BPFdoor in Telecom Networks: Sleeper Cells in the Backbone
2026-03-27T07:23:44Z•db26ffd548fe998cff6b9bf287f1c849f704e0f00503c99495f3ae3d1ddd318c
AT-commandsBPFdoorBSI C5CVE-2025-64328CVE-2026-29058CVE-2026-3055CitrixIoTMetasploitNetScalerRed MenshenSAMLVector Commandcellular-modulescomplianceespionagehardware-tamperinginformation-disclosurenation-statetelecom-intrusiontelecommunicationsweb-application-security
What happened
Rapid7 Labs published multiple security updates: a months-long investigation uncovered “BPFdoor” sleeper cells deployed by a China‑nexus threat actor (Red Menshen) inside telecommunications infrastructure, enabling stealthy, persistent espionage and the ability to intercept or pivot across provider networks. Rapid7 also documented a critical Citrix NetScaler ADC/Gateway vulnerability (CVE-2026-3055) — an unauthenticated out‑of‑bounds read with a CVSS of 9.3 that impacts systems configured as a SAML Identity Provider and can leak sensitive memory. New research and a whitepaper describe weaponiz
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- db26ffd548fe998cff6b9bf287f1c849f704e0f00503c99495f3ae3d1ddd318c
- Enrichment time
- 2026-03-27T07:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.