More than 600 organisations across 80 countries since 2019, including US carriers and the lawful-intercept systems they run. The metadata was always the point.
An authentication bypass on the appliance that decides who is inside. The intruder inherits every assumption built on it.
Foothold to exfiltration in about 72 minutes. Every response process that assumes a human decides in time is now mistimed.
Mass credential compromise across tens of thousands of firewalls. Patching fixes the device; it does not un-disclose the credentials.
Four vendors, one campaign. Largest attack surface, least visibility, highest trust — and both states and criminals use the same door.
Detected and remediated in about nine hours, with exposure limited to names and numbers. Fast containment is a decision, not luck.
A session token read out of appliance memory bypasses the second factor entirely, because authentication already happened.
Management interfaces are built on the assumption that whoever reaches them is already trusted.
A stolen session token arrives after authentication. Multi-factor is not bypassed — it is never consulted.
The vendor did not tell customers to update the appliance. It told them to throw it away.