✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
AI-Assisted Cyberattack Compromises 600+ FortiGate Firewalls Globally
Between January 11 and February 18, 2026, a Russian-speaking threat actor utilized commercial generative AI tools to compromise over 600 Fortinet FortiGate firewalls across 55 countries. The attacker exploited exposed management interfaces and weak credentials lacking two-factor authentication, without leveraging any specific software vulnerabilities. Once access was gained, AI-generated scripts were employed to extract and decrypt sensitive data, including SSL-VPN credentials, administrative passwords, and network configurations. This information facilitated further network infiltration and reconnaissance activities. ([cybernews.com](https://cybernews.com/security/threat-actor-ai-tools-claude-fortinet-fortigate/?utm_source=openai)) This incident underscores the evolving threat landscape where AI tools enable even low-skilled attackers to execute large-scale, sophisticated cyberattacks. Organizations must reassess their security postures, emphasizing the importance of robust authentication mechanisms and the need to secure management interfaces against unauthorized access.
4 months ago
Kill Chain
South Korea Tax Agency's Data Exposure Results in $4.8M Crypto Theft
In February 2026, South Korea's National Tax Service (NTS) inadvertently exposed the mnemonic recovery phrase of a seized cryptocurrency wallet in an official press release. This oversight allowed unauthorized individuals to access and transfer approximately 4 million Pre-Retogeum (PRTG) tokens, valued at $4.8 million, from the wallet. The incident underscores significant lapses in the secure handling of digital assets by governmental bodies. This event highlights the critical need for stringent operational security measures when managing and disclosing information related to digital assets. The exposure of sensitive data, such as wallet recovery phrases, can lead to substantial financial losses and erode public trust in institutional competence.
5 months ago
Kill Chain
QuickLens Chrome Extension Compromised: A Cautionary Tale for Browser Security
In February 2026, the 'QuickLens - Search Screen with Google Lens' Chrome extension, initially a legitimate tool with approximately 7,000 users, was compromised following a change in ownership. The new version 5.8 introduced malicious scripts that stripped browser security headers and executed arbitrary JavaScript, enabling the theft of cryptocurrency wallets and sensitive user data. This incident underscores the risks associated with browser extensions, particularly those that undergo ownership changes, and highlights the need for vigilant monitoring of software supply chains to prevent similar attacks.
5 months ago
Kill Chain
ClawJacked Vulnerability Exposes Critical Flaw in OpenClaw AI Agents
In February 2026, a critical security vulnerability, dubbed 'ClawJacked,' was discovered in OpenClaw, an open-source AI agent platform. This flaw allowed malicious websites to exploit the WebSocket protocol to hijack locally running OpenClaw agents by brute-forcing the gateway password, leading to unauthorized control over the AI agent. The attack sequence involved a malicious site initiating a WebSocket connection to the local OpenClaw gateway, bypassing security mechanisms due to the gateway's trust in local connections. This vulnerability was promptly addressed in version 2026.2.25, released on February 26, 2026. ([thehackernews.com](https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html?utm_source=openai)) The ClawJacked incident underscores the escalating security challenges associated with AI agent platforms. As these agents gain deeper integration into enterprise environments, they become attractive targets for cyber threats. This event highlights the necessity for robust security measures, including stringent authentication protocols and vigilant monitoring, to safeguard against emerging vulnerabilities in AI systems.
5 months ago
Kill Chain
Kimwolf Botnet's 2026 Rampage: A Wake-Up Call for IoT Security
In late 2025, the Kimwolf botnet emerged as a significant cybersecurity threat, infecting over 2 million Android devices worldwide, primarily targeting off-brand smart TVs and set-top boxes. Exploiting vulnerabilities in residential proxy networks and exposed Android Debug Bridge (ADB) services, Kimwolf transformed these devices into nodes for large-scale distributed denial-of-service (DDoS) attacks. Notably, in November 2025, the botnet launched a record-setting DDoS attack peaking at 31.4 terabits per second, underscoring its unprecedented scale and impact. ([thehackernews.com](https://thehackernews.com/2026/02/aisurukimwolf-botnet-launches-record.html?utm_source=openai)) The rapid proliferation and sophistication of Kimwolf highlight the escalating threat posed by botnets leveraging IoT devices. This incident underscores the urgent need for enhanced security measures in consumer electronics and the importance of proactive defense strategies to mitigate the risks associated with large-scale botnet attacks.
5 months ago
Kill Chain
Malicious Go Module Exploits Open-Source Ecosystem to Steal Credentials and Deploy Backdoor
In February 2026, cybersecurity researchers uncovered a malicious Go module named 'github.com/xinfeisoft/crypto' that impersonated the legitimate 'golang.org/x/crypto' library. This module was designed to harvest passwords entered via terminal prompts and deploy a Linux backdoor known as Rekoobe. Upon execution, the module exfiltrated captured credentials to a remote server and executed a shell script that installed the backdoor, granting attackers persistent access to compromised systems. The campaign exploited GitHub's infrastructure to host and distribute the malicious code, highlighting the risks associated with supply chain attacks in open-source ecosystems. This incident underscores the growing trend of supply chain attacks targeting developers and the open-source community. By leveraging trusted platforms and repositories, attackers can distribute malicious code to a wide audience, emphasizing the need for enhanced vigilance and security measures in software development and distribution processes.
5 months ago
Kill Chain
Marquis 2025 Ransomware Attack via SonicWall Breach
In August 2025, Marquis Software Solutions, a Texas-based fintech firm serving over 700 banks and credit unions, experienced a ransomware attack. The breach was traced back to unauthorized access through its SonicWall firewall, leading to the exposure of sensitive data, including names, addresses, Social Security numbers, and financial account information of over 400,000 individuals associated with 74 financial institutions. The attackers exploited a known but unpatched vulnerability in SonicWall’s firewall software (CVE-2024-40766), allowing them to infiltrate Marquis's network and deploy ransomware. This incident underscores the critical importance of timely patch management and the potential risks associated with third-party service providers. ([techradar.com](https://www.techradar.com/pro/security/over-70-us-banks-and-credit-unions-affected-by-marquis-ransomware-breach-heres-what-we-know?utm_source=openai)) The Marquis breach highlights the escalating trend of cyberattacks targeting supply chain vulnerabilities, emphasizing the need for organizations to scrutinize the security postures of their vendors. Additionally, it serves as a stark reminder of the consequences of delayed patching, as threat actors increasingly exploit known vulnerabilities to gain unauthorized access to sensitive data.
5 months ago
Kill Chain
HexStrike-AI: AI-Powered Exploitation of Citrix Vulnerabilities in 2025
In September 2025, cybersecurity firm Check Point Research identified that cybercriminals were leveraging HexStrike-AI, an AI-driven offensive security framework, to exploit vulnerabilities in Citrix NetScaler ADC and Gateway systems. HexStrike-AI integrates large language models with over 150 cybersecurity tools, enabling automated penetration testing and vulnerability research. Attackers utilized this tool to target specific Citrix vulnerabilities—CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424—achieving unauthenticated remote code execution, installing webshells, and maintaining persistent access. The automation capabilities of HexStrike-AI significantly reduced the time required to exploit these vulnerabilities, narrowing the window for organizations to implement patches and defenses. This incident underscores the escalating sophistication of cyber threats, where AI-powered tools are employed to automate and enhance attack vectors. Organizations must prioritize timely patch management and adopt advanced security measures to mitigate such rapidly evolving threats.
5 months ago
Kill Chain
Trend Micro Apex One 2026 Critical RCE Vulnerabilities
In February 2026, Trend Micro identified and patched two critical vulnerabilities (CVE-2025-71210 and CVE-2025-71211) in its Apex One endpoint security platform. These flaws, both with a CVSS score of 9.8, allowed unauthenticated remote attackers to execute arbitrary code via path traversal weaknesses in the management console. Exploitation required access to the console, posing significant risks to organizations with externally exposed management interfaces. Trend Micro released Critical Patch Build 14136 to address these issues and advised customers to update promptly. This incident underscores the persistent threat posed by vulnerabilities in security management consoles, emphasizing the need for organizations to implement stringent access controls and maintain up-to-date systems to mitigate potential exploitation.
5 months ago
Kill Chain
UAT-10027's Dohdoor Backdoor: A New Threat to U.S. Education and Healthcare
In December 2025, the threat actor group UAT-10027 initiated a sophisticated cyber campaign targeting the U.S. education and healthcare sectors. The attackers employed a novel backdoor named Dohdoor, which utilizes DNS-over-HTTPS (DoH) for covert command-and-control communications, effectively evading traditional network monitoring tools. The initial infection vector is suspected to involve phishing emails that execute PowerShell scripts, leading to the download and execution of malicious DLLs via DLL side-loading techniques. These DLLs facilitate the deployment of additional payloads, such as Cobalt Strike Beacons, directly into the memory of compromised systems. The campaign's use of legitimate Windows processes and encrypted communications poses significant challenges for detection and mitigation. ([thehackernews.com](https://thehackernews.com/2026/02/uat-10027-targets-us-education-and.html?utm_source=openai)) This incident underscores a growing trend of advanced persistent threats (APTs) leveraging encrypted communication channels like DoH to conceal malicious activities. The targeting of critical sectors such as education and healthcare highlights the urgent need for enhanced cybersecurity measures and vigilance against sophisticated attack vectors. ([thehackernews.com](https://thehackernews.com/2026/02/uat-10027-targets-us-education-and.html?utm_source=openai))
5 months ago
Kill Chain
Chinese Police Exploit ChatGPT in Smear Campaign Against Japan's PM Takaichi
In October 2025, OpenAI identified and banned a ChatGPT account linked to Chinese law enforcement that was used to orchestrate a smear campaign against Japan's Prime Minister, Sanae Takaichi. The individual behind the account attempted to leverage ChatGPT to generate and amplify negative content about Takaichi, including drafting complaints impersonating Japanese citizens and creating social media posts to incite public dissent. These activities were part of a broader, covert influence operation aimed at discrediting foreign officials critical of China's policies. ([theregister.com](https://www.theregister.com/2026/02/25/chinese_law_enforcement_chatgpt_abuse/?utm_source=openai)) This incident underscores the evolving use of artificial intelligence in state-sponsored disinformation campaigns. The exposure of such tactics highlights the need for vigilance against AI-driven influence operations, especially as they become more sophisticated and harder to detect. ([axios.com](https://www.axios.com/2026/02/25/openai-chatgpt-china-japan-prime-minister?utm_source=openai))
5 months ago
Kill Chain
Ex-L3Harris Executive Sentenced for Selling Zero-Day Exploits to Russian Broker
Between 2022 and 2025, Peter Williams, a 39-year-old Australian national and former general manager of Trenchant—a cybersecurity unit of defense contractor L3Harris—stole at least eight sensitive cyber-exploit components intended exclusively for the U.S. government and its allies. Williams sold these zero-day exploits to Operation Zero, a Russian cyber-tools broker that advertises its services to non-NATO buyers, including the Russian government. The theft resulted in $35 million in losses to L3Harris and potentially enabled unauthorized access to millions of devices worldwide. In October 2025, Williams pleaded guilty to two counts of theft of trade secrets and, in February 2026, was sentenced to 87 months in federal prison, forfeiting $1.3 million in cryptocurrency, a house, and luxury items. ([justice.gov](https://www.justice.gov/opa/pr/former-general-manager-us-defense-contractor-sentenced-87-months-selling-stolen-trade?utm_source=openai)) This incident underscores the critical threat posed by insider threats within defense and cybersecurity sectors. The sale of zero-day exploits to adversarial entities highlights the urgent need for robust internal security measures, comprehensive employee vetting, and continuous monitoring to prevent unauthorized access and exfiltration of sensitive information.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports