✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Pakistan-Linked APT Launches Gopher Strike & Sheet Attack Against Indian Government in 2025
In September 2025, cybersecurity researchers uncovered coordinated cyber campaigns—dubbed Gopher Strike and Sheet Attack—targeting Indian government entities. Attributed to a Pakistan-linked Advanced Persistent Threat (APT) group, the operations leveraged novel, undocumented tactics involving phishing and multi-stage malware to compromise government networks. Attackers exploited existing security gaps, conducted lateral movement, and exfiltrated sensitive data, threatening the confidentiality and integrity of official communications. The campaigns remained undetected for an extended period, highlighting the advanced tradecraft and persistent nature of the threat actor. These incidents underscore the growing risk posed by state-aligned actors employing increasingly sophisticated tactics to target critical government infrastructure. The discovery of new tools and techniques in these attacks signals an escalation in South Asian regional cyber conflict and emphasizes the need for updated security controls and rapid detection capabilities.
6 months ago
Kill Chain
Sandworm Wiper Campaign Frustrated at Poland Power Grid
In May 2024, cyber researchers reported a high-profile attack attempt targeting Poland’s power grid infrastructure. The operation was attributed to Sandworm, a Russian APT group notorious for wiper malware and sabotage against critical national infrastructure. Attackers leveraged custom malware designed to disrupt grid operations, but strong detection and security controls reportedly thwarted the attempt, preventing widespread outages. The incident highlighted Sandworm’s persistent focus on critical infrastructure in Central Europe and their evolving tactics for sabotaging operational technology environments. This case underscores a larger trend of state-aligned threat actors targeting energy and critical infrastructure in Europe, leveraging specialized wiper tools and lateral movement techniques. It also emphasizes increasing cross-border cyber risk as geopolitical tensions escalate and underscores new regulatory scrutiny for critical sectors.
6 months ago
Kill Chain
Konni APT Leverages AI-Generated PowerShell to Breach Blockchain Developers
In January 2026, the North Korean-linked APT group Konni conducted a sophisticated phishing campaign targeting blockchain developers and engineering teams in Japan, Australia, and India. Using AI-generated PowerShell malware, attackers successfully penetrated targeted organizations by delivering malicious payloads through convincing spear-phishing emails. Once inside, the adversaries leveraged lateral movement and exfiltration techniques to access sensitive intellectual property and digital assets, expanding their historical targeting beyond South Korea and parts of Europe. The breach underscores the evolution of attacker tradecraft—adopting AI to evade traditional defenses and efficiently craft malicious code. This incident is highly relevant as it marks a notable surge in both AI-driven malware and the targeting of the blockchain sector. With threat actors broadening their geographic reach and operational sophistication, organizations must urgently re-evaluate their security controls, specifically around code execution, endpoint monitoring, and identity access management, to defend against emerging threats.
6 months ago
Kill Chain
DPRK's Konni: AI-Generated Backdoor Hits Blockchain Developers in 2024
In early 2024, the North Korean threat group Konni launched a sophisticated supply-chain attack targeting blockchain developers by deploying an AI-generated PowerShell backdoor within compromised development environments. The operation exploited development tools to surreptitiously gain access to cryptocurrency assets, leveraging advanced evasion techniques and encrypted communications to avoid detection. Victims faced risks of cryptocurrency theft, business disruption, and potential regulatory exposure, with the attackers demonstrating a deep understanding of both blockchain technologies and modern security controls. This incident highlights the growing convergence of AI-generated malware and targeted supply-chain attacks, especially against financially lucrative industries like cryptocurrency. As threat actors increasingly leverage custom malware and automated tools, organizations with high-value digital assets face mounting pressure to improve internal visibility, zero-trust enforcement, and incident response capabilities.
6 months ago
Kill Chain
Sandworm’s Failed DynoWiper Attack on Poland’s Energy Grid: A 2025 Nation-State Case Study
In late December 2025, Polish energy infrastructure was targeted in a sophisticated cyberattack attributed to Sandworm, a notorious Russian state-sponsored hacking group. The attackers attempted to deploy 'DynoWiper', a destructive data-wiping malware, against two combined heat and power facilities and key management systems for renewable energy assets. Although the wiper aimed to erase files and render systems inoperable, Polish officials confirmed the attack was detected and mitigated before operational disruption occurred. Attribution to Sandworm, linked to Russia’s GRU, underscores continued targeting of critical infrastructure by advanced persistent threats. This incident is highly relevant given the continued escalation of cyber operations against national infrastructure, particularly in Europe. It highlights the evolving use of destructive malware by state-backed actors and signals the necessity for robust cross-sector cyber defenses and detection mechanisms.
6 months ago
Kill Chain
Sandworm’s DynoWiper Attack on Poland’s Power Grid: How Cyberdefenders Stopped a Nation-State Threat
In late December 2025, Poland’s power sector faced the largest cyberattack in its history, attributed to the notorious Russian state-backed Sandworm group. The attackers deployed a new destructive malware strain dubbed DynoWiper, attempting to disrupt critical energy operations by wiping systems within operational networks. Polish cyber defense teams identified the attack early through advanced threat monitoring and contained the threat before any operational damage occurred. No loss of service or data was reported, and authorities confirmed that core infrastructure remained uncompromised. The incident has intensified scrutiny of nation-state threats to Europe’s energy grid, reinforcing calls for resilient cybersecurity postures across all critical infrastructure assets. Sandworm’s use of a novel wiper malware and focus on lateral movement echo a sharp uptick in high-impact, geopolitically motivated attacks targeting EU utilities. This case highlights the growing sophistication and persistence of nation-state cyber operations, raising fresh challenges for defenders in the energy sector and beyond.
6 months ago
Kill Chain
Konni Deploys AI-Built Malware Against Blockchain Engineers in 2026 Cyber Campaign
In January 2026, the North Korean-linked Konni APT (also known as Opal Sleet or TA406) launched a targeted cyber campaign against blockchain developers and engineers in the Asia-Pacific region, deploying bespoke PowerShell malware suspected of being generated using AI tools. Attackers lured victims with Discord-hosted ZIP files containing malicious shortcut links that, when launched, initiated a multi-stage infection chain. This included staged extraction of obfuscated PowerShell backdoors, privilege detection, scheduled task creation for persistence, and hourly beaconing to a remote command-and-control server. The malware focused on extracting sensitive development environment credentials, API keys, and potentially cryptocurrency wallet access, posing significant risks to both individuals and organizations handling blockchain assets. This incident exemplifies a sharp escalation in attacker sophistication, particularly the operational use of AI-powered malware, accelerating the pace at which advanced persistent threats can scale, adapt, and evade detection. As malicious actors increasingly leverage generative AI to develop modular, well-commented, and evasive code, organizations in crypto and other high-value sectors face a heightened need for adaptive security controls and rapid incident detection to keep defenses aligned with evolving attack techniques.
6 months ago
Kill Chain
Researchers Disclose Widespread Automotive and EV Vulnerabilities at Pwn2Own 2026
In January 2026, security researchers at the Pwn2Own Automotive World competition uncovered and exploited dozens of critical vulnerabilities in modern vehicle infotainment systems and EV (electric vehicle) chargers from multiple manufacturers. By chaining flaws across network interfaces and poorly secured APIs, attackers demonstrated the ability to remotely compromise vehicle systems, extract sensitive data, and gain unauthorized control over critical vehicle functions. While these attacks were conducted in a controlled, ethical hacking contest, they highlighted the substantial risks posed by connected automotive platforms, which often lack robust segmentation and encryption for internal and external communications. This incident underscores the rapidly escalating threat landscape facing the automotive industry as vehicles integrate more digital and cloud-connected components. The research-driven breach foreshadows what real-world adversaries may attempt, making it urgent for OEMs and suppliers to adopt zero trust, comprehensive monitoring, and proactive vulnerability management.
