The Containment Era is here. →Explore

Industry Category

Computer/Network Security

Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.

853 threat reports
Page 33 of 72

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer/Network Security Threat Reports

Showing 385396 / 853 reports
Dutch Police 2026 Phishing Attack: A Closer Look at the Security Breach
Impact· LOW

Dutch Police 2026 Phishing Attack: A Closer Look at the Security Breach

In March 2026, the Dutch National Police experienced a security breach due to a successful phishing attack. The agency's Security Operations Center promptly detected the incident and blocked the attackers' access. Preliminary investigations indicate that the impact was limited, with no exposure of citizens' data or investigative information. A criminal investigation has been initiated to further assess the breach. This incident underscores the persistent threat of phishing attacks targeting governmental institutions. Despite previous breaches and subsequent security enhancements, such as the 2024 data breach linked to a state actor, the recurrence highlights the need for continuous vigilance and adaptive cybersecurity measures.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
European Commission's AWS Account Breach in 2026: A Wake-Up Call for Cloud Security
Impact· CRITICAL

European Commission's AWS Account Breach in 2026: A Wake-Up Call for Cloud Security

In March 2026, the European Commission, the executive body of the European Union, experienced a significant security breach when a threat actor gained unauthorized access to its Amazon Web Services (AWS) cloud environment. The attacker claimed to have exfiltrated over 350 GB of data, including multiple databases containing sensitive information about Commission employees and internal communications. The breach was promptly detected, and the Commission's cybersecurity incident response team initiated an investigation to assess the extent of the intrusion and mitigate potential damages. This incident underscores the escalating risks associated with cloud infrastructure security, especially for governmental organizations handling sensitive data. It highlights the necessity for robust cloud security measures, continuous monitoring, and rapid response capabilities to address emerging threats in the digital landscape.

4 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Fake VS Code Alerts on GitHub Distribute Malware to Developers
Impact· HIGH

Fake VS Code Alerts on GitHub Distribute Malware to Developers

In March 2026, a large-scale campaign targeted developers on GitHub by posting fake Visual Studio Code (VS Code) security alerts in the Discussions sections of various projects. These deceptive posts, crafted as vulnerability advisories with titles like 'Severe Vulnerability - Immediate Update Required,' included fake CVE IDs and urgent language. Attackers impersonated real code maintainers or researchers to enhance credibility. The posts contained links to purportedly patched versions of VS Code extensions hosted on external services such as Google Drive. Clicking these links led to a redirection chain that executed a JavaScript reconnaissance script, collecting victims' system information and sending it to the attackers' command-and-control server. This campaign highlights the increasing sophistication of social engineering attacks targeting developers through trusted platforms. Similar tactics have been observed in previous incidents, such as the March 2025 phishing campaign that targeted 12,000 GitHub repositories with fake security alerts, leading to unauthorized access to developers' accounts and repositories. The recurrence of such attacks underscores the need for heightened vigilance and robust security practices within the developer community.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
LiteLLM Supply Chain Attack: A Wake-Up Call for Open-Source Security
Impact· HIGH

LiteLLM Supply Chain Attack: A Wake-Up Call for Open-Source Security

In March 2026, the widely used Python library LiteLLM was compromised in a supply chain attack. Threat actors, identified as TeamPCP, gained access to the LiteLLM account and released malicious versions 1.82.7 and 1.82.8 on the PyPI repository. These versions contained backdoors that harvested sensitive data, including SSH keys, cloud tokens, Kubernetes secrets, and crypto wallets. The malware also attempted lateral movement across Kubernetes clusters by deploying privileged pods and established persistence via systemd backdoors. ([techradar.com](https://www.techradar.com/pro/security/top-llm-pypl-package-compromised-to-steal-user-details-heres-what-we-know?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting open-source software repositories. The compromise of LiteLLM, a tool integral to AI model management, highlights the critical need for enhanced security measures in software development pipelines to prevent similar breaches.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Unveiling Red Menshen's 2026 BPFDoor Espionage in Telecom Networks
Impact· HIGH

Unveiling Red Menshen's 2026 BPFDoor Espionage in Telecom Networks

In 2026, the China-linked threat actor Red Menshen, also known as Earth Bluecrow, conducted a prolonged cyber espionage campaign targeting telecommunications networks across the Middle East and Asia. Utilizing the stealthy Linux backdoor BPFDoor, the group infiltrated critical infrastructure, including Home Subscriber Servers (HSS), to exfiltrate sensitive subscriber data. BPFDoor's advanced evasion techniques allowed it to bypass traditional security measures, enabling Red Menshen to maintain persistent access and conduct surveillance undetected for extended periods. This incident underscores the increasing sophistication of nation-state cyber threats targeting telecom infrastructure. The use of kernel-level implants and passive backdoors like BPFDoor highlights the need for enhanced detection capabilities and proactive security measures to protect critical communication networks from such covert operations.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Red Menshen's BPFDoor Malware: A 2026 Telecom Security Wake-Up Call
Impact· CRITICAL

Red Menshen's BPFDoor Malware: A 2026 Telecom Security Wake-Up Call

In early 2026, the Chinese state-sponsored Advanced Persistent Threat (APT) group known as Red Menshen executed a sophisticated cyber-espionage campaign targeting telecommunications providers across multiple regions, including South America and Southeast Asia. Utilizing an advanced variant of their BPFDoor malware, the attackers exploited vulnerabilities in edge network devices to gain initial access. Once inside, they deployed custom Linux-based implants to establish persistent backdoors, enabling them to conduct extensive reconnaissance and exfiltrate sensitive subscriber data over an extended period. The stealthy nature of BPFDoor allowed the attackers to bypass traditional security measures, remaining undetected for months. This breach underscores the evolving tactics of nation-state actors in targeting critical infrastructure sectors, particularly telecommunications, to gather intelligence and potentially disrupt services. The incident highlights the urgent need for enhanced security measures, including robust monitoring of network edge devices and the implementation of advanced threat detection systems to identify and mitigate such sophisticated attacks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Checkmarx 2026 Supply Chain Attack: A Wake-Up Call for CI/CD Security
Impact· HIGH

Checkmarx 2026 Supply Chain Attack: A Wake-Up Call for CI/CD Security

In March 2026, the threat actor group TeamPCP executed a sophisticated supply chain attack by compromising Checkmarx's GitHub Actions, specifically the 'ast-github-action' repository. The attackers injected credential-stealing malware into all 91 tags of the repository, from v0.1-alpha through v2.3.32, enabling unauthorized access to cloud services, GitHub repositories, and CI/CD pipelines of organizations utilizing these actions. This breach underscores the critical vulnerabilities present in software supply chains and the potential for widespread impact when trusted development tools are compromised. This incident highlights the escalating trend of supply chain attacks targeting development infrastructure, emphasizing the necessity for organizations to implement stringent security measures within their CI/CD pipelines. The event also serves as a reminder of the importance of continuous monitoring and rapid response strategies to mitigate the risks associated with such sophisticated cyber threats.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Aqua Security Trivy Supply Chain Attack: A 2026 Case Study
Impact· CRITICAL

Aqua Security Trivy Supply Chain Attack: A 2026 Case Study

In March 2026, a supply chain attack targeted Aqua Security's Trivy, a widely used open-source vulnerability scanner. Unauthorized code was discovered in versions 1.8.12 and 1.8.13 of the Trivy VS Code extension on the OpenVSX registry, uploaded on February 27 and 28, 2026. The malicious code introduced hidden natural-language prompts designed to exploit developers' AI coding tools, turning them into silent data collection instruments. This tampering was not present in the public GitHub repository, making detection challenging. ([cryptika.com](https://www.cryptika.com/threat-actors-exploit-openvsx-aqua-trivy-with-malicious-ai-prompts-to-hijack-local-coding-tools/?utm_source=openai)) This incident underscores the growing trend of supply chain attacks targeting development tools, emphasizing the need for rigorous validation of third-party components. Organizations must enhance their security practices to mitigate risks associated with compromised software dependencies.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Emerging Threat: The Underground Trade of Paid AI Accounts in 2026
Impact· MEDIUM

Emerging Threat: The Underground Trade of Paid AI Accounts in 2026

In early 2026, cybersecurity researchers uncovered a burgeoning underground market where cybercriminals are actively trading access to paid AI accounts. These accounts, associated with platforms like ChatGPT, Claude, Microsoft Copilot, and Perplexity, are being sold on dark web forums and encrypted messaging channels. Threat actors obtain these accounts through various means, including credential theft, exploitation of exposed API keys, and abuse of trial programs. The illicit access enables cybercriminals to leverage advanced AI tools for malicious activities such as crafting sophisticated phishing campaigns, automating fraudulent operations, and generating convincing social engineering content. This trend underscores the evolving tactics of cybercriminals who are increasingly integrating AI capabilities into their operations to enhance the scale and effectiveness of their attacks. Organizations must recognize the critical importance of securing AI platform credentials and monitoring for unauthorized access to prevent potential misuse. ([flare.io](https://flare.io/learn/resources/webinars-events/how-the-dark-web-is-reacting-to-the-ai-revolution-2?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
GlassWorm Malware Exploits Open VSX Extensions to Target macOS Systems
Impact· HIGH

GlassWorm Malware Exploits Open VSX Extensions to Target macOS Systems

In late January 2026, a sophisticated supply chain attack compromised the Open VSX Registry, a platform for Visual Studio Code extensions. Threat actors gained unauthorized access to the developer account 'oorzc' and published malicious updates to four widely used extensions, collectively downloaded over 22,000 times. These updates embedded the GlassWorm malware loader, which, upon installation, targeted macOS systems to steal credentials, browser data, and cryptocurrency wallet information. The malware employed advanced evasion techniques, including locale-based profiling and utilizing the Solana blockchain for command-and-control communication, complicating detection and mitigation efforts. ([socket.dev](https://socket.dev/blog/glassworm-loader-hits-open-vsx-via-suspected-developer-account-compromise?utm_source=openai)) This incident underscores the escalating risks associated with software supply chain attacks, particularly within trusted development ecosystems. The use of blockchain technology for command-and-control highlights the evolving sophistication of threat actors, necessitating enhanced vigilance and robust security measures in software development and distribution processes.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Palo Alto Networks' 2025 Data Breach: A Supply Chain Attack via Salesloft Drift
Impact· MEDIUM

Palo Alto Networks' 2025 Data Breach: A Supply Chain Attack via Salesloft Drift

In August 2025, Palo Alto Networks experienced a significant data breach resulting from a supply chain attack targeting the Salesloft Drift platform. Attackers exploited stolen OAuth tokens to gain unauthorized access to Salesforce environments, leading to the exfiltration of sensitive data, including business contacts, internal sales records, and support case information. The breach affected hundreds of organizations globally, with Palo Alto Networks among the impacted entities. ([techradar.com](https://www.techradar.com/pro/security/palo-alto-networks-becomes-the-latest-to-confirm-it-was-hit-by-salesloft-drift-attack?utm_source=openai)) This incident underscores the escalating risks associated with third-party integrations and the critical need for robust supply chain security measures. The attack highlights the importance of vigilant monitoring and rapid response strategies to mitigate potential vulnerabilities in interconnected systems. ([breached.company](https://breached.company/major-supply-chain-attack-palo-alto-networks-and-zscaler-hit-by-salesloft-drift-breach/?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Aqua Security's Trivy Repository Compromised in AI-Powered Supply Chain Attack
Impact· CRITICAL

Aqua Security's Trivy Repository Compromised in AI-Powered Supply Chain Attack

In late February 2026, Aqua Security's Trivy repository was compromised through a sophisticated supply chain attack. Threat actors exploited a misconfigured GitHub Actions workflow to steal a Personal Access Token, enabling them to publish malicious versions (1.8.12 and 1.8.13) of the Trivy VS Code extension on the OpenVSX registry. These versions contained hidden AI prompts designed to hijack local AI coding assistants, such as GitHub Copilot and OpenAI Codex, to perform system reconnaissance and attempt data exfiltration. The malicious extensions were quickly identified and removed, mitigating potential widespread impact. ([awesomeagents.ai](https://awesomeagents.ai/news/hackerbot-claw-trivy-github-actions-compromise/?utm_source=openai)) This incident underscores the escalating threat of AI-powered exploits in software supply chains. As AI tools become more integrated into development environments, they present new vectors for attackers to manipulate and exploit, highlighting the need for enhanced security measures and vigilance in CI/CD pipelines.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports