The Containment Era is here. →Explore

Industry Category

Computer/Network Security

Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.

860 threat reports
Page 54 of 72

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer/Network Security Threat Reports

Showing 637648 / 860 reports
France's Ministry of the Interior Breached in Nation-State Attack: 2024 Suspect Arrested
Impact· low

France's Ministry of the Interior Breached in Nation-State Attack: 2024 Suspect Arrested

In June 2024, French authorities arrested a 22-year-old suspect in connection with a cyberattack targeting the Ministry of the Interior. The attack took place earlier in the month and was orchestrated using sophisticated nation-state level tactics, resulting in unauthorized access to sensitive government infrastructure. Although the Ministry quickly identified the incursion and initiated prompt containment measures, the breach underscored significant vulnerabilities in the security perimeter of key government agencies. Investigators believe the attacker leveraged advanced persistence techniques and attempted to exfiltrate confidential information before being apprehended. This incident underscores the growing sophistication of cyber operations targeting European governmental institutions. As nation-state and advanced persistent threats (APTs) escalate in frequency and impact, public sector organizations must reinforce zero trust segmentation, threat detection, and traffic encryption controls to stay ahead of evolving risks.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
ForumTroll APT Strikes Again: Russian Political Scientists Hit by Sophisticated Phishing Scheme
Impact· medium

ForumTroll APT Strikes Again: Russian Political Scientists Hit by Sophisticated Phishing Scheme

In October 2025, the ForumTroll advanced persistent threat (APT) group launched a spear-phishing campaign targeting Russian political science scholars and researchers. Victims received personalized emails disguised as plagiarism report notifications from a fake scientific library domain, prompting them to download a malicious archive. Opening the archive triggered a PowerShell-based attack chain, culminating in the deployment of the Tuoni red-teaming framework via a custom obfuscated loader, with persistence achieved through COM Hijacking. Attacker infrastructure included typosquatted domains and Fastly-based C2 servers. This incident underscores the increasing shift by APT actors to highly targeted, socially engineered phishing attacks, even when technical sophistication is dialed back. Organizations must contend with the reality of persistent, multi-phase campaigns adapting both commercial and bespoke toolkits, heightening the urgency for advanced detection and resilient user training.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ForumTroll Launches Sophisticated Phishing Attack on Russian Scholars Using Fake eLibrary Emails
Impact· low

ForumTroll Launches Sophisticated Phishing Attack on Russian Scholars Using Fake eLibrary Emails

In October 2025, Operation ForumTroll, a previously identified threat actor, launched a targeted phishing campaign against Russian academic and scholarly communities. Using convincingly crafted phishing emails that impersonated official eLibrary notifications, attackers distributed malicious attachments designed to harvest credentials and enable broader espionage operations. The campaign, identified by Kaspersky, marks a decisive tactical shift from prior attacks on organizations to focused targeting of individuals, raising concerns about the security posture of research and educational institutions in the region. This incident highlights the increasing trend of sophisticated phishing campaigns that employ social engineering and trusted brands to bypass traditional defenses. The focused targeting of scholars and intellectuals points towards a rise in espionage-motivated threats seeking sensitive research data, emphasizing the need for robust user education, multifactor authentication, and advanced anomaly detection.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
How BlueDelta (APT28) Targeted UKR.NET with Persistent Credential Harvesting (2024-2025)
Impact· medium

How BlueDelta (APT28) Targeted UKR.NET with Persistent Credential Harvesting (2024-2025)

Between June 2024 and April 2025, Russian state-sponsored threat group BlueDelta (APT28) orchestrated a persistent credential-harvesting campaign targeting users of UKR.NET, a leading Ukrainian webmail and news service. The threat actor employed convincing UKR.NET-lookalike login portals hosted on free services like Mocky, DNS EXIT, ngrok, and Serveo to steal usernames, passwords, and two-factor authentication codes. Phishing lures, primarily PDF attachments embedded with malicious links, were distributed to evade email scanning and sandboxing. Attackers continuously evolved their infrastructure—moving from compromised routers to anonymized tunneling platforms and adding new operational layers—reflecting increasing sophistication and resilience in support of GRU intelligence goals. This campaign exemplifies ongoing adaptations by nation-state actors to Western infrastructure takedowns and detection mechanisms, highlighting escalating risks to critical digital identities. Its advanced evasion techniques, modular infrastructure, and creative abuse of free online services signal a new phase in credential theft, underscoring the urgent need for organizations to reassess their defenses, particularly in the face of targeted phishing and lateral movement threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
A $0 Transaction Triggers a Nation-State Cyberattack on Anthropic’s AI Platform
Impact· low

A $0 Transaction Triggers a Nation-State Cyberattack on Anthropic’s AI Platform

In early 2024, Anthropic, a leading artificial intelligence company, was targeted in a sophisticated nation-state cyber espionage campaign. Adversaries utilized compromised payment cards—previously validated through Chinese-operated card-testing services—to attempt unauthorized access to Anthropic's AI platform. The attackers leveraged an established cybercriminal kill chain: stealing card data, validating credentials through tester merchants, and ultimately using the compromised accounts to escalate their intrusion attempts. While no sensitive customer data was confirmed to be compromised, the incident underscored the vulnerability of downstream cloud-based AI assets to upstream financial fraud and highlighted the intersection of cybercrime with state-sponsored intelligence objectives. This attack serves as a high-profile example of how advanced fraud intelligence can act as an early detection mechanism for state-sponsored cyber operations. The incident exemplifies rapid convergence between financial fraud and targeted espionage, emphasizing the need for cross-domain threat visibility and proactive controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Russian Nation-State Hackers Breach Critical Infrastructure via Edge Device Flaws
Impact· low

Russian Nation-State Hackers Breach Critical Infrastructure via Edge Device Flaws

In early 2024, Russian-linked APT actors launched a prolonged cyberattack campaign targeting critical infrastructure organizations globally, with a particular focus on the energy sector. Leveraging misconfigured edge networking devices, attackers gained initial access to internal networks, allowing them to perform lateral movement and conduct espionage on sensitive operational systems. The campaign, detailed by Amazon's security division, utilized unencrypted management traffic, enabling threat actors to intercept data-in-transit and issue command-and-control instructions undetected. Widespread exploitation resulted in data exfiltration, system compromise, and operational disruptions for affected organizations. This incident highlights a surge in advanced persistent threats exploiting basic configuration weaknesses in edge devices. The continued targeting of critical sectors by nation-state actors underscores the urgent need for stronger segmentation, encrypted network traffic, and improved detection capabilities, as attackers are increasingly adept at bypassing conventional perimeter defenses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
2025 Ransomware Attack Disrupts Venezuela’s State Oil Giant PDVSA
Impact· high

2025 Ransomware Attack Disrupts Venezuela’s State Oil Giant PDVSA

In December 2025, Petróleos de Venezuela (PDVSA), Venezuela’s national oil and gas company, experienced a significant ransomware attack that targeted its administrative systems. While official company communications downplayed the incident and attributed blame to international adversaries, media reports indicated substantial disruption: the attack resulted in major outages, took down vital IT systems, impacted cargo deliveries, and forced network disconnections. Efforts to remediate using antivirus software exacerbated downtime, and export activities, including loading instructions, were suspended. The incident highlighted operational fragility due to reliance on legacy infrastructure and a lack of segmentation between administrative and critical operational technologies. This breach spotlights the ongoing wave of ransomware attacks targeting energy and critical infrastructure sectors worldwide. It underscores how geopolitically charged environments, and legacy technologies without zero trust segmentation, remain especially vulnerable. The incident serves as a stark warning for the urgent adoption of robust east-west traffic controls and resilient response playbooks to mitigate emerging ransomware TTPs.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Sandworm Shifts Tactics: How Misconfigured AWS Edge Devices Enabled State Espionage in 2025
Impact· low

Sandworm Shifts Tactics: How Misconfigured AWS Edge Devices Enabled State Espionage in 2025

In early 2025, Amazon Threat Intelligence disclosed a sustained campaign by Russia's GRU-linked Sandworm (APT44) targeting Western critical infrastructure, with a focus on the energy sector. The threat actors shifted tactics from exploiting software vulnerabilities to exploiting misconfigured network edge devices hosted on AWS as their primary entry vector. Once inside, attackers intercepted sensitive network traffic to steal credentials and leveraged these to expand and maintain access across enterprise and critical infrastructure environments, including electric utilities, energy providers, and managed security providers. Remediation included notification of affected customers, removal of compromised AWS EC2 instances, and intelligence sharing with partners. This incident marks a concerning evolution in nation-state attack tradecraft: adversaries are prioritizing misconfigurations over traditional exploits, highlighting the need for organizations to reassess cloud and hybrid network security. The prevalence of cloud-hosted infrastructure increases urgency around identity and segmentation defenses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Illusory Systems 2022 Crypto Breach: Smart Contract Flaw Leads to FTC Settlement
Impact· high

Illusory Systems 2022 Crypto Breach: Smart Contract Flaw Leads to FTC Settlement

In July 2022, Illusory Systems (also known as Nomad) suffered a major security breach when attackers exploited an application security flaw in its Token Bridge smart contract platform. After pushing inadequately tested and poorly secured code to production, the company left the cross-chain bridge exposed to a vulnerability that was quickly leveraged by hackers to drain approximately $186 million in user-held cryptocurrencies. The breach went undetected internally, with staff first learning about it from a user on social media; response delays and lack of effective controls allowed attackers to empty the bridge. Regulatory investigation found misaligned security claims, absence of key safeguards, lack of automated fraud monitoring, and ineffective incident response processes, leading to severe financial and reputational damages for Illusory Systems. This incident echoes the rising threat landscape targeting blockchain infrastructure, with smart contract vulnerabilities increasingly exploited for high-value thefts. The FTC’s enforcement action against Illusory Systems highlights growing regulatory scrutiny and the urgent need for strong application security practices in the crypto-asset sector.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
How Attackers Exploit Windows Race Conditions with Path Lookups
Impact· medium

How Attackers Exploit Windows Race Conditions with Path Lookups

In December 2025, security researchers identified a critical exploitation technique leveraging race conditions within the Windows Object Manager namespace. Attackers can use specially crafted path lookups, combining recursive directories, symbolic links, shadow directories, and hash collisions, to artificially inflate kernel resource lookup times—sometimes up to several minutes. By exploiting this behavior, an attacker could significantly increase the window to win race conditions, potentially bypassing security checks and securing unauthorized access or escalating privileges. The impact of this exploit affects modern Windows 11 systems and is especially relevant for environments relying heavily on object access protections. This exploitation method highlights an enduring structural weakness that remains open even in recent Windows releases. With a broader trend toward complex system attacks and system resource manipulation, awareness and mitigations for race-based vulnerabilities have become a growing priority for enterprises and regulators.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Venezuelan Oil Giant PDVSA Hit by Cyberