The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
How Interpol's Operation Jackal IV Exposed Global Cybercrime Infrastructure
Operation Jackal IV, an international law enforcement operation coordinated by Interpol, resulted in 58 arrests and identification of 263 suspects across multiple countries, targeting West African organized crime groups including Black Axe. The operation disrupted extensive money laundering networks, business email compromise schemes, and romance scams that generated hundreds of millions in criminal proceeds. Authorities seized $2.67 million in cash, blocked 257 bank accounts, and uncovered a 143 million euro investment fraud operation, demonstrating the global reach and sophisticated financial infrastructure of these cybercriminal syndicates. This incident highlights the evolving threat landscape where traditional organized crime groups increasingly leverage digital platforms and cryptocurrencies to scale their operations globally, requiring enhanced international cooperation and advanced financial crime detection capabilities to combat their sophisticated money laundering networks.
1 month ago
Kill Chain
Critical Calix Router Flaw Exposes Millions of Home Networks to Internet Attackers
A critical unpatched vulnerability (CVE-2026-75501) in Calix GS7 XGS residential routers allows remote unauthenticated attackers to bypass NAT and firewall protections by creating arbitrary port-forwarding rules. The flaw affects EXOS/6.6.47 firmware and exposes the MiniUPnPd control endpoint on the WAN interface without authentication, enabling attackers to expose internal devices like cameras, NAS systems, and IoT appliances to the public internet with a single SOAP request. Major U.S. broadband providers including Cox Communications, Brightspeed, and ALLO deploy these vulnerable routers to residential customers. This vulnerability highlights the growing risk of perimeter-based security failures in an era where remote work and IoT adoption have expanded attack surfaces. With no vendor patch available and limited workarounds, this incident underscores the urgent need for zero-trust network architectures that don't rely solely on NAT and traditional firewall protections.
1 month ago
Kill Chain
Operation QUICSILVER Exploits Government Trust: How QUICAgent Backdoor Evaded Detection
Operation QUICSILVER is a cyber espionage campaign targeting Myanmar's government and IT sectors, attributed to a China-nexus threat actor with moderate confidence. First observed in April 2026, the campaign uses graduation ceremony invitation lures written in Burmese to deliver QUICAgent, a custom Go-based backdoor. The attack chain begins with malicious VHD files containing Windows shortcuts that masquerade as PDF documents, ultimately deploying the backdoor which communicates over QUIC protocol on UDP port 443 for command and control operations. This incident highlights the continued targeting of Southeast Asian governments by suspected Chinese APT groups, representing the evolving use of legitimate protocols like QUIC to evade detection. The campaign demonstrates sophisticated social engineering tactics using culturally relevant lures and reflects the ongoing geopolitical tensions in the region through cyber means.
1 month ago
Kill Chain
ToxicPanda 2.0: The Android Banking Trojan That Hijacks VPN Permissions
ToxicPanda 2.0 Android malware emerged in August 2026 with sophisticated capabilities targeting 349 banking and financial applications across 16 countries. The malware exploits VPN service permissions to create local network interfaces that block Google Play communications, preventing security updates and Play Protect interference. It leverages Accessibility Services to automatically enable Wireless ADB debugging, gaining shell-level access to execute high-privilege commands and bypass Android security restrictions. The malware supports 167 remote commands and includes invisible phishing overlays that capture credentials and device PINs while maintaining persistence across major Android device manufacturers. Mobile banking trojans are experiencing a resurgence in 2026, with threat actors increasingly targeting VPN permissions and ADB abuse techniques to circumvent Google's enhanced security measures and maintain persistent access to compromised devices.
1 month ago
Kill Chain
TrueConf Server Supply Chain Attack: How Head Mare Exploited Critical CVE-2026-72529 Vulnerability
In August 2026, CISA ordered federal agencies to patch two critical TrueConf Server vulnerabilities (CVE-2026-72529 and CVE-2026-72530) within two weeks after adding them to the Known Exploited Vulnerabilities catalog. The flaws allow unauthenticated remote code execution and sandbox escape attacks on the self-hosted communications platform. The Head Mare hacktivist group has been actively exploiting these vulnerabilities since July 2026 to replace legitimate client installers with backdoor-laden versions, targeting Russian organizations across transportation, energy, and IT sectors. This incident follows previous TrueConf compromises, including Operation True Chaos linked to Chinese threat actors in April 2026. This attack highlights the growing trend of supply chain compromises targeting enterprise communication platforms, particularly as organizations increasingly rely on self-hosted solutions for secure corporate messaging and video conferencing amid rising cybersecurity concerns about cloud-based alternatives.
1 month ago
Kill Chain
Automotive Cybersecurity Alert: First Android Head Unit Malware Targets Connected Vehicles
In June 2026, Kaspersky researchers discovered the first documented case of Android malware specifically targeting automotive head units. The MoYu Group, linked to the BADBOX botnet, exploited legitimate update mechanisms in DoFun head unit firmware to distribute multi-stage malware through the TWCore system application. The attack chain deployed a sophisticated dropper that ultimately created a proxy botnet for ad fraud operations. The malware spread through built-in firmware updaters without user knowledge, establishing command and control infrastructure to recruit infected vehicles into their botnet network. This incident represents a critical expansion of botnet operations into automotive systems, highlighting the growing threat surface as vehicles become increasingly connected. With automotive head units now proven vulnerable to the same malware techniques used against smartphones and IoT devices, the automotive industry faces new cybersecurity challenges requiring immediate attention.
