BPFdoor in Telecom Networks: Sleeper Cells in the Backbone

2026-03-27T07:23:44Zdb26ffd548fe998cff6b9bf287f1c849f704e0f00503c99495f3ae3d1ddd318c
AT-commandsBPFdoorBSI C5CVE-2025-64328CVE-2026-29058CVE-2026-3055CitrixIoTMetasploitNetScalerRed MenshenSAMLVector Commandcellular-modulescomplianceespionagehardware-tamperinginformation-disclosurenation-statetelecom-intrusiontelecommunicationsweb-application-security

What happened

Rapid7 Labs published multiple security updates: a months-long investigation uncovered “BPFdoor” sleeper cells deployed by a China‑nexus threat actor (Red Menshen) inside telecommunications infrastructure, enabling stealthy, persistent espionage and the ability to intercept or pivot across provider networks. Rapid7 also documented a critical Citrix NetScaler ADC/Gateway vulnerability (CVE-2026-3055) — an unauthenticated out‑of‑bounds read with a CVSS of 9.3 that impacts systems configured as a SAML Identity Provider and can leak sensitive memory. New research and a whitepaper describe weaponiz

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
db26ffd548fe998cff6b9bf287f1c849f704e0f00503c99495f3ae3d1ddd318c
Enrichment time
2026-03-27T07:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.