CCITT Standardizes SS7 (Signaling System No. 7)
CCITT standardized the SS7 protocol suite in 1988 across mobile and fixed networks, built on implicit operator trust with no authentication — the root cause of every later signaling attack.
CCITT standardized the SS7 protocol suite in 1988 across mobile and fixed networks, built on implicit operator trust with no authentication — the root cause of every later signaling attack.
3GPP Release 99 standardized 3G UMTS, introducing bidirectional mutual authentication (3G AKA) to defeat rogue base stations (IMSI catchers) and replacing A5/1 with the KASUMI block cipher.
Automated botnets scanned global IP blocks for exposed SIP UDP port 5060, brute-forcing default extension credentials on Asterisk PBXs to route millions of unauthorized calls to high-cost premium-rate numbers in Somalia, Cuba, and Latvia.
Symantec and Kaspersky exposed Regin, an extraordinarily sophisticated nation-state malware platform specifically engineered to infiltrate GSM cellular base station controllers and telecom routing cores.
Security researchers demonstrated that 4G LTE Diameter signaling networks inherited the unauthenticated trust vulnerabilities of SS7, allowing subscriber tracking and denial-of-service over IPX interconnects.
Positive Technologies disclosed critical architectural flaws in GTP (GPRS Tunnelling Protocol) across 2G, 3G, and 4G networks, demonstrating how attackers on IPX roaming networks could hijack subscriber data sessions and execute over-the-air fraud.
Cybereason revealed Operation Soft Cell, a massive multi-year cyber espionage campaign by suspected nation-state actors that completely compromised multiple telecommunications providers to exfiltrate raw subscriber Call Detail Records.
CrowdStrike revealed that the LightBasin (UNC1945) APT had compromised 13+ global telecom operators since at least 2016 using custom GTP and SS7 tooling to masquerade as roaming infrastructure.
The GSM Association launched its formal Coordinated Vulnerability Disclosure (CVD) program and Hall of Fame, establishing standard operating procedures for researchers to responsibly report 2G–5G protocol and core vulnerabilities.
5G Standalone (Release 16, 2020) replaced SS7/Diameter trust assumptions with HTTP/2 service-based APIs over TLS, OAuth 2.0 token authentication, and cryptographically concealed subscriber identities (SUCI).
A global consortium of journalists revealed that NSO Group's Pegasus spyware had targeted 50,000+ phone numbers across 50 countries, utilizing zero-click SMS/iMessage parser vulnerabilities.
Threat intelligence researchers uncovered RedEye / ChamelGang deploying custom eBPF (Extended Berkeley Packet Filter) kernel rootkits directly inside telecom core network servers to intercept subscriber GTP data and signaling stealthily.
3GPP and leading telecom vendors standardized the Network Data Analytics Function (NWDAF), integrating machine learning and deep reinforcement learning directly into 5G Core signaling planes to detect sub-second zero-day signaling exploits autonomously.
3GPP SA3 finalized Release 19 security specifications integrating NIST Post-Quantum Cryptography (FIPS 203 ML-KEM and FIPS 204 ML-DSA) to protect 5G subscriber privacy (SUCI) and inter-operator Service-Based Architecture (SBA) tunnels against Harvest-Now-Decrypt-Later threats.