Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

29 / 29 results
Active filter:tag: #telecommunications✕ clear
Cisco patches 12 critical SD-WAN and IOS XE flaws, three rated 9.8+criticalbug_reportVulnerability
bug_reportVulnerability

Cisco patches 12 critical SD-WAN and IOS XE flaws, three rated 9.8+

Cisco Catalyst SD-WAN Software (all versions prior to 20.9, versions 20.9–26.1); Cisco IOS XE Software versions 17.9–26.1 running in autonomous or controller mode; Cisco Integrated Management Controller (IMC) web interface.

Cisco6 Aug · 15:13 UTC
Cisco IOS/IOS XE vulnerabilities require immediate patchinghighbug_reportVulnerability
bug_reportVulnerability

Cisco IOS/IOS XE vulnerabilities require immediate patching

Cisco IOS and IOS XE platforms. Specific affected versions not disclosed in advisory. Scope includes network infrastructure devices (routers, switches) running these operating systems.

Cisco6 Aug · 13:38 UTC
Fuyao Campaign: Android TV Boxes Weaponized for Ad Fraud and Proxy Abusehighperson_alertThreat Actor
person_alertThreat Actor

Fuyao Campaign: Android TV Boxes Weaponized for Ad Fraud and Proxy Abuse

Zhejiang Fengwo IoT Technology Co., Ltd. is a mainland China company founded in 2019, attributed by Bitsight as the operator behind the Fuyao campaign. The attribution is based on shared TLS certificate data, exposed wiki files, reused email addresse…

Samsung31 Jul · 12:45 UTC
84 flaws in 4G/5G core networks enable DoS and session hijackinghighbug_reportVulnerability
bug_reportVulnerability

84 flaws in 4G/5G core networks enable DoS and session hijacking

4G and 5G core network implementations: Open5GS (LTE/5G), free5GC, OpenAirInterface (LTE/5G), SD-Core, and eUPF. Vulnerabilities affect GTP-C and PFCP signaling protocols. 83 of 84 flaws confirmed, 81 assigned CVE identifiers.

The Hacker News31 Jul · 09:55 UTC
South Korea fines KT Corp $39M for telecom data breach violationshighpublicGeopolitical
publicGeopolitical

South Korea fines KT Corp $39M for telecom data breach violations

The substantial fine against KT Corporation, one of South Korea's largest telecommunications providers, underscores Seoul's increasingly assertive regulatory posture on data protection and critical infrastructure security.

KT Corporation30 Jul · 20:28 UTC
Russian APT exploits OWA XSS flaw for persistent mailbox accesshighbug_reportVulnerability
bug_reportVulnerability

Russian APT exploits OWA XSS flaw for persistent mailbox access

Microsoft Outlook Web Access (OWA) vulnerable to CVE-2026-42897 (CVSS 8.1), a cross-site scripting flaw. Targets include U.S. and European government entities, telecommunications, financial, hospitality, and aerospace sectors.

Microsoft30 Jul · 05:40 UTC
SonicWall SMA 1000 VPN zero-days exploited by UTA0533 for root accesscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA 1000 VPN zero-days exploited by UTA0533 for root access

SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. Specific vulnerable versions not disclosed. All SMA 1000 deployments should be considered at risk until vendor guidance is available.

SonicWall19 Jul · 11:18 UTC
KDDI breach exposes 12M records across Japanese ISP ecosystemhighpublicGeopolitical
publicGeopolitical

KDDI breach exposes 12M records across Japanese ISP ecosystem

The breach of KDDI, one of Japan's three major telecommunications carriers, represents a significant compromise of critical infrastructure in a key U.S. Indo-Pacific ally.

KDDI8 Jul · 09:24 UTC
Tenda router backdoor allows admin access bypass (CVE-2026-11405)criticalbug_reportVulnerability
bug_reportVulnerability

Tenda router backdoor allows admin access bypass (CVE-2026-11405)

Tenda routers running vulnerable firmware versions. Specific models and version ranges not disclosed in available data. Affects web management interface authentication mechanism.

CVE-2026-114057 Jul · 04:40 UTC
Cisco Unified CM vulnerability under active exploitation post-patchhighbug_reportVulnerability
bug_reportVulnerability

Cisco Unified CM vulnerability under active exploitation post-patch

Cisco Unified Communications Manager (Unified CM). Specific vulnerable versions not disclosed; patched versions available since early June 2024. Affects organizations running unpatched Unified CM deployments.

Cisco2 Jul · 09:35 UTC
RustDuck Botnet Targets IoT Devices for DDoS Operationshighperson_alertThreat Actor
person_alertThreat Actor

RustDuck Botnet Targets IoT Devices for DDoS Operations

RustDuck is a two-stage malware family written in Rust, designed to compromise Internet of Things (IoT) devices including home routers, IP cameras, Android set-top boxes, and inadequately secured servers.

Generic routers30 Jun · 15:45 UTC
KDDI breach exposes 14.2M email accounts across Japanese ISP ecosystemhighpublicGeopolitical
publicGeopolitical

KDDI breach exposes 14.2M email accounts across Japanese ISP ecosystem

The breach at KDDI Corporation, one of Japan's largest telecommunications operators, highlights systemic vulnerabilities in shared infrastructure models within critical communications sectors.

KDDI Corporation28 Jun · 12:13 UTC
Polish Authorities Dismantle SIM-Swapping Gang Targeting Crypto Assetshighperson_alertThreat Actor
person_alertThreat Actor

Polish Authorities Dismantle SIM-Swapping Gang Targeting Crypto Assets

This organized cybercrime group operated in Poland, conducting SIM-swapping attacks with the primary motivation of financial gain through cryptocurrency theft.

BleepingComputer25 Jun · 20:37 UTC
Cisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)criticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)

Cisco Catalyst SD-WAN devices. Specific affected versions not disclosed in available information. Attackers gain root-level access and can create persistent rogue accounts.

CVE-2026-2024524 Jun · 19:29 UTC
Cisco Unified CM critical flaw under active exploitation, root access riskcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Unified CM critical flaw under active exploitation, root access risk

Cisco Unified Communications Manager (CUCM) and Unified CM SME. Specific affected versions not provided in available data. Vulnerability affects HTTP request handling with unauthenticated remote attack vector.

CVE-2026-2023024 Jun · 04:50 UTC
Cisco Unified Communications Manager SSRF under active exploitationhighbug_reportVulnerability
bug_reportVulnerability

Cisco Unified Communications Manager SSRF under active exploitation

Cisco Unified Communications Manager (CUCM). Specific affected versions not disclosed. SSRF vulnerability (CVE-2026-20230) allows attackers to force the server to make unauthorized requests to internal or external resources.

CVE-2026-2023023 Jun · 19:48 UTC
AryStinger Malware Infects 4,300+ Routers for Recon Operationshighperson_alertThreat Actor
person_alertThreat Actor

AryStinger Malware Infects 4,300+ Routers for Recon Operations

AryStinger is a newly discovered malware family identified by QiAnXin's XLab threat research team. Unlike traditional DDoS botnets, AryStinger is purpose-built for pre-attack reconnaissance and distributed proxy operations.

Legacy Router Manufacturers22 Jun · 04:57 UTC
AryStinger botnet compromises 4,000+ legacy D-Link routers as proxieshighbug_reportVulnerability
bug_reportVulnerability

AryStinger botnet compromises 4,000+ legacy D-Link routers as proxies

Over 4,000 outdated D-Link routers worldwide, specifically legacy models no longer receiving security updates. Exact models not specified in available data.

D-Link21 Jun · 12:14 UTC
Three high-severity XSS flaws in VMware Telco Cloud and Aria Operationshighbug_reportVulnerability
bug_reportVulnerability

Three high-severity XSS flaws in VMware Telco Cloud and Aria Operations

VMware Telco Cloud/vSphere Foundation and VMware Aria Operations. Specific affected versions not provided in advisory; consult VMware security bulletin for version details.

VMware8 Jun · 13:05 UTC
Check Point VPN auth bypass under active exploit via IKEv1 flawcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point VPN auth bypass under active exploit via IKEv1 flaw

Check Point Remote Access VPN and Mobile Access deployments using deprecated IKEv1 protocol. Specific product versions not disclosed. Does not affect IKEv2 configurations.

CVE-2026-507518 Jun · 12:17 UTC
Gafgyt C0XMO botnet exploits DD-WRT router flaw, kills rival malwarehighbug_reportVulnerability
bug_reportVulnerability

Gafgyt C0XMO botnet exploits DD-WRT router flaw, kills rival malware

DD-WRT router firmware (specific versions not disclosed). Affects devices across multiple CPU architectures. No CVE assigned yet.

DD-WRT7 Jun · 12:17 UTC
Cisco Unified Communications Manager high severity flaw with public PoChighbug_reportVulnerability
bug_reportVulnerability

Cisco Unified Communications Manager high severity flaw with public PoC

Cisco Unified Communications Manager (CUCM). Specific affected versions not disclosed in alert. CVE identifier not yet assigned or published.

Cisco5 Jun · 03:28 UTC
Dutch authorities dismantle botnet controlling 17M infected deviceshighbug_reportVulnerability
bug_reportVulnerability

Dutch authorities dismantle botnet controlling 17M infected devices

At least 17 million infected devices globally including computers, tablets, smartphones, and IoT devices. Over 200 command-and-control servers located in the Netherlands were seized.

The Hacker News31 May · 10:22 UTC
ShinyHunters Breaches Charter Communications, Exfiltrates 4.9M Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches Charter Communications, Exfiltrates 4.9M Records

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting enterprises. The group specializes in exfiltrating sensitive customer data from corporate databases and either selling the…

Charter Communications29 May · 06:29 UTC
ShinyHunters Extorts Charter Communications After Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Extorts Charter Communications After Data Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.

Charter Communications26 May · 17:46 UTC
Showboat Linux Malware Targets Middle East Telecom Since Mid-2022highperson_alertThreat Actor
person_alertThreat Actor

Showboat Linux Malware Targets Middle East Telecom Since Mid-2022

The threat actor behind Showboat remains unattributed. The campaign demonstrates sophisticated targeting of telecommunications infrastructure in the Middle East, suggesting a motivated adversary with strategic intelligence collection objectives.

The Hacker News21 May · 12:17 UTC
Chinese APT Deploys Showboat and JFMBackdoor Against Telecom Sectorhighperson_alertThreat Actor
person_alertThreat Actor

Chinese APT Deploys Showboat and JFMBackdoor Against Telecom Sector

Chinese state-sponsored threat actors conducting cyber-espionage operations against telecommunications infrastructure. The actors demonstrate cross-platform capabilities with custom Linux and Windows malware tooling.

BleepingComputer21 May · 12:00 UTC
Cisco Catalyst SD-WAN auth bypass grants admin access to attackerscriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN auth bypass grants admin access to attackers

Cisco Catalyst SD-WAN platform. Specific affected versions not disclosed. Vulnerability allows authentication bypass leading to administrative access on SD-WAN infrastructure components.

Cisco18 May · 12:16 UTC
MikroTik RouterOS auth bypass via certificate validation flawhighbug_reportVulnerability
bug_reportVulnerability

MikroTik RouterOS auth bypass via certificate validation flaw

MikroTik RouterOS - versions not specified. Affects OpenVPN, CAPsMAN (wireless management), and 802.1X (Dot1x) services that rely on certificate-based authentication.

CVE-2025-4261110 Apr · 07:08 UTC