Originally published on satyamrastogi.com
KDDI's breach via zero-day in third-party email system demonstrates supply chain attack methodology targeting telecom infrastructure. 12M impacted via ISP email access compromise.
KDDI Zero-Day Supply Chain Attack: 12M ISP Email Compromise
Executive Summary
KDDI Corporation's breach affecting 12 million customers represents a textbook supply chain attack vector: exploitation of a zero-day vulnerability in third-party email infrastructure supporting ISP operations. From an offensive perspective, this incident reveals critical gaps in telco security posture around third-party system isolation and email authentication controls.