6 months ago
Kill Chain
Fortinet FortiCloud Auth Bypass: Patched Firewalls Remain at Risk in 2026
In January 2026, Fortinet confirmed the existence of a critical authentication bypass (CVE-2025-59718) affecting its FortiCloud SSO feature, leaving fully patched devices vulnerable to compromise. Attackers exploited a patch bypass to gain administrative access, quickly creating VPN-enabled accounts and exfiltrating firewall configurations. Despite an earlier advisory, threat actors continued to exploit an unaddressed attack path, with the campaign becoming automated and impacting organizations globally. Evidence included unauthorized logins and suspect account creation, prompting urgent investigation and forensic response from network teams. This breach illustrates the growing risk posed by incomplete patches and the relentless pursuit by attackers of residual vulnerabilities, particularly in widely deployed network security products. It underscores the critical need for continuous monitoring, rapid patch validation, and limiting administrative access to sensitive management interfaces.
6 months ago
Kill Chain
AI-Generated Code Exposes New Honeypot Security Risks at Intruder (2026)
In January 2026, Intruder Security revealed an application security vulnerability in their intentionally vulnerable honeypot, stemming from AI-generated code that mishandled client-supplied IP headers. The AI-assisted system incorrectly trusted IP values in HTTP headers without enforcing a trust boundary, allowing attackers to inject payloads or spoof source IP information. This oversight, undetected by common static analysis tools, resulted in attacker-controlled inputs influencing system logic, posing potential risks for local file disclosure or server-side request forgery had the vulnerable code path been used differently. While the actual impact remained low due to the isolated nature of the honeypot, the incident highlights significant gaps in current AI-assisted development and security review processes. This event underscores the growing prevalence of AI-generated vulnerabilities and the limitations of automated security tools in identifying nuanced flaws. As enterprises increasingly rely on AI-driven coding and automation, such oversights are likely to become more common, emphasizing the need for robust validation and updated security governance.
6 months ago
Kill Chain
US ATM Jackpotting 2024: Venezuelan Hackers Steal Hundreds of Thousands Using Malware
In early 2024, federal prosecutors in South Carolina uncovered a sophisticated ATM jackpotting scheme perpetrated by two Venezuelan nationals. Employing financial malware, the attackers compromised U.S. bank ATM networks and extracted hundreds of thousands of dollars in cash. The scheme involved the unauthorized installation of malware on ATM machines, which enabled the criminals to override withdrawal limits and rapidly dispense large sums of money. Following their arrest, both individuals were convicted and will be deported after serving their sentences, highlighting significant vulnerabilities in ATM security and network segmentation. This incident reflects a growing trend in financial crime, where cybercriminals target banking infrastructure using advanced malware and physical access techniques. Regulators and banks are increasingly focused on hardening ATM systems and tightening controls to prevent similar attacks as cyber-enabled fraud remains a persistent and evolving threat.
6 months ago
Kill Chain
Fortinet 2026 Breach: Authentication Bypass Leads to Firewall Configuration Theft
In January 2026, Fortinet FortiGate devices became the target of a coordinated cyberattack exploiting an authentication bypass vulnerability (CVE-2025-59718) associated with the FortiCloud SSO feature. Attackers accessed vulnerable firewalls, created rogue administrative accounts, and swiftly exfiltrated firewall configuration data using automated tools, demonstrating significant threat actor sophistication. Reports indicated the campaign began on January 15, 2026, and quickly escalated as even patched devices were compromised—suggesting a patch bypass or incomplete remediation. Affected organizations faced exposure of sensitive security configurations and heightened risk of follow-on breaches or lateral movement within their networks. This incident spotlights the urgent challenges posed by cloud-exposed assets and incomplete vulnerability remediation. It emphasizes the criticality of rapid patch cycles, zero trust principles, and robust monitoring amid a trend of identity and configuration–focused attacks targeting enterprise infrastructure platforms.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports