The Containment Era is here. →Explore

Industry Category

Computer/Network Security

Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.

858 threat reports
Page 52 of 72

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer/Network Security Threat Reports

Showing 613624 / 858 reports
Trust Wallet Chrome Extension Breach: $8.5M Lost in Shai-Hulud Supply Chain Attack
Impact· high

Trust Wallet Chrome Extension Breach: $8.5M Lost in Shai-Hulud Supply Chain Attack

In December 2025, Trust Wallet suffered a major supply chain attack targeting its Google Chrome browser extension. Attackers exploited leaked GitHub secrets to gain unauthorized access to Trust Wallet's source code and Chrome Web Store API keys, bypassing the firm’s standard release reviews. Malicious actors then uploaded a trojanized extension update that harvested user wallet mnemonic phrases and exfiltrated them to attacker-controlled infrastructure. The breach led to a rapid compromise of at least 2,520 digital wallets and the theft of approximately $8.5 million in cryptocurrency, prompting a large-scale reimbursement and investigation effort by Trust Wallet. This incident highlights the escalating trend of supply chain attacks exploiting trusted software dependencies and underscores the urgent need for rigorous release controls and key management in the software lifecycle.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
HoneyMyte APT Unleashes Kernel-Mode Rootkit with ToneShell Backdoor in Southeast Asia
Impact· high

HoneyMyte APT Unleashes Kernel-Mode Rootkit with ToneShell Backdoor in Southeast Asia

In early 2025, the HoneyMyte APT group launched a targeted cyberespionage campaign against government organizations in Southeast and East Asia, primarily Myanmar and Thailand. Leveraging a stolen digital certificate, HoneyMyte deployed a malicious kernel-mode rootkit disguised as a signed driver to inject the advanced ToneShell backdoor into high-privilege system processes. The attack chain delivered full process, registry, and file protection for malicious activity, making removal and detection by security tools exceedingly challenging. The backdoor enabled covert remote access, data exfiltration, and command execution via communications camouflaged to resemble legitimate encrypted TLS traffic. This incident is a stark example of modern APT evolution, showcasing new levels of stealth and persistence through kernel-level threats and advanced obfuscation. It highlights a broader shift towards supply-chain and trusted-cert abuse, increasing risk for public sector and critical infrastructure targets in the Asia-Pacific region.

6 months ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Trust Wallet Chrome Extension Supply Chain Attack Results in $7 Million Crypto Theft
Impact· high

Trust Wallet Chrome Extension Supply Chain Attack Results in $7 Million Crypto Theft

In December 2023, Trust Wallet, a prominent cryptocurrency wallet provider, suffered a supply chain attack via its Chrome extension. Attackers compromised the extension update process on December 24, distributing malicious code to unsuspecting users. As a result, users who installed the tainted update had their crypto wallets drained, collectively losing over $7 million worth of digital assets. The attack leveraged phishing domains to trick users and highlighted gaps in software supply chain security. Trust Wallet responded swiftly with advisories and efforts to contain further compromise while warning all extension users. This breach underscores the escalating threat and sophistication of supply chain attacks targeting digital assets, echoing a sharp rise in attacks exploiting third-party software update channels. Organizations must prioritize controls around extension security, continuous monitoring, and response plans to mitigate similar high-impact incidents.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Trust Wallet Chrome Extension Breach: $7M in Crypto Lost to Supply Chain Attack
Impact· high

Trust Wallet Chrome Extension Breach: $7M in Crypto Lost to Supply Chain Attack

In December 2025, Trust Wallet suffered a major supply chain attack when a malicious version (2.68) of its Chrome browser extension was published via a compromised Chrome Web Store API key. The attacker embedded backdoored code that exfiltrated users’ decrypted mnemonic phrases to an external server, allowing theft of approximately $7 million in cryptocurrencies. Over 2,500 wallet addresses were impacted, with stolen funds laundered through centralized exchanges and cross-chain bridges. Trust Wallet responded by urging users to upgrade to a safe version, launching a reimbursement program, and enhancing release procedures. This breach highlights the growing risks of supply chain attacks targeting widely-used browser extensions, especially in the cryptocurrency sector. With attackers demonstrating sophistication by bypassing official release processes and leveraging trusted analytics tools for data exfiltration, organizations face mounting pressure to secure development and release pipelines against insider threats and credential misuse.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
LastPass 2022 Breach Fuels Years-Long Cryptocurrency Heists by Russian Actors
Impact· high

LastPass 2022 Breach Fuels Years-Long Cryptocurrency Heists by Russian Actors

In 2022, LastPass suffered a significant data breach that enabled attackers to steal encrypted password vaults, exposing sensitive customer credentials, including cryptocurrency wallet keys and seed phrases. According to research by TRM Labs, Russian cybercriminals exploited weak master passwords over subsequent years, decrypting vaults offline and siphoning more than $35 million in digital assets as recently as late 2025. Stolen funds were laundered using advanced cryptocurrency mixing and routed through sanctioned Russian exchanges. The incident underscores a persistent threat model: stolen encrypted data can remain exploitable for years if password hygiene and vault security are neglected. The breach’s fallout continues to evolve, heightening urgency for organizations to reassess encryption, password management, and layered defense strategies.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
MacSync Stealer 2025: Notarized macOS Malware Defeats Gatekeeper Protections
Impact· high

MacSync Stealer 2025: Notarized macOS Malware Defeats Gatekeeper Protections

In June 2025, security researchers uncovered a new campaign leveraging a variant of the MacSync information stealer, which specifically targets macOS devices. In this incident, attackers distributed malware using a digitally signed and Apple-notarized Swift-based application disguised as a messaging app installer. This approach allowed the threat to bypass Apple Gatekeeper security controls designed to prevent unauthorized software execution. Once executed, the stealer harvested sensitive user data—such as browser credentials, wallets, and system information—and exfiltrated it to remote attacker-controlled servers, posing significant operational and reputational risks to affected organizations and users. This incident highlights a growing trend wherein adversaries employ legitimate-looking, signed applications to circumvent platform defenses. With an uptick in sophisticated macOS attacks and abuse of code-signing, organizations need to bolster defenses and maintain heightened vigilance for notarized application threats in enterprise environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Webrat Infostealer Campaign: How Fake GitHub Exploits Breached the Cybersecurity Supply Chain
Impact· medium

Webrat Infostealer Campaign: How Fake GitHub Exploits Breached the Cybersecurity Supply Chain

In early 2025, security researchers identified a campaign distributing the Webrat infostealer through malicious GitHub repositories. The threat actors disguised their malware as proof-of-concept exploits for high-profile vulnerabilities, targeting not only gamers and users of cracked software, but also inexperienced cybersecurity professionals and students. Victims who downloaded these fake exploits unwittingly executed a dropper that installed Webrat, granting attackers administrator privileges, disabling security controls, and enabling data theft from wallets and communication platforms while providing backdoor access and surveillance. This incident underscores a growing attacker trend of abusing trust in open-source platforms and targeting cybersecurity researchers themselves. As the use of AI-generated content and supply chain attacks increase, professionals must exercise greater scrutiny when handling code from unverified sources, amplifying the need for security awareness and robust isolation practices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
WebRAT Infostealer Abuses GitHub: 2024 Supply Chain Attack Exposed
Impact· medium

WebRAT Infostealer Abuses GitHub: 2024 Supply Chain Attack Exposed

In June 2024, cybersecurity researchers observed a campaign distributing the WebRAT infostealer through malicious GitHub repositories. Threat actors uploaded repositories pretending to offer proof-of-concept exploits for recent vulnerabilities, luring security professionals and researchers to download and execute the malware. Once installed, WebRAT exfiltrates sensitive information, leverages encrypted channels to evade detection, and can facilitate follow-on attacks via credential or data theft. This campaign underscores the risks in sourcing security tools or code from unverified public repositories and demonstrates the sophistication of modern software supply chain attacks. The incident highlights the growing trend of cybercriminals abusing trusted platforms like GitHub to reach a wide audience. With infostealer malware evolving and developer-targeted attacks increasing, organizations must remain vigilant about supply chain security and implement controls to detect and block lateral movement or data exfiltration.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
How Russian State-Sponsored Cyberattacks Targeted Denmark’s Critical Infrastructure and Elections in 2024
Impact· high

How Russian State-Sponsored Cyberattacks Targeted Denmark’s Critical Infrastructure and Elections in 2024

In December 2025, Danish authorities attributed two major cyberattacks in 2024 to Russian-backed groups. The first attack targeted a Danish water utility, causing significant operational disruption, and was attributed to Z-Pentest, a pro-Russian threat actor. The second involved a series of distributed denial-of-service (DDoS) attacks against Danish municipal and regional council websites on the eve of critical elections, orchestrated by NoName057(16), another threat group with ties to Russia. These incidents highlighted the vulnerabilities of critical infrastructure and democratic processes to foreign state-sponsored actors. The fallout from these attacks underscores a broader pattern of rising state-sponsored cyber operations targeting essential services and democratic institutions across Europe. Heightened geopolitical tensions and the growing sophistication of threat actors are driving urgent calls for improved cyber defenses and regulatory responses.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
WatchGuard 2025 RCE Breach Exposes 115,000+ Firebox Firewalls Globally
Impact· medium

WatchGuard 2025 RCE Breach Exposes 115,000+ Firebox Firewalls Globally

In December 2025, a critical remote code execution (RCE) vulnerability, CVE-2025-14733, was disclosed impacting over 115,000 WatchGuard Firebox firewalls running Fireware OS. The flaw, residing in the OS iked process, allowed unauthenticated attackers to execute arbitrary code over the network when IKEv2 VPN was enabled. Actively exploited in the wild, the vulnerability placed thousands of organizations worldwide at risk of compromise. Shadowserver reported over 117,000 unpatched instances exposed online days after patches were released. U.S. federal agencies were ordered to patch affected firewalls within one week, with WatchGuard providing indicators of compromise, urgent mitigation steps, and guidance for customers unable to patch immediately. This incident underscores the persistent risk of edge device vulnerabilities and rapid attacker exploitation cycles. With federal mandates, ongoing zero-day disclosures, and increasingly sophisticated attack vectors targeting VPN and firewall infrastructure, organizations must prioritize timely patching and layered defenses to reduce exposure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ASUS Live Update Supply Chain Breach: Lessons from a Sophisticated APT Attack
Impact· low

ASUS Live Update Supply Chain Breach: Lessons from a Sophisticated APT Attack

In 2018, ASUS suffered a major supply chain compromise in which attackers, believed to be a state-linked APT group, infiltrated the ASUS Live Update utility and distributed a malicious software update to potentially hundreds of thousands of users. The attackers inserted a sophisticated backdoor into the official ASUS update, enabling targeted compromise of devices based on specific MAC addresses. Although the vulnerability (CVE-2025-59374) has only been formally cataloged recently, the incident itself occurred years ago, impacting trust in widely used supply chain components. This breach remains relevant due to the ongoing risk of similar supply chain tactics by advanced threat actors and the late inclusion of legacy vulnerabilities in compliance and threat feeds. Security leaders must recognize that historic supply chain compromises may resurface in compliance audits or be exploited in future campaigns through neglected, end-of-life software.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Malicious npm Package Exposes WhatsApp Accounts in 2025 Supply Chain Attack
Impact· medium

Malicious npm Package Exposes WhatsApp Accounts in 2025 Supply Chain Attack

In May 2025, a malicious npm package named "lotusbail" was uploaded to the JavaScript ecosystem, masquerading as a fully functional WhatsApp API. Created by a user known as "seiren_primrose," the package was downloaded over 56,000 times before discovery. Behind its legitimate capabilities, "lotusbail" stealthily exfiltrated WhatsApp credentials, intercepted all messages, harvested contacts, installed a persistent backdoor, and linked attacker devices to victims’ WhatsApp accounts for continuous unauthorized access. Data was encrypted and exfiltrated to attacker-controlled servers, with covert device pairing persisting even after package removal, compounding the risk to both individuals and organizations reliant on WhatsApp for communication. This incident highlights the growing risk of advanced supply chain attacks via trusted open-source repositories. Attackers increasingly use sophisticated evasion tactics—like anti-debugging, code obfuscation, and reputation laundering—to slip past static and reputation-based security controls. As software supply chain threats intensify, organizations must urgently reassess the hygiene, monitoring, and zero trust posture of their development pipelines.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports