✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Checkmarx KICS Supply Chain Breach: A 2026 Case Study
In April 2026, Checkmarx's KICS analysis tool suffered a significant supply chain attack. Threat actors compromised Docker images and VS Code extensions associated with KICS, embedding malware designed to harvest sensitive data from developer environments. The malware targeted credentials such as GitHub tokens, cloud service keys, and SSH keys, exfiltrating them to domains mimicking legitimate Checkmarx infrastructure. The breach was active between April 22, 2026, 14:17:59 UTC and April 22, 2026, 15:41:31 UTC, during which malicious artifacts were distributed through official channels. This incident underscores the escalating trend of supply chain attacks targeting development tools, emphasizing the need for enhanced security measures in software distribution pipelines. Organizations must remain vigilant, as such attacks can lead to widespread credential theft and unauthorized access to critical systems.
3 months ago
Kill Chain
Bitwarden CLI npm Package Compromised in Supply Chain Attack
In April 2026, attackers compromised Bitwarden's CLI by uploading a malicious version (2026.4.0) to npm, available between 5:57 PM and 7:30 PM ET on April 22. The malicious package contained credential-stealing malware that harvested developer secrets, including npm tokens, GitHub authentication tokens, SSH keys, and cloud credentials. The malware exfiltrated this data by creating public GitHub repositories under the victim's account. Bitwarden confirmed the incident, stating that the breach was limited to the npm distribution channel for the CLI and did not affect end-user vault data or production systems. The company revoked compromised access, deprecated the malicious release, and initiated remediation steps immediately. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/bitwarden-cli-npm-package-compromised-to-steal-developer-credentials/?utm_source=openai)) This incident underscores the growing threat of supply chain attacks targeting developer tools and CI/CD pipelines. Organizations must enhance their security measures to protect against such vulnerabilities, as similar attacks have been linked to the threat actor known as TeamPCP, who previously targeted developer packages in other supply chain attacks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/bitwarden-cli-npm-package-compromised-to-steal-developer-credentials/?utm_source=openai))
3 months ago
Kill Chain
Project Glasswing: AI's Role in Cybersecurity Vulnerability Detection
In April 2026, Anthropic unveiled Project Glasswing, a collaborative initiative with major technology companies such as Amazon, Apple, Microsoft, and Cisco, aimed at enhancing cybersecurity defenses through advanced AI. Central to this project is Claude Mythos Preview, an unreleased AI model that autonomously identified thousands of previously undetected vulnerabilities across critical software systems, including a 27-year-old bug in OpenBSD and a 16-year-old flaw in FFmpeg. To mitigate potential misuse, Anthropic has restricted access to this powerful model to select partners and committed significant resources to support open-source security organizations. This initiative underscores the growing importance of AI in cybersecurity, highlighting both its potential to fortify defenses and the risks associated with its misuse. As AI capabilities advance, the industry faces the dual challenge of leveraging these tools for protection while preventing their exploitation by malicious actors.
3 months ago
Kill Chain
GopherWhisper APT Exploits Go-Based Backdoors to Target Mongolian Government
In January 2025, ESET researchers identified a previously undocumented China-aligned advanced persistent threat (APT) group named GopherWhisper targeting Mongolian governmental institutions. The group employs a suite of tools primarily written in Go, including injectors and loaders, to deploy various backdoors such as LaxGopher, RatGopher, and BoxOfFriends. GopherWhisper leverages legitimate services like Discord, Slack, Microsoft 365 Outlook, and file.io for command-and-control (C&C) communications and data exfiltration. The group's activities have been ongoing since at least November 2023, compromising at least 12 systems within a Mongolian government entity. ([globenewswire.com](https://www.globenewswire.com/news-release/2026/04/23/3279634/0/en/ESET-Research-discovers-new-China-aligned-group-GopherWhisper-It-abuses-messaging-services-Discord-Slack-and-Outlook-to-spy.html?utm_source=openai)) This incident underscores the evolving tactics of state-sponsored threat actors who exploit widely used communication platforms to evade detection. The use of Go-based malware highlights a trend towards more versatile and cross-platform attack tools, posing significant challenges for traditional security measures. Organizations must adapt their defenses to address these sophisticated techniques.
