Telecom protocol abuse and a separate GlobalProtect fraud campaign
Cyble describes nation-state telecom abuses including Salt Typhoon, while SOCRadar reports a separate 2026 GlobalProtect fraud campaign that sent millions of fake bills.
The two reports describe separate incidents, not conflicting accounts of one event. Cyble says nation-state operators abuse trust assumptions in SS7, Diameter, and BGP, citing DHS warnings that U.S. carriers are exposed and a 2010 China Telecom BGP incident that briefly routed about 15 percent of internet destinations through Chinese servers. A 2025 CISA advisory says PRC actors, including Salt Typhoon, compromised backbone and edge routers with known Ivanti, Palo Alto, and Cisco flaws and kept access through GRE tunnels, while the FCC pushed RPKI-based BGP security plans for large providers. Separately, SOCRadar reported Operation Master from April to mid-September 2026, which exploited CVE-2026-0257, a GlobalProtect authentication bypass, to create VPN sessions on seven gateways in four countries. Attackers ran SQL injection against at least nine databases, exfiltrated records including 24,558 debtor contacts through DNS, and used a panel and hijacked Microsoft 365 mailboxes to send 2,468,335 emails and 1,487,294 SMS messages, mainly toward Brazilian customers. Logged invoices totaled about R$150.4 million, payments were not confirmed, the exposed infrastructure went offline in mid-September, and operators also used AdaptixC2, device-code phishing, and vishing.
- A 2025 CISA advisory says PRC actors, including Salt Typhoon, hit telecom backbone and edge routers using CVE-2024-21887, CVE-2023-46805, CVE-2024-3400, CVE-2023-20273, and CVE-2023-20198, then persisted with GRE tunnels.
- DHS has said U.S. carriers are exposed to SS7 and Diameter attacks; those protocols lack strong caller authorization, enabling tracking and interception.
- A 2010 China Telecom BGP incident briefly drew about 15 percent of internet destinations through Chinese servers; the FCC pushed RPKI-based BGP security plans for large providers.
- SOCRadar reported Operation Master, active from April to mid-September 2026, exploiting CVE-2026-0257 to open GlobalProtect sessions without valid credentials on seven gateways in four countries.
- Attackers used SQL injection against at least nine databases and DNS exfiltration, including 24,558 debtor contacts from one billing server.
- A fraud panel sent 2,468,335 emails and 1,487,294 SMS messages impersonating utilities, mainly toward Brazilian customers, using hijacked Microsoft 365 mailboxes.
- Logged invoice values totaled about R$150.4 million in attempted exposure; money received was not confirmed, and the exposed infrastructure went offline in mid-September 2026. Operators also used AdaptixC2, Microsoft 365 device-code…
Coverage timelineoldest first · each row is one article
- · 6d agoInside the Telecom Attack Surface: SS7, BGP Hijacking, and the Technical Reality of Nation-State Intrusions
Cyble· 60
Nation-state actors abuse SS7, BGP, and unpatched telecom routers, including Salt Typhoon persistence via GRE tunnels.
- · 3d agoHackers Exploit GlobalProtect Flaw and Turn Stolen Data Into 2.4 Million Fraud Messages
Cyber Security News· 78
Criminals exploited a GlobalProtect bypass, stole customer records, and sent 2.4 million fake bills.
Vulnerabilities in this storyAll →
- CVE-2023-2019810.0100%Unauthenticated Privilege Escalation in Cisco IOS XE Web UI (Actively Exploited)published · Cisco IOS XE (Web UI feature) KEV