May 2026
Published 2026-05-01
Diameter S6a abuse still leading interconnect finding
Q1 audit sample from the P1 caseload: 78% of Diameter interconnect audits found at least one exploitable S6a category-2 or -3 misuse path (IDR, PUR, CLR). Category-1 filtering is largely mature; the fine-grained categories remain weak.
S6a CLR abuse pattern of the quarter
Signaling
Repeated pattern: origin-realm spoofing on Cancel-Location-Request to force UE detach. Sole defense is realm-plus-IMSI consistency check at the DEA, which many deployments still skip.
Baseband CVEs and operator responsibility
Vulnerability
Following prior Exynos and MediaTek baseband CVEs, operators face growing questions about what "operator responsibility" for handset firmware currency looks like — particularly for branded CPE and IoT SIMs.
GSMA T-ISAC visibility expands
Regulatory
More national CERTs began contributing signaling attack telemetry to T-ISAC. First cross-operator campaign correlation reports on SS7 location scanning were shared to member operators.