3 months ago
Kill Chain
Chinese APT GopherWhisper Exploits Cloud Services in Mongolian Cyber Espionage
In April 2026, ESET researchers uncovered a Chinese advanced persistent threat (APT) group named GopherWhisper targeting Mongolian government institutions. Active since at least November 2023, GopherWhisper deployed multiple custom backdoors—LaxGopher, CompactGopher, RatGopher, BoxOfFriends, and SSLORDoor—each utilizing different cloud services like Slack, Discord, Microsoft Outlook, and file.io for command-and-control communications and data exfiltration. This campaign compromised at least 12 systems within a Mongolian governmental institution, with indications of broader impact across the region. This incident underscores a growing trend of APT groups leveraging legitimate cloud services to evade detection and maintain persistent access. Organizations must enhance their monitoring of cloud-based communications and implement robust security measures to detect and mitigate such sophisticated threats.
3 months ago
Kill Chain
Checkmarx Supply Chain Breach: Malicious KICS Docker Images and VS Code Extensions Detected
In April 2026, Checkmarx's supply chain was compromised when attackers uploaded malicious images to the official 'checkmarx/kics' Docker Hub repository. These images, including versions v2.1.20 and a fraudulent v2.1.21, contained modified KICS binaries with unauthorized data collection and exfiltration capabilities. Additionally, certain Visual Studio Code extensions were altered to execute remote code without user consent. Organizations using these compromised tools to scan infrastructure-as-code files risked exposing sensitive credentials and configurations. ([thehackernews.com](https://thehackernews.com/2026/04/malicious-kics-docker-images-and-vs.html?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting widely-used development tools. It highlights the necessity for organizations to implement stringent security measures, such as verifying the integrity of third-party software and continuously monitoring for unauthorized modifications, to safeguard against similar vulnerabilities.
3 months ago
Kill Chain
Insider Threat: Ransomware Negotiator's Guilty Plea in BlackCat Scheme
In April 2026, Angelo Martino, a former ransomware negotiator at DigitalMint, pleaded guilty to conspiring with the BlackCat/ALPHV ransomware group to extort U.S. companies in 2023. Martino exploited his position by providing BlackCat with confidential information about his clients' insurance policy limits and negotiation strategies, enabling the attackers to maximize ransom demands. Alongside co-conspirators Ryan Goldberg and Kevin Martin, Martino participated in deploying ransomware attacks, resulting in at least $1.2 million in Bitcoin payments from a single victim. Law enforcement has seized approximately $10 million in assets from Martino, including digital currency and luxury items. This case underscores the critical risk posed by insider threats within cybersecurity roles. The incident highlights the evolving tactics of ransomware groups and the importance of stringent internal controls to prevent insider collusion. Organizations must reassess their security protocols and ensure clear separation of duties to mitigate such risks.
3 months ago
Kill Chain
Critical Vulnerability in Cohere AI's Terrarium: CVE-2026-5752
In April 2026, a critical vulnerability (CVE-2026-5752) was identified in Cohere AI's Terrarium, a Python-based sandbox environment. This flaw allows attackers to execute arbitrary code with root privileges on the host process by exploiting JavaScript prototype chain traversal. The vulnerability has a CVSS score of 9.3, indicating its severity. ([thehackernews.com](https://thehackernews.com/2026/04/cohere-ai-terrarium-sandbox-flaw.html?utm_source=openai)) The discovery underscores the risks associated with sandbox environments, especially those handling untrusted code. Organizations utilizing Terrarium should assess their deployments and implement recommended mitigations to prevent potential exploits. ([thehackernews.com](https://thehackernews.com/2026/04/cohere-ai-terrarium-sandbox-flaw.html?utm_source=openai))
3 months ago
Kill Chain
Mustang Panda's LOTUSLITE Variant Targets Indian Banks and South Korean Policy Circles
In April 2026, cybersecurity researchers identified a new variant of the LOTUSLITE malware, attributed to the Chinese state-sponsored group Mustang Panda. This variant targeted India's banking sector and South Korean policy circles. The attack began with spear-phishing emails containing Compiled HTML (CHM) files that, when executed, deployed a backdoor communicating with a dynamic DNS-based command-and-control server over HTTPS. This backdoor facilitated remote shell access, file operations, and session management, indicating espionage-focused objectives rather than financial gain. The malware was disguised as legitimate banking software, notably referencing HDFC Bank, to deceive victims. This incident underscores the evolving tactics of nation-state actors like Mustang Panda, who are expanding their targets beyond traditional government entities to include financial institutions and policy organizations. The use of familiar yet effective techniques, such as DLL side-loading and spear-phishing, highlights the persistent threat posed by such groups and the need for organizations to remain vigilant against sophisticated cyber espionage campaigns.
3 months ago
Kill Chain
Lotus Wiper Malware Targets Venezuelan Energy Systems in Destructive Attack
In late 2025 and early 2026, a previously undocumented malware known as Lotus Wiper targeted Venezuela's energy and utilities sector. The attack began with batch scripts that disabled system defenses and disrupted operations, paving the way for the wiper to erase recovery mechanisms, overwrite physical drives, and systematically delete files, rendering systems inoperable. ([securelist.com](https://securelist.com/tr/lotus-wiper/119472/?utm_source=openai)) This incident underscores the escalating threat of destructive malware against critical infrastructure. The absence of ransom demands suggests a focus on disruption rather than financial gain, highlighting the need for robust cybersecurity measures in essential services. ([securityweek.com](https://www.securityweek.com/new-wiper-malware-targeted-venezuelan-energy-sector-prior-to-us-intervention/?utm_source=openai))
3 months ago
Kill Chain
Moltbook's 2026 Security Breach: A Wake-Up Call for AI Platform Security
In late January 2026, Moltbook, a social network designed exclusively for AI agents, suffered a significant security breach due to an exposed Supabase API key embedded in client-side JavaScript. This vulnerability allowed unauthorized access to the platform's production database, exposing 1.5 million API tokens, 35,000 email addresses, and private messages between agents. The breach was promptly identified and reported by cybersecurity firm Wiz, leading to a swift response from Moltbook to patch the vulnerability and reset all agent API keys. ([techradar.com](https://www.techradar.com/pro/security/ai-agent-social-media-network-moltbook-is-a-security-disaster-millions-of-credentials-and-other-details-left-unsecured?utm_source=openai)) This incident underscores the critical importance of implementing robust security measures, especially in rapidly developed AI-driven platforms. The exposure of sensitive data not only compromises user privacy but also highlights the potential risks associated with 'vibe coding'—developing applications with AI assistance without thorough security oversight. Organizations must prioritize security protocols to prevent similar breaches in the future. ([trustfinance.com](https://www.trustfinance.com/en-US/blog/wiz-finds-major-data-leak-in-moltbook-ai-social-network?utm_source=openai))
3 months ago
Kill Chain
Unveiling Critical APT Exploit Chains: A 2026 Analysis
In April 2026, Praetorian's analysis revealed that out of 500,000 vulnerability findings, only 14 endpoints were susceptible to critical exploit chains capable of full host compromise. These chains combined multiple vulnerabilities, including CVE-2025-4918 and CVE-2025-2857, to enable zero-click attacks through browser exploits. Notably, one chain was actively exploited by the Russian-aligned APT group RomCom, targeting sectors such as government, defense, and energy across Europe and North America. This incident underscores the necessity for organizations to move beyond traditional CVSS-based vulnerability assessments and adopt exploit chain analysis to identify and mitigate real-world attack paths effectively. The increasing sophistication of APT groups in leveraging complex exploit chains highlights the urgent need for enhanced threat intelligence integration and proactive security measures to protect critical infrastructure and sensitive data.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports