✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
SprySOCKS Windows Variant: A New Threat to Government Cybersecurity
In 2023 and 2024, the China-linked cyber-espionage group FishMonger, also known as Earth Lusca and Aquatic Panda, deployed a Windows variant of the SprySOCKS backdoor against government organizations in Honduras, Taiwan, Thailand, and Pakistan. This variant utilizes malicious kernel drivers to evade detection, allowing the backdoor to conceal its processes and files by intercepting system calls and modifying outputs. The attackers likely gained initial access through exploiting vulnerabilities in public-facing servers. The emergence of this Windows variant underscores the evolving tactics of nation-state actors in enhancing malware stealth capabilities. Organizations should be vigilant about the use of kernel drivers in malware, as they pose significant challenges to detection and mitigation efforts.
1 month ago
Kill Chain
Fortinet FortiSandbox Critical Vulnerabilities CVE-2026-39813 and CVE-2026-39808
In April 2026, Fortinet disclosed two critical vulnerabilities in its FortiSandbox product: CVE-2026-39813 and CVE-2026-39808, both with a CVSS score of 9.1. CVE-2026-39813 is a path traversal vulnerability in the JRPC API, allowing unauthenticated attackers to bypass authentication via specially crafted HTTP requests. CVE-2026-39808 is an OS command injection flaw that enables unauthorized code execution through crafted HTTP requests. These vulnerabilities affect FortiSandbox versions 4.4.0 through 4.4.8 and 5.0.0 through 5.0.5. Fortinet has released patches to address these issues. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/04/16/fortinet-fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808/?utm_source=openai)) The exploitation of these vulnerabilities could lead to full system compromise, undermining the integrity of the security infrastructure. Organizations are urged to apply the patches promptly to mitigate potential risks. ([action1.com](https://www.action1.com/vulnerabilities/cve-2026-39813/?utm_source=openai))
1 month ago
Kill Chain
UNC6508: Unveiling the Stealthy Chinese Espionage Group Targeting North American Research
In late 2025, Google's Threat Intelligence Group identified UNC6508, a Chinese state-sponsored espionage group, which had infiltrated U.S. and Canadian organizations since September 2023. The group exploited vulnerabilities in externally facing REDCap servers to deploy a custom backdoor named INFINITERED, enabling them to steal administrative credentials and sensitive data from medical research universities, clinical providers, and military health institutions. UNC6508 remained undetected for over two years, highlighting the sophistication and stealth of their operations. ([cyberscoop.com](https://cyberscoop.com/google-unc6508-china-espionage-threat/?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber espionage groups targeting critical infrastructure and sensitive research sectors. The ability of such groups to operate undetected for extended periods emphasizes the need for enhanced cybersecurity measures and vigilance within organizations handling sensitive data. ([cyberscoop.com](https://cyberscoop.com/google-unc6508-china-espionage-threat/?utm_source=openai))
1 month ago
Kill Chain
Critical Authentication Bypass in SimpleHelp: CVE-2026-48558
In June 2026, a critical vulnerability (CVE-2026-48558) was discovered in SimpleHelp remote management software versions 5.5.15 and earlier, as well as 6.0 pre-release versions. This flaw allows unauthenticated attackers to create privileged technician accounts by exploiting improper validation of identity tokens in the OpenID Connect (OIDC) authentication flow. Consequently, attackers can gain unauthorized access to managed endpoints, execute scripts, and perform administrative actions without user interaction. SimpleHelp addressed this issue by releasing patched versions 5.5.16 and 6.0 RC2 on June 9, 2026. Organizations are urged to update their systems promptly to mitigate potential exploitation risks. This incident underscores the critical importance of robust authentication mechanisms and thorough validation processes in remote management tools. The exploitation of OIDC vulnerabilities highlights a growing trend where attackers target identity and access management systems to gain unauthorized access, emphasizing the need for continuous vigilance and timely patch management.
1 month ago
Kill Chain
U.S. Government Restricts Access to Anthropic's Advanced AI Models
In June 2026, the U.S. government issued an export control directive requiring Anthropic to suspend access to its advanced AI models, Fable 5 and Mythos 5, for all foreign nationals, including those within the United States. This action was taken due to national security concerns over potential vulnerabilities that could allow the models to be exploited for identifying software flaws. As a result, Anthropic disabled these models for all users to ensure compliance. This unprecedented move underscores the growing tension between technological advancement and national security, highlighting the challenges in regulating AI technologies. The directive has sparked international debate over the balance between innovation and security, with European leaders expressing concerns about overreliance on American AI providers and advocating for greater technological sovereignty.
1 month ago
Kill Chain
Evil MSI Background: Unveiling the 2026 Phishing Campaign
In June 2026, a sophisticated phishing campaign emerged, leveraging WeTransfer links to distribute malicious JavaScript files. These scripts, upon execution, utilized obfuscation techniques to decode and run PowerShell commands, which subsequently downloaded additional payloads, including a .NET DLL designed to manipulate Windows Task Scheduler. This method facilitated the execution of further malicious activities, potentially leading to persistent system compromise. The campaign notably exploited legitimate cloud services like Cloudflare Workers and R2 storage to host and distribute its malicious components, thereby enhancing its stealth and effectiveness. This incident underscores a growing trend where threat actors increasingly abuse trusted cloud platforms to host and disseminate malware, complicating detection and mitigation efforts. The use of obfuscated scripts and legitimate services highlights the evolving sophistication of phishing attacks, emphasizing the need for enhanced vigilance and advanced security measures to detect and prevent such threats.
1 month ago
Kill Chain
Anthropic's AI Models Disabled Amid National Security Concerns
In June 2026, the U.S. government ordered Anthropic to suspend foreign access to its advanced AI models, Fable 5 and Mythos 5, citing national security concerns over potential 'jailbreaking' vulnerabilities that could bypass safety restrictions. This directive led Anthropic to disable these models entirely to comply with export controls, affecting both foreign nationals and certain employees. The incident underscores the challenges in balancing AI innovation with security, as similar capabilities exist in other publicly accessible models. The government's stringent response highlights the growing scrutiny over AI technologies and their potential misuse, emphasizing the need for robust security measures and regulatory frameworks in the rapidly evolving AI landscape.
1 month ago
Kill Chain
Unveiling App.MenuItem: A New Forensic Artifact in macOS Tahoe 26
In June 2026, researchers identified a new artifact in macOS Tahoe 26, named App.MenuItem, which logs specific menu selections made by users across the operating system. This artifact provides a detailed record of user actions, such as compressing files or emptying the trash, offering critical context for forensic investigations. Located at ~/Library/Biome/streams/restricted/App.MenuItem/local, the artifact contains SEGB-encapsulated protobuf entries that require specific tools to parse. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/?_wpnonce=c8aaaf1bea&lg=en&pdf=download&utm_source=openai)) The discovery of App.MenuItem is significant for digital forensics, as it allows examiners to reconstruct user workflows with greater precision. By capturing exact menu choices and timestamps, investigators can gain insights into user intent and actions, enhancing the accuracy of forensic analyses. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/?_wpnonce=c8aaaf1bea&lg=en&pdf=download&utm_source=openai))
1 month ago
Kill Chain
Tchap Messenger Breach: Data of 73,000 French Government Employees Exposed
In June 2026, the French government's encrypted messaging platform, Tchap, experienced a security breach when a threat actor gained access through a compromised user account. This intrusion led to the exposure of data from public chat rooms, affecting over 73,000 public sector employees. The compromised information included users' names, email addresses, avatar images, and their affiliated public sector organizations. Private conversations remained encrypted and were not accessed during the breach. This incident underscores the persistent threat posed by social engineering attacks and highlights the importance of securing even internal communication platforms. Organizations must remain vigilant and continuously enhance their security measures to protect sensitive information from unauthorized access.
1 month ago
Kill Chain
phpBB Authentication Bypass Vulnerability Exposes User Accounts
In June 2026, a critical authentication bypass vulnerability was discovered in phpBB, a widely used open-source forum software. This flaw, present for over a decade, allowed attackers to log in as any user, including administrators, without requiring a password. The vulnerability affected phpBB versions up to 3.3.16 and 4.0.0-a2. Exploiting this issue was straightforward, requiring only a single HTTP request, and could be executed on default configurations without special knowledge. The phpBB team promptly addressed the issue by releasing version 3.3.17 on June 6, 2026, which patched the vulnerability. This incident underscores the importance of regular security audits and prompt patching in open-source software. The ease of exploitation and the widespread use of phpBB made this vulnerability particularly concerning, highlighting the need for vigilance in maintaining and updating software to protect against emerging threats.
1 month ago
Kill Chain
Massive Compromise of Arch Linux AUR Packages Leads to Deployment of Infostealer and eBPF Rootkit
In June 2026, attackers compromised over 400 packages in the Arch User Repository (AUR), modifying their build scripts to deploy a Rust-based credential stealer. This malware targeted developer secrets, including browser cookies, SSH keys, and API tokens. When executed with root privileges, it could also install an eBPF rootkit to conceal its presence. The attack exploited the trust model of the AUR by adopting orphaned packages and altering their build instructions, while the package names and histories remained unchanged. This incident underscores the vulnerabilities inherent in community-maintained repositories and highlights the need for rigorous package vetting processes. The use of eBPF rootkits represents an evolution in malware techniques, emphasizing the importance of advanced detection mechanisms to identify and mitigate such sophisticated threats.
1 month ago
Kill Chain
Anthropic's Claude Fable 5: Balancing Advanced AI Capabilities with Security
In June 2026, Anthropic released Claude Fable 5, a public version of its advanced AI model, Claude Mythos 5, which was previously restricted due to security concerns. Fable 5 is designed to perform complex tasks autonomously, including software development and research. To mitigate potential misuse in sensitive areas like cybersecurity and biology, Anthropic implemented safeguards that redirect high-risk queries to a less capable model, Claude Opus 4.8. This approach aims to balance the model's powerful capabilities with safety considerations. The release of Claude Fable 5 underscores the ongoing challenge of deploying advanced AI systems responsibly. As AI models become more capable, ensuring they are used ethically and securely remains a critical concern for developers and users alike.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports