The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
CISA Flags Samsung Mobile Devices for Critical Exploited Vulnerability (CVE-2025-21042)
In November 2025, CISA added CVE-2025-21042, an out-of-bounds write vulnerability affecting Samsung Mobile Devices, to its Known Exploited Vulnerabilities (KEV) Catalog following active exploitation in the wild. Threat actors have leveraged this flaw to gain unauthorized control over affected devices, potentially allowing them to execute arbitrary code, escalate privileges, and compromise sensitive user data. The vulnerability poses significant risks to both federal agencies and commercial enterprises, prompting CISA to mandate remediation by federal civilian agencies under Binding Operational Directive (BOD) 22-01. Failure to remediate exposes organizations to data breaches and operational disruption. This incident highlights a broader wave of targeted exploits against widely used mobile platforms, illustrating attackers’ ongoing shift toward mobile devices as primary entry vectors. With regulatory attention intensifying, the urgency for rapid vulnerability management and proactive defense measures is escalated for all sectors.
8 months ago
Kill Chain
ClickFix Hospitality Breach: Infostealer Attack Impacts Hotels and Their Customers
In early 2024, a cybercrime campaign known as "ClickFix" targeted hospitality providers globally using infostealer and remote access trojan (RAT) malware. Threat actors gained initial access via spear phishing and malicious links, compromising hotel systems to harvest sensitive booking data and customer contact information. Attackers leveraged this stolen data to conduct highly convincing secondary phishing attacks directed at hotel customers via both email and WhatsApp channels, exposing guests to social engineering, fraud, and further credential theft. This cascading impact emphasized the attacker's focus on exploiting trusted relationships across business and customer environments. The incident is notable for its dual-target strategy, harnessing a single breach to fuel broader downstream attacks and demonstrating attackers' sophisticated use of layered social engineering. As infostealer activity surges across the hospitality and service sectors, defenders must adapt to increasingly persistent, multi-stage campaigns that pose risks for both enterprise operations and their customers.
8 months ago
Kill Chain
Landfall Malware: Covert Mobile Surveillance Hits Samsung Galaxy in 2024
In early 2024, cybersecurity researchers uncovered a sophisticated mobile surveillance campaign targeting Samsung Galaxy users through a malware strain dubbed 'Landfall.' Delivered primarily via malicious apps and phishing schemes, Landfall granted attackers covert access to device microphones, cameras, geolocation, and sensitive stored data. The threat actors capitalized on advanced evasion tactics to remain undetected, enabling them to record conversations, track user locations, collect photos, and exfiltrate contacts without the victims’ knowledge. The incident highlights the growing complexity of targeted mobile threats and the operational risks facing organizations with a mobile workforce. With the rise of mobile malware like Landfall exploiting modern smartphones’ vast attack surface, security teams must reassess their controls for device management, east-west traffic monitoring, and policy enforcement. This case underscores the urgency for enterprises to adopt zero trust defenses and adapt to evolving mobile threat tactics.
8 months ago
Kill Chain
APT Groups Exploit Hybrid & Multicloud Gaps: Insights from ESET Q2–Q3 2025 Activity Report
In Q2 and Q3 of 2025, ESET Research identified a surge in advanced persistent threat (APT) activity, with multiple sophisticated threat actors targeting organizations across various industries and geographies. These groups leveraged techniques such as east-west lateral movement within hybrid and multicloud environments, encrypted traffic tunneling, and exploitation of zero trust segmentation gaps. Attackers infiltrated networks via phishing campaigns, supply chain vulnerabilities, and exploitation of unpatched cloud workloads, achieving persistent access and data exfiltration. The business impacts included service disruptions, data breaches, and regulatory scrutiny for affected organizations. This incident underscores the increasing complexity of APT operations in cloud-centric architectures and highlights the urgency of implementing comprehensive east-west visibility, zero trust controls, and robust anomaly detection. The trends reported by ESET indicate a continued escalation of multicloud security risks and a persistent threat landscape adapting to modern enterprise environments.
8 months ago
Kill Chain
How State-Sponsored APTs Bypassed Multi-Cloud Defenses in 2025
Between Q2 and Q3 2025, ESET researchers identified a significant rise in sophisticated Advanced Persistent Threat (APT) attacks spanning multiple regions and industry verticals. State-sponsored actors leveraged encrypted communications and advanced lateral movement tactics to compromise organizations’ east-west cloud traffic, successfully bypassing conventional perimeter defenses. These campaigns exploited unmonitored internal traffic and insufficient network segmentation, leading to the exfiltration of sensitive data and critical infrastructure disruptions. The attackers demonstrated thorough knowledge of multi-cloud environments, combining zero-day exploits with stolen credentials to maintain persistent access and evade detection for weeks. This incident is emblematic of a broader trend—APT groups are accelerating the use of sophisticated, stealthy methods in hybrid cloud contexts. Modern enterprises must recognize the increased risk to east-west workloads, stay vigilant to evolving TTPs, and augment internal defenses in the face of rising geopolitical tensions and regulatory enforcement.
8 months ago
Kill Chain
Landfall Spyware Campaign Exposes Samsung Galaxy Devices in the Middle East
In mid-2024, security researchers from Palo Alto Networks' Unit 42 uncovered 'Landfall', a sophisticated commercial-grade spyware campaign targeting Samsung Galaxy S22, S23, S24, and Fold/Flip devices in the Middle East, specifically in Iran, Iraq, Morocco, and Turkey. Attackers exploited a Samsung-specific zero-day vulnerability using malicious DNG image files, often distributed via WhatsApp, enabling zero-click infection without user interaction. Once compromised, Landfall enables extensive surveillance capabilities, such as microphone activation and unauthorized data collection—including contacts and photos. While attribution remains inconclusive, similarities in infrastructure hint at possible links to the Stealth Falcon APT group. This incident highlights the rising use of zero-click exploits and highly-targeted mobile spyware attacks against consumer devices. The sophistication and persistence of such campaigns are forcing device vendors, regulators, and enterprises to invest in rapid patching, threat detection, and zero trust mobile security strategies to counter fast-evolving mobile threats.
8 months ago
Kill Chain
Cisco Firewalls Under Siege: 2024 Zero-Day Flaws Trigger DoS Attacks on ASA & FTD
In June 2024, Cisco disclosed that two actively exploited zero-day vulnerabilities in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) firewalls were being weaponized in the wild. Attackers leveraged these flaws (CVE-2024-20353 and CVE-2024-20359) to trigger repeated reboot loops, effectively causing Denial-of-Service (DoS) on critical network perimeter defenses. Initial exploitation began as targeted zero-days, but attackers quickly adopted the flaws in larger campaigns, dramatically impacting the availability and security of organizations relying on Cisco ASA or FTD devices. The incident underscores a growing trend of targeting infrastructure security devices as a primary attack vector, especially given the rise of ransomware actors and APT groups seeking disruption over data theft. Exploitation of device vulnerabilities for DoS attacks highlights the heightened urgency for rapid patching and robust segmentation in modern enterprise environments.
8 months ago
Kill Chain
LandFall Spyware: Samsung Zero-Day Exploited Through WhatsApp (2024 Attack Insights)
In early 2024, cybersecurity researchers identified that a sophisticated threat actor exploited a zero-day vulnerability in Samsung’s Android image processing library to deploy a previously unknown spyware, dubbed 'LandFall.' The attackers delivered malicious images via WhatsApp messages, abusing the image parsing process to gain device access without user interaction. Once installed, LandFall enabled covert surveillance, exfiltration of private data, and remote control capabilities, putting millions of Samsung devices at risk globally—especially given the attack’s stealthy, user-independent execution method. The breach demonstrates a significant advancement in mobile spyware delivery and a major supply chain risk for mobile OS providers. This incident is highly relevant as attackers increasingly leverage messaging platforms and zero-click vulnerabilities to distribute advanced spyware. The weaponization of zero-days against widespread consumer hardware underscores the urgent need for rapid vulnerability detection and robust response protocols across the mobile ecosystem.
