✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
GlassWorm Malware Takedown: Securing the Developer Supply Chain
In May 2026, CrowdStrike, in collaboration with Google and the Shadowserver Foundation, executed a coordinated takedown of the GlassWorm botnet, a sophisticated malware campaign targeting software developers through compromised open-source packages and malicious Visual Studio Code extensions. This operation simultaneously disrupted all command-and-control channels associated with GlassWorm, effectively severing the operators' access to infected systems and halting the distribution of new malicious payloads. The GlassWorm campaign, active since early 2025, had systematically infiltrated developer tools and repositories, embedding malware in over 400 projects across platforms like GitHub, npm, and the Open VSX Registry. By compromising these widely used resources, the attackers aimed to steal credentials, access tokens, and sensitive data, thereby facilitating broader supply chain attacks that could impact numerous downstream organizations and users. The successful dismantling of GlassWorm underscores the critical importance of securing the software development supply chain. As developers increasingly become prime targets for cyber adversaries, this incident highlights the necessity for enhanced vigilance, robust security practices, and collaborative efforts to protect the integrity of open-source ecosystems and prevent similar future threats.
2 months ago
Kill Chain
Anthropic's AI Model Uncovers Thousands of Software Vulnerabilities
In April 2026, Anthropic launched Project Glasswing, utilizing its advanced AI model, Claude Mythos Preview, to identify vulnerabilities in critical software systems. Within the first month, the initiative uncovered over 10,000 high- or critical-severity vulnerabilities across various platforms, including major operating systems and web browsers. Notably, partners like Cloudflare reported discovering 2,000 bugs, with 400 classified as high or critical severity. This rapid identification underscores the model's capability to detect longstanding vulnerabilities that have eluded traditional methods. The surge in discovered vulnerabilities has shifted the cybersecurity focus from detection to remediation. The bottleneck now lies in the human capacity to triage, report, and deploy patches for these issues. As AI models like Mythos become more prevalent, organizations must adapt their security strategies to address the increasing volume of vulnerabilities and the urgency of timely patching.
2 months ago
Kill Chain
Anthropic's Claude Mythos: Revolutionizing Cybersecurity with AI
In April 2026, Anthropic introduced 'Claude Mythos,' an advanced AI model with exceptional capabilities in identifying and exploiting software vulnerabilities. The model demonstrated the ability to autonomously develop sophisticated cyberattacks, raising significant concerns about its potential misuse. To mitigate these risks, Anthropic restricted public access to Mythos, collaborating with select partners through Project Glasswing to enhance cybersecurity defenses. ([euronews.com](https://www.euronews.com/next/2026/04/08/why-anthropics-most-powerful-ai-model-mythos-preview-is-too-dangerous-for-public-release?utm_source=openai)) The emergence of AI models like Claude Mythos signifies a paradigm shift in cybersecurity, where AI can both uncover and exploit vulnerabilities at unprecedented speeds. This development underscores the urgent need for robust security measures and proactive strategies to address the dual-use nature of such technologies. ([cfr.org](https://www.cfr.org/articles/six-reasons-claude-mythos-is-an-inflection-point-for-ai-and-global-security?utm_source=openai))
2 months ago
Kill Chain
Lazarus Group's RemotePE: A New Memory-Only Threat to Financial Institutions
In May 2026, cybersecurity researchers uncovered a sophisticated attack campaign by the North Korean state-sponsored Lazarus Group targeting financial and cryptocurrency organizations. The group deployed a cross-platform, memory-only Remote Access Trojan (RAT) named RemotePE, which operates entirely in memory, leaving no artifacts on the filesystem. The attack chain involves two loaders: DPAPILoader, which decrypts and loads RemotePELoader using the Windows Data Protection API, and RemotePELoader, which contacts a command-and-control server to fetch and execute RemotePE in memory. This multi-stage approach allows the malware to evade traditional detection mechanisms and maintain persistent access to compromised systems. ([thehackernews.com](https://thehackernews.com/2026/05/lazarus-deploys-remotepe-memory-only.html?utm_source=openai)) The discovery of RemotePE highlights the Lazarus Group's continued evolution in cyber-attack methodologies, emphasizing the need for organizations to adopt advanced threat detection and response strategies. The use of memory-only malware underscores the importance of monitoring in-memory activities and implementing robust endpoint detection and response (EDR) solutions to detect and mitigate such sophisticated threats.
2 months ago
Kill Chain
AI Model Identifies Over 10,000 Critical Software Vulnerabilities in One Month
In April 2026, Anthropic launched Project Glasswing, utilizing its advanced AI model, Claude Mythos Preview, to autonomously identify vulnerabilities in critical software. Within a month, the initiative uncovered over 10,000 high- or critical-severity flaws across major operating systems and web browsers. Notably, the AI detected a 27-year-old bug in OpenBSD and a 16-year-old issue in FFmpeg, highlighting its unprecedented detection capabilities. This rapid discovery rate has effectively ended the traditional "patch window," as over 99% of the identified vulnerabilities remain unpatched, posing significant risks to global economies, public safety, and national security. The emergence of AI-driven vulnerability discovery tools like Claude Mythos Preview signifies a paradigm shift in cybersecurity. While these tools enhance defensive capabilities, they also compress the timeline between vulnerability discovery and potential exploitation. Organizations must adapt by implementing resilience-based security models, hardening binaries, and adopting runtime protections to mitigate the risks associated with this accelerated threat landscape.
2 months ago
Kill Chain
Understanding Stack String Obfuscation: A New Challenge in Malware Detection
In May 2026, cybersecurity researchers highlighted the 'stack string' obfuscation technique, where malware dynamically constructs strings on the stack at runtime, evading detection by static analysis tools. This method involves assembling strings character-by-character directly onto the stack, making them invisible to traditional string extraction utilities. The technique poses significant challenges for malware analysts and underscores the need for advanced detection methods. The resurgence of stack string obfuscation reflects a broader trend of malware authors adopting sophisticated evasion tactics. As traditional detection tools become less effective against such techniques, there is an urgent need for enhanced analysis tools and methodologies to identify and mitigate these evolving threats.
2 months ago
Kill Chain
Understanding CVE-2026-0265: PAN-OS CAS Authentication Bypass
In May 2026, a critical authentication bypass vulnerability, CVE-2026-0265, was identified in Palo Alto Networks' PAN-OS software. This flaw allows unauthenticated attackers to forge JSON Web Tokens (JWTs) and gain unauthorized access to systems where the Cloud Authentication Service (CAS) is enabled. The vulnerability affects both GlobalProtect portals and management interfaces, potentially compromising VPN user sessions and administrative controls. Palo Alto Networks has released patches for affected versions, and organizations are urged to update to fixed versions or disable CAS to mitigate the risk. The discovery of CVE-2026-0265 underscores the ongoing challenges in securing authentication mechanisms within network infrastructure. As attackers continue to exploit such vulnerabilities, it is imperative for organizations to stay vigilant, apply timely patches, and adhere to best practices in access control to safeguard their systems against unauthorized access.
2 months ago
Kill Chain
Ghostwriter's Prometheus Phishing Campaign Targets Ukrainian Government
In May 2026, the Belarus-aligned threat actor known as Ghostwriter (also referred to as UAC-0057 and UNC1151) launched a phishing campaign targeting Ukrainian government entities. The attackers utilized compromised accounts to send emails containing PDF attachments that, when interacted with, led to the deployment of a multi-stage malware chain. This chain involved the execution of JavaScript files (OYSTERFRESH and OYSTERSHUCK) designed to install the OYSTERBLUES payload, which harvested system information and facilitated the deployment of Cobalt Strike, a tool commonly used for post-exploitation activities. The campaign exploited lures related to Prometheus, a Ukrainian online learning platform, to enhance the credibility of the phishing emails. ([thehackernews.com](https://thehackernews.com/2026/05/ghostwriter-targets-ukraine-government.html?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors employing sophisticated phishing techniques to infiltrate government networks. The use of legitimate platforms as lures and the deployment of multi-stage malware highlight the evolving tactics of such groups, emphasizing the need for robust cybersecurity measures and user awareness to mitigate these risks.
2 months ago
Kill Chain
Arrest of Kimwolf Botnet Operator Highlights IoT Security Risks
In May 2026, Canadian authorities arrested Jacob Butler, known online as "Dort," for allegedly creating and operating the Kimwolf botnet. This botnet infected millions of Internet-of-Things (IoT) devices, such as digital photo frames and web cameras, to execute massive distributed denial-of-service (DDoS) attacks. Some of these attacks reached nearly 30 terabits per second, causing financial losses exceeding one million dollars for certain victims. The U.S. Department of Justice has charged Butler with aiding and abetting computer intrusion, and he faces potential extradition to the United States. ([krebsonsecurity.com](https://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canada/?utm_source=openai)) The Kimwolf botnet's unprecedented scale and impact underscore the growing threat posed by IoT-based cyberattacks. This incident highlights the critical need for enhanced security measures in IoT devices and increased international cooperation to combat cybercrime effectively.
2 months ago
Kill Chain
CISA Contractor's GitHub Repository Exposes Sensitive Government Credentials
In May 2026, a contractor for the U.S. Cybersecurity and Infrastructure Security Agency (CISA) inadvertently exposed sensitive credentials by publishing them in a public GitHub repository named 'Private-CISA'. The repository contained plaintext passwords, AWS GovCloud keys, and internal documentation detailing CISA's software deployment processes. This exposure raised significant concerns about operational security and the potential for unauthorized access to critical government systems. ([techradar.com](https://www.techradar.com/pro/security/cisa-contractor-apparently-leaked-highly-sensitive-government-aws-keys-on-github?utm_source=openai)) This incident underscores the critical importance of stringent access controls and the need for robust monitoring of code repositories to prevent accidental exposure of sensitive information. It also highlights the necessity for organizations to implement comprehensive security training for all personnel, including contractors, to mitigate the risk of similar breaches.
2 months ago
Kill Chain
CISA Adds Two Known Exploited Vulnerabilities to Catalog
On May 21, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2025-34291, an origin validation error in Langflow, and CVE-2026-34926, a directory traversal flaw in Trend Micro Apex One (on-premise). Both vulnerabilities have been actively exploited, posing significant risks to affected systems. ([thehackernews.com](https://thehackernews.com/2026/05/cisa-adds-exploited-langflow-and-trend.html?utm_source=openai)) The inclusion of these vulnerabilities in the KEV Catalog underscores the ongoing threat posed by unpatched software flaws. Organizations are urged to prioritize remediation efforts to mitigate potential exploitation and safeguard their systems against emerging cyber threats.
2 months ago
Kill Chain
CISA Adds Langflow and Trend Micro Apex One Vulnerabilities to KEV Catalog
On May 21, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2025-34291, an origin validation error in Langflow with a CVSS score of 9.4, and CVE-2026-34926, a directory traversal flaw in on-premise versions of Trend Micro Apex One with a CVSS score of 6.7. Both vulnerabilities have been actively exploited, with CVE-2025-34291 being leveraged by the Iranian state-sponsored group MuddyWater to gain initial access to target networks. ([thehackernews.com](https://thehackernews.com/2026/05/cisa-adds-exploited-langflow-and-trend.html?utm_source=openai)) The inclusion of these vulnerabilities in the KEV catalog underscores the persistent threat posed by state-sponsored actors and the critical need for organizations to promptly address known security flaws. Federal agencies are mandated to apply necessary fixes by June 4, 2026, highlighting the urgency of mitigating these risks to protect sensitive systems and data. ([thehackernews.com](https://thehackernews.com/2026/05/cisa-adds-exploited-langflow-and-trend.html?utm_source=openai))
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports