The Containment Era is here. →Explore

Industry Category

Computer/Network Security

Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.

853 threat reports
Page 45 of 72

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer/Network Security Threat Reports

Showing 529540 / 853 reports
Microsoft's New Scanner Bolsters AI Security by Detecting LLM Backdoors
Impact· LOW

Microsoft's New Scanner Bolsters AI Security by Detecting LLM Backdoors

In February 2026, Microsoft unveiled a lightweight scanner designed to detect backdoors in open-weight large language models (LLMs). This tool identifies malicious alterations by analyzing three key behavioral signals: distinctive attention patterns triggered by specific inputs, unintended data memorization, and activation by multiple similar triggers. The scanner operates efficiently without requiring additional model training or prior knowledge of potential backdoors, making it applicable across various GPT-style models. However, it necessitates access to model files and is most effective against deterministic backdoors. This development underscores Microsoft's commitment to enhancing AI security and trustworthiness. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/02/04/detecting-backdoored-language-models-at-scale/?utm_source=openai)) The release of this scanner is particularly timely given the increasing integration of LLMs into critical applications. Recent research highlights the ease with which backdoors can be embedded into AI models, even with minimal malicious data. ([arstechnica.com](https://arstechnica.com/ai/2025/10/ai-models-can-acquire-backdoors-from-surprisingly-few-malicious-documents/?utm_source=openai)) Microsoft's proactive approach addresses these emerging threats, aiming to safeguard AI systems from covert manipulations that could compromise their integrity and reliability.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
GlassWorm Malware Compromises Open VSX Registry in 2026 Supply Chain Attack
Impact· MEDIUM

GlassWorm Malware Compromises Open VSX Registry in 2026 Supply Chain Attack

In late January 2026, a sophisticated supply chain attack compromised the Open VSX Registry, an open-source marketplace for Visual Studio Code extensions. Threat actors gained unauthorized access to a trusted developer's account, 'oorzc,' and injected malicious code into four widely-used extensions: FTP/SFTP/SSH Sync Tool, I18n Tools, vscode mindmap, and scss to css. These extensions, collectively downloaded over 22,000 times, delivered the GlassWorm malware, which targeted macOS systems to exfiltrate sensitive data, including browser credentials, cryptocurrency wallets, and developer secrets. The malware employed advanced evasion techniques, such as locale checks to avoid Russian systems and utilizing the Solana blockchain for command-and-control communications. ([thehackernews.com](https://thehackernews.com/2026/02/open-vsx-supply-chain-attack-used.html?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks within the developer ecosystem. The exploitation of trusted extensions highlights the need for enhanced security measures in open-source platforms. Organizations must prioritize the integrity of their development tools and implement robust monitoring to detect unauthorized modifications promptly.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Step Finance's $40M Crypto Theft: A Wake-Up Call for Endpoint Security
Impact· CRITICAL

Step Finance's $40M Crypto Theft: A Wake-Up Call for Endpoint Security

In late January 2026, Step Finance, a prominent Solana-based DeFi platform, suffered a significant security breach resulting in the theft of approximately $40 million worth of digital assets. The attackers gained unauthorized access to the company's treasury wallets by compromising devices belonging to its executive team. This breach led to the unauthorized transfer of 261,854 SOL tokens, valued at around $29 million at the time, and caused the platform's native STEP token to plummet over 80% within 24 hours. ([ainvest.com](https://www.ainvest.com/news/step-finance-treasury-theft-27m-sol-outflow-step-token-collapse-2602/?utm_source=openai)) This incident underscores the critical importance of robust endpoint security measures, especially for individuals with access to substantial organizational assets. The breach highlights the growing trend of targeting high-level personnel through device compromises, emphasizing the need for comprehensive security protocols and regular audits to safeguard against such sophisticated attacks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
eScan Antivirus Update Server Compromised in 2026 Supply Chain Attack
Impact· HIGH

eScan Antivirus Update Server Compromised in 2026 Supply Chain Attack

In January 2026, MicroWorld Technologies' eScan antivirus update infrastructure was compromised, allowing attackers to distribute a malicious update for approximately two hours on January 20. The malicious update replaced the legitimate 'Reload.exe' binary with a forged version that established persistence, disabled updates, bypassed AMSI, and deployed multi-stage PowerShell payloads. This incident affected enterprise and consumer endpoints globally, particularly in regions such as India, Bangladesh, Sri Lanka, and the Philippines. The breach rendered the antivirus software ineffective and tampered with system configurations to prevent automatic remediation. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/01/29/escan-antivirus-update-supply-chain-compromised/?utm_source=openai)) This incident underscores the critical importance of securing software supply chains, especially for security products that have elevated privileges on endpoints. The ability of attackers to exploit trusted update mechanisms highlights the need for organizations to implement robust monitoring and verification processes for software updates to prevent similar supply chain attacks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
GlassWorm macOS Supply Chain Attack: A Wake-Up Call for Developer Security
Impact· MEDIUM

GlassWorm macOS Supply Chain Attack: A Wake-Up Call for Developer Security

In January 2026, the GlassWorm malware campaign targeted macOS developers by infiltrating the Open VSX marketplace with malicious Visual Studio Code extensions. These extensions, downloaded over 50,000 times before removal, masqueraded as legitimate tools like 'Prettier Pro' and other productivity enhancers. Once installed, the malware delayed execution to evade detection, then decrypted and executed an AES-256-CBC encrypted JavaScript payload. It established persistence via LaunchAgents, harvested sensitive data—including GitHub and npm credentials, SSH keys, and macOS Keychain entries—and attempted to replace hardware wallet applications such as Ledger Live and Trezor Suite with trojanized versions. Command-and-control communication was maintained through the Solana blockchain, complicating traditional detection and mitigation efforts. This incident underscores the evolving sophistication of supply chain attacks targeting developer ecosystems, emphasizing the need for rigorous extension vetting processes and heightened awareness of the security risks associated with third-party development tools.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
OpenClaw's ClawHub Compromised: A 2026 Supply Chain Attack
Impact· HIGH

OpenClaw's ClawHub Compromised: A 2026 Supply Chain Attack

In early 2026, security researchers uncovered a significant supply chain attack within the ClawHub marketplace, a platform for OpenClaw AI assistant extensions. Over 340 malicious 'skills' were identified, many masquerading as cryptocurrency tools, which, upon installation, executed obfuscated commands leading to the deployment of the Atomic macOS Stealer (AMOS) malware. This malware targeted sensitive user data, including browser information and cryptocurrency wallets, affecting both Windows and macOS users. The incident underscores the vulnerabilities in open-source ecosystems and the critical need for rigorous vetting of third-party extensions. The proliferation of such attacks highlights the evolving tactics of cybercriminals, emphasizing the importance of user vigilance and the implementation of robust security measures to protect against sophisticated social engineering and malware distribution strategies.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical OpenClaw Vulnerability Exposes Systems to Remote Code Execution
Impact· HIGH

Critical OpenClaw Vulnerability Exposes Systems to Remote Code Execution

In early February 2026, a critical vulnerability (CVE-2026-25253) was identified in OpenClaw, an open-source AI personal assistant. This flaw allowed attackers to execute remote code on a victim's system by exploiting the application's handling of the 'gatewayUrl' parameter. By crafting a malicious link, attackers could trick users into initiating a WebSocket connection that transmitted authentication tokens without validation, leading to full system compromise. The issue was addressed in version 2026.1.29, released on January 30, 2026. ([thehackernews.com](https://thehackernews.com/2026/02/openclaw-bug-enables-one-click-remote.html?utm_source=openai)) This incident underscores the importance of rigorous input validation and user confirmation mechanisms in software development. The ease of exploitation and the potential for widespread impact highlight the need for organizations to promptly apply security patches and educate users about the risks associated with clicking untrusted links.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Poland's Energy Sector Cyberattack: A Wake-Up Call for Critical Infrastructure Security
Impact· CRITICAL

Poland's Energy Sector Cyberattack: A Wake-Up Call for Critical Infrastructure Security

On December 29, 2025, coordinated cyberattacks targeted over 30 wind and photovoltaic farms, a manufacturing company, and a large combined heat and power plant in Poland. The attacks, attributed to the Russian state-sponsored group Static Tundra (also known as Berserk Bear or Dragonfly), aimed to disrupt energy infrastructure by deploying wiper malware designed to destroy data and disable systems. While the attacks caused communication disruptions, they did not interrupt energy production or heat supply to consumers. ([cert.pl](https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/?utm_source=openai)) This incident underscores the escalating threat of nation-state cyberattacks on critical infrastructure, highlighting the need for enhanced cybersecurity measures and international cooperation to protect essential services from sophisticated adversaries.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Sandworm's DynoWiper Targets Poland's Energy Sector in 2025 Cyberattack
Impact· LOW

Sandworm's DynoWiper Targets Poland's Energy Sector in 2025 Cyberattack

In late December 2025, Poland's energy infrastructure was targeted by a cyberattack involving a data-wiping malware named DynoWiper. The attack aimed to disrupt operations at two combined heat and power plants and several renewable energy facilities. ESET researchers attributed the attack to the Russian state-sponsored group Sandworm, noting similarities to previous incidents involving the group. Fortunately, the malware was intercepted before causing any substantial damage, and no operational disruptions were reported. ([welivesecurity.com](https://www.welivesecurity.com/en/eset-research/eset-research-sandworm-cyberattack-poland-power-grid-late-2025/?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors to critical infrastructure. The timing, coinciding with the tenth anniversary of Sandworm's first known assault on Ukraine’s power grid in 2015, highlights the group's continued focus on energy sector targets and disruptive operations. ([welivesecurity.com](https://www.welivesecurity.com/en/eset-research/eset-research-sandworm-cyberattack-poland-power-grid-late-2025/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Bybit's 2025 Security Breach: A Deep Dive into the $1.4 Billion Ethereum Theft
Impact· CRITICAL

Bybit's 2025 Security Breach: A Deep Dive into the $1.4 Billion Ethereum Theft

In February 2025, Dubai-based cryptocurrency exchange Bybit suffered a significant security breach, resulting in the theft of approximately 401,000 Ethereum (ETH), valued at over $1.4 billion. The attackers exploited vulnerabilities in Bybit's multi-signature cold wallet system, facilitated by compromised infrastructure at Safe{Wallet}, a third-party provider. This incident stands as the largest cryptocurrency exchange hack to date. ([en.wikipedia.org](https://en.wikipedia.org/wiki/Bybit?utm_source=openai)) The breach was attributed to the North Korean state-sponsored Lazarus Group, known for their sophisticated cyber operations targeting financial institutions. The stolen funds were laundered through various channels, including privacy-focused platforms, complicating recovery efforts. ([en.wikipedia.org](https://en.wikipedia.org/wiki/Lazarus_Group?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Safeguarding AI Assets: Lessons from the 2025 Model Extraction Attack
Impact· CRITICAL

Safeguarding AI Assets: Lessons from the 2025 Model Extraction Attack

In 2025, a significant AI model extraction attack was identified, where adversaries systematically queried a proprietary machine learning model's API to replicate its functionality. By sending carefully crafted inputs and analyzing the outputs, attackers reconstructed a substitute model that closely mirrored the original's behavior. This breach exposed the model's intellectual property, leading to potential competitive disadvantages and financial losses for the organization. The incident underscores the vulnerabilities inherent in exposing AI models through APIs without adequate security measures. ([techtarget.com](https://www.techtarget.com/searchsecurity/tip/AI-model-theft-Risk-and-mitigation-in-the-digital-era?utm_source=openai)) The rise of such model extraction attacks highlights the urgent need for organizations to implement robust defenses, including rate limiting, output perturbation, and behavioral monitoring, to protect their AI assets from unauthorized replication and misuse. ([snyk.io](https://snyk.io/articles/ai-model-theft/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Swarmer Tool: Exploiting Windows Legacy Features for Stealthy Registry Persistence
Impact· MEDIUM

Swarmer Tool: Exploiting Windows Legacy Features for Stealthy Registry Persistence

In February 2025, Praetorian Inc. introduced 'Swarmer,' a tool designed to achieve stealthy Windows registry persistence without triggering Endpoint Detection and Response (EDR) systems. By exploiting legacy Windows features such as mandatory user profiles and the Offline Registry API, Swarmer allows low-privilege users to modify the NTUSER hive covertly. This method bypasses standard registry APIs monitored by EDR solutions, enabling attackers to establish persistence without detection. The release of Swarmer underscores the ongoing challenges in cybersecurity, particularly the exploitation of overlooked system functionalities. As attackers continue to innovate, it is imperative for organizations to reassess and fortify their security postures against such sophisticated techniques.

5 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports