P1 Security @p1security.bsky.social · 08/10/2026QCSuper has a sequel: DiagNG, a new GUI-based open source tool for Linux producing PCAP/GSMTAP captures from Qualcomm Snapdragon basebands for Wireshark, NR/5G included. Blog: www.p1sec.com/blog/present... Code: github.com/P1sec/DiagNG 010
P1 Security @p1security.bsky.social · 01/10/2026P1 Security will be at India Mobile Congress 2026, 7 to 10 October, Yashobhoomi, New Delhi. Want to talk signalling, interconnect or 5G core security? Book a slot with our team: www.p1sec.com/contact #IMC2026 #TelecomSecurity 000
P1 Security @p1security.bsky.social · 29/09/2026The AMF trusts the device (N1), the gNB (N2) and the 5G core (SBI) in three different ways. Our AMF Under Pressure replay walks the attack paths on each. watch.getcontrast.io/register/p1-se… 001
P1 Security @p1security.bsky.social · 24/09/2026Most O-RAN interface protections are mandatory to support and optional to enable. The gap between supported and switched on is a fixable deployment question. New O-RAN security whitepaper: www.p1sec.com/white-paper/o-ran-sec… #ORAN #TelecomSecurity 010
P1 Security @p1security.bsky.social · 22/09/2026A pentest describes your network on the day it was tested. Mobile networks keep changing: new elements, new interconnects, new releases, configuration drift. Assessment belongs on a cycle, paired with continuous visibility. www.p1sec.com/ugtmns #TelecomSecurity 000
P1 Security @p1security.bsky.social · 17/09/2026Interconnect filtering decides which messages may reach the HLR or HSS. It says nothing about how the element answers a malformed one. Our research on assessing the subscriber database itself: www.p1sec.com/white-paper/hacking-t… #TelecomSecurity 010
P1 Security @p1security.bsky.social · 15/09/2026191 articles on mobile network security, filed into 14 chapters. SS7 and Diameter through 5G SBA, O-RAN, IMS, roaming, detection and regulation. Enter by attack surface, by role, or by generation. No gate, no form, no download. www.p1sec.com/ugtmns 010
P1 Security @p1security.bsky.social · 10/09/2026A CVE feed says a vulnerability exists. It does not say what it does inside a mobile network. The P1 VKB: 2,200+ telecom vulnerabilities from SS7 to 5G, with impact and remediation context. www.p1sec.com/product/vulnerability… #TelecomSecurity 010
P1 Security @p1security.bsky.social · 08/09/202611 September 2026: the CRA reporting clock starts. Actively exploited vulnerabilities in products with digital elements, early warning in 24 hours. Telecom equipment included. www.p1sec.com/services/supply-chain… #TelecomSecurity 000
P1 Security @p1security.bsky.social · 21/08/2026The most damaging findings in 5G core pentests are rarely exotic: default credentials, reused root SSH keys, SSRF that turns the SCP into an internal scanner. New whitepaper on the five classes we find most. www.p1sec.com/white-paper/... #5G #TelecomSecurity 011
P1 Security @p1security.bsky.social · 17/08/2026P1 Security is at LEAP 2026 in Riyadh, 31 August to 3 September. Vikas Sharma is there taking meetings on what the signalling layer exposes: SS7, Diameter, GTP, IMS, 5G core, RAN. contact@p1sec.com 000
P1 Security @p1security.bsky.social · 28/07/2026Ask an operator where its attack surface is and the answer depends who is in the room: SS7, GTP, IMS, RAN. TelcoASM puts them in one matrix so you can see where exposure concentrates. Self-assessment, no scan. telcoasm.p1sec.com #TelecomSecurity 000
P1 Security @p1security.bsky.social · 23/07/2026Smishing isn't an inbox problem. The fraud lives in signalling: origins spoofed over SS7, A2P grey routes past the SMSC. Content filters can't see that. www.p1sec.com/blog/sms-based-attack… #SS7 #Smishing 000
P1 Security @p1security.bsky.social · 22/07/2026Three ways into the AMF, each trusting a different neighbour: N1 (device/NAS), N2 (radio/NGAP), SBI (peer NFs/HTTP2). Free webinar, Wed 29 Jul 15:00 CET: watch.getcontrast.io/register/p1-se… 010
P1 Security @p1security.bsky.social · 21/07/2026EECC, NIS2, ENISA, the EU 5G Toolbox: Europe's telecom security rules overlap and evolve. Our whitepaper maps how they fit together, for operators and regulators. www.p1sec.com/white-paper/towards-h… #NIS2 #Compliance 000
P1 Security @p1security.bsky.social · 16/07/2026Deploy private 5G/4G or CBRS and you're now a mobile network operator: a core, RAN, SIMs and signaling to defend, often with no telecom security team. Slice isolation and exposed OAM are risks IT scanners miss. www.p1sec.com/services/private-5g-s… 001
P1 Security @p1security.bsky.social · 15/07/20265G standalone's core speaks HTTP/2, JSON and REST APIs over the SBI, not SS7 or Diameter. So it inherits web-app risk: broken authZ between NFs, broad tokens, injection, weak TLS. An API problem, not just signaling. securityhub.p1sec.com/guide 000
P1 Security @p1security.bsky.social · 09/07/2026Telecom security training is easier to judge when someone walks you through it. Want a live look at P1 Academy (SS7 to 5G, hands-on labs)? We will give you a 30-min walkthrough. Email contact@p1sec.com or see online-training.p1sec.com #Training 000
P1 Security @p1security.bsky.social · 07/07/2026Voice runs on SIP now. VoLTE, VoWiFi and VoNR inherit IP-style risks: spoofing, malformed messages, weak transport. SBCs miss it. Why SIP IDS matters: www.p1sec.com/blog/international-ip… #TelecomSecurity #IMS 000
P1 Security @p1security.bsky.social · 01/07/2026Your firewall sees packets, not a MAP operation or a Diameter command, so signalling attacks, fraud and GTP-C misuse slip through for months. Telecom IDS is the missing layer. How PTM catches what firewalls miss: www.p1sec.com/product/intrusion-det… 000
P1 Security @p1security.bsky.social · 01/07/2026GTP-C sets up sessions, GTP-U carries the data, and both cross the same roaming links. That trust gets abused for DoS, overbilling and data disclosure. Common GTP attacks and defences: www.p1sec.com/blog/common-attacks-o… 000
P1 Security @p1security.bsky.social · 15/04/2026APTs target telecom cores for tracking & intel. Recording: watch.getcontrast.io/register/p1-... #5GSecurity #TelecomSecurity 000
P1 Security @p1security.bsky.social · 08/04/2026Cyber conflict has a long memory. In this clip, Hamid Kashfi touches on how methods evolve and resurface over time. Replay: watch.getcontrast.io/register/p1-... #telcosec #telecomsecurity 010
P1 Security @p1security.bsky.social · 02/04/2026Where are we actually exposed? TelcoASM helps telecom teams quickly visualize network risk exposure and benchmark it in minutes. Free: telcoasm.p1sec.com 000
P1 Security @p1security.bsky.social · 01/04/2026At a radio site, they feared metal theft. The bigger risk was RAN to core compromise. Watch: watch.getcontrast.io/register/p1-security-physical-to-5g-core-compromise 010
P1 Security @p1security.bsky.social · 18/03/2026Next week: TelcoSec Talk #2 with Philippe Langlois and Hamid Kashfi on the Iran cyber threat landscape, using ApexThreats. Register: watch.getcontrast.io/register/p1-... #CyberThreatIntelligence #TelecomSecurity #ThreatIntelligence #CyberSecurity #APT #Iran #TelcoSec #P1Security 000
P1 Security @p1security.bsky.social · 11/03/2026MWC is done. The badge is off. The conversations are not. What stood out most? Telecom security is a real operational priority. If we missed you at MWC, let’s continue the discussion: contact@p1sec.com #MWC26 #TelecomSecurity #5GSecurity #CyberSecurity #P1Security 000
P1 Security @p1security.bsky.social · 03/03/2026P1 Security will be part of the Online [un]prompted conference this week. Philippe Langlois, our founder and CEO, will moderate a lunchtime Zoom chat session titled: Defense and Offense of Critical Infrastructure in the Age of AI Contact: contact@p1sec.com #AISecurity 010
P1 Security @p1security.bsky.social · 26/02/2026“Open it temporarily so it works” is how 5G networks get permanently exposed. “No firewall matrix, no traffic flow visibility, so people open the network until things work… then leave it like it is.” Recording: watch.getcontrast.io/register/p1-... #5GSecurity #TelecomSecurity #ZeroTrust 010
P1 Security @p1security.bsky.social · 12/02/2026SMS blasters = high volume spam or fraud. At #MWC2026 in Barcelona, we’re bringing a fun SMS Blaster Detector experiment. Let’s meet: www.p1sec.com/mwc-2026 110
P1 Security @p1security.bsky.social · 03/02/2026Physical access is not “local only”. In many environments it can become a network foothold, then pivot via the management plane, weak segmentation, insecure remote access, or stolen creds until the 5G core is reachable. Register: watch.getcontrast.io/register/p1-... 000
P1 Security @p1security.bsky.social · 20/01/2026How does physical exposure translate into risk for mobile critical infrastructure, and how can teams reduce it without slowing operations down? Physical to 5G Core Compromise Red team lessons learned + practical takeaways Thu 5 Feb 2026, 14:00 CET Register: watch.getcontrast.io/register/p1-... 000
P1 Security @p1security.bsky.social · 04/12/2025We released the Telco Attack Surface Matrix to help teams visualise exposure across RAN, Core, IMS, signalling and more. Try it and share your feedback so we can improve it. telcoasm.p1sec.com #telcosec 000
P1 Security @p1security.bsky.social · 13/11/2025Weak passwords still break 5G in 2025. No zero days needed. If your access controls rely on bad defaults, start fixing them. Replay 👉 watch.getcontrast.io/register/p1-... 000
P1 Security @p1security.bsky.social · 29/10/2025In 5G, you don’t lose the network when someone gets in you lose it when you realize there was never proper control in the first place. Full replay: watch.getcontrast.io/register/p1-... #5GSecurity #TelecomSecurity #CoreNetworkSecurity #5GPentest 010
P1 Security @p1security.bsky.social · 24/10/2025Wednesday we held our webinar “Top 5G Security Vulnerabilities: Insights from P1 Security Pentest Activities.” Thanks for joining. As promised, here’s the recording — watch and share with your team: watch.getcontrast.io/register/p1-... #5GSecurity #Cybersecurity #Telecom 030
P1 Security @p1security.bsky.social · 14/10/2025LTE’s All-IP design expands the attack surface—legacy SS7 meets Diameter, S1, X2 & GTP risks. Read real flaws & mitigations in the *LTE Pwnage* ebook: www.p1sec.com/white-paper/... #LTE #CyberSecurity #P1Security 010
P1 Security @p1security.bsky.social · 09/10/2025Everyone talks about resilience. We focus on the foundation. Strong passwords mean nothing if your 5G core is exploitable. Join 5G Penetration Tester El Mehdi Regragui as he reveals real pentest findings across signaling & OAM. 🔗 watch.getcontrast.io/register/p1-... #5GSecurity 000
P1 Security @p1security.bsky.social · 23/09/2025🌏 Our Global Account Manager, Thilip Suppaiah, is at #DNSKualaLumpur representing P1 Security. Attending? Reach out: contact@p1sec.com #DigitalNationSummit #GSMA 000
P1 Security @p1security.bsky.social · 27/08/20255G was built to be “secure by design.” In practice, many deployments still expose Diameter, GTP & SBA interfaces attackers can abuse. Full replay 👉 watch.getcontrast.io/register/p1-... Is your network secure in practice? Book a call 👉 calendly.com/yves-mangamb... #5G #TelecomSecurity #P1Security 000
P1 Security @p1security.bsky.social · 29/07/2025🎥 O-RAN: Disaggregation = Bigger Attack Surface More flexibility means more interfaces — and more exposure. In this clip, we break down the real risks we see in the field. 📩 Rolling out O-RAN? Let’s talk: www.p1sec.com/contact #ORAN #5GSecurity #TelcoSec 000
P1 Security @p1security.bsky.social · 17/07/2025O-RAN isn’t just open — it’s a full shift in how mobile networks are built. In the intro to our webinar, we lay the groundwork: what O-RAN is, and why it introduces both flexibility and risk. 🎥 Watch the full session → app.getcontrast.io/register/p1-... #ORAN #5GSecurity #TelcoSec 000
P1 Security @p1security.bsky.social · 16/07/2025Telecom networks are under fire—attackers exploit core weaknesses, silently and persistently. 📅 Sept 10 | 🕒 15:00–16:00 CET 🎙️ Valeri Dragoev, P1 Security 📡 Real attack traces via PTM 🔗 app.getcontrast.io/register/p1-... #TelecomSecurity #5GSecurity #PTM #CyberSecurity #SignalingSecurity 010
P1 Security @p1security.bsky.social · 10/07/2025O-RAN’s flexibility comes at a cost: more interfaces = more attack surfaces. In our latest webinar, we dive into how openness and vendor diversity reshape both deployment and the threat landscape. 🔗 Watch the recording: app.getcontrast.io/register/p1-... 010
P1 Security @p1security.bsky.social · 08/07/2025Is reverse engineering legal? It depends where — and how — you do it. 📘 Our whitepaper breaks down laws in EU, US, Japan & China. Get clarity on decompilation, fair use & interoperability rules. 🔗 www.p1sec.com/white-paper/... #ReverseEngineering #CyberLaw 010
P1 Security @p1security.bsky.social · 03/07/2025This short demo showcases an attack on the O-FH towards an emulated open-source O-RU, where a specially crafted malicious O-FH C-Plane message is sent towards the O-RU and results in a crash. Join us today at 16:00 CET for a live deep dive. 🔗 app.getcontrast.io/register/p1-... #ORAN #TelcoSec 000
P1 Security @p1security.bsky.social · 27/06/2025Thank you to GSMA and BT Group for welcoming us in beautiful Birmingham for the FASG #32 this week! We enjoyed 3 days of fascinating discussions around various topics. It was great connecting with telecom security professionals from across the industry to address emerging threats in mobile networks. 000
P1 Security @p1security.bsky.social · 23/06/2025🎤 Catch us at #TelcoSecDay tomorrow at #Troopers in Heidelberg! Jimmy Billaud will present: “Security risk of International IP-based SIP network and effectiveness of SIP IDS” Come say hi! #VoIP #TelecomSecurity #MobileNetworkSecurity #troopers25 010
P1 Security @p1security.bsky.social · 06/06/2025🚨 CVE-2025-32433 lets attackers run remote code on Erlang/OTP SSH servers before login. Telcos & IoT infra exposed. Lateral movement, RCE, full compromise. Fix it fast. Full breakdown: app.getcontrast.io/register/p1-... #P1Security #RCE #Telcosec #Erlang #SSH #VulnerabilityIntelligence 000