted and east-west traffic, with attackers adapting quickly to shifting network topologies. This incident highlights the increasing sophistication of IoT-focused botnets and their opportunistic exploitation of cloud service disruptions. Organizations with hybrid or cloud-connected assets are strongly urged to reassess east-west traffic controls, segmentation, and anomaly detection, as automated threats now more readily exploit both vulnerable devices and network instability.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Comcast Fined After 2024 Vendor Data Breach Hits 270,000 Customers
Impact· high

Comcast Fined After 2024 Vendor Data Breach Hits 270,000 Customers

In February 2024, Comcast, one of the largest U.S. telecommunications providers, suffered a significant data breach due to a third-party vendor's security lapse. The incident resulted in unauthorized access to the personally identifiable information (PII) of nearly 275,000 Comcast customers. Exposed data included names, addresses, and partial account credentials. The breach was traced to vulnerabilities in the vendor's security infrastructure, highlighting risks posed by supply chain and vendor relationships. Following the breach, the Federal Communications Commission fined Comcast $1.5 million as part of its investigation into the company's responsibilities and controls over customer data. This case underscores the persistent and growing threat of supply chain breaches, which are increasingly targeted by cyber adversaries seeking to exploit trust relationships between organizations and their service providers. Regulatory bodies are intensifying scrutiny and penalties around third-party risk management following a pattern of similar high-impact incidents.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports