
Telecoms
Known, unpatched CVEs are how the biggest telecom breaches start.
Operational and business support systems, network management, and 5G core software combine vendor equipment firmware with large open-source stacks. The most damaging telecom intrusions have not needed novel exploits; they have walked in through known vulnerabilities that were never patched.
The software underneath
- OSS/BSS and network-management software
- 5G core and packet-processing software
- Vendor equipment and firmware
- Billing, CRM, and customer self-service portals
Salt Typhoon
2024 to 2025A campaign attributed to China's Ministry of State Security compromised telecom providers and critical infrastructure across more than 80 countries, reaching hundreds of organisations. It relied on known, published vulnerabilities in widely used Cisco, Ivanti, and Palo Alto Networks products rather than zero-days.
If you cannot see and fix the known-vulnerable components in your stack, a nation-state does not need anything more sophisticated.
NIS2
Telecom operators are essential entities under NIS2 and must manage supply-chain risk across their suppliers and the software components in their networks.
Match your tree against advisories
Cross-reference every direct and transitive dependency against the public vulnerability databases, so a known CVE cannot sit unnoticed.
Fix or gate
Bump to the nearest fixed release automatically, or fail the build until it is addressed.
Track what changed
Keep an SBOM and a clean record of components, so you can answer what is running where.
Have you used Verifi in telecoms?
We are building our library of real-world results. Tell us how your team runs Verifi and we will help you write it up, or request a case study for your sector.