✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Critical RCE Vulnerability Exposes Trend Micro Apex Central (2026)
In January 2026, Trend Micro disclosed a critical security vulnerability (CVE-2025-69258, CVSS 9.8) in its on-premise Apex Central for Windows, allowing unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges. The flaw exploited a LoadLibraryEX vulnerability in the MsgReceiver.exe component, enabling attacker-controlled DLL injection via specially crafted messages sent over TCP port 20001. Two accompanying vulnerabilities (CVE-2025-69259 and CVE-2025-69260, CVSS 7.5) could permit denial-of-service attacks. The vulnerabilities impacted Apex Central installations below Build 7190 and were responsibly disclosed by Tenable in August 2025. Organizations were urged to patch immediately to prevent potential system compromise. This incident highlights ongoing risks from remote code execution vulnerabilities in security management platforms. Attackers increasingly target critical infrastructure using sophisticated message-based exploits, making timely patching and enhanced segmentation crucial, especially amid rising regulatory scrutiny and a surge in supply chain attacks.
6 months ago
Kill Chain
Inside Vercel’s 2025 React2Shell Race: Supply-Chain RCE and the Open Source Security Wake-up Call
In late 2025, Vercel—maintainers of the popular Next.js framework—faced a critical cybersecurity incident involving the React2Shell vulnerability (CVE-2025-55182). Discovered just after Thanksgiving, this supply-chain flaw in React Server Components enabled unauthenticated remote code execution across multiple frameworks and bundlers in default configurations. A rapid, global response mobilized Vercel, open-source contributors, major cloud providers, and security vendors who coordinated mitigations and validated patches within days. Despite these efforts, over 60 organizations were compromised, with attackers from cybercriminal, ransomware, and nation-state groups exploiting disclosed weaknesses, leading to millions of exploit attempts and sustained attack volumes. The React2Shell episode highlighted the ongoing risks inherent in reliance on open-source components and the urgent need for collaborative, industry-wide response standards. Attackers have rapidly adopted similar techniques, sustaining high exploitation rates and revealing critical gaps in software supply-chain security.
6 months ago
Kill Chain
Cisco 2026 ISE Vulnerability: How Public Exploits Undermine Zero Trust
In January 2026, Cisco disclosed a critical vulnerability (CVE-2026-20029) affecting its widely used Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The flaw, caused by improper XML parsing in the web-based management interface, allows attackers with valid administrative credentials to upload a malicious file and access otherwise restricted files on the underlying operating system. While Cisco has not identified any active exploitation in the wild, proof-of-concept exploit code is publicly available and even privileged enterprise environments are exposed until patched. Administrators manage authentication, access, and segmentation policies through ISE, so exploitation could grant attackers access to highly sensitive network information or credentials, potentially undermining zero trust controls and compliance postures. This incident is particularly relevant as it highlights the ongoing risk posed by public exploit code, privilege escalation bugs, and gaps in patch hygiene for critical access-management tools. Increased regulatory scrutiny and the sophistication of attackers targeting identity and segmentation controls mean organizations cannot delay patching or segmentation efforts, especially as similar vulnerabilities continue to be a primary vector for advanced threats.
6 months ago
Kill Chain
China-Linked UAT-7290: Telecom Espionage Strikes via Linux Malware and ORB Nodes
In early 2026, a sophisticated China-linked threat actor designated UAT-7290 orchestrated targeted espionage campaigns against telecommunications providers across South Asia and Southeastern Europe. The attackers conducted meticulous intelligence gathering before leveraging one-day vulnerabilities and SSH brute-forcing to compromise exposed edge devices. Malicious payloads—including RushDrop, DriveSwitch, and the advanced SilentRaid—enabled persistent access, covert lateral movement, and deployment of Operational Relay Box (ORB) infrastructure, which can be used by other threat groups. Their arsenal blends open-source tools and bespoke Linux implants, demonstrating mature tradecraft and adaptability. This campaign reflects the increasing frequency and complexity of transnational espionage assaults on critical infrastructure, exploiting modern hybrid networks and advanced malware suites. Organizations in telecom and related sectors face mounting pressure to enhance east-west traffic controls, patch velocity, and incident response capabilities to defend against evolving APT operations.