8 months ago
Kill Chain
Samsung 2025: LANDFALL Zero-Day Spyware Breach Exposes Enterprise Mobile Risks
In October 2025, a critical zero-day vulnerability (CVE-2025-21042) in Samsung Galaxy Android devices was actively exploited in the wild to deploy commercial-grade Android spyware known as LANDFALL. Attackers leveraged an out-of-bounds write flaw in the 'libimagecodec.quram.so' component through remote zero-click techniques, enabling arbitrary code execution without user interaction. Targeted campaigns, primarily in the Middle East, allowed adversaries to gain full device access and conduct covert surveillance until Samsung issued an urgent patch. The attacks highlight the sophistication and stealth of modern mobile threat actors and the increasing use of zero-day exploits to compromise mobile endpoints. This incident exemplifies the rise of highly targeted mobile spyware attacks leveraging zero-day vulnerabilities in globally popular hardware. It signals a broader trend in which commercial surveillance tools are abused by both state and non-state actors, driving greater urgency around mobile threat detection, zero-trust controls, and rapid patch management in enterprise environments.
8 months ago
Kill Chain
Chinese Nation-State Hackers Breach U.S. Non-Profit Using Legacy Bugs
In early 2025, a China-linked advanced persistent threat (APT) group carried out a sophisticated cyber espionage campaign targeting a prominent U.S. non-profit focused on policy issues. Leveraging legacy vulnerabilities such as Log4j and Microsoft IIS flaws, the attackers gained initial access, established persistent footholds, and conducted covert data exfiltration operations while remaining undetected for several months. According to detailed analyses by Symantec and Carbon Black, the group focused on harvesting sensitive documents related to U.S. government policy and influencing discussions through clandestine activity within compromised systems, amplifying strategic risk to both the organization and its stakeholders. This incident exemplifies a broader trend of nation-state actors weaponizing unpatched, well-known vulnerabilities for long-term espionage. Organizations with legacy infrastructure are increasingly attractive targets, underscoring the urgent need for proactive vulnerability management, encrypted traffic controls, and robust east-west security to counter evolving, identity-driven threats.
8 months ago
Kill Chain
LANDFALL Spyware: Exploiting CVE-2025-21042 Against Samsung Android Devices
In early 2025, the commercial-grade spyware known as LANDFALL was discovered targeting Samsung Android devices. Leveraging the newly identified CVE-2025-21042, attackers embedded the spyware in specially crafted malicious DNG image files. When unsuspecting users opened these images, the exploit chain compromised the underlying image processing library, granting attackers unauthorized access to device data, communications, and possibly real-time surveillance capabilities. This incident highlights yet another example of sophisticated supply chain exploitation aimed at high-value mobile assets, resulting in potential data exposure, loss of privacy, and reputational damage for affected organizations and individuals. LANDFALL’s attack chain signals an alarming new era for mobile threats, emphasizing the rapid weaponization of zero-days on widely deployed platforms. With growing regulatory scrutiny, businesses must closely examine mobile security controls and incident response readiness given the increasing complexity of modern spyware campaigns.
8 months ago
Kill Chain
Cisco's 2024 Critical UCCX Flaw Exposes Root-Level Risks
In June 2024, Cisco disclosed a critical vulnerability (CVE-2024-20253) in its Unified Contact Center Express (UCCX) software, which could allow remote attackers to execute arbitrary commands with root privileges on affected systems. The flaw, which is due to improper validation of user-supplied input, does not require user authentication and is rated 9.9 out of 10 in severity. Malicious actors exploiting this vulnerability could gain full control over the underlying infrastructure, potentially leading to data breaches, service interruptions, or lateral movement within an organization's network. Cisco has issued security patches, and there are currently no reports of exploitation in the wild. The incident underscores the urgent need for prompt patch management and reinforces the trend of attackers rapidly leveraging zero-day and critical vulnerabilities in widely deployed enterprise platforms. Organizations must prioritize vulnerability management and maintain strict network segmentation to contain similar risks in their environments.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports