Return to Threats

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

thehackernews.com 2026-07-31 AI supply chain Critical

What Happened

An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network session. The findings have been released by a group of researchers from Singapore's Nanyang Technological University

Why It Matters

The article reports an academic study that used the iFinder multi-agent system to uncover 84 previously unknown vulnerabilities in 4G/5G core implementations (Open5GS, free5GC, OpenAirInterface, SD-Core, eUPF) across GTP-C and PFCP signaling, largely caused by implicit trust and missing validation between core network components.[1][5] Researchers further demonstrated a real-world session hijacking attack on commercial 5G cores via malicious PFCP Session Modification requests that can redirect user traffic, as well as denial-of-service conditions.[5] From a RealGround perspective, these findings highlight systemic software supply-chain and architecture risks in telecom-core software—especially open-source components and cloud-native deployments—that can propagate into AI-powered network automation, observability, and orchestration layers. Organizations should treat 4G/5G core stacks and associated AI-based management planes as critical supply-chain elements: maintain SBOMs, continuously assess CVE exposure in signaling protocols, and integrate these core vulnerabilities into broader AI Security Readiness and dependency risk reviews.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/07/researchers-report-84-flaws-in-4g-and.html

Talk to AI CISO