✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
US Marshals Crypto Theft 2026: Insider Threat Exposed
In March 2026, the FBI arrested John Daghita on the Caribbean island of Saint Martin for allegedly stealing over $46 million in cryptocurrency from the U.S. Marshals Service (USMS). Daghita, son of Dean Daghita—president of Command Services & Support (CMDSS), a firm contracted by the USMS to manage seized digital assets—allegedly exploited his insider access to siphon funds from government-controlled wallets. The theft was uncovered by blockchain investigator ZachXBT, who traced the illicit transactions back to Daghita after he inadvertently exposed his control over the funds during a recorded Telegram dispute. This incident underscores the critical need for stringent oversight and security measures when managing sensitive digital assets, especially within government agencies. The breach highlights the vulnerabilities associated with insider threats and the importance of robust monitoring and auditing protocols to prevent unauthorized access and theft of digital currencies.
4 months ago
Kill Chain
FBI and Europol Dismantle LeakBase Cybercriminal Forum in 2026
In early March 2026, a coordinated international law enforcement operation led by the FBI and Europol successfully dismantled LeakBase, one of the world's largest online forums for cybercriminals. Established in 2021, LeakBase had over 142,000 registered users and facilitated the trade of stolen data, including account credentials, credit card numbers, and other sensitive personal information. The operation involved seizing the forum's domains, arresting key individuals, and preserving extensive user data for evidentiary purposes. ([justice.gov](https://www.justice.gov/usao-ut/pr/united-states-leads-dismantlement-one-worlds-largest-hacker-forums?utm_source=openai)) This takedown underscores the escalating global efforts to combat cybercrime and disrupt platforms that enable the illicit exchange of stolen data. The success of this operation highlights the importance of international collaboration in addressing the growing threat posed by cybercriminal forums and marketplaces.
4 months ago
Kill Chain
Bing AI Promotes Malicious OpenClaw Installers Distributing Info-Stealing Malware
In February 2026, threat actors exploited the popularity of OpenClaw, an open-source AI agent, by creating malicious GitHub repositories posing as legitimate OpenClaw installers. These repositories were promoted through Microsoft's Bing AI-enhanced search results, leading users to download and execute malware-laden installers. Upon execution, these installers deployed various malicious payloads, including the Vidar information stealer and GhostSocks proxy malware, compromising sensitive user data and converting infected machines into proxy nodes for further malicious activities. This incident underscores the evolving tactics of cybercriminals who leverage trusted platforms and emerging technologies to distribute malware. The use of AI-enhanced search results to promote malicious content highlights the need for enhanced vigilance and security measures in AI-driven platforms and search engines.
4 months ago
Kill Chain
UAT-9244's New Malware Threatens South American Telecoms
Since 2024, the China-linked advanced persistent threat actor UAT-9244 has been targeting telecommunication service providers in South America, compromising Windows, Linux, and network-edge devices. The group employs three previously undocumented malware families: TernDoor, a Windows backdoor; PeerTime, a Linux backdoor utilizing the BitTorrent protocol; and BruteEntry, a brute-force scanner that establishes proxy infrastructure. These tools enable UAT-9244 to maintain persistent access, execute remote commands, and expand their network infiltration. This incident underscores the evolving sophistication of state-sponsored cyber threats targeting critical infrastructure. The use of novel malware and advanced techniques highlights the need for enhanced cybersecurity measures and vigilance within the telecommunications sector.
4 months ago
Kill Chain
OpenClaw AI Security Breach 2026: A Wake-Up Call for AI Security
In early 2026, OpenClaw, an open-source AI assistant, experienced multiple security breaches due to misconfigurations and vulnerabilities. Attackers exploited exposed instances to gain unauthorized access, leading to data exfiltration and system compromises. Notably, over 40,000 instances were found exposed on the public internet, with many lacking proper authentication, allowing cybercriminals to deploy infostealer malware and hijack AI agents. ([blog.barrack.ai](https://blog.barrack.ai/openclaw-security-vulnerabilities-2026/?utm_source=openai)) These incidents underscore the critical need for robust security measures in AI deployments. The rapid adoption of AI agents like OpenClaw, coupled with inadequate security configurations, has created significant attack surfaces. Organizations must prioritize securing AI systems to prevent unauthorized access and data breaches, especially as AI integration becomes more prevalent in personal and professional environments.
4 months ago
Kill Chain
Critical Vulnerability in Tauri Framework's Shell Plugin Leads to Remote Code Execution
In April 2025, a critical vulnerability (CVE-2025-31477) was identified in the Tauri framework's shell plugin, which is used for building cross-platform desktop applications. This flaw allowed unregulated access to system shell operations, enabling attackers to execute arbitrary code on affected systems. The vulnerability stemmed from improper validation of allowed protocols in the plugin's 'open' endpoint, permitting potentially dangerous protocols like 'file://', 'smb://', and 'nfs://'. Exploitation required either direct exposure of the endpoint to application users or code execution within the frontend of a Tauri application. The issue was addressed in version 2.2.1 of the plugin. ([github.com](https://github.com/tauri-apps/plugins-workspace/security/advisories/GHSA-c9pr-q8gx-3mgp?utm_source=openai)) This incident underscores the importance of rigorous input validation and protocol handling in application development. As frameworks like Tauri gain popularity for their efficiency in building cross-platform applications, ensuring the security of their components becomes paramount. Developers are urged to promptly update to patched versions and adhere to best practices in secure coding to mitigate such vulnerabilities.
4 months ago
Kill Chain
BadeSaba Calendar App Hack: A New Front in Cyber Warfare
In late February 2026, during coordinated military strikes by the United States and Israel on Iranian targets, the BadeSaba Calendar app—a widely used prayer-timing application with over 5 million downloads—was compromised. Users received push notifications in Persian urging military personnel and civilians to defect, lay down arms, or join opposition forces. Messages included phrases such as "Help has arrived" and "It's time for reckoning." This cyber operation coincided with physical airstrikes and resulted in a near-total internet blackout in Iran, disrupting government communications, state media, and public services. ([en.wikipedia.org](https://en.wikipedia.org/wiki/Cyberwarfare_during_the_2026_Iran_war?utm_source=openai)) This incident underscores the evolving landscape of cyber warfare, where digital platforms are exploited to disseminate psychological operations alongside kinetic military actions. The strategic use of a trusted religious app to deliver propaganda highlights the need for robust cybersecurity measures, especially for applications with significant user bases in geopolitically sensitive regions.
4 months ago
Kill Chain
Unveiling the 2025 Salesloft Drift Supply Chain Attack: Implications and Lessons
In August 2025, a significant supply chain attack targeted the Salesloft Drift AI chatbot integration, compromising OAuth tokens and affecting over 700 organizations, including Cloudflare, Palo Alto Networks, and Zscaler. Attackers exploited these tokens to gain unauthorized access to Salesforce instances, exfiltrating sensitive data such as AWS access keys and passwords. The breach originated from a compromised Salesloft GitHub account, accessed between March and June 2025, allowing attackers to manipulate repositories and establish malicious workflows. This incident underscores the critical vulnerabilities present in third-party integrations and the necessity for stringent security measures in interconnected systems. The attack highlights the growing trend of cybercriminals leveraging trusted platforms to infiltrate organizations, emphasizing the need for enhanced monitoring and control over third-party services.
4 months ago
Kill Chain
Global Operation Dismantles Tycoon2FA Phishing Platform
In March 2026, a coordinated international operation led by Europol and Microsoft successfully dismantled Tycoon2FA, a prominent phishing-as-a-service (PhaaS) platform active since August 2023. Tycoon2FA enabled cybercriminals to bypass multi-factor authentication (MFA) by intercepting live authentication sessions, capturing credentials, one-time passcodes, and session cookies in real time. This service was responsible for tens of millions of phishing emails each month, targeting over 500,000 organizations globally, including schools, hospitals, and public institutions. The takedown involved seizing 330 domains that formed the platform's core infrastructure, significantly disrupting its operations and mitigating further harm. ([blogs.microsoft.com](https://blogs.microsoft.com/on-the-issues/2026/03/04/how-a-global-coalition-disrupted-tycoon/?utm_source=openai)) The dismantling of Tycoon2FA underscores the evolving sophistication of cyber threats, particularly the commoditization of tools that facilitate large-scale MFA bypass attacks. This incident highlights the critical need for organizations to adopt phishing-resistant authentication mechanisms and enhance their cybersecurity posture to defend against such advanced threats. ([newsroom.trendmicro.com](https://newsroom.trendmicro.com/2026-03-04-TrendAI-TM-Helps-Drive-Global-Takedown-of-Tycoon-2FA-MFA-Bypass-Phishing-Service?utm_source=openai))
4 months ago
Kill Chain
UMMC's 2026 Ransomware Attack: A Wake-Up Call for Healthcare Cybersecurity
In February 2026, the University of Mississippi Medical Center (UMMC) experienced a significant ransomware attack attributed to the Medusa ransomware group. The attack led to the closure of 35 clinics and the cancellation of elective procedures, severely disrupting healthcare services. UMMC's electronic health record system and communication networks were compromised, necessitating a shift to manual operations. The medical center collaborated with federal authorities, including the FBI, to investigate and mitigate the attack. After nine days, UMMC restored its systems and resumed normal operations. ([nationaltoday.com](https://nationaltoday.com/us/ms/jackson/news/2026/03/04/ummc-resumes-operations-after-ransomware-attack/?utm_source=openai)) This incident underscores the escalating threat of ransomware attacks targeting critical infrastructure, particularly in the healthcare sector. The Medusa group's double extortion tactics, involving data encryption and threats to release sensitive information, highlight the urgent need for robust cybersecurity measures to protect patient data and ensure uninterrupted medical services. ([aha.org](https://www.aha.org/news/headline/2025-03-14-advisory-warns-medusa-ransomware-activity?utm_source=openai))
4 months ago
Kill Chain
Coruna iOS Exploit Kit: A 2025 Cybersecurity Threat Analysis
In 2025, the Coruna iOS exploit kit emerged as a sophisticated tool targeting iPhone users across multiple campaigns. Initially identified in February 2025, it was deployed by a surveillance vendor's customer. By summer, the same exploit kit was utilized by the Russian espionage group UNC6353 in watering hole attacks on Ukrainian websites. Later in the year, the financially motivated Chinese threat actor UNC6691 employed Coruna to compromise fake Chinese gambling and cryptocurrency sites. The kit comprises 23 exploits forming five full exploit chains, affecting iOS versions 13.0 through 17.2.1. These exploits enable remote code execution, sandbox escapes, and kernel privilege escalation, leading to unauthorized access and data exfiltration. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/spyware-grade-coruna-ios-exploit-kit-now-used-in-crypto-theft-attacks/?utm_source=openai)) The proliferation of Coruna underscores a concerning trend: advanced exploit kits, possibly originating from state-sponsored entities, are increasingly accessible to a broader range of threat actors. This shift highlights the urgent need for organizations to stay vigilant, update their systems promptly, and implement robust security measures to mitigate the risks posed by such sophisticated tools. ([wired.com](https://www.wired.com/story/coruna-iphone-hacking-toolkit-us-government/?utm_source=openai))
4 months ago
Kill Chain
Critical Cisco Firewall Vulnerabilities Disclosed in 2026
In March 2026, Cisco disclosed two critical vulnerabilities in its Secure Firewall Management Center (FMC) software: an authentication bypass flaw (CVE-2026-20079) and a remote code execution (RCE) vulnerability (CVE-2026-20131). Both vulnerabilities allow unauthenticated, remote attackers to gain root access to affected devices. CVE-2026-20079 enables attackers to execute scripts and commands by sending crafted HTTP requests, while CVE-2026-20131 allows execution of arbitrary Java code through crafted serialized Java objects. These flaws affect both on-premises FMC installations and Cisco's Security Cloud Control (SCC) Firewall Management. Cisco has released patches to address these issues and recommends immediate updates to mitigate potential risks. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh?utm_source=openai)) The disclosure of these vulnerabilities underscores the ongoing challenges in securing network management interfaces. Organizations are urged to review their security postures, especially concerning remote access and authentication mechanisms, to prevent potential exploitation of similar flaws in the future.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports