AI agents uncover 84 5G core security vulnerabilities in telecom networks
Researchers at Nanyang Technological University utilized the iFinder multi-agent AI system to identify 84 previously unknown vulnerabilities across several 4G and 5G core network implementations. The findings, which include a critical session hijacking risk, underscore the urgent need for zero-trust security architectures in cloud-native telecom environments.
Key Takeaways
- The iFinder AI system discovered 84 flaws across seven different 4G and 5G core implementations, with 83 confirmed by researchers.
- CVE-2026-8233 enables session hijacking, allowing attackers to redirect subscriber uplink traffic in commercial 5G deployments.
- Vulnerabilities were primarily concentrated in the User Plane Function (UPF) and Serving Gateway components.
- The report calls for zero-trust architectures to replace current trust assumptions in cloud-native telecom environments.
Why It Matters
The discovery of dozens of flaws via AI agents signals a shift in how infrastructure security must be managed as mobile cores move to cloud-native environments. For streaming providers and edge compute operators, these vulnerabilities in the User Plane Function represent a direct threat to data integrity and session stability. As internal interfaces like N4 and GTP-C become viable attack surfaces, the industry must move away from perimeter-based defense toward strict mutual authentication and message validation. This development suggests that automated exploitation by adversaries is now a practical risk rather than a theoretical one. Watch for telecom vendors to accelerate patch cycles and integrate session-state validation as a standard engineering requirement.
Additional Context
Nanyang Technological University's iFinder system represents a growing wave of AI-assisted security research targeting telecom infrastructure. In March 2025, the GSMA published updated security guidelines for 5G core networks emphasizing the need for automated threat detection across service-based interfaces, noting that cloud-native architectures expand the attack surface beyond traditional perimeter defenses. The iFinder findings align with broader industry concern that 5G's microservices-based design introduces inter-service communication risks that legacy security tools were not built to address. Ericsson's 2025 Security Report identified that 67% of telecom operators had experienced at least one security incident involving core network functions in the preceding 12 months, reinforcing the urgency of the NTU research.
Regulatory pressure on 5G core security is intensifying across multiple jurisdictions. The European Union Agency for Cybersecurity (ENISA) released its 5G Security Toolbox update in January 2025, recommending that member states mandate continuous vulnerability assessment for cloud-native network functions, a requirement that would directly benefit AI-driven scanning approaches like iFinder. In the United States, the FCC's Cybersecurity and Infrastructure Security Agency joint advisory from April 2025 warned that state-sponsored actors were actively probing 5G core interfaces for exploitation, citing GTP protocol weaknesses that overlap with several of the vulnerability classes NTU identified. These regulatory moves suggest that operators may soon face compliance obligations requiring automated, continuous security testing of their core network implementations.
The technical implications of AI-driven vulnerability discovery extend beyond telecom into adjacent infrastructure domains. A 2025 study from the University of Cambridge demonstrated that large language model agents could identify zero-day vulnerabilities in open-source network protocol implementations at a rate 4.3 times faster than traditional fuzzing tools, though the researchers noted that false positive rates remained higher than manual analysis. For streaming and edge compute operators, the NTU findings carry direct relevance because the 3GPP Release 18 specifications introduced new User Plane Function interfaces that expand the potential attack surface for content delivery and edge processing workloads, including those used by video platforms for low-latency distribution. The convergence of AI-assisted offensive and defensive security tools suggests that patch cycles for telecom infrastructure will need to compress significantly, with implications for any service that depends on mobile network integrity for content delivery.
Read full article at fiercewireless.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source