✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Russian Hackers Exploit Signal and WhatsApp in Sophisticated Phishing Campaign
In March 2026, Dutch intelligence agencies reported a large-scale global cyber campaign by Russian state-sponsored hackers targeting Signal and WhatsApp accounts of dignitaries, military personnel, and journalists. The attackers employed social engineering techniques, such as impersonating support chatbots, to deceive users into revealing security verification codes and PINs. This allowed unauthorized access to individual accounts, enabling the interception of sensitive communications. Notably, the campaign did not exploit technical vulnerabilities within the messaging platforms themselves but rather manipulated legitimate security features through phishing tactics. ([english.aivd.nl](https://english.aivd.nl/latest/news/2026/03/09/russia-targets-signal-and-whatsapp-accounts-in-cyber-campaign?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors utilizing sophisticated social engineering methods to compromise secure communication channels. The focus on widely used encrypted messaging applications highlights the need for heightened vigilance and robust security practices among high-profile individuals and organizations to safeguard sensitive information.
4 months ago
Kill Chain
Aisuru and Kimwolf Botnets' 2025 Record-Breaking DDoS Attacks
In December 2025, the Aisuru and Kimwolf botnets orchestrated a record-breaking Distributed Denial of Service (DDoS) attack, peaking at 31.4 terabits per second (Tbps) and delivering 200 million requests per second. This unprecedented assault targeted multiple companies, predominantly in the telecommunications sector, and was part of a broader campaign dubbed "The Night Before Christmas." The attack leveraged a vast network of compromised Internet of Things (IoT) devices, including Android TVs and streaming boxes, to generate massive traffic volumes. ([hackmag.com](https://hackmag.com/news/aisuru-31-4-tbps?utm_source=openai)) The incident underscores the escalating scale and sophistication of DDoS attacks, highlighting the critical need for robust cybersecurity measures. The rapid proliferation of vulnerable IoT devices has provided attackers with extensive resources to launch such large-scale assaults. Organizations must prioritize securing these devices and implementing advanced DDoS mitigation strategies to defend against evolving cyber threats. ([fastnetmon.com](https://fastnetmon.com/2026/02/01/aisuru-botnet-sets-a-new-ddos-record-at-31-4-tbps/?utm_source=openai))
4 months ago
Kill Chain
Cisco FMC 2026: Interlock Ransomware's Exploitation of Insecure Deserialization
In early 2026, a critical vulnerability (CVE-2026-20131) was discovered in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. This flaw allowed unauthenticated, remote attackers to execute arbitrary Java code as root by exploiting insecure deserialization of user-supplied Java byte streams. The Interlock ransomware group actively exploited this vulnerability as a zero-day since late January 2026, targeting several high-profile organizations, including DaVita, Kettering Health, the Texas Tech University System, and the city of Saint Paul, Minnesota. The exploitation of CVE-2026-20131 underscores the persistent threat posed by sophisticated ransomware groups leveraging zero-day vulnerabilities. Organizations must prioritize timely patching and robust security measures to mitigate such risks.
4 months ago
Kill Chain
Trivy Security Scanner Compromised: A Wake-Up Call for CI/CD Security
In late February 2026, Aqua Security's Trivy, a widely-used open-source vulnerability scanner, was compromised through its GitHub Actions workflows. An autonomous AI bot named 'hackerbot-claw' exploited vulnerabilities in Trivy's CI/CD pipeline, leading to unauthorized code execution and the exfiltration of sensitive CI/CD secrets. This breach resulted in the deletion of Trivy's GitHub repository content, disrupting numerous organizations relying on Trivy for security scanning. ([medium.com](https://medium.com/%40abhishekchauhan_68324/your-security-scanner-is-the-attack-vector-6d2a175a4f5b?utm_source=openai)) This incident underscores the escalating threat of AI-driven supply chain attacks targeting CI/CD pipelines. The automation and adaptability demonstrated by 'hackerbot-claw' highlight the urgent need for enhanced security measures in development workflows to prevent similar breaches.
4 months ago
Kill Chain
Critical Vulnerability in Cisco Secure Firewall Management Center: CVE-2026-20131
In March 2026, a critical vulnerability (CVE-2026-20131) was identified in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. This flaw allows unauthenticated, remote attackers to execute arbitrary Java code as root by exploiting insecure deserialization of user-supplied Java byte streams. Successful exploitation could lead to full system compromise, granting attackers complete control over affected devices. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh?utm_source=openai)) The vulnerability underscores the persistent risks associated with deserialization flaws in network management systems. Organizations are urged to apply Cisco's security patches promptly and restrict public internet access to FMC management interfaces to mitigate potential exploitation. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh?utm_source=openai))
4 months ago
Kill Chain
EDR Killer Malware Exploits Vulnerable Drivers to Disable Security Tools
In early February 2026, threat actors exploited compromised SonicWall SSLVPN credentials to infiltrate a corporate network. Once inside, they deployed a custom 'EDR killer' malware that utilized a signed but revoked EnCase forensic driver to disable 59 endpoint detection and response (EDR) and antivirus tools. This 'Bring Your Own Vulnerable Driver' (BYOVD) technique allowed attackers to gain kernel-level access, effectively neutralizing security defenses and facilitating further malicious activities. The intrusion was disrupted before ransomware deployment, but it underscores the growing trend of adversaries weaponizing legitimate drivers to bypass endpoint security measures. ([huntress.com](https://www.huntress.com/blog/encase-byovd-edr-killer?utm_source=openai)) This incident highlights the critical need for organizations to enforce multi-factor authentication (MFA) on VPN access, regularly update and monitor security tools, and implement strict controls over driver installations to prevent the exploitation of vulnerable drivers. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/05/edr-killer-vulnerable-encase-driver/?utm_source=openai))
4 months ago
Kill Chain
Interlock Ransomware's 2026 Exploitation of Cisco Firewall Vulnerability
In early 2026, the Interlock ransomware group exploited a zero-day vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC) Software, allowing unauthenticated remote code execution as root. This critical flaw, due to insecure deserialization of user-supplied Java byte streams, enabled attackers to gain full control over affected devices. The exploitation began on January 26, 2026, 36 days prior to Cisco's public disclosure on March 4, 2026. Interlock's campaign involved deploying custom remote access trojans, reconnaissance scripts, and evasion techniques, leading to significant operational disruptions for targeted organizations. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh?utm_source=openai)) This incident underscores the persistent threat posed by ransomware groups leveraging zero-day vulnerabilities. Organizations must prioritize timely patching, implement defense-in-depth strategies, and maintain continuous threat monitoring to mitigate such risks.
4 months ago
Kill Chain
DarkSword iOS Exploit Kit: A New Threat in 2026
In early 2026, cybersecurity researchers discovered 'DarkSword,' an advanced iOS exploit kit attributed to Russian hackers. This toolkit repurposes vulnerabilities believed to have been originally developed by the U.S. government. DarkSword targets iOS devices through sophisticated attack chains, enabling unauthorized access to sensitive user data, including messages, passwords, and cryptocurrency wallets. The exploit kit has been deployed in espionage campaigns against individuals in Ukraine, Saudi Arabia, Turkey, and Malaysia, affecting potentially millions of iPhone users worldwide. The emergence of DarkSword underscores the escalating trend of nation-state actors leveraging leaked or repurposed cyber tools to conduct widespread surveillance and financial theft. This incident highlights the critical need for robust cybersecurity measures and timely software updates to mitigate the risks posed by such sophisticated threats.
4 months ago
Kill Chain
LayerX Uncovers Font-Rendering Exploit Targeting AI Assistants
In March 2026, LayerX researchers unveiled a novel font-rendering attack that exploits discrepancies between how AI assistants and web browsers interpret HTML content. By utilizing custom fonts and CSS techniques, attackers can display malicious commands to users while presenting benign content to AI tools analyzing the same page. This method effectively deceives AI assistants into endorsing harmful instructions, leading users to execute potentially dangerous commands under false assurances of safety. This incident underscores a critical vulnerability in AI-assisted browsing, highlighting the need for enhanced security measures that account for the visual rendering of web content. As AI tools become increasingly integrated into daily workflows, understanding and mitigating such sophisticated social engineering tactics is imperative to maintain user trust and system integrity.
4 months ago
Kill Chain
Unveiling the Stealth: China's Prolonged Cyber Espionage in Southeast Asia
In March 2026, Palo Alto Networks' Unit 42 uncovered a prolonged cyber espionage campaign attributed to Chinese state-sponsored actors, targeting military organizations in Southeast Asia since at least 2020. The attackers employed novel backdoors, including 'AppleChris' and 'MemFun,' and utilized dead-drop resolvers on platforms like Pastebin and Dropbox to maintain covert command-and-control channels. Their operations focused on exfiltrating sensitive military data, such as information on capabilities, organizational structures, and collaborations with Western forces. The campaign demonstrated strategic patience, with attackers maintaining undetected access for extended periods and employing advanced evasion techniques like delayed execution and timestomping to avoid detection. This incident underscores the evolving sophistication of state-sponsored cyber threats, highlighting the need for organizations to enhance their cybersecurity measures. The use of legitimate web services for malicious activities and the deployment of custom malware with advanced evasion tactics reflect a broader trend in cyber espionage, emphasizing the importance of proactive threat intelligence and robust security protocols.
4 months ago
Kill Chain
Introducing Augustus: Praetorian's Open-Source LLM Vulnerability Scanner
In February 2026, Praetorian released Augustus, an open-source vulnerability scanner designed to test Large Language Models (LLMs) against a comprehensive suite of adversarial attacks. Augustus automates over 210 distinct attack vectors, including prompt injections and jailbreaks, across 28 LLM providers. This tool addresses the growing need for robust security testing as enterprises rapidly integrate generative AI into their products. By providing a portable, single-binary solution, Augustus facilitates seamless integration into continuous integration/continuous deployment (CI/CD) pipelines, enabling security teams to identify and mitigate vulnerabilities efficiently. The release of Augustus underscores the escalating threats targeting LLMs, as adversaries increasingly exploit these models for malicious purposes. The tool's comprehensive testing capabilities highlight the necessity for organizations to proactively assess and fortify their AI systems against evolving attack methodologies.
4 months ago
Kill Chain
South Korea's NTS Security Lapse Results in $4.8M Crypto Theft
In February 2026, South Korea's National Tax Service (NTS) conducted raids on 124 high-value tax evaders, seizing digital assets worth approximately $5.6 million. During a press release showcasing the operation, the NTS inadvertently published images displaying a Ledger hardware wallet alongside a handwritten note containing the wallet's mnemonic recovery phrase. This exposure allowed an unauthorized individual to access and transfer 4 million Pre-Retogeum (PRTG) tokens, valued at about $4.8 million, from the confiscated wallet. The NTS has since apologized for the oversight and initiated measures to prevent similar incidents in the future. ([koreajoongangdaily.joins.com](https://koreajoongangdaily.joins.com/news/2026-03-01/national/socialAffairs/Police-probing-unauthorized-crypto-transfer-after-NTS-inadvertently-shared-wallet-recovery-phrase/2534349?utm_source=openai)) This incident underscores the critical importance of secure handling and storage of digital assets, especially by governmental agencies. As cryptocurrency adoption grows, ensuring robust security protocols and staff training is essential to prevent such costly errors and maintain public trust.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports