Two secretive surveillance vendors are exploiting critical vulnerabilities in the global telecommunications infrastructure to conduct long-term location tracking of high-profile targets worldwide.
These "ghost" companies masquerade as legitimate telecom operators. By abusing the SS7 and Diameter protocols, they use telecom carriers including 019Mobile, Tango Networks and Airtel Jersey as staging points for their surveillance operations. The attackers even leverage SIMjacker technology to send covert commands to target handsets, turning them directly into location-tracking devices.
Researchers warn that this is merely the tip of the iceberg of millions of similar attacks across the globe, laying bare the massive flaws in the security authentication mechanisms of mobile communication networks.
https://t.co/ReE5Hy10L1
Excited to announce our first TyphoonCon 2026 training! "Exploiting 10x Faster: LLM Agents and MCPs for Modern Vulnerability Research" by @beta_b0t and @G1ND1L4
https://t.co/CqHbDrrW9t
Stay tuned for more!
🌪️ It is a privilege to welcome @theflow0 as our first keynote speaker at #TyphoonCon2025 🎤🔥
Join us in Seoul on May 29-30 for an insightful and inspiring session! 🔗 https://t.co/BewhLLAhGi
🌪️ TyphoonCon 2025 Early Bird tickets now on sale! 🌪️
Dive into exploits, reverse engineering, and cutting-edge insights in offensive security. May 29–30 in Seoul, South Korea. ‘
🎟️ Limited tickets available: https://t.co/MKFEnL7JeT
🎉🎄 End the year in style! (or not🤪)
Join the SSD Secure Disclosure End-of-Year Raffle for a chance to win our ugly Christmas sweater! 👕
Hackers deserve holiday cheer too—don’t miss out!
Enter now 👉🏻 https://t.co/J3BJruQXXO
🚨 New advisory was just published! 🚨
The Uniview IPC2322LB processes authentication requests allows remote attackers to bypass the authentication process and gain unauthorized access. If this is combined with a CLI escape, the Uniview device's security can be completely compromised: https://t.co/qdU9nFum5J
🌪️Announcing Typhooncon 2024 Training Final Lineup!
💻WinDbg for Security Researchers and Engineers
By Yarden Shafir @yarden_shafir
https://t.co/u7RypMcb8Y
🔒Fuzzing & Attacking Deeply Embedded Devices
By Tobias Scharnowski @ScepticCtf & Marius Muench @nSinusR
https://t.co/5vylNKJ4eP
👨🏻💻Software Deobfuscation Techniques
By Tim Blazytko @mr_phrazer
https://t.co/t1N6qKXDtD
Huge thanks to all those who submitted training proposals for Typhooncon 2024.
Hope to see you all in Seoul in the future.
@ipvideo@CharlesRollet1@SecuriTeam_SSD Are you sure? In my experience working with them, nothing is ever being disclosed to anyone other than the vendor- and surely not for any hacking purposes.
🌪️ “The Future of Windows Vulnerability Research” will be presented by @aionescu at #TyphoonCon23!
🌪️ Learn more and get your tickets today: https://t.co/sOoe2xvyYm
🚨 New advisory is now out! 🚨
Find out how a vulnerability in https://t.co/S7Uk1yR4C6 client allows remote attackers to cause a victim clicking on a seemingly harmless link to execute arbitrary commands.
https://t.co/KpYFpGlma1
New advisory is now out!
NetMotion Mobility is a secure platform for remote workers in mobile environments.
Find out how vulnerabilities in NetMotion Mobility allow an unauthenticated attacker to run arbitrary code on the server with SYSTEM privileges.
https://t.co/xTc58D1ajx