Sign in

P1 Security

@p1security.bsky.social
16 followers 2 following 61 posts

Global experts in mobile network security. We help operators and governments secure 2G to 5G networks through offensive security testing, monitoring solutions, and specialized telecom security training.

PostsRepliesMedia
P1 Security @p1security.bsky.social · 08/10/2026
QCSuper has a sequel: DiagNG, a new GUI-based open source tool for Linux producing PCAP/GSMTAP captures from Qualcomm Snapdragon basebands for Wireshark, NR/5G included. Blog: www.p1sec.com/blog/present... Code: github.com/P1sec/DiagNG
010
P1 Security @p1security.bsky.social · 01/10/2026
P1 Security will be at India Mobile Congress 2026, 7 to 10 October, Yashobhoomi, New Delhi. Want to talk signalling, interconnect or 5G core security? Book a slot with our team: www.p1sec.com/contact #IMC2026 #TelecomSecurity
P1 Security branded telecom security visual
000
P1 Security @p1security.bsky.social · 29/09/2026
The AMF trusts the device (N1), the gNB (N2) and the 5G core (SBI) in three different ways. Our AMF Under Pressure replay walks the attack paths on each. watch.getcontrast.io/register/p1-se…
P1 Security branded telecom security visual
001
P1 Security @p1security.bsky.social · 24/09/2026
Most O-RAN interface protections are mandatory to support and optional to enable. The gap between supported and switched on is a fixable deployment question. New O-RAN security whitepaper: www.p1sec.com/white-paper/o-ran-sec… #ORAN #TelecomSecurity
P1 Security branded telecom security visual
010
P1 Security @p1security.bsky.social · 22/09/2026
A pentest describes your network on the day it was tested. Mobile networks keep changing: new elements, new interconnects, new releases, configuration drift. Assessment belongs on a cycle, paired with continuous visibility. www.p1sec.com/ugtmns #TelecomSecurity
P1 Security branded telecom security visual
000
P1 Security @p1security.bsky.social · 17/09/2026
Interconnect filtering decides which messages may reach the HLR or HSS. It says nothing about how the element answers a malformed one. Our research on assessing the subscriber database itself: www.p1sec.com/white-paper/hacking-t… #TelecomSecurity
P1 Security branded telecom security visual
010
P1 Security @p1security.bsky.social · 15/09/2026
191 articles on mobile network security, filed into 14 chapters. SS7 and Diameter through 5G SBA, O-RAN, IMS, roaming, detection and regulation. Enter by attack surface, by role, or by generation. No gate, no form, no download. www.p1sec.com/ugtmns
P1 Security branded telecom security visual
010
P1 Security @p1security.bsky.social · 10/09/2026
A CVE feed says a vulnerability exists. It does not say what it does inside a mobile network. The P1 VKB: 2,200+ telecom vulnerabilities from SS7 to 5G, with impact and remediation context. www.p1sec.com/product/vulnerability… #TelecomSecurity
P1 Security branded telecom security visual
010
P1 Security @p1security.bsky.social · 08/09/2026
11 September 2026: the CRA reporting clock starts. Actively exploited vulnerabilities in products with digital elements, early warning in 24 hours. Telecom equipment included. www.p1sec.com/services/supply-chain… #TelecomSecurity
P1 Security branded telecom security visual
000
P1 Security @p1security.bsky.social · 21/08/2026
The most damaging findings in 5G core pentests are rarely exotic: default credentials, reused root SSH keys, SSRF that turns the SCP into an internal scanner. New whitepaper on the five classes we find most. www.p1sec.com/white-paper/... #5G #TelecomSecurity
011
P1 Security @p1security.bsky.social · 17/08/2026
P1 Security is at LEAP 2026 in Riyadh, 31 August to 3 September. Vikas Sharma is there taking meetings on what the signalling layer exposes: SS7, Diameter, GTP, IMS, 5G core, RAN. contact@p1sec.com
P1 Security branded telecom security visual
000
P1 Security @p1security.bsky.social · 28/07/2026
Ask an operator where its attack surface is and the answer depends who is in the room: SS7, GTP, IMS, RAN. TelcoASM puts them in one matrix so you can see where exposure concentrates. Self-assessment, no scan. telcoasm.p1sec.com #TelecomSecurity
P1 Security branded telecom security visual
000
P1 Security @p1security.bsky.social · 23/07/2026
Smishing isn't an inbox problem. The fraud lives in signalling: origins spoofed over SS7, A2P grey routes past the SMSC. Content filters can't see that. www.p1sec.com/blog/sms-based-attack… #SS7 #Smishing
P1 Security branded telecom security visual
000
P1 Security @p1security.bsky.social · 22/07/2026
Three ways into the AMF, each trusting a different neighbour: N1 (device/NAS), N2 (radio/NGAP), SBI (peer NFs/HTTP2). Free webinar, Wed 29 Jul 15:00 CET: watch.getcontrast.io/register/p1-se…
P1 Security branded telecom security visual
010
P1 Security @p1security.bsky.social · 21/07/2026
EECC, NIS2, ENISA, the EU 5G Toolbox: Europe's telecom security rules overlap and evolve. Our whitepaper maps how they fit together, for operators and regulators. www.p1sec.com/white-paper/towards-h… #NIS2 #Compliance
P1 Security branded telecom security visual
000
P1 Security @p1security.bsky.social · 16/07/2026
Deploy private 5G/4G or CBRS and you're now a mobile network operator: a core, RAN, SIMs and signaling to defend, often with no telecom security team. Slice isolation and exposed OAM are risks IT scanners miss. www.p1sec.com/services/private-5g-s…
P1 Security branded telecom security visual
001
P1 Security @p1security.bsky.social · 15/07/2026
5G standalone's core speaks HTTP/2, JSON and REST APIs over the SBI, not SS7 or Diameter. So it inherits web-app risk: broken authZ between NFs, broad tokens, injection, weak TLS. An API problem, not just signaling. securityhub.p1sec.com/guide
P1 Security branded telecom security visual
000
P1 Security @p1security.bsky.social · 09/07/2026
Telecom security training is easier to judge when someone walks you through it. Want a live look at P1 Academy (SS7 to 5G, hands-on labs)? We will give you a 30-min walkthrough. Email contact@p1sec.com or see online-training.p1sec.com #Training
P1 Security branded telecom security visual
000
P1 Security @p1security.bsky.social · 07/07/2026
Voice runs on SIP now. VoLTE, VoWiFi and VoNR inherit IP-style risks: spoofing, malformed messages, weak transport. SBCs miss it. Why SIP IDS matters: www.p1sec.com/blog/international-ip… #TelecomSecurity #IMS
P1 Security branded telecom security visual
000
P1 Security @p1security.bsky.social · 01/07/2026
Your firewall sees packets, not a MAP operation or a Diameter command, so signalling attacks, fraud and GTP-C misuse slip through for months. Telecom IDS is the missing layer. How PTM catches what firewalls miss: www.p1sec.com/product/intrusion-det…
P1 Security branded telecom security visual
000
P1 Security @p1security.bsky.social · 01/07/2026
GTP-C sets up sessions, GTP-U carries the data, and both cross the same roaming links. That trust gets abused for DoS, overbilling and data disclosure. Common GTP attacks and defences: www.p1sec.com/blog/common-attacks-o…
P1 Security branded telecom security visual
000
P1 Security @p1security.bsky.social · 15/04/2026
APTs target telecom cores for tracking & intel. Recording: watch.getcontrast.io/register/p1-... #5GSecurity #TelecomSecurity
000
P1 Security @p1security.bsky.social · 08/04/2026
Cyber conflict has a long memory. In this clip, Hamid Kashfi touches on how methods evolve and resurface over time. Replay: watch.getcontrast.io/register/p1-... #telcosec #telecomsecurity
010
P1 Security @p1security.bsky.social · 02/04/2026
Where are we actually exposed? TelcoASM helps telecom teams quickly visualize network risk exposure and benchmark it in minutes. Free: telcoasm.p1sec.com
000
P1 Security @p1security.bsky.social · 01/04/2026
At a radio site, they feared metal theft. The bigger risk was RAN to core compromise. Watch: watch.getcontrast.io/register/p1-security-physical-to-5g-core-compromise
010
P1 Security @p1security.bsky.social · 18/03/2026
Next week: TelcoSec Talk #2 with Philippe Langlois and Hamid Kashfi on the Iran cyber threat landscape, using ApexThreats. Register: watch.getcontrast.io/register/p1-... #CyberThreatIntelligence #TelecomSecurity #ThreatIntelligence #CyberSecurity #APT #Iran #TelcoSec #P1Security
000
P1 Security @p1security.bsky.social · 11/03/2026
MWC is done. The badge is off. The conversations are not. What stood out most? Telecom security is a real operational priority. If we missed you at MWC, let’s continue the discussion: contact@p1sec.com #MWC26 #TelecomSecurity #5GSecurity #CyberSecurity #P1Security
000
P1 Security @p1security.bsky.social · 03/03/2026
P1 Security will be part of the Online [un]prompted conference this week. Philippe Langlois, our founder and CEO, will moderate a lunchtime Zoom chat session titled: Defense and Offense of Critical Infrastructure in the Age of AI Contact: contact@p1sec.com #AISecurity
010
P1 Security @p1security.bsky.social · 26/02/2026
“Open it temporarily so it works” is how 5G networks get permanently exposed. “No firewall matrix, no traffic flow visibility, so people open the network until things work… then leave it like it is.” Recording: watch.getcontrast.io/register/p1-... #5GSecurity #TelecomSecurity #ZeroTrust
010
P1 Security @p1security.bsky.social · 12/02/2026
SMS blasters = high volume spam or fraud. At #MWC2026 in Barcelona, we’re bringing a fun SMS Blaster Detector experiment. Let’s meet: www.p1sec.com/mwc-2026
110
P1 Security @p1security.bsky.social · 03/02/2026
Physical access is not “local only”. In many environments it can become a network foothold, then pivot via the management plane, weak segmentation, insecure remote access, or stolen creds until the 5G core is reachable. Register: watch.getcontrast.io/register/p1-...
000
P1 Security @p1security.bsky.social · 20/01/2026
How does physical exposure translate into risk for mobile critical infrastructure, and how can teams reduce it without slowing operations down? Physical to 5G Core Compromise Red team lessons learned + practical takeaways Thu 5 Feb 2026, 14:00 CET Register: watch.getcontrast.io/register/p1-...
000
P1 Security @p1security.bsky.social · 04/12/2025
We released the Telco Attack Surface Matrix to help teams visualise exposure across RAN, Core, IMS, signalling and more. Try it and share your feedback so we can improve it. telcoasm.p1sec.com #telcosec
Risk Matrix Overview showing exposure levels across telecom domains. Rows include Management Plane, Signalling Plane, Supply Chain, Virtualization Stack, and Monitoring and Analysis. Columns include 4G RAN, 5G RAN, 4G Packet Core, 5G Packet Core, IMS and VoLTE Core, and Legacy 2G and 3G. Cells display color coded risk levels such as Low, Moderate, High, and Critical, with some areas marked as Unknown. The matrix highlights higher exposure in Legacy 2G and 3G as well as in core and signalling domains.
000
P1 Security @p1security.bsky.social · 13/11/2025
Weak passwords still break 5G in 2025. No zero days needed. If your access controls rely on bad defaults, start fixing them. Replay 👉 watch.getcontrast.io/register/p1-...
000
P1 Security @p1security.bsky.social · 29/10/2025
In 5G, you don’t lose the network when someone gets in you lose it when you realize there was never proper control in the first place. Full replay: watch.getcontrast.io/register/p1-... #5GSecurity #TelecomSecurity #CoreNetworkSecurity #5GPentest
010
P1 Security @p1security.bsky.social · 24/10/2025
Wednesday we held our webinar “Top 5G Security Vulnerabilities: Insights from P1 Security Pentest Activities.” Thanks for joining. As promised, here’s the recording — watch and share with your team: watch.getcontrast.io/register/p1-... #5GSecurity #Cybersecurity #Telecom
030
P1 Security @p1security.bsky.social · 14/10/2025
LTE’s All-IP design expands the attack surface—legacy SS7 meets Diameter, S1, X2 & GTP risks. Read real flaws & mitigations in the *LTE Pwnage* ebook: www.p1sec.com/white-paper/... #LTE #CyberSecurity #P1Security
010
P1 Security @p1security.bsky.social · 09/10/2025
Everyone talks about resilience. We focus on the foundation. Strong passwords mean nothing if your 5G core is exploitable. Join 5G Penetration Tester El Mehdi Regragui as he reveals real pentest findings across signaling & OAM. 🔗 watch.getcontrast.io/register/p1-... #5GSecurity
000
P1 Security @p1security.bsky.social · 23/09/2025
🌏 Our Global Account Manager, Thilip Suppaiah, is at #DNSKualaLumpur representing P1 Security. Attending? Reach out: contact@p1sec.com #DigitalNationSummit #GSMA
000
P1 Security @p1security.bsky.social · 27/08/2025
5G was built to be “secure by design.” In practice, many deployments still expose Diameter, GTP & SBA interfaces attackers can abuse. Full replay 👉 watch.getcontrast.io/register/p1-... Is your network secure in practice? Book a call 👉 calendly.com/yves-mangamb... #5G #TelecomSecurity #P1Security
000
P1 Security @p1security.bsky.social · 29/07/2025
🎥 O-RAN: Disaggregation = Bigger Attack Surface More flexibility means more interfaces — and more exposure. In this clip, we break down the real risks we see in the field. 📩 Rolling out O-RAN? Let’s talk: www.p1sec.com/contact #ORAN #5GSecurity #TelcoSec
000
P1 Security @p1security.bsky.social · 17/07/2025
O-RAN isn’t just open — it’s a full shift in how mobile networks are built. In the intro to our webinar, we lay the groundwork: what O-RAN is, and why it introduces both flexibility and risk. 🎥 Watch the full session → app.getcontrast.io/register/p1-... #ORAN #5GSecurity #TelcoSec
000
P1 Security @p1security.bsky.social · 16/07/2025
Telecom networks are under fire—attackers exploit core weaknesses, silently and persistently. 📅 Sept 10 | 🕒 15:00–16:00 CET 🎙️ Valeri Dragoev, P1 Security 📡 Real attack traces via PTM 🔗 app.getcontrast.io/register/p1-... #TelecomSecurity #5GSecurity #PTM #CyberSecurity #SignalingSecurity
010
P1 Security @p1security.bsky.social · 10/07/2025
O-RAN’s flexibility comes at a cost: more interfaces = more attack surfaces. In our latest webinar, we dive into how openness and vendor diversity reshape both deployment and the threat landscape. 🔗 Watch the recording: app.getcontrast.io/register/p1-...
010
P1 Security @p1security.bsky.social · 08/07/2025
Is reverse engineering legal? It depends where — and how — you do it. 📘 Our whitepaper breaks down laws in EU, US, Japan & China. Get clarity on decompilation, fair use & interoperability rules. 🔗 www.p1sec.com/white-paper/... #ReverseEngineering #CyberLaw
010
P1 Security @p1security.bsky.social · 03/07/2025
This short demo showcases an attack on the O-FH towards an emulated open-source O-RU, where a specially crafted malicious O-FH C-Plane message is sent towards the O-RU and results in a crash. Join us today at 16:00 CET for a live deep dive. 🔗 app.getcontrast.io/register/p1-... #ORAN #TelcoSec
000
P1 Security @p1security.bsky.social · 27/06/2025
Thank you to GSMA and BT Group for welcoming us in beautiful Birmingham for the FASG #32 this week! We enjoyed 3 days of fascinating discussions around various topics. It was great connecting with telecom security professionals from across the industry to address emerging threats in mobile networks.
000
P1 Security @p1security.bsky.social · 23/06/2025
🎤 Catch us at #TelcoSecDay tomorrow at #Troopers in Heidelberg! Jimmy Billaud will present: “Security risk of International IP-based SIP network and effectiveness of SIP IDS” Come say hi! #VoIP #TelecomSecurity #MobileNetworkSecurity #troopers25
010
P1 Security @p1security.bsky.social · 06/06/2025
🚨 CVE-2025-32433 lets attackers run remote code on Erlang/OTP SSH servers before login. Telcos & IoT infra exposed. Lateral movement, RCE, full compromise. Fix it fast. Full breakdown: app.getcontrast.io/register/p1-... #P1Security #RCE #Telcosec #Erlang #SSH #VulnerabilityIntelligence
000