1 month ago
Kill Chain
First Android Car Malware Campaign Targets Vehicle Head Units Through Update Compromise
In June 2026, Kaspersky discovered the first documented malware specifically targeting Android-based vehicle head units, marking a significant expansion of cybercriminal operations into automotive systems. The malware, attributed to the MoYu Group behind the BADBOX botnet, infected DoFun-powered head units through compromised legitimate update mechanisms. Attackers weaponized the TWCore system app's MQTT-based update channel to deliver JarService dropper malware, enabling ad fraud and proxy botnet creation. The sophisticated attack chain demonstrates how threat actors are adapting traditional mobile malware techniques for automotive platforms, exploiting SIM-enabled connectivity in modern vehicle infotainment systems. This incident highlights the emerging threat landscape as connected vehicles become mainstream targets, with automotive cybersecurity gaps creating new attack vectors for established cybercriminal groups seeking to monetize vehicle connectivity infrastructure.
1 month ago
Kill Chain
Delta Flight 591 Wi-Fi Hack: When DEF CON Tools Turn Into In-Flight Threats
In August 2026, a passenger on Delta Air Lines Flight 591 from Las Vegas to Atlanta compromised the aircraft's in-flight Wi-Fi system following the Black Hat and DEF CON conferences. The attacker disabled the legitimate Wi-Fi service and created a rogue access point named "Delta WiFi Fast" that redirected users to a phishing page designed to harvest credentials. Federal authorities launched an investigation into the incident, with suspicion falling on DEF CON attendees who may have used commercially available Wi-Fi Pineapple devices purchased at the conference. This incident highlights the growing risk of in-flight cybersecurity threats as aviation systems become increasingly connected. The ease with which commercially available penetration testing tools can be weaponized in confined, high-security environments demonstrates critical gaps in aviation cybersecurity protocols and passenger device restrictions during flight operations.
1 month ago
Kill Chain
CISA Adds Critical TrueConf Server Vulnerabilities to Known Exploited Vulnerabilities Catalog
CISA has added two critical TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation in the wild. CVE-2026-72529 involves missing authentication for critical functions, while CVE-2026-72530 represents a code injection vulnerability, both allowing attackers to gain total control of affected systems. These vulnerabilities pose significant risks to federal enterprises and private organizations using TrueConf's video conferencing solutions, with threat actors actively leveraging these flaws to establish persistent access and execute unauthorized commands on compromised servers. This incident highlights the growing trend of attackers targeting collaboration and communication platforms, particularly as hybrid work environments continue to expand the attack surface of enterprise networks and create new pathways for initial compromise and lateral movement.
1 month ago
Kill Chain
Cisco Patches Nine Critical Vulnerabilities Including Five CVSS 10.0 Flaws in Network Infrastructure
In August 2026, Cisco released critical security patches addressing nine severe vulnerabilities across its Crosswork platforms and Secure Workload software. The flaws included five vulnerabilities scoring CVSS 10.0, affecting network management and workload security products used extensively in enterprise environments. Four vulnerabilities impacted Crosswork Data Gateway, Network Controller, and Planning platforms, including SQL injection and missing authentication issues. Five additional vulnerabilities affected Cisco Secure Workload deployments, encompassing improper access control, authentication bypass, and command injection flaws. These vulnerabilities were discovered during internal security testing and were not known to be actively exploited at the time of disclosure. The widespread deployment of Cisco infrastructure in enterprise networks makes these vulnerabilities particularly concerning, as they could provide attackers with significant access to critical network management and security monitoring systems if exploited.
1 month ago
Kill Chain
Record 77-Year Sentence for 764 Network Leader Signals Escalating Fight Against Nihilistic Violent Extremists
Kyle William Spitze, a 27-year-old original member and administrator of the nihilistic violent extremist group 764, was sentenced to 77 years in prison in January 2025, marking the longest federal sentence ever imposed on a nihilistic violent extremist. Spitze, operating under aliases including "Chrimhn" and "Criminal," led the 764 offshoot "Harm Nation" and coerced dozens of minors through threats of doxing and swatting to produce child sexual abuse material, self-mutilate, and torture animals. The FBI investigation began in December 2023 after Discord reported the group's activities, leading to Spitze's arrest and guilty plea to multiple federal charges including production and distribution of CSAM. This sentencing represents a significant escalation in law enforcement's response to online extremist networks that exploit children, as FBI Director Kash Patel reported a 500% increase in arrests of nihilistic violent extremist offenders in 2024, highlighting the growing threat these decentralized criminal enterprises pose to vulnerable populations.
1 month ago
Kill Chain
Manic Android Malware Introduces Peer-to-Peer Data Exfiltration via Nearby Devices
The Manic Android malware, active since February 2026, represents a sophisticated mobile threat targeting banking, government, and cryptocurrency applications across Central and Western Europe, with primary focus on Ukraine. This malware employs transparent overlays to capture user inputs, leverages Android Accessibility services for comprehensive device control, and implements an innovative peer-to-peer data exfiltration mechanism using Wi-Fi Direct and Bluetooth connections through nearby infected devices. Manic can intercept SMS messages, capture lock PINs, monitor screens, collect location data, and provide remote access to operators via WebRTC sessions, targeting over 169 applications including banking, eID, payment, and authenticator apps. This incident highlights the evolving sophistication of mobile banking malware and the increasing threat to critical infrastructure applications, particularly government eID systems, as attackers develop novel exfiltration methods that bypass traditional network-based security controls.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports