✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Dutch Authorities Dismantle Massive 17 Million-Device Botnet
In May 2026, Dutch authorities dismantled a massive botnet comprising 17 million infected devices, including computers, tablets, and smartphones. The operation involved seizing over 200 servers located in the Netherlands that controlled the botnet's infrastructure. This network was utilized for various cyberattacks, such as distributed denial-of-service (DDoS) attacks and malicious traffic proxying. The botnet was linked to a service called Asocks, which offered proxy services using compromised devices without the owners' knowledge. This incident underscores the growing threat posed by botnets leveraging residential devices, highlighting the need for enhanced security measures to protect consumer hardware from unauthorized exploitation.
1 month ago
Kill Chain
Major Supply Chain Attacks Target Nx Console and GitHub Repositories in 2026
In May 2026, two significant supply chain attacks targeted the developer ecosystem. The first involved a compromised version of the Nx Console Visual Studio Code extension (v18.95.0), which was live for approximately 18 minutes on May 18, 2026. This malicious extension exfiltrated credentials from developer machines, leading to unauthorized access and exfiltration of approximately 3,800 internal GitHub repositories. The second attack, dubbed 'Megalodon,' occurred on the same day and compromised over 5,500 GitHub repositories by injecting malicious GitHub Actions workflows designed to harvest CI/CD secrets and cloud credentials. These incidents underscore the escalating threat landscape targeting software development pipelines and the critical need for robust security measures in CI/CD environments. The rapid execution and widespread impact of these attacks highlight the urgency for organizations to implement stringent supply chain security practices and continuous monitoring to detect and mitigate such threats promptly.
1 month ago
Kill Chain
Kimsuky's Advanced Cyber Attacks: A New Era of AI-Driven Threats
In March and April 2026, the North Korean state-sponsored threat actor Kimsuky launched sophisticated cyber attacks targeting South Korean military and corporate entities. Utilizing advanced social engineering tactics, they spoofed security software installation pages and crafted fake Webex meeting pages to distribute malware. These campaigns delivered variants of the HTTPSpy remote access trojan, enabling extensive control over compromised systems, including command execution, file manipulation, and data exfiltration. Notably, Kimsuky employed legitimate tools like Visual Studio Code's remote tunneling feature and DWAgent for post-exploitation activities, enhancing their ability to evade detection. The increasing integration of artificial intelligence in cyber attack methodologies, as demonstrated by Kimsuky's use of large language models to develop malware like HelloDoor, signifies a significant evolution in threat actor capabilities. This trend underscores the urgent need for organizations to adopt advanced, behavior-based detection systems and regularly update threat intelligence to effectively counter these sophisticated and rapidly evolving cyber threats.
1 month ago
Kill Chain
Harnessing AI: LLMs in EDR Evasion Techniques
In May 2026, Praetorian published a blog post titled 'Adversarial Oracles: LLM-Guided EDR Signature Reduction,' detailing the use of Large Language Models (LLMs) to automate the evasion of Endpoint Detection and Response (EDR) signatures. The post describes a methodology where LLMs analyze detection patterns from services like VirusTotal, identify specific triggers in offensive security tools, and suggest code modifications to reduce detection rates. This approach was applied to tools like 'goffloader,' resulting in a significant decrease in antivirus detections without altering the tools' core functionalities. This development is significant as it highlights the evolving arms race between offensive and defensive cybersecurity measures. The use of AI to circumvent EDR systems underscores the need for adaptive defense strategies and raises ethical considerations regarding the deployment of AI in cybersecurity.
1 month ago
Kill Chain
FortiClient EMS Vulnerability Leads to EKZ Infostealer Deployment
In May 2026, threat actors exploited a critical authentication bypass vulnerability (CVE-2026-35616) in Fortinet's FortiClient Enterprise Management Server (EMS) versions 7.4.5 and 7.4.6. This flaw allowed unauthenticated remote attackers to execute arbitrary code via specially crafted requests. Leveraging this vulnerability, attackers delivered the EKZ infostealer malware, disguised as a legitimate Fortinet endpoint update, through FortiClient-managed VPN scripting workflows. The malware targeted credentials and sensitive data stored in web browsers, exfiltrating them to attacker-controlled servers. Fortinet released emergency patches to address this issue, and organizations were urged to apply them promptly to mitigate the risk of compromise. This incident underscores the critical importance of timely patch management and vigilance against sophisticated social engineering tactics. The exploitation of trusted security infrastructure highlights the evolving strategies of threat actors, emphasizing the need for organizations to adopt a proactive and layered security approach to protect against such vulnerabilities.
2 months ago
Kill Chain
Exploitation of FortiClient EMS Vulnerability Leads to Credential Theft
In May 2026, threat actors exploited a critical vulnerability (CVE-2026-35616) in Fortinet's FortiClient Endpoint Management Server (EMS) to deploy credential-stealing malware across managed endpoints. By abusing the trusted endpoint management infrastructure, attackers disguised the malicious payload as a legitimate Fortinet update, executing it via PowerShell. This allowed them to harvest sensitive data, including passwords and autofill details from web browsers, and exfiltrate the information to attacker-controlled servers. The exploitation of this vulnerability underscores the risks associated with unpatched management systems and the potential for widespread compromise through centralized infrastructure. Organizations are urged to apply the latest patches and review endpoint management configurations to mitigate such threats.
2 months ago
Kill Chain
Microsoft Addresses Risks of Uncoordinated Zero-Day Disclosures
In May 2026, security researcher Chaotic Eclipse publicly disclosed multiple zero-day vulnerabilities affecting Windows components such as Defender and BitLocker. These disclosures were made without prior notification to Microsoft, leading to active exploitation of vulnerabilities like BlueHammer (CVE-2026-33825), RedSun (CVE-2026-41091), and UnDefend (CVE-2026-45498). Microsoft criticized this uncoordinated approach, emphasizing the risks posed to customers and advocating for Coordinated Vulnerability Disclosure (CVD) to allow vendors time to address issues before public release. This incident underscores the ongoing tension between independent security researchers and software vendors regarding disclosure practices. The rapid exploitation of these vulnerabilities highlights the critical need for timely and coordinated communication to mitigate risks and protect end-users effectively.
2 months ago
Kill Chain
FBI Issues Warning on Silent Ransom Group's In-Person Data Theft Tactics
In May 2026, the FBI issued a warning about the Silent Ransom Group (SRG), a Russia-linked data extortion gang targeting U.S. law firms. SRG employs a combination of social engineering tactics, including phone calls and phishing emails, to impersonate IT support staff. If these remote attempts fail, the group escalates to in-person visits, where operatives physically access computers to steal sensitive data using external storage devices. This method has led to the compromise of over 100 law firms, with data from more than 38 firms publicly leaked. The group's focus on law firms is strategic, exploiting the highly sensitive nature of legal data to exert pressure for ransom payments. SRG's unique approach, combining remote social engineering with physical intrusion, underscores the evolving threat landscape and the need for robust security measures in the legal sector.
2 months ago
Kill Chain
FBI Issues Warning on Silent Ransom Group's In-Person Data Theft Tactics
In May 2026, the FBI issued a warning about the Silent Ransom Group (SRG), an extortion gang targeting U.S. law firms through sophisticated social engineering tactics. SRG actors impersonate IT support personnel via phone calls and phishing emails to gain remote access to victim computers. If these attempts fail, they escalate their efforts by sending individuals in person to the victim's location to physically access computers and exfiltrate sensitive data using external storage devices. The stolen data is then used to extort victims, with threats to sell or publicly disclose the information if ransom demands are not met. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/fbi-warns-of-silent-ransom-group-in-person-data-theft-attacks/?utm_source=openai)) This incident underscores a concerning evolution in cybercriminal tactics, blending traditional phishing with physical infiltration to bypass digital defenses. The legal sector, known for handling highly sensitive information, is particularly vulnerable to such targeted attacks. Organizations must enhance their security protocols, including employee training on social engineering, strict access controls, and monitoring for unauthorized physical access, to mitigate the risks posed by such multifaceted threats.
2 months ago
Kill Chain
Malicious npm Package Compromises Claude AI User Data
In May 2026, cybersecurity researchers identified a malicious npm package named "mouse5212-super-formatter" designed to exfiltrate files from the "/mnt/user-data" directory utilized by Anthropic's Claude AI tool. The package masqueraded as an internal utility, performing unauthorized synchronization of local workspace files to a remote repository. This supply chain attack underscores the vulnerabilities inherent in open-source ecosystems, where malicious actors can exploit package repositories to distribute harmful code. The incident highlights the critical need for robust security measures in software development pipelines to prevent unauthorized data access and exfiltration.
2 months ago
Kill Chain
Mini Shai-Hulud 2026: Unveiling TeamPCP's Supply Chain Attack on AI Developer Tools
In May 2026, the cybercriminal group TeamPCP executed a sophisticated supply chain attack known as 'Mini Shai-Hulud,' compromising over 170 npm and PyPI packages across 19 namespaces. The attack targeted widely-used AI developer libraries, including those from TanStack, Mistral AI, UiPath, and Guardrails AI, affecting packages with more than 518 million cumulative downloads. Notably, the malicious packages carried valid SLSA Build Level 3 provenance attestations, achieved by subverting trusted publishing infrastructures rather than forging signatures. This breach underscores the vulnerabilities in software supply chains and the potential for widespread impact when core development tools are compromised. ([labs.cloudsecurityalliance.org](https://labs.cloudsecurityalliance.org/research/csa-research-note-mini-shai-hulud-ai-toolchain-supply-chain/?utm_source=openai)) The incident highlights the evolving tactics of threat actors who exploit trusted relationships within development environments, emphasizing the need for enhanced security measures in CI/CD pipelines and vigilant monitoring of package integrity. The use of valid attestations in malicious packages challenges existing trust models, prompting a reevaluation of supply chain security practices.
2 months ago
Kill Chain
AI-Driven Exploit Development: A New Era of Cyber Threats
In May 2026, cybersecurity researchers reported a significant acceleration in exploit development timelines due to the integration of artificial intelligence (AI). Attackers have reduced the time to develop exploits for known vulnerabilities from 125 days to just 0.5 days by leveraging AI-assisted development tools. This rapid development has outpaced the ability of traditional vulnerability scanners to detect and mitigate threats, creating substantial visibility gaps for security teams. The use of large language models (LLMs) enables threat actors to analyze code changes and generate proof-of-concept exploits swiftly, increasing the risk of unpatched vulnerabilities being exploited soon after disclosure. This development underscores the urgent need for organizations to adopt proactive security measures that can keep pace with AI-driven threats. Traditional detection methods are becoming less effective, necessitating the implementation of continuous software inventory analysis, real-time threat intelligence integration, and automated patch management to mitigate the risks associated with rapid exploit development.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports