May 2026

Published 2026-05-01

Diameter S6a abuse still leading interconnect finding

Q1 audit sample from the P1 caseload: 78% of Diameter interconnect audits found at least one exploitable S6a category-2 or -3 misuse path (IDR, PUR, CLR). Category-1 filtering is largely mature; the fine-grained categories remain weak.

S6a CLR abuse pattern of the quarter

Signaling

Repeated pattern: origin-realm spoofing on Cancel-Location-Request to force UE detach. Sole defense is realm-plus-IMSI consistency check at the DEA, which many deployments still skip.

Baseband CVEs and operator responsibility

Vulnerability

Following prior Exynos and MediaTek baseband CVEs, operators face growing questions about what "operator responsibility" for handset firmware currency looks like — particularly for branded CPE and IoT SIMs.

GSMA T-ISAC visibility expands

Regulatory

More national CERTs began contributing signaling attack telemetry to T-ISAC. First cross-operator campaign correlation reports on SS7 location scanning were shared to member operators.