✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
VSCode IDE Forks Expose Software Supply Chain Risks via Recommended Extensions
In late 2025, researchers at Koi Security identified a vulnerability across several AI-powered IDEs forked from Microsoft Visual Studio Code—including Cursor, Windsurf, Google Antigravity, and Trae—whereby hardcoded lists of "recommended" extensions pointed to namespaces that were unclaimed in the OpenVSX extension registry. Threat actors could exploit this by registering these namespaces and publishing malicious extensions, leveraging user trust in built-in recommendations. The risk affected any developer using these IDE forks, potentially opening the door for supply chain malware. After reporting, project maintainers began removing vulnerable recommendations and placeholder, non-functional extensions were uploaded to block exploitation. No evidence of active malicious abuse was found prior to remediation. This incident underscores the growing risk of software supply chain attacks, particularly via open-source repositories and trusted platform recommendations. As more AI-powered tools automate software development environments, attackers are increasingly targeting overlooked dependency and plugin ecosystems, forcing organizations to enhance extension and third-party controls.
6 months ago
Kill Chain
Bitfinex 2016 Hack: Anatomy of a Record Crypto Heist and Its Aftermath
In 2016, cryptocurrency exchange Bitfinex suffered one of the largest crypto thefts to date when hackers, including Ilya Lichtenstein, exploited security weaknesses to steal nearly 120,000 Bitcoins, worth billions of dollars at the time. Lichtenstein laundered the stolen funds through a sophisticated network of wallets and exchanges to obscure the assets' origin. Following a lengthy investigation, U.S. authorities arrested Lichtenstein in 2022, later convicting and sentencing him for money laundering tied to this high-profile breach. The Bitfinex hack has become a landmark case in cryptocurrency security and digital money laundering tactics. Its legacy persists as the industry faces increased regulatory scrutiny and ongoing threats targeting exchanges via increasingly sophisticated cyber methods.
6 months ago
Kill Chain
Russia-Aligned Group UAC-0184 Breaches Ukrainian Government via Viber Attack
In early 2025, the Russia-aligned cyber-espionage group UAC-0184 undertook a targeted campaign against Ukrainian military and government organizations. Leveraging the popular Viber messaging platform, the threat actors distributed malicious ZIP archives to infiltrate sensitive networks. Security researchers from the 360 Threat Intelligence Center noted that these operations demonstrated continued intelligence-gathering efforts, employing social engineering tactics and the abuse of trusted communication channels. The attack resulted in the unauthorized access and potential exposure of confidential government and defense information, further escalating the cyber hostilities related to the conflict in Ukraine. This incident highlights a growing trend in the weaponization of encrypted messaging apps for cyber-espionage, as nation-state actors increasingly exploit trusted consumer platforms to bypass traditional enterprise security controls. The breach underscores the urgency for robust east-west traffic monitoring, zero trust segmentation, and advanced detection capabilities across critical sectors.
6 months ago
Kill Chain
Resecurity 2025: How a Cybersecurity Firm Turned an Alleged Breach Into a Threat Intelligence Win
In December 2025, threat actors identifying as the 'Scattered Lapsus$ Hunters' claimed they had breached systems belonging to cybersecurity firm Resecurity, stealing employee data, internal communications, threat intelligence reports, and client information. The attackers published screenshots to support their claims, including evidence of access to collaboration platforms. However, Resecurity quickly countered the claims, explaining that the compromised environment was actually a carefully monitored honeypot populated with synthetic datasets and fake credentials, intentionally designed to attract cybercriminals for research purposes. The company monitored and logged the attackers’ behaviors, collected valuable intelligence—including reconnaissance, OPSEC failures, and the use of residential proxy infrastructure—and shared key data with law enforcement. No real customer data or production systems were at risk during the incident, according to Resecurity. This case highlights the growing trend of cyber attackers targeting security firms as retaliation for investigations, as well as the strategic use of deceptive honeypots to gather adversary intelligence. The incident underlines the importance of controlled cyber deception, advanced detection, and proactive threat intelligence amid an escalating environment of data theft claims and public leak extortion tactics.
6 months ago
Kill Chain
GlassWorm Malware Hits macOS: Supply Chain Attack via Malicious VSCode Extensions (2026)
In late 2025 and into January 2026, a new wave of the "GlassWorm" malware campaign targeted macOS developers by infiltrating Visual Studio Code and OpenVSX extension marketplaces. Malicious extensions, embedding AES-256-CBC–encrypted JavaScript payloads, were uploaded using covert techniques. Once installed, the malware stole sensitive credentials, including GitHub, NPM, and crypto wallet data, and established persistence via AppleScript and LaunchAgents. The campaign also attempted to replace popular hardware cryptocurrency wallet apps like Ledger Live and Trezor Suite, although this payload failed due to incomplete attacker infrastructure. Over 33,000 installs were recorded, potentially impacting individual developers and organizations reliant on secure software supply chains. GlassWorm’s evolution targets not only Windows but also macOS ecosystems, signaling a rising trend in sophisticated supply chain attacks against developer tooling. This incident is a cautionary reminder for organizations and developers to tightly scrutinize third-party plugins, raising urgency to implement stronger extension vetting, threat detection, and least-privilege controls.
6 months ago
Kill Chain
AI Supply Chain: Ultralytics, Nx, and ChatGPT Breaches Expose Massive Secrets Leakage
Between late 2024 and mid-2025, a series of major AI supply chain security breaches exposed severe vulnerabilities in widely used machine learning and development platforms. In December 2024, the Ultralytics AI library was compromised and distributed malicious code that hijacked victims’ systems for illicit cryptocurrency mining. By August 2025, attackers published malicious Nx packages that leaked over 2,300 GitHub, cloud, and AI credentials, enabling unauthorized access to sensitive resources. Throughout 2024, vulnerabilities in ChatGPT enabled cross-user data extractions via memory leakage, resulting in the exposure of personal and proprietary information. In total, an alarming 23.77 million secrets were leaked through AI-centric software and supply chain vectors within this period. This string of incidents impacted a wide spectrum of organizations, undermining trust in AI-based workflows and amplifying compliance and regulatory risk. These attacks underscore the rapidly escalating risk of supply chain compromise in AI-centric infrastructure. As organizations increasingly rely on open-source ML libraries and cloud-native platforms, threats targeting code dependencies, API memory, and package repositories are proliferating, outpacing traditional security controls. The incident highlights the urgent need for AI-aware, zero-trust frameworks, advanced east-west traffic monitoring, and routine credential hygiene to prevent similar future exposures.
6 months ago
Kill Chain
Trust Wallet Breach 2023: How a Shai-Hulud NPM Supply Chain Attack Stole $8.5M
In November 2023, Trust Wallet suffered a significant security breach in which an attacker exploited a malicious NPM supply chain package—most notably associated with the "Shai-Hulud" attack campaign. By leveraging this industry-wide incident, threat actors managed to compromise the Trust Wallet web browser extension, executing a targeted attack to steal approximately $8.5 million from over 2,500 crypto wallets. The threat actors utilized sophisticated techniques to inject malicious code via the open-source software supply chain, highlighting vulnerabilities in component dependencies and the risk of lateral movement within affected environments. This incident is especially relevant as supply chain attacks using compromised open-source packages are on the rise, impacting a broad range of organizations that rely on third-party code. The Trust Wallet breach underscores the urgency for robust supply chain security strategies, better monitoring of dependencies, and solid east-west traffic controls to detect anomalous behaviors and restrict lateral movement.
- Computer Software/Engineering
- Computer/Network Security
- Investment Management/Hedge Fund/Private Equity
6 months ago
Kill Chain
Mustang Panda’s 2025 Kernel Rootkit: How a Signed Driver Enabled Stealth Espionage in Asia
In mid-2025, the Chinese cyber espionage group Mustang Panda deployed a previously undocumented, signed kernel-mode rootkit to secretly load a TONESHELL backdoor variant during targeted attacks against government organizations in Southeast and East Asia—mainly Myanmar and Thailand. Leveraging a stolen legacy digital certificate, the attackers installed a Windows minifilter driver to inject TONESHELL into system processes, evade security controls, and shield their malware and associated files from detection. The backdoor enabled ongoing remote control, data exfiltration, and further malware deployments via encrypted channels, establishing persistent clandestine access. This incident is notable for its innovative use of signed kernel drivers to enhance stealth, resilience, and anti-forensic measures. It reflects a broader trend among sophisticated threat actors who increasingly leverage advanced rootkit technology and certificate abuse to bypass endpoint protections and remain undetected for extended periods.
6 months ago
Kill Chain
Worm in the Code: Shai Hulud & Cobalt Strike Unleash Supply Chain Threats on npm and Maven (2025)
In December 2025, researchers identified a modified strain of the Shai Hulud worm circulating in the npm registry via the package '@vietmoney/react-big-calendar.' While detected early with no large-scale infections, analysis showed the worm’s ability to compromise developer environments, harvest API keys, cloud credentials, and npm/GitHub tokens, and exfiltrate them to attacker-controlled GitHub repositories. Simultaneously, an unrelated but similar threat surfaced on Maven Central, where a typosquatted 'org.fasterxml.jackson.core/jackson-databind' package delivered an obfuscated Cobalt Strike beacon through supply chain compromise. Both incidents exploited weaknesses in public software repositories, targeting developer trust and facilitating potential lateral spread across the ecosystem. These incidents underscore the escalating risks of open source supply chain attacks, in which adversaries leverage trusted development components to sneak malware into organizations. With attacker sophistication growing and repository defenses lagging, enterprises face pressure to enhance visibility, automate dependency monitoring, and enforce zero-trust principles for third-party code integration.
6 months ago
Kill Chain
How the 2022 LastPass Breach Fueled $35M+ in Crypto Thefts
In 2022, LastPass suffered a significant data breach after attackers infiltrated a developer environment and stole company source code, later exploiting stolen credentials to breach cloud storage and extract encrypted customer password vaults. Despite vault encryption, weak or reused master passwords allowed attackers to eventually crack vaults offline, exposing sensitive credentials—including cryptocurrency wallet keys and seed phrases. Over the following years, coordinated threat actors drained victim wallets in distinct waves, laundering more than $35 million through techniques such as CoinJoin mixing, before cashing out via Russian-linked exchanges. This incident highlights the security risks of weak master passwords and illustrates the growing sophistication of post-breach credential exploitation, including the long-tail impact on industries handling digital assets. Organizations now face mounting regulatory pressure to strengthen secrets management and rapidly adapt to evolving attacker tradecraft targeting credential stores.
6 months ago
Kill Chain
478,000 Patients Impacted: Covenant Health Suffers Major Qilin Ransomware Breach in 2025
In May 2025, Covenant Health, a prominent Catholic healthcare provider in New England and Pennsylvania, experienced a significant ransomware attack by the Qilin group. The attackers breached the organization's systems on May 18, exfiltrated approximately 852GB of sensitive data—including names, addresses, social security numbers, medical records, and health insurance information—and subsequently encrypted essential files. Discovery of the breach occurred on May 26, with the scale initially underestimated, before forensic analysis revealed that nearly 478,000 patients were affected. The organization launched a comprehensive investigation, secured its systems, and is offering 12 months of free identity protection to impacted individuals. This breach highlights the continued targeting of healthcare organizations by sophisticated ransomware groups seeking to exploit large troves of sensitive personal and medical data. With ransomware tactics evolving and threat actors increasingly publishing stolen data for extortion, robust data protection and incident response have become critical priorities for healthcare providers.
6 months ago
Kill Chain
Trust Wallet Chrome Extension Breach: $8.5M Lost in Shai-Hulud Supply Chain Attack
In December 2025, Trust Wallet suffered a major supply chain attack targeting its Google Chrome browser extension. Attackers exploited leaked GitHub secrets to gain unauthorized access to Trust Wallet's source code and Chrome Web Store API keys, bypassing the firm’s standard release reviews. Malicious actors then uploaded a trojanized extension update that harvested user wallet mnemonic phrases and exfiltrated them to attacker-controlled infrastructure. The breach led to a rapid compromise of at least 2,520 digital wallets and the theft of approximately $8.5 million in cryptocurrency, prompting a large-scale reimbursement and investigation effort by Trust Wallet. This incident highlights the escalating trend of supply chain attacks exploiting trusted software dependencies and underscores the urgent need for rigorous release controls and key management in the software lifecycle.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports