<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" href="/__sitemap__/style.xsl"?>
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:video="http://www.google.com/schemas/sitemap-video/1.1" xmlns:xhtml="http://www.w3.org/1999/xhtml" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd http://www.google.com/schemas/sitemap-image/1.1 http://www.google.com/schemas/sitemap-image/1.1/sitemap-image.xsd" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
    <url>
        <loc>https://telcosec.net/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/5g-network-security-architecture/</loc>
        <lastmod>2026-05-15</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/5g-architecture-hero.webp</image:loc>
            <image:title>5G Network Security Architecture</image:title>
            <image:caption>TelcoSec&apos;s 5G security architecture deep dive: SBA vulnerabilities, SEPP protection proxies, SUCI encryption, and cloud-native telecom security threat modeling.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/5g-network-slicing-security/</loc>
        <lastmod>2026-05-15</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/network-slicing-hero.webp</image:loc>
            <image:title>5G Network Slicing Security</image:title>
            <image:caption>TelcoSec 5G network slicing security risks in Standalone architecture — cross-slice isolation failures, shared NF abuse, RAN starvation, and Kubernetes threats.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/5g-nrf-oauth2-token-abuse/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/5g-sba-architecture-diagram.webp</image:loc>
            <image:title>5G SBA NRF OAuth2 Token Abuse and NF Impersonation</image:title>
            <image:caption>How rogue NFs abuse missing NF Instance ID binding in NRF OAuth2 token issuance to impersonate AMF/UDM and exfiltrate 5G core subscriber data.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/5g-sepp-n32-roaming-bypass/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/5g-architecture-hero.webp</image:loc>
            <image:title>5G SEPP N32 Roaming Interface Security Bypass</image:title>
            <image:caption>How SEPP N32-c capability negotiation can be downgraded to unencrypted N32-f, letting IPX-positioned adversaries intercept roaming SBI traffic in plaintext.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/5g-suci-null-scheme-supi-exposure/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/stingray-hero.webp</image:loc>
            <image:title>5G SUCI Null-Scheme Attacks: The IMSI Catcher Evolution</image:title>
            <image:caption>How misconfigured 5G SUCI null-scheme fallback negates subscriber identity concealment, letting rogue gNBs harvest SUPI in plaintext and revive IMSI-catcher tracking.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/10-telecom-threat-intelligence-resources-for-mno-soc/</loc>
        <lastmod>2026-05-18</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/telecom-threat-intel-hero.webp</image:loc>
            <image:title>10 Threat Intelligence Resources for MNO SOC Teams</image:title>
            <image:caption>TelcoSec-curated telecom threat intelligence resources for MNO SOC teams — 10 evaluated feeds covering SS7, Diameter, GTP anomaly detection, and subscriber tracking alerts.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/about/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/acceptable-use/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/apt41-double-dragon-telecom-billing-fraud/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/telecom-threat-intel-hero.webp</image:loc>
            <image:title>APT41 (Double Dragon): When State Espionage Meets Telecom Billing Fraud</image:title>
            <image:caption>APT41/Double Dragon runs Beijing-directed espionage and for-profit cybercrime from the same toolset — telecom OSS/BSS billing systems are the crossover point.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/articles/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/baseband-exploitation-modern-smartphones/</loc>
        <lastmod>2026-05-15</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/baseband-exploitation-hero.webp</image:loc>
            <image:title>Baseband Exploitation in Modern Smartphones</image:title>
            <image:caption>TelcoSec research on smartphone baseband exploitation: attack surfaces, Shannon/MediaTek firmware analysis, OTA fuzzing methods, and zero-click vulnerabilities.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/categories/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/contact/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/editorial-guidelines/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/gallium-soft-cell-telecom-apt/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/5g-architecture-hero.webp</image:loc>
            <image:title>GALLIUM (Operation Soft Cell): 7 Years Inside 10 Global Carriers</image:title>
            <image:caption>GALLIUM/Soft Cell pivoted from enterprise IT into telecom management infrastructure, harvesting CDR and AD data from 10 carriers across 30+ countries for 7+ years.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/glossary/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/imsi-catchers-and-rogue-base-stations/</loc>
        <lastmod>2026-05-15</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/stingray-hero.webp</image:loc>
            <image:title>IMSI Catchers and Rogue Base Stations</image:title>
            <image:caption>TelcoSec IMSI catcher and rogue base station analysis across 2G-5G: passive identity collection, MitM interception, downgrade attacks, and detection techniques.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/mission/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/mitre-fight-telecom-attack-vector-index/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/5g-architecture-hero.webp</image:loc>
            <image:title>MITRE FiGHT for Telecom: A Field Guide to 5G Attack Techniques</image:title>
            <image:caption>A field guide to the MITRE FiGHT framework&apos;s technique taxonomy across UE, RAN, O-RAN, 5G core, signaling, and physical telecom attack surfaces.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/mobile-network-evolution-3gpp-releases/</loc>
        <lastmod>2026-05-15</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/3gpp-evolution-hero.webp</image:loc>
            <image:title>Mobile Network Evolution: Understanding 3GPP Releases</image:title>
            <image:caption>TelcoSec guide to 3GPP security standards and cellular network evolution from 2G to 5G Advanced: security milestones, authentication, and hardening implications.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/muddywater-telecom-espionage/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/5g-architecture-hero.webp</image:loc>
            <image:title>MuddyWater: Iran&apos;s Long-Running Telecom Espionage Campaign</image:title>
            <image:caption>MuddyWater (MERCURY) is an Iranian MOIS-linked APT running ongoing spearphishing and VPN-exploitation espionage against Middle East telecom operators.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/privacy/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/projects/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/ran-wireless-security-assessment-methodology/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/ran-air-interface-hero.webp</image:loc>
            <image:title>RAN &amp; Wireless Security Assessment: A Practical Methodology</image:title>
            <image:caption>Hands-on RAN/wireless security assessment methodology: SDR lab setup, 2G-5G air interface capture, X2/Xn/fronthaul testing, and rogue BTS detection.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/salt-typhoon-telecom-apt/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/telecom-threat-intel-hero.webp</image:loc>
            <image:title>Salt Typhoon: Inside the Breach That Compromised US Carrier Wiretap Systems</image:title>
            <image:caption>How a PRC state-sponsored actor exploited an unpatched Cisco IOS-XE router (CVSS 10.0) to reach CALEA lawful-intercept systems inside US carriers.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/sandworm-telecom-destructive-attacks/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/5g-architecture-hero.webp</image:loc>
            <image:title>Sandworm: The GRU Unit Behind NotPetya Targets Telecom as a Weapon</image:title>
            <image:caption>How GRU Unit 74455&apos;s Sandworm turns telecom infrastructure into a disruption force multiplier — from Ukraine grid blackouts to NotPetya and beyond.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/services/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/setting-up-private-lte-5g-lab/</loc>
        <lastmod>2026-05-15</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/private-lab-hero.webp</image:loc>
            <image:title>Setting up a Private LTE/5G Environment</image:title>
            <image:caption>TelcoSec private 5G security research lab setup: USRP B210 hardware, Open5GS, srsRAN, Faraday cage requirements, and RF legal compliance step-by-step guide.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/signaling/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/sim-cloning-and-sim-swap-attacks/</loc>
        <lastmod>2026-05-15</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/sim-card-hero.webp</image:loc>
            <image:title>SIM Cloning and SIM Swap Attacks</image:title>
            <image:caption>TelcoSec SIM cloning and SIM swap attack analysis: physical cloning, SIMjacker remote exploitation, eSIM provisioning risks, and iSIM security architecture.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/sitemap/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/telco-vs-computer-networks/</loc>
        <lastmod>2026-05-15</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/telco-computer-convergence-hero.webp</image:loc>
            <image:title>Telco vs Computer Networks: Architecture &amp; Convergence</image:title>
            <image:caption>TelcoSec: telecom vs computer networks — architectural differences, 5G convergence security, and the cross-domain attack surfaces of modern telco.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/telecom-osint-reconnaissance-methodology/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/signaling-attack-vector.webp</image:loc>
            <image:title>Telecom OSINT: A Reconnaissance Methodology for Carrier Infrastructure</image:title>
            <image:caption>A 4-phase OSINT methodology for mapping carrier PLMN, SS7/Diameter, and 5G core infrastructure using only public sources — no active exploitation.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/telecom-penetration-testing-methodologies/</loc>
        <lastmod>2026-05-15</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/telecom-pentest-hero.webp</image:loc>
            <image:title>Methodology: Telecom Penetration Testing Lifecycle</image:title>
            <image:caption>TelcoSec telecom penetration testing lifecycle: SS7/Diameter exploitation, RAN attacks, 5G core vectors, and MITRE FiGHT framework mapping.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/telecom-threat-actor-tracking-framework/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/telecom-threat-intel-hero.webp</image:loc>
            <image:title>How We Track Telecom Threat Actors: MITRE ATT&amp;CK, FiGHT, and the Kill Chain</image:title>
            <image:caption>The combined ATT&amp;CK, MITRE FiGHT, and Lockheed Martin kill-chain framework TelcoSec uses to analyze and compare telecom-targeting APTs.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/terms/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/volt-typhoon-critical-infrastructure-prepositioning/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/5g-architecture-hero.webp</image:loc>
            <image:title>Volt Typhoon: Pre-Positioning for Wartime Disruption of US Telecoms</image:title>
            <image:caption>How Volt Typhoon used living-off-the-land techniques and hijacked SOHO routers to pre-position inside US telecom, energy, and water infrastructure.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/vulnerabilities-in-5g-sba/</loc>
        <lastmod>2026-05-15</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/sba-vulnerabilities-hero.webp</image:loc>
            <image:title>Vulnerabilities in the 5G SBA</image:title>
            <image:caption>TelcoSec exposes 5G SBA vulnerabilities: NRF poisoning, BOLA in telecom APIs, container breakout paths in Kubernetes-deployed 5G cores, and zero-trust defenses.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/vulnerabilities-of-the-ran-air-interface/</loc>
        <lastmod>2026-05-15</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/ran-air-interface-hero.webp</image:loc>
            <image:title>RAN Vulnerabilities: A Deep Dive into the Air Interface</image:title>
            <image:caption>TelcoSec RAN air interface security vulnerabilities: O-RAN exploitation, IMSI catcher deployment, NAS/RRC manipulation, and MEC attack surface analysis.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/why-telecom-teams-outgrow-generic-threat-intelligence/</loc>
        <lastmod>2026-05-18</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/why-telecom-outgrow-hero.webp</image:loc>
            <image:title>Why Telecoms Outgrow Generic Threat Intelligence</image:title>
            <image:caption>TelcoSec on telecom-specific threat intelligence: why MNO SOC teams outgrow generic feeds and a roadmap for evaluating curated telecom threat intelligence platforms.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/projects/3gpp/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/projects/academy/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/projects/blog/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/projects/calculators/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/projects/ctf/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/projects/library/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/projects/rdnsx/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/projects/tools/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/services/corporate-training/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/services/dedicated-labs/</loc>
    </url>
    <url>
        <loc>https://telcosec.net/signaling/camel-initialdp-call-redirect/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/signaling-attack-vector.webp</image:loc>
            <image:title>CAMEL InitialDP Call Redirection and Charging Fraud</image:title>
            <image:caption>TelcoSec CAMEL/CAP exploitation guide: rogue SCP injection via InitialDP for call redirect, covert interception, and CDR charging manipulation.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/signaling/diameter-clr-forced-deregistration/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/signaling-attack-vector.webp</image:loc>
            <image:title>Diameter S6a CLR Forced Subscriber Deregistration</image:title>
            <image:caption>How adversaries abuse the Diameter S6a Cancel-Location-Request to impersonate the HSS, force subscriber detach, and stage attach-hijack race conditions.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/signaling/diameter-ulr-location-disclosure/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/signaling-attack-vector.webp</image:loc>
            <image:title>Diameter S6a ULR Subscriber Location Disclosure</image:title>
            <image:caption>How attackers abuse Diameter S6a Update-Location-Request messages across IPX interconnects to track LTE subscribers and exfiltrate subscription profiles.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/signaling/diameter/</loc>
        <lastmod>2026-05-15</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/diameter-protocol-hero.webp</image:loc>
            <image:title>Diameter Protocol Security Analysis</image:title>
            <image:caption>TelcoSec Diameter protocol security in 4G/LTE roaming networks: DEA/DRA bypass, AVP manipulation, realm spoofing, and signaling firewall evasion techniques.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/signaling/gtp-c-tunnel-hijack-overbilling/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/signaling-attack-vector.webp</image:loc>
            <image:title>GTP-C Tunnel Hijacking and IMSI Overbilling Fraud</image:title>
            <image:caption>How forged GTP-C Create/Modify Bearer Request messages let GRX/IPX-positioned attackers hijack PDP/EPS tunnels and commit IMSI-attributed billing fraud.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/signaling/lightbasin-unc1945-telecom-apt/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/signaling-attack-vector.webp</image:loc>
            <image:title>LightBasin (UNC1945): The APT That Lived in Roaming Networks for 5 Years</image:title>
            <image:caption>How LightBasin (UNC1945) exploited GRX roaming trust and SS7/GTP protocols to persist inside 13 global carriers for five years without tripping EDR.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/signaling/liminal-panda-telecom-apt/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/signaling-attack-vector.webp</image:loc>
            <image:title>Liminal Panda: A 4-Year SS7 and Diameter Espionage Campaign</image:title>
            <image:caption>Liminal Panda ran a 4+ year China-nexus espionage campaign exploiting both SS7 and Diameter against telecom carriers in SE Asia and Africa.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/signaling/sip-register-identity-spoofing/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/signaling-attack-vector.webp</image:loc>
            <image:title>IMS SIP REGISTER Identity Spoofing in VoLTE</image:title>
            <image:caption>TelcoSec IMS SIP REGISTER spoofing analysis: how weak IMS-AKA authentication lets attackers hijack VoLTE calls, SMSoIP, and bypass OTP delivery.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/signaling/ss7-sms-interception/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/signaling-attack-vector.webp</image:loc>
            <image:title>SS7 MAP SMS Interception via UpdateLocation</image:title>
            <image:caption>How attackers abuse SS7 MAP UpdateLocation to hijack a subscriber&apos;s serving MSC/VLR, silently rerouting SMS and OTP/2FA codes to attacker infrastructure.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/signaling/ss7-sri-sm-geolocation/</loc>
        <lastmod>2026-07-04</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/signaling-attack-vector.webp</image:loc>
            <image:title>SS7 SRI-for-SM Subscriber Geolocation Attacks</image:title>
            <image:caption>How MAP SendRoutingInfoForSM is abused for real-time subscriber geolocation over SS7 interconnects, with GSMA FS.11 mitigations and defense controls.</image:caption>
        </image:image>
    </url>
    <url>
        <loc>https://telcosec.net/signaling/ss7/</loc>
        <lastmod>2026-05-15</lastmod>
        <image:image>
            <image:loc>https://telcosec.net/images/articles/signaling-attack-vector.webp</image:loc>
            <image:title>SS7 Location Tracking Vulnerabilities</image:title>
            <image:caption>TelcoSec SS7 MAP exploitation guide: subscriber tracking, SMS interception, and call redirection via SendRoutingInfo and ProvideSubscriberInfo attacks.</image:caption>
        </image:image>
    </url>
</urlset>
<!-- XML Sitemap generated by @nuxtjs/sitemap v7.6.0 at 2026-07-26T22:27:17.980Z -->