CriticalSecurity & Privacy
Citizen Lab details two spying campaigns that abuse weaknesses in the SS7 and Diameter protocols across 2G, 3G, 4G, and 5G networks to track people's locations (Lorenzo Franceschi-Bicchierai/TechCrunch)
Citizen Lab has uncovered sophisticated spying campaigns exploiting fundamental vulnerabilities in SS7 and Diameter protocols across all mobile network generations (2G-5G), enabling threat actors to track individuals' locations undetected for extended periods. This reveals a critical gap in telecom infrastructure security that bypasses traditional endpoint defenses like VPNs, creating enterprise-wide risk for employee mobility and supply chain communications. IT organizations must urgently reassess their mobile security posture and work with telecom providers to implement protocol-level protections, as this represents a fundamental infrastructure vulnerability beyond the control of traditional cybersecurity tools.

Lorenzo Franceschi-Bicchierai / TechCrunch: Citizen Lab details two spying campaigns that abuse weaknesses in the SS7 and Diameter protocols across 2G, 3G, 4G, and 5G networks to track people's locations — Security researchers have uncovered two separate spying campaigns that are abusing well-known weaknesses in the global telecoms infrastructure to track people's locations.