6 months ago
Kill Chain
Multi-Vector Malware Attack Targets DShield Honeypots in January 2024
In January 2024, a sophisticated multi-vector malware campaign targeted DShield honeypot sensors, leveraging SSH brute force and automated malware delivery techniques. Multiple threat actors deployed different malware strains, including Redtail, orchestrating the attacks from a wide array of source IPs and employing frequent file uploads with changing hashes and filenames. Analysis of 30 days of ELK database sensor logs revealed that attackers exploited unmonitored remote access opportunities to move laterally and repeatedly bypass conventional defenses, successfully delivering malicious payloads using diverse infrastructure. This incident exemplifies the evolution of malware attacks that integrate automation, multi-stage delivery, and dynamic infrastructure to overwhelm detection systems. It mirrors broader industry concerns about increasingly sophisticated threat actor capabilities, especially as organizations face mounting regulatory pressure to improve east-west traffic visibility, segmentation, and cloud-native threat response.
6 months ago
Kill Chain
GoBruteforcer Botnet Hits Crypto Projects via AI-Configured Default Credentials
In January 2026, a significant wave of GoBruteforcer botnet attacks targeted cryptocurrency and blockchain projects by exploiting misconfigured, internet-facing servers. Attackers leveraged weak default credentials in commonly used XAMPP, MySQL, PostgreSQL, FTP, and phpMyAdmin deployments—many set up using AI-generated configuration examples. After brute-forcing access, threat actors deployed web shells and specialized utilities to scan for vulnerable cryptocurrency wallets, aiming to exfiltrate crypto assets from compromised infrastructure. Over 50,000 servers were estimated at risk, with threat actors automating large-scale scans and credential spraying campaigns over public IP space. This campaign highlights a critical trend: the proliferation of weak security settings driven by widespread adoption of AI-generated setup scripts, as well as persistent use of outdated, insecure server stacks. The convergence of automation, botnet-scale brute-forcing, and blockchain-targeted payloads marks an evolution in how cybercriminals exploit configuration drift and endpoint exposure in modern DevOps environments.
6 months ago
Kill Chain
Ransomware at Sedgwick Government Solutions: What the 2026 TridentLocker Breach Reveals
In January 2026, Sedgwick confirmed a security incident at its subsidiary, Sedgwick Government Solutions, a contractor serving over 20 U.S. federal agencies including CISA, DHS, and the U.S. Coast Guard. The breach was perpetrated by the TridentLocker ransomware group, which claimed to have stolen 3.39 GB of sensitive documents and subsequently leaked data on its Tor site. The attackers gained access via an isolated file transfer system; however, Sedgwick asserts no evidence of compromise to core claims servers or operational disruption. External cybersecurity experts and law enforcement were immediately engaged, and affected systems were properly segmented from the wider parent company network. This incident highlights the increased targeting of government contractors by ransomware operators and underscores the importance of network segmentation, prompt incident response, and continuous monitoring. The breach reflects growing regulatory and client demands for transparent reporting and robust data protection as ransomware groups escalate their tactics.
6 months ago
Kill Chain
DCRat Delivered Through Fake Booking Emails Hits European Hotels in 2026
In early 2026, a sophisticated cyberattack campaign, tracked as PHALT#BLYX, targeted the European hospitality sector using malicious fake booking emails. These emails redirected recipients to fraudulent Blue Screen of Death (BSoD) pages, pressuring hotel staff to install fake fixes. This social engineering technique resulted in the deployment of DCRat, a remote access trojan capable of stealing sensitive data, harvesting credentials, and providing attackers with persistent network access. The campaign, reported by Securonix, underscores the increasing professionalization of phishing lures and multi-stage malware delivery aimed at high-turnover verticals like hospitality. The attack highlights a recent trend of leveraging socially engineered booking-themed lures paired with malware disguised as system utilities. As similar TTPs proliferate and more malware-as-a-service tools become accessible, such incidents foreshadow growing risks for sectors with transient workforces and limited security training.
6 months ago
Kill Chain
Insider Threat Reality: US Cyber Pros Caught as BlackCat Ransomware Affiliates
In 2023, two U.S.-based cybersecurity professionals—formerly employed by major security firms—pleaded guilty to acting as affiliates for the ALPHV/BlackCat ransomware group. The individuals leveraged their insider knowledge and technical expertise to facilitate the deployment of the ransomware, compromising sensitive systems in targeted organizations. By exploiting weaknesses in internal security protocols and bypassing detection mechanisms, they assisted in the encryption of files and extortion of affected businesses, resulting in operational disruptions and significant reputational damage across multiple sectors. This incident highlights an escalating threat posed by insiders with privileged knowledge and skills, who collaborate with sophisticated ransomware groups like BlackCat. The convergence of advanced ransomware-as-a-service operations and trusted industry insiders signals a dangerous shift, amplifying calls for more robust zero trust strategies, stricter network segmentation, and improved insider threat monitoring.
6 months ago
Kill Chain
Inside the ClickFix Campaign: How Hospitality Firms Were Hit with DCRat Remote Access Attacks
In early 2024, a sophisticated phishing campaign known as 'ClickFix' targeted organizations in the hospitality sector with convincing fake 'Blue Screen of Death' error messages. Attackers leveraged social engineering techniques combined with a legitimate Microsoft utility to trick victims into executing malicious payloads. Once engaged, the attack delivered the DCRat remote access trojan, granting cybercriminals ongoing access and control over affected systems. The campaign demonstrated how legitimate tools and realistic lures can bypass conventional defenses, resulting in compromised credentials, lateral network movement, and potential data exfiltration. This incident reflects a wider trend of threat actors increasingly turning to legitimate software and advanced social engineering to evade detection. Remote access trojans like DCRat continue to be used in targeted attacks, particularly against sectors with complex digital footprints and limited security controls, making it vital for organizations to adapt their threat detection capabilities.
6 months ago
Kill Chain
NordVPN 2026: False Data Breach Claim Traced to Vendor Test Environment
In January 2026, a threat actor claimed to have breached NordVPN's internal Salesforce development servers, alleging access to over ten databases containing sensitive Salesforce API keys and Jira tokens. The attacker purportedly leveraged brute-force tactics against a misconfigured server; however, NordVPN clarified that the data originated from a vendor's temporary test environment used months prior for automated testing. The breached environment contained only non-sensitive, dummy data, was never linked to NordVPN's production infrastructure, and did not expose customer information or production credentials. The company immediately investigated, engaged with the affected vendor, and publicly denied any compromise of its operational assets. This incident highlights how false breach claims—when amplified by threat actors and forums—can impact enterprise reputation, erode trust, and distract security teams. The event also spotlights the importance of robust controls and clear communication regarding third-party environments, even those used only for testing, as threat actors increasingly seek to exploit every operational touchpoint.
6 months ago
Kill Chain
VSCode IDE Forks Expose Software Supply Chain Risks via Recommended Extensions
In late 2025, researchers at Koi Security identified a vulnerability across several AI-powered IDEs forked from Microsoft Visual Studio Code—including Cursor, Windsurf, Google Antigravity, and Trae—whereby hardcoded lists of "recommended" extensions pointed to namespaces that were unclaimed in the OpenVSX extension registry. Threat actors could exploit this by registering these namespaces and publishing malicious extensions, leveraging user trust in built-in recommendations. The risk affected any developer using these IDE forks, potentially opening the door for supply chain malware. After reporting, project maintainers began removing vulnerable recommendations and placeholder, non-functional extensions were uploaded to block exploitation. No evidence of active malicious abuse was found prior to remediation. This incident underscores the growing risk of software supply chain attacks, particularly via open-source repositories and trusted platform recommendations. As more AI-powered tools automate software development environments, attackers are increasingly targeting overlooked dependency and plugin ecosystems, forcing organizations to enhance extension and third-party controls.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports