✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Checkmarx Jenkins Plugin Compromised in 2026 Supply Chain Attack
In May 2026, Checkmarx's Jenkins Application Security Testing (AST) plugin was compromised by the hacker group TeamPCP. The attackers published a malicious version of the plugin on the Jenkins Marketplace, embedding credential-stealing malware. This breach was facilitated by credentials obtained from a prior supply chain attack on the Trivy vulnerability scanner in March 2026. The malicious plugin, version 2026.5.09, was uploaded on May 9, 2026, and users who installed this version are advised to rotate all secrets and investigate for potential lateral movement or persistence. This incident underscores the escalating trend of supply chain attacks targeting development tools and the critical need for robust security measures in CI/CD pipelines. Organizations must remain vigilant, ensuring the integrity of third-party plugins and promptly addressing any security advisories to mitigate potential risks.
2 months ago
Kill Chain
TeamPCP's Supply Chain Attack on Checkmarx Jenkins AST Plugin: A Wake-Up Call for CI/CD Security
In May 2026, the cybercriminal group TeamPCP executed a supply chain attack by publishing a malicious version of the Checkmarx Jenkins AST plugin to the Jenkins Marketplace. This compromised plugin, identified as version 2026.5.09, was designed to exfiltrate sensitive information from Jenkins instances, including GitHub tokens, cloud credentials, and SSH keys. Checkmarx promptly advised users to revert to the verified safe version 2.0.13-829.vc72453fa_1c16, released on December 17, 2025, and to rotate all potentially exposed secrets. This incident underscores the escalating threat posed by supply chain attacks targeting development tools and the necessity for organizations to implement stringent security measures within their CI/CD pipelines. The recurrence of such attacks highlights the importance of continuous monitoring and verification of third-party components to safeguard against unauthorized modifications and potential data breaches.
2 months ago
Kill Chain
Cybercriminals Harness AI for Sophisticated Attacks in 2026
In early 2026, cybersecurity researchers observed a significant uptick in threat actors leveraging artificial intelligence (AI) to enhance their cyberattack capabilities. These adversaries utilized AI to automate reconnaissance, develop sophisticated exploits, and orchestrate complex attack sequences, leading to faster and more efficient breaches. Notably, a Russian-speaking threat actor employed generative AI tools to compromise over 600 FortiGate firewalls across 55 countries by exploiting weak credentials and exposed management interfaces. This campaign, which spanned from January 11 to February 18, 2026, underscored the evolving threat landscape where AI lowers the technical barrier for large-scale cyber intrusions. ([aws.amazon.com](https://aws.amazon.com/blogs/security/ai-augmented-threat-actor-accesses-fortigate-devices-at-scale/?utm_source=openai)) The increasing integration of AI into cyber operations has accelerated the speed and scale of attacks, challenging traditional defense mechanisms. Organizations must adapt by implementing AI-driven security solutions, enhancing threat detection capabilities, and fostering a culture of continuous cybersecurity education to mitigate the risks posed by AI-augmented adversaries.
2 months ago
Kill Chain
Authorities Dismantle Rebooted Crimenetwork Marketplace in 2026
In May 2026, German authorities, in collaboration with international partners, dismantled the rebooted version of the illicit online marketplace 'Crimenetwork' and arrested its 35-year-old German administrator in Mallorca, Spain. This platform, which emerged shortly after the original Crimenetwork was shut down in December 2024, facilitated the sale of stolen data, drugs, and counterfeit documents, amassing over 22,000 users and generating approximately €3.6 million in revenue. The operation led to the seizure of assets worth around €194,000 and extensive user and transaction data to aid further investigations. ([finanznachrichten.de](https://www.finanznachrichten.de/nachrichten-2026-05/68437271-darknet-plattform-crimenetwork-erneut-abgeschaltet-003.htm?utm_source=openai)) This incident underscores the persistent challenge posed by the rapid re-emergence of dismantled cybercriminal platforms. Despite law enforcement's efforts, the swift reconstruction of such marketplaces highlights the need for continuous vigilance and adaptive strategies to combat cybercrime effectively.
2 months ago
Kill Chain
JDownloader Website Compromised: Malicious Installers Distribute Python RAT Malware
In early May 2026, the official website of JDownloader, a widely-used download management application, was compromised. Attackers exploited an unpatched vulnerability in the site's content management system, allowing them to modify download links without authentication. As a result, users who downloaded the Windows 'Download Alternative Installer' or the Linux shell installer between May 6 and May 7, 2026, received malicious payloads instead of legitimate software. The Windows payload deployed a heavily obfuscated Python-based remote access trojan (RAT), granting attackers unauthorized access to infected systems. The Linux installer was similarly altered to include malicious code that installed a SUID-root binary, enabling persistent unauthorized access. This incident underscores the escalating threat of supply chain attacks targeting widely-used software platforms. By compromising trusted distribution channels, attackers can disseminate malware to a vast user base, bypassing traditional security measures. Organizations must prioritize securing their software supply chains and implement robust monitoring to detect unauthorized modifications promptly.
2 months ago
Kill Chain
Former Government Contractors Convicted for Deleting Federal Databases
In February 2025, twin brothers Muneeb and Sohaib Akhter, both 34 and former federal contractors, were terminated from their positions after their prior felony convictions for unauthorized access to U.S. State Department systems were discovered. Immediately following their dismissal, they accessed their employer's systems without authorization, deleting approximately 96 government databases containing sensitive information, including investigative documents and Freedom of Information Act records. They also attempted to cover their tracks by seeking guidance from an AI assistant on clearing system logs and wiping company-issued laptops before returning them. This incident underscores the critical need for stringent access controls and monitoring mechanisms to prevent insider threats, especially from individuals with prior offenses. The case highlights the potential risks associated with rehiring individuals with a history of cyber offenses and the importance of comprehensive background checks and continuous monitoring to safeguard sensitive government data.
2 months ago
Kill Chain
Trellix Source Code Breach: A Wake-Up Call for Cybersecurity Firms
In April 2026, cybersecurity firm Trellix experienced unauthorized access to a portion of its source code repository. The breach was publicly disclosed on May 1, 2026, with Trellix stating that forensic experts and law enforcement were engaged immediately. The company reported no evidence that its source code release or distribution processes were affected or that the source code had been exploited. Subsequently, the RansomHouse threat group claimed responsibility for the intrusion, alleging that the attack occurred on April 17 and resulted in data encryption. They published screenshots suggesting access to Trellix's appliance management system, though the authenticity of these claims remains unverified. This incident underscores the escalating trend of cybercriminals targeting cybersecurity vendors to exploit their products and services. The breach highlights the critical need for robust internal security measures within security firms, as unauthorized access to source code can potentially lead to the discovery of vulnerabilities, enabling attackers to develop sophisticated exploits or conduct supply chain attacks.
2 months ago
Kill Chain
TCLBANKER: A New Threat to Financial Platforms via WhatsApp and Outlook
In May 2026, Elastic Security Labs identified a new Brazilian banking trojan named TCLBANKER, which targets 59 banking, fintech, and cryptocurrency platforms. The malware is distributed through a trojanized Logitech installer and employs advanced anti-analysis techniques. Once installed, TCLBANKER monitors browser activity and overlays fraudulent interfaces to steal user credentials. Additionally, it propagates via WhatsApp and Outlook by sending malicious links to the victim's contacts, facilitating further infections. This incident underscores the evolving sophistication of banking trojans, particularly in their use of legitimate applications for distribution and self-propagation through popular communication platforms. Organizations must enhance their security measures to detect such advanced threats and educate users on recognizing and avoiding malicious links.
2 months ago
Kill Chain
Karakurt Ransomware Negotiator Sentenced to 102 Months in Prison
In May 2026, Latvian national Deniss Zolotarjovs was sentenced to 102 months in U.S. federal prison for his role as a negotiator in the Karakurt ransomware group. Operating between June 2021 and August 2023, Zolotarjovs was instrumental in extorting over 54 companies, leading to more than $56 million in losses. He employed aggressive tactics, including leveraging sensitive data such as children's health records, to pressure victims into paying ransoms. This sentencing marks a significant milestone in the fight against international cybercrime, highlighting the global reach of law enforcement agencies in apprehending and prosecuting cybercriminals. The case underscores the persistent threat posed by ransomware groups and the importance of robust cybersecurity measures to protect sensitive information.
2 months ago
Kill Chain
Fake Claude AI Website Distributes Beagle Windows Malware
In May 2026, a fraudulent website mimicking the legitimate Claude AI platform offered a malicious download named 'Claude-Pro Relay,' which installed a previously undocumented Windows backdoor called 'Beagle.' The attackers advertised this software as a high-performance relay service for Claude-Code developers. Upon execution, the installer added files to the Startup folder, enabling persistent remote access through the Beagle backdoor, which supports commands like executing system commands, file manipulation, and directory operations. The campaign utilized DLL sideloading techniques involving a signed G Data updater to deploy the malware, with command-and-control communications secured via AES encryption over TCP and UDP protocols. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/fake-claude-ai-website-delivers-new-beagle-windows-malware/amp/?utm_source=openai)) This incident underscores the growing trend of cybercriminals exploiting the popularity of AI platforms to distribute malware. The use of sophisticated techniques such as DLL sideloading and encrypted communications highlights the evolving nature of threats targeting both individual users and organizations. Vigilance in verifying software sources and monitoring for unusual system behavior remains crucial in mitigating such risks.
2 months ago
Kill Chain
Crypto Gang Member Sentenced for $250M Heist Involving Physical Burglaries
Between late 2023 and early 2025, a criminal network orchestrated a sophisticated scheme combining social engineering, hacking, and physical burglaries to steal over $250 million in cryptocurrency from victims across the United States. When digital methods failed, the group relied on Marlon Ferro, known online as 'GothFerrari,' to physically break into victims' homes and steal hardware wallets containing substantial digital assets. Ferro's actions included a February 2024 burglary in Texas, where he stole a wallet with approximately 100 Bitcoins, then valued at over $5 million. In May 2026, Ferro was sentenced to 78 months in federal prison, ordered to pay $2.5 million in restitution, and serve three years of supervised release. This case underscores the evolving tactics of cybercriminals who blend online fraud with traditional burglary to exploit vulnerabilities in digital asset security. It highlights the critical need for robust security measures, including physical safeguards for hardware wallets, to protect against such multifaceted threats.
2 months ago
Kill Chain
PCPJack Worm: A New Threat to Cloud Infrastructures
In May 2026, a new malware framework named PCPJack was discovered targeting exposed cloud infrastructures, including services like Docker, Kubernetes, Redis, MongoDB, and RayML. The malware infiltrates Linux-based cloud systems via a shell script, establishes persistence, and orchestrates credential theft at scale. Notably, PCPJack actively removes existing infections from the TeamPCP group, a known threat actor responsible for previous high-profile supply-chain breaches. This suggests that PCPJack may have been developed by a former TeamPCP affiliate or member who started their own operation. The emergence of PCPJack highlights the evolving landscape of cyber threats, where malware not only seeks to exploit systems but also competes with other malicious actors for control. This trend underscores the need for organizations to implement robust security measures, including multi-factor authentication, proper service authentication, and adherence to the principle of least privilege, to protect against such sophisticated attacks.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports