The Containment Era is here. →Explore

Industry Category

Computer/Network Security

Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.

851 threat reports
Page 31 of 71

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer/Network Security Threat Reports

Showing 361372 / 851 reports
Drift Protocol's $285 Million Exploit: A Case Study in DeFi Vulnerabilities
Impact· CRITICAL

Drift Protocol's $285 Million Exploit: A Case Study in DeFi Vulnerabilities

On April 1, 2026, Solana-based decentralized exchange Drift Protocol suffered a significant security breach resulting in the loss of approximately $285 million. The attackers employed a sophisticated strategy involving the creation of a fictitious asset, CarbonVote Token (CVT), which was manipulated to appear as legitimate collateral through wash trading and oracle exploitation. Utilizing pre-signed durable nonce transactions and social engineering tactics, the attackers gained unauthorized access to Drift's administrative controls, enabling them to list CVT as valid collateral and remove withdrawal limits. This allowed for rapid, large-scale withdrawals of genuine assets, including USDC, SOL, and JLP tokens, within a 12-minute window. The stolen funds were swiftly bridged to Ethereum, complicating recovery efforts. ([trmlabs.com](https://www.trmlabs.com/resources/blog/north-korean-hackers-attack-drift-protocol-in-285-million-heist?utm_source=openai)) This incident underscores the evolving threat landscape in decentralized finance (DeFi), highlighting the vulnerabilities associated with governance mechanisms, oracle dependencies, and administrative controls. The use of durable nonce transactions and social engineering reflects a trend towards more complex and coordinated attacks targeting DeFi platforms. Additionally, the suspected involvement of North Korean state-sponsored actors emphasizes the geopolitical dimensions of cyber threats in the cryptocurrency sector. ([thehackernews.com](https://thehackernews.com/2026/04/drift-loses-285-million-in-durable.html?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
TA416's Renewed Cyber Espionage Campaigns Target European Governments
Impact· HIGH

TA416's Renewed Cyber Espionage Campaigns Target European Governments

In mid-2025, the China-aligned threat actor TA416 resumed cyber espionage operations targeting European government and diplomatic entities after a two-year hiatus. The group employed sophisticated techniques, including web bug reconnaissance and evolving malware delivery methods, to deploy the PlugX backdoor via DLL sideloading. These campaigns primarily focused on individuals associated with NATO and EU delegations, leveraging compromised accounts and freemail services to distribute malicious payloads. ([proofpoint.com](https://www.proofpoint.com/us/blog/threat-insight/id-come-running-back-eu-again-ta416-resumes-european-government-espionage?utm_source=openai)) This resurgence underscores the persistent threat posed by state-sponsored actors to governmental institutions, highlighting the need for enhanced cybersecurity measures and vigilance against evolving attack vectors. ([proofpoint.com](https://www.proofpoint.com/us/blog/threat-insight/id-come-running-back-eu-again-ta416-resumes-european-government-espionage?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CoBRA: Revolutionizing Malware Analysis by Simplifying MBA Obfuscation
Impact· NONE

CoBRA: Revolutionizing Malware Analysis by Simplifying MBA Obfuscation

On April 3, 2026, Trail of Bits released CoBRA, an open-source tool designed to simplify Mixed Boolean-Arithmetic (MBA) obfuscation. MBA obfuscation, commonly used by malware authors and software protectors, disguises simple operations behind complex arithmetic and bitwise expressions, making analysis challenging. CoBRA effectively simplifies 99.86% of over 73,000 tested expressions, providing security professionals with a powerful resource for deobfuscating code and enhancing malware analysis. The release of CoBRA addresses a significant challenge in cybersecurity, as MBA obfuscation has been a persistent hurdle in malware analysis. By automating the simplification process, CoBRA enables faster and more accurate analysis of obfuscated code, thereby improving threat detection and response capabilities.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
ICE's Deployment of Paragon Spyware in 2026: A Privacy Concern
Impact· HIGH

ICE's Deployment of Paragon Spyware in 2026: A Privacy Concern

In April 2026, U.S. Immigration and Customs Enforcement (ICE) confirmed the deployment of Paragon Solutions' spyware, Graphite, in domestic drug trafficking investigations. This decision followed the reactivation of a $2 million contract with Paragon in September 2025, after an initial suspension due to privacy concerns. The spyware enables ICE to access encrypted communications, such as WhatsApp messages, directly from targeted devices, raising significant constitutional and privacy issues. The use of Graphite has been linked to previous surveillance of journalists and activists in Europe, intensifying concerns about potential misuse within the United States. The deployment of such advanced surveillance tools by ICE underscores the ongoing tension between national security objectives and individual privacy rights, highlighting the need for robust oversight and clear legal frameworks to prevent potential abuses.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Residential Proxies: The Silent Threat Bypassing IP Reputation Systems
Impact· LOW

Residential Proxies: The Silent Threat Bypassing IP Reputation Systems

In April 2026, cybersecurity intelligence firm GreyNoise analyzed 4 billion malicious sessions over three months, revealing that 39% originated from residential networks, with 78% of these evading IP reputation systems. This evasion is attributed to the rapid rotation and short lifespan of residential proxies, which are often used for network scanning and reconnaissance. The study highlights the challenges in distinguishing malicious traffic from legitimate users due to the dynamic nature of residential proxies. The increasing use of residential proxies by threat actors underscores the limitations of traditional IP reputation systems. Organizations are urged to adopt behavior-based detection methods, such as monitoring for sequential probing from rotating IPs and tracking device fingerprints that persist despite IP changes, to effectively identify and mitigate such threats.

3 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Anthropic's 2026 Claude Code Source Code Leak Exploited to Distribute Infostealer Malware
Impact· MEDIUM

Anthropic's 2026 Claude Code Source Code Leak Exploited to Distribute Infostealer Malware

In March 2026, Anthropic inadvertently exposed over 500,000 lines of Claude Code's source code due to a packaging error, leading to its rapid dissemination on platforms like GitHub. Threat actors exploited this leak by creating malicious GitHub repositories that masqueraded as the leaked code, enticing users to download files that deployed Vidar infostealer malware upon execution. This incident underscores the critical need for robust internal security measures and vigilance against opportunistic cyber threats that capitalize on such exposures. The exploitation of this leak highlights a growing trend where cybercriminals swiftly leverage publicly disclosed vulnerabilities to distribute malware, emphasizing the importance of prompt incident response and comprehensive security protocols to mitigate potential damages.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
WhatsApp 2026: Italian Surveillance Firm's Fake iOS App Distributes Spyware
Impact· MEDIUM

WhatsApp 2026: Italian Surveillance Firm's Fake iOS App Distributes Spyware

In April 2026, WhatsApp identified approximately 200 users, primarily in Italy, who were deceived into installing a counterfeit version of the app containing spyware. The malicious application was developed by ASIGINT, a subsidiary of the Italian surveillance firm SIO, and was distributed through unofficial channels. Upon discovery, WhatsApp logged affected users out of their accounts, alerted them to the security risks, and advised them to reinstall the official app from trusted sources. This incident underscores the persistent threat posed by social engineering tactics and the importance of downloading applications exclusively from official app stores. The proliferation of sophisticated spyware tools like those developed by ASIGINT highlights the evolving landscape of cyber threats targeting mobile devices. Organizations and individuals must remain vigilant against such deceptive practices to safeguard their privacy and security.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Security Alert: CVE-2026-5281 in Google Chrome's Dawn Component
Impact· HIGH

Critical Security Alert: CVE-2026-5281 in Google Chrome's Dawn Component

In April 2026, a critical use-after-free vulnerability, identified as CVE-2026-5281, was discovered in Google Chrome's Dawn component, which handles WebGPU operations. This flaw allows remote attackers who have compromised the renderer process to execute arbitrary code via crafted HTML pages. The vulnerability affects Chrome versions prior to 146.0.7680.178. Google has released a patch to address this issue, and users are strongly advised to update their browsers immediately to mitigate potential risks. ([leakycreds.com](https://www.leakycreds.com/vulnerability/CVE-2026-5281?utm_source=openai)) The inclusion of CVE-2026-5281 in CISA's Known Exploited Vulnerabilities catalog underscores the severity of the threat, as it has been actively exploited in the wild. This incident highlights the ongoing challenges in securing widely used software components and the importance of timely updates to protect against emerging threats. ([thecyberthrone.in](https://thecyberthrone.in/2026/04/02/cve-2026-5281-google-chrome-dawn-use-after-free-under-active-exploitation/?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Coruna iPhone Hacking Toolkit Leak: A Wake-Up Call for Cybersecurity
Impact· HIGH

Coruna iPhone Hacking Toolkit Leak: A Wake-Up Call for Cybersecurity

In early 2026, security researchers uncovered 'Coruna,' a sophisticated iPhone hacking toolkit comprising 23 exploits across five attack chains, targeting iOS versions 13.0 through 17.2.1. Initially developed by U.S. defense contractor L3Harris's division Trenchant, Coruna was intended for government use. However, it leaked and was subsequently utilized by Russian espionage groups and Chinese cybercriminals, leading to widespread data theft and compromising tens of thousands of devices. ([techcrunch.com](https://techcrunch.com/2026/03/09/an-iphone-hacking-toolkit-used-by-russian-spies-likely-came-from-u-s-military-contractor/?utm_source=openai)) The Coruna incident underscores the risks associated with the proliferation of advanced cyber tools beyond their original intent. It highlights the urgent need for robust security measures and timely software updates to protect against such sophisticated threats. ([techcrunch.com](https://techcrunch.com/2026/03/26/a-major-hacking-tool-has-leaked-online-putting-millions-of-iphones-at-risk-heres-what-you-need-to-know/?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
CERT-UA Impersonation Campaign: UAC-0255's AGEWHEEZE Malware Attack
Impact· LOW

CERT-UA Impersonation Campaign: UAC-0255's AGEWHEEZE Malware Attack

In late March 2026, the threat actor group UAC-0255 launched a phishing campaign impersonating the Computer Emergency Response Team of Ukraine (CERT-UA). The attackers sent emails on March 26 and 27, 2026, posing as CERT-UA to distribute a password-protected ZIP archive hosted on Files.fm, urging recipients to install the 'specialized software.' The ZIP file ('CERT_UA_protection_tool.zip') is designed to download malware packaged as security software from the agency. The targets of the campaign included state organizations, medical centers, security companies, educational institutions, financial institutions, and software development companies. Some of the emails were sent from the email address 'incidents@cert-ua[.]tech.'

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
UNC1069's 2026 Supply Chain Attack on Axios: A Wake-Up Call for Open-Source Security
Impact· HIGH

UNC1069's 2026 Supply Chain Attack on Axios: A Wake-Up Call for Open-Source Security

In late March 2026, the widely-used JavaScript library Axios was compromised through a sophisticated supply chain attack. Attackers gained access to the npm account of a lead maintainer and published two malicious versions: axios@1.14.1 and axios@0.30.4. These versions included a trojanized dependency, 'plain-crypto-js@4.2.1', which executed a cross-platform Remote Access Trojan (RAT) upon installation, targeting Windows, macOS, and Linux systems. The malicious packages were live for approximately three hours before being removed, but the potential impact was significant due to Axios's extensive use in the developer community. ([securitylabs.datadoghq.com](https://securitylabs.datadoghq.com/articles/axios-npm-supply-chain-compromise/?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks, particularly those targeting open-source ecosystems. The attribution to North Korean threat actor UNC1069 highlights the increasing involvement of state-sponsored groups in such attacks, emphasizing the need for enhanced security measures in software development pipelines. ([cyberkendra.com](https://www.cyberkendra.com/2026/04/north-korean-hackers-behind-axios-npm.html?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
TeamPCP's 2026 Cloud Breaches: A Wake-Up Call for Supply Chain Security
Impact· HIGH

TeamPCP's 2026 Cloud Breaches: A Wake-Up Call for Supply Chain Security

In March 2026, the threat actor group TeamPCP executed a series of sophisticated supply chain attacks, compromising widely used open-source tools such as Trivy, KICS, LiteLLM, and Telnyx. By injecting malicious code into these trusted software packages, TeamPCP deployed infostealer malware to harvest sensitive credentials, including API keys, SSH keys, and cloud service tokens. Utilizing the stolen credentials, the group swiftly breached cloud environments across AWS, Azure, and various SaaS platforms, conducting extensive reconnaissance and data exfiltration activities. This campaign underscores the critical need for organizations to promptly rotate and revoke compromised credentials to mitigate the risk of unauthorized access and data breaches. The rapid escalation and breadth of TeamPCP's attacks highlight a concerning trend in cyber threats, emphasizing the importance of securing software supply chains and implementing robust monitoring mechanisms to detect and respond to credential misuse promptly.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports