Home/Digest/Telecommunications/Past issues
Telecommunications digest,
Telecommunications: Warlock Ransomware Targets Critical… (+2 more)
Vulnerabilities
Estonia Enhances Cybersecurity Ahead of Upcoming Elections Amid AI Threats
Estonia is ramping up investments in cybersecurity, particularly for e-voting, due to a significant increase in cyberattacks, including those potentially utilizing artificial intelligence. The Information System Authority (RIA) director noted that while no AI-based cyberattacks have been confirmed in Estonia, the number of damaging incidents has reportedly doubled each year. The government is facing challenges in securing additional funding for cybersecurity, with Prime Minister Kristen Michal indicating that resources may need to be reallocated from other areas. Justice and Digital Minister Liisa-Ly Pakosta emphasized the importance of both technology and personnel in safeguarding the elections, stating that a backup plan for paper voting is in place if necessary. As Estonia prepares for elections in March, the urgency to bolster defenses against evolving cyber threats is critical.
Vulnerability · 2 sources · score 59
Ransomware
Warlock Ransomware Targets Critical Infrastructure in Spanish and Portuguese Regions
The Warlock ransomware group, tracked as Longlegs or Storm-2603, has targeted critical infrastructure in Portuguese- and Spanish-speaking countries, including a water utility, a telecommunications provider, a regional government body, and an university. Recent attacks exploited vulnerabilities in Microsoft SharePoint, particularly the ToolShell exploit chain and potentially newer CVEs. The group has been observed using techniques such as DLL sideloading and a vulnerable signed driver to disable security software before deploying ransomware. In one incident, attackers disabled security software on 40 hosts within two hours and deployed Warlock on at least 33 of them by staging it in the domain's SYSVOL. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned about the of these vulnerabilities. The focus on critical sectors highlights the potential for significant disruption and data loss.
APT · 15 sources · score 79 · CVE-2025-1055, CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771
Breaches
Hackers Charged in AT&T Data Breach Involving 50 Billion Records
The U.S. government has indicted Connor Moucka and John Binns for hacking into Snowflake, a cloud data storage provider, leading to the theft of approximately 50 billion AT&T customer call and text records. The breach, which affected nearly all of AT&T's cellular and landline customers, was discovered on April 19, 2026, after the intrusion occurred on April 14. The hackers reportedly extorted at least three victims, obtaining 36 Bitcoin, worth around $2.5 million at the time. AT&T had previously announced it would notify 110 million customers about the breach. The indictment describes the victims without naming them, but details align with AT&T's disclosures. Moucka was arrested in Canada, while Binns was arrested in Turkey. The breach also impacted other companies using Snowflake, including Ticketmaster and Santander Bank, highlighting a broader issue with data security in cloud services.
Breach · 2 sources · score 55
Get the next one by email
The telecommunications digest is free and arrives on Tuesdays. One click to leave.
Subscribe to the telecommunications digest
A free account turns the digest into a personal watchlist: choose what you want to follow.