| website | https://samsclass.info |

| website | https://samsclass.info |
The European Commission is investigating a security breach after a threat actor gained access to its Amazon cloud infrastructure.
Really good research from Rapid7 here, where they’ve found multiple new versions of BPFdoor which do things like listen and backdoor on extremely uncommon 4G and 5G signaling protocols - it strongly suggests BPFDoor has been placed far inside telcos for surveillance.
They provide a tool to check for the new implant - I would strongly suggest telcos look for this on their Linux systems, including call infrastructure.
https://www.rapid7.com/blog/post/tr-bpfdoor-telecom-networks-sleeper-cells-threat-research-report/

A months-long investigation by Rapid7 Labs has uncovered evidence of an advanced China-nexus threat actor placing stealthy digital sleeper cells in telecommunications networks, in order to carry out high-level espionage – including against government networks. Read more in a new blog.