The Containment Era is here. →Explore

Industry Category

Computer/Network Security

Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.

853 threat reports
Page 42 of 72

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer/Network Security Threat Reports

Showing 493504 / 853 reports
Marquis Software Solutions Ransomware Attack: A Supply Chain Vulnerability Exposed
Impact· CRITICAL

Marquis Software Solutions Ransomware Attack: A Supply Chain Vulnerability Exposed

In August 2025, Marquis Software Solutions, a Texas-based fintech firm serving over 700 financial institutions, experienced a ransomware attack that compromised sensitive data of more than 780,000 individuals across at least 80 banks and credit unions. The attackers exploited a vulnerability in SonicWall's firewall backup service, gaining unauthorized access to Marquis's network and exfiltrating personal information, including names, addresses, Social Security numbers, and financial account details. This breach underscores the critical importance of securing third-party services and the potential cascading effects of supply chain vulnerabilities. The incident highlights the growing trend of cybercriminals targeting supply chain weaknesses to infiltrate organizations, emphasizing the need for comprehensive security assessments and robust vendor management practices to mitigate such risks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Chinese Cyberspies Exploit Google Sheets in 2026 Telecom Breach
Impact· HIGH

Chinese Cyberspies Exploit Google Sheets in 2026 Telecom Breach

In February 2026, Google's Threat Intelligence Group, in collaboration with Mandiant and other partners, disrupted a sophisticated cyber-espionage campaign attributed to a Chinese state-sponsored actor known as UNC2814. This campaign, active since at least 2023, targeted 53 organizations across 42 countries, primarily within the telecommunications and government sectors. The attackers deployed a novel backdoor named 'GRIDTIDE,' which exploited the Google Sheets API to facilitate covert command-and-control operations, effectively blending malicious traffic with legitimate network activity. The initial access vector remains unidentified; however, UNC2814 has a history of exploiting vulnerabilities in web servers and edge systems to infiltrate target networks. ([thehackernews.com](https://thehackernews.com/2026/02/google-disrupts-unc2814-gridtide.html?utm_source=openai)) The disruption of this campaign underscores the persistent and evolving nature of cyber threats posed by state-sponsored actors. The use of legitimate services like Google Sheets for command-and-control highlights the increasing sophistication of such attacks, making detection and mitigation more challenging. Organizations, especially those in critical infrastructure sectors, must remain vigilant and adopt comprehensive cybersecurity measures to defend against these advanced persistent threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
L3Harris Insider Breach: Zero-Day Exploits Sold to Russian Broker
Impact· HIGH

L3Harris Insider Breach: Zero-Day Exploits Sold to Russian Broker

In October 2025, Peter Williams, a 39-year-old Australian national and former general manager at L3Harris's Trenchant division, pleaded guilty to stealing and selling eight zero-day exploits to a Russian broker, Operation Zero. Over a three-year period, Williams transferred these sensitive cyber-exploit components, originally intended for U.S. government and allied use, in exchange for approximately $1.3 million in cryptocurrency. This unauthorized sale resulted in significant national security concerns and financial losses exceeding $35 million for L3Harris. ([techcrunch.com](https://techcrunch.com/2025/10/29/former-l3harris-trenchant-boss-pleads-guilty-to-selling-zero-day-exploits-to-russian-broker/?utm_source=openai)) This incident underscores the critical need for stringent internal security measures within defense contractors, especially concerning personnel with high-level access to sensitive information. The case highlights the growing threat posed by insider threats and the importance of robust monitoring and compliance frameworks to prevent unauthorized dissemination of national security assets.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Google Disrupts UNC2814's Global Cyber Espionage Campaign
Impact· HIGH

Google Disrupts UNC2814's Global Cyber Espionage Campaign

In February 2026, Google, in collaboration with industry partners, disrupted a sophisticated cyber espionage campaign orchestrated by the Chinese-linked group UNC2814. Active since at least 2017, UNC2814 infiltrated 53 organizations across 42 countries, primarily targeting telecommunications and government sectors. The group employed a novel backdoor, GRIDTIDE, which exploited the Google Sheets API to disguise command-and-control (C2) communications, enabling the execution of arbitrary shell commands and data exfiltration. The attackers gained initial access by compromising web servers and edge systems, subsequently moving laterally within networks using service accounts and living-off-the-land techniques. ([thehackernews.com](https://thehackernews.com/2026/02/google-disrupts-unc2814-gridtide.html?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors in leveraging legitimate cloud services to evade detection. The global scale and sophistication of UNC2814's operations highlight the critical need for organizations to enhance their cybersecurity measures, particularly in monitoring and securing cloud-based applications and APIs. ([thehackernews.com](https://thehackernews.com/2026/02/google-disrupts-unc2814-gridtide.html?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(low)
Read Report
Critical Security Flaws Discovered in Gardyn Home Kit: What You Need to Know
Impact· CRITICAL

Critical Security Flaws Discovered in Gardyn Home Kit: What You Need to Know

In February 2026, multiple critical vulnerabilities were identified in the Gardyn Home Kit, an AI-powered indoor gardening system. These flaws included insecure credential exchange (CVE-2025-29628), weak default SSH credentials (CVE-2025-29629), command injection vulnerabilities (CVE-2025-29631), and API credential leakage (CVE-2025-1242). Exploitation could have allowed unauthenticated users to remotely control devices, access user information, and pivot to other devices within the Gardyn cloud environment. Gardyn promptly addressed these issues by releasing firmware updates and advising users to ensure their devices were connected to the internet to receive automatic updates. ([mygardyn.com](https://mygardyn.com/blog/security-update/?utm_source=openai)) This incident underscores the growing security challenges in IoT devices, particularly those integrated into personal living spaces. The vulnerabilities highlight the importance of robust security practices in the development and maintenance of smart home technologies to prevent unauthorized access and potential data breaches.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
L3Harris Executive Sentenced for Selling Zero-Day Exploits to Russian Broker
Impact· HIGH

L3Harris Executive Sentenced for Selling Zero-Day Exploits to Russian Broker

In February 2026, Peter Williams, a former executive at L3Harris's cyber division Trenchant, was sentenced to 87 months in prison for selling eight zero-day exploits to a Russian broker, Operation Zero. Over a three-year period, Williams stole proprietary cyber tools intended for exclusive use by the U.S. government and its allies, causing an estimated $35 million in losses to L3Harris. He received approximately $1.3 million in cryptocurrency for the stolen exploits, which he used to purchase luxury items. This case underscores the severe risks posed by insider threats within defense contracting firms, especially concerning sensitive cybersecurity tools. The incident highlights the critical need for robust internal security measures and monitoring to prevent unauthorized access and exfiltration of proprietary information. Additionally, the U.S. Department of the Treasury sanctioned Operation Zero and its founder, Sergey Zelenyuk, for their role in acquiring and distributing cyber tools harmful to U.S. national security.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
ShinyHunters Breach Exposes 6.2 Million Odido Customers in 2026
Impact· HIGH

ShinyHunters Breach Exposes 6.2 Million Odido Customers in 2026

In February 2026, Dutch telecommunications provider Odido suffered a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers infiltrated Odido's customer service system, compromising sensitive personal information of approximately 6.2 million customers. The stolen data included full names, home addresses, email addresses, phone numbers, bank account numbers (IBAN), dates of birth, and identity document details such as passport and driver's license numbers. ShinyHunters threatened to release this data on the dark web unless a ransom was paid. Odido confirmed the breach and advised customers to remain vigilant for potential misuse of their personal information. ([scancomply.com](https://scancomply.com/blog/february-2026-data-breach-report?utm_source=openai)) This incident underscores the escalating threat posed by sophisticated cybercriminal groups like ShinyHunters, who have previously targeted major organizations worldwide. The breach highlights the critical need for robust cybersecurity measures, especially in sectors handling vast amounts of personal data. Organizations must prioritize the implementation of advanced security protocols and employee training to mitigate the risks associated with such targeted attacks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Anthropic Uncovers Unauthorized Distillation Attacks by Chinese AI Firms in 2026
Impact· HIGH

Anthropic Uncovers Unauthorized Distillation Attacks by Chinese AI Firms in 2026

In February 2026, Anthropic, a U.S.-based AI company, reported that three Chinese AI firms—DeepSeek, Moonshot AI, and MiniMax—conducted large-scale distillation attacks to extract capabilities from its Claude AI model. These companies generated over 16 million interactions using approximately 24,000 fraudulent accounts, violating Anthropic's terms of service and regional access restrictions. The attacks focused on Claude's advanced features, including reasoning, coding, and tool use, aiming to enhance their own AI models without proper authorization. This incident underscores the escalating risks of intellectual property theft in the AI sector, particularly through distillation techniques. Such activities not only compromise proprietary technologies but also pose significant national security concerns, as models developed through illicit means may lack essential safety measures, potentially facilitating malicious applications.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
UnsolicitedBooker's Strategic Shift: Targeting Central Asian Telecoms with Advanced Backdoors
Impact· HIGH

UnsolicitedBooker's Strategic Shift: Targeting Central Asian Telecoms with Advanced Backdoors

In late 2025 and early 2026, the China-aligned threat actor UnsolicitedBooker targeted telecommunications companies in Kyrgyzstan and Tajikistan. The group employed sophisticated phishing campaigns to deploy two distinct backdoors, LuciDoor and MarsSnake, enabling unauthorized access and data exfiltration. These attacks signify a strategic shift from UnsolicitedBooker's previous focus on Saudi Arabian entities to Central Asian infrastructure. This incident underscores the evolving tactics of state-sponsored cyber-espionage groups and highlights the critical need for enhanced cybersecurity measures within the telecommunications sector. The use of rare tools of Chinese origin and the targeting of critical infrastructure emphasize the importance of vigilance and proactive defense strategies.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
ATM Jackpotting Attacks Surge in 2025, Resulting in Over $20 Million in Losses
Impact· HIGH

ATM Jackpotting Attacks Surge in 2025, Resulting in Over $20 Million in Losses

In 2025, the United States experienced a significant surge in ATM "jackpotting" attacks, with over 700 incidents reported, resulting in losses exceeding $20 million. ([thehackernews.com](https://thehackernews.com/2026/02/fbi-reports-1900-atm-jackpotting.html?utm_source=openai)) These attacks involve criminals gaining physical access to ATMs, often using generic keys to open the machines. Once inside, they install or replace hard drives with malware, such as the Ploutus family, which exploits the eXtensions for Financial Services (XFS) API to dispense cash without bank authorization. ([livemint.com](https://www.livemint.com/news/world/fbi-warns-of-rising-atm-jackpotting-cases-reports-20-million-in-losses-in-2025-5-indicators-to-detect-foul-play-11771729139858.html?utm_source=openai)) This alarming trend underscores the evolving tactics of cybercriminals targeting financial institutions. The FBI has issued warnings and recommended mitigation strategies, including enhancing physical security measures, regularly updating ATM software, and monitoring for unauthorized access, to combat this growing threat. ([thehackernews.com](https://thehackernews.com/2026/02/fbi-reports-1900-atm-jackpotting.html?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Anthropic's Claude Model Targeted in Large-Scale AI Distillation Attack by Chinese Labs
Impact· MEDIUM

Anthropic's Claude Model Targeted in Large-Scale AI Distillation Attack by Chinese Labs

In February 2026, Anthropic, a U.S.-based AI startup, reported that three Chinese AI laboratories—DeepSeek, Moonshot, and MiniMax—conducted large-scale 'distillation' attacks to extract capabilities from Anthropic's Claude model. These labs utilized 24,000 fraudulent accounts to send approximately 16 million requests to Claude, aiming to enhance their own AI models. This unauthorized extraction of intellectual property not only violated Anthropic's terms of service but also posed significant national security risks by potentially enabling offensive cyber operations and mass surveillance. ([cyberscoop.com](https://cyberscoop.com/anthropic-accuses-chinese-labs-ai-distillation-cyber-risk/?utm_source=openai)) This incident underscores the growing threat of AI model distillation as a method for intellectual property theft. The scale and sophistication of these attacks highlight the urgent need for robust security measures and regulatory frameworks to protect proprietary AI technologies from unauthorized exploitation.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
SANDWORM_MODE: A New Era of Supply Chain Attacks Targeting Developers
Impact· HIGH

SANDWORM_MODE: A New Era of Supply Chain Attacks Targeting Developers

In February 2026, a sophisticated supply chain attack, dubbed SANDWORM_MODE, targeted the npm ecosystem by distributing at least 19 malicious packages. These packages were designed to harvest sensitive information, including system data, access tokens, environment secrets, and API keys from developer environments. The malware propagated by exploiting compromised npm and GitHub accounts, enabling widespread credential theft and unauthorized access to development infrastructures. Notably, the attack introduced a module that infiltrated AI coding assistants, extracting API keys from nine large language model providers and injecting malicious servers into tool configurations. This incident underscores the escalating complexity and reach of supply chain attacks, particularly those leveraging trusted open-source repositories. The integration of AI toolchain manipulation highlights a concerning evolution in attacker tactics, emphasizing the need for enhanced vigilance and security measures within development environments.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports