✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Fortinet’s 2024 Zero-Day SSO Breach: Key Lessons in Cloud Identity Security
In June 2024, Fortinet disclosed a critical zero-day vulnerability that was actively exploited by threat actors to compromise FortiCloud single sign-on (SSO) authentication, enabling unauthorized access to customer devices. Attackers leveraged the flaw to perform malicious SSO logins, bypassing authentication controls and potentially moving laterally within affected network environments. In response, Fortinet took the unprecedented step of disabling FortiCloud SSO services temporarily for all users while investigating and developing a fix. This incident underscores significant risks associated with identity and access management in cloud-delivered network security platforms. This breach highlights the growing prevalence of zero-day exploitation targeting authentication mechanisms and cloud infrastructure. As attackers increasingly focus on SSO and federated identity systems, organizations must reassess their reliance on third-party authentication, strengthen monitoring, and accelerate adoption of zero trust strategies.
6 months ago
Kill Chain
Fake Dating App Used to Deliver Android Spyware in Pakistan
In early 2024, an Android spyware campaign was uncovered by ESET researchers targeting users in Pakistan via a fraudulent dating app masquerading as a legitimate platform. The attackers lured victims using romance scam tactics, convincing users to download the malicious app outside of trusted marketplaces. Once installed, the spyware harvested sensitive data including call logs, messages, and device information, forwarding it to remote command-and-control servers linked to an ongoing espionage operation. The threat actors exhibited targeted behavior, indicating a capability for victim profiling and data exfiltration on mobile devices. This incident underscores a broader cybersecurity trend: growing use of socially engineered lures and repurposed surveillance tooling in region-specific espionage. Mobile attack vectors are increasingly leveraged for targeted intelligence gathering, amplifying urgency for robust defenses and heightened awareness of app distribution risks.
6 months ago
Kill Chain
Fortinet’s 2026 Zero-Day: Attackers Bypass FortiCloud SSO to Compromise Firewalls
In January 2026, Fortinet disclosed a critical zero-day vulnerability (CVE-2026-24858) affecting FortiCloud’s single sign-on authentication, enabling attackers with a FortiCloud account and a registered device to bypass authentication controls and gain privileged access to FortiGate firewalls and other products. Malicious actors leveraged the flaw in the wild, making unauthorized configuration changes, creating unauthorized accounts, and manipulating VPN settings across exposed management interfaces. Fortinet responded by disabling FortiCloud SSO, blocking the known malicious accounts, and issuing mitigations, though patches for multiple affected products remained unavailable at disclosure. This incident highlights the persistent targeting of network infrastructure devices by threat actors seeking initial access and lateral movement. With thousands of Fortinet instances exposed globally and repeated inclusion of Fortinet CVEs in known exploited vulnerabilities catalogs, organizations face increased regulatory scrutiny and pressure to rapidly address vulnerabilities affecting critical network management infrastructure.
6 months ago
Kill Chain
Kingdom Market Darknet Takedown: How Law Enforcement Disrupted a Global Cybercrime Hub (2021–2023)
Between March 2021 and December 2023, the Kingdom Market darknet platform operated as a large-scale cybercrime marketplace facilitating the sale of narcotics, cybercrime tools, stolen personal information, and fraudulent documents. Slovakian national Alan Bill, also known as "Vend0r" or "KingdomOfficial," admitted in January 2026 to administering the illicit platform, handling site infrastructure, and orchestrating anonymous cryptocurrency payments. The marketplace boasted over 42,000 illegal listings and tens of thousands of customer accounts. Its takedown culminated in coordinated law enforcement actions, domain seizures, and Bill's arrest in the U.S., where evidence linked him directly to site operations. This case highlights the persistent challenge of global, darknet-enabled cybercrime, the evolution of anonymous payment technologies, and the international scope of enforcement efforts. Cybercrime marketplaces remain a top concern for regulators and enterprises alike, with attackers rapidly adapting business models and operational security to evade detection.
6 months ago
Kill Chain
Enterprise AI at Risk: Hackers Hijack Exposed LLM Endpoints in Bizarre Bazaar Operation
In early June 2024, security researchers revealed an active campaign—dubbed the Bizarre Bazaar operation—where threat actors systematically scanned for and exploited publicly exposed Large Language Model (LLM) service endpoints. Attackers hijacked these AI/ML endpoints by bypassing inadequate API controls and leveraging unsecured cloud configurations, enabling unauthorized access to advanced AI resources. Compromised infrastructure became part of an underground market offering illicit AI compute power, leading to business risks ranging from intellectual property leakage to tool misuse and service disruption for impacted organizations. This incident spotlights the growing exploitation of AI infrastructure, with attackers rapidly adopting novel tactics as organizations rush to deploy LLMs. Weak segmentation, lack of egress controls, and poor visibility have left many organizations vulnerable to sophisticated abuse, elevating urgency for robust enterprise AI security and compliance measures.
6 months ago
Kill Chain
Empire Market Dark Web Takedown: Owner Pleads Guilty in $430M Cybercrime Plot
In January 2026, U.S. authorities announced that Raheim Hamilton (“Sydney”/“ZeroAngel”), a co-founder of the notorious Empire Market, pleaded guilty to federal drug conspiracy charges. From 2018 to 2020, Empire Market operated as a large-scale dark web marketplace accessible via TOR, facilitating over $430 million in illegal transactions, primarily enabling drug sales but also distributing stolen credentials, hacking tools, and counterfeit currency. Hamilton and partner Thomas Pavey laundered illicit proceeds through cryptocurrency and designed the site to evade law enforcement, directly overseeing vendor disputes and operational security. This prosecution underscores the ongoing threat and operational sophistication of dark web cybercrime marketplaces, even after earlier takedowns. As digital criminal platforms persistently adapt, law enforcement and organizations must address the evolving risks involving anonymized markets, cryptocurrency transactions, and the proliferation of illicit digital goods and services.
6 months ago
Kill Chain
MicroWorld eScan Update Server Breach Exposes Supply Chain Risks
In June 2024, MicroWorld Technologies, developers of eScan antivirus, experienced a breach where attackers compromised one of its update servers. The intruders leveraged this access to push a malicious software update to a limited subset of customers, effectively deploying unauthorized code via the trusted antivirus delivery mechanism. MicroWorld quickly detected the incident, notified impacted users, and began forensic analysis with assistance from cybersecurity experts. The compromised update posed potential risks including malware infection and lateral network movement. This incident is part of a growing trend of supply chain attacks, where adversaries exploit trusted update channels to infiltrate enterprise environments. As organizations increasingly rely on third-party software, vigilance and layered security controls around update infrastructures have become a pressing necessity.
6 months ago
Kill Chain
Mustang Panda’s 2025 Cyber Espionage: Updated COOLCLIENT Backdoor Hits Government
In late 2025, cyber espionage group Mustang Panda (also known as Earth Preta and Twill Typhoon) launched a series of targeted attacks against government entities, deploying an updated version of the COOLCLIENT backdoor. These intrusions leveraged spear-phishing and custom malware to establish persistent access, exfiltrate sensitive government data, and conduct surveillance. The campaign relied on advanced command-and-control infrastructure and encrypted traffic to evade detection, demonstrating the group’s evolving tactics and technical sophistication. The breach resulted in notable data theft and highlighted vulnerabilities in governmental East-West network security and policy enforcement. This incident underscores a rising trend of state-sponsored attackers continuously updating malware toolsets and intensifying operations against government organizations. The sophistication and stealth of these campaigns demand enhanced data protection, visibility, and zero trust network controls to meet regulatory and operational requirements.
6 months ago
Kill Chain
Russian ELECTRUM APT Strikes Polish Power Grid with Coordinated December 2025 Attack
In December 2025, a coordinated cyber attack disrupted multiple sites within Poland's national power grid, marking the first significant compromise of distributed energy operational technology in the region. The campaign, attributed with medium confidence to Russian state-sponsored APT group ELECTRUM, leveraged supply chain vulnerabilities and advanced lateral movement techniques to infiltrate the grid's OT networks. Attackers exploited unencrypted east-west traffic and segmentation gaps, enabling persistent access and operational disruption that triggered brief power outages and forced manual intervention by Polish operators. The incident showcased a notable escalation in critical infrastructure targeting methods by highly skilled actors. This incident highlights the increasing risk of state-sponsored attacks on energy infrastructure, especially in the context of rising geopolitical tensions and adversarial use of sophisticated supply chain compromise and network segmentation evasion. Organizations should reassess their visibility and controls for east-west and encrypted traffic to mitigate similar risks.
6 months ago
Kill Chain
US ATM Jackpotting: Tren de Aragua's Ploutus Malware Heist Exposed
In late 2025 and early 2026, US law enforcement charged 31 additional suspects in a major campaign of ATM jackpotting attacks attributed to the Venezuelan criminal gang Tren de Aragua. The attackers breached numerous ATMs across the United States, installing Ploutus malware by physically accessing internal components and deploying malware to force the machines to dispense large quantities of cash. The sophisticated attacks leveraged swapped hard drives or infected USB devices and allowed the perpetrators to launder stolen funds internationally, inflicting millions of dollars in losses on banks and credit unions. To date, over 87 individuals have been charged in this transnational criminal scheme. This incident highlights the evolving tactics of financially motivated threat groups combining physical access and technical expertise. The designation of Tren de Aragua as a Foreign Terrorist Organization underscores law enforcement’s recognition of cyber-enabled financial crime as a national security threat and signals intensified global scrutiny on such operations.
6 months ago
Kill Chain
Mustang Panda’s CoolClient Infostealer: 2026 Global Espionage Campaign Unveiled
In January 2026, Chinese state-sponsored group Mustang Panda leveraged an updated version of its CoolClient backdoor to conduct targeted espionage campaigns against government organizations in Myanmar, Mongolia, Malaysia, Russia, and Pakistan. The attackers used legitimate Sangfor software for initial infection and subsequently deployed tailored infostealers that extracted login credentials from major browsers, monitored clipboard data, and profiled compromised systems. The operation featured advanced tactics such as DLL side-loading, remote shell plugins, encrypted multi-stage payloads, and the use of public cloud services (via hardcoded tokens) for stealthy data exfiltration. This breach highlights the rapid advancement and operational innovation among state-backed APT actors, particularly regarding infostealer deployment and C2 evasion using legitimate cloud infrastructure. Organizations in APAC, government, and critical infrastructure sectors remain top targets as attacker toolsets evolve to bypass both endpoint and network security controls.
6 months ago
Kill Chain
2026 Fortinet Zero-Day SSO Breach: How Authentication Bypass Exposed Critical Devices
In January 2026, Fortinet disclosed a critical zero-day vulnerability (CVE-2026-24858) in its FortiCloud SSO authentication mechanism that allowed attackers to bypass security controls and gain unauthorized administrative access to FortiOS, FortiManager, and FortiAnalyzer devices. By leveraging rogue FortiCloud accounts, threat actors exploited an alternate authentication path—even on fully patched systems—to create new local admin and VPN-enabled accounts, exfiltrating firewall configuration data from customer environments within seconds. Fortinet mitigated active attacks by disabling vulnerable FortiCloud SSO connections and initiating global blocks before a patch was available, but over 25,000 devices were at risk during the attack window. This incident is highly relevant due to the growing sophistication and automation of supply chain and SSO-based attacks, with adversaries increasingly targeting trusted cloud management platforms. The event underscores the need for stricter access controls, rapid incident response capabilities, and heightened vigilance around identity infrastructure, especially as SAML and SSO adoption expands in modern enterprises.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports