Citizen Lab details two spying campaigns that abuse weaknesses in the SS7 and Diameter protocols across 2G, 3G, 4G, and 5G networks to track people's locations (Lorenzo Franceschi-Bicchierai/TechCrunch)

Citizen Lab has uncovered sophisticated spying campaigns exploiting fundamental vulnerabilities in SS7 and Diameter protocols across all mobile network generations (2G-5G), enabling threat actors to track individuals' locations undetected for extended periods. This reveals a critical gap in telecom infrastructure security that bypasses traditional endpoint defenses like VPNs, creating enterprise-wide risk for employee mobility and supply chain communications. IT organizations must urgently reassess their mobile security posture and work with telecom providers to implement protocol-level protections, as this represents a fundamental infrastructure vulnerability beyond the control of traditional cybersecurity tools.

Lorenzo Franceschi-BicchieraiTechMeme2 min read
Read full article
Citizen Lab details two spying campaigns that abuse weaknesses in the SS7 and Diameter protocols across 2G, 3G, 4G, and 5G networks to track people's locations (Lorenzo Franceschi-Bicchierai/TechCrunch)
Lorenzo Franceschi-Bicchierai / TechCrunch: Citizen Lab details two spying campaigns that abuse weaknesses in the SS7 and Diameter protocols across 2G, 3G, 4G, and 5G networks to track people's locations — Security researchers have uncovered two separate spying campaigns that are abusing well-known weaknesses in the global telecoms infrastructure to track people's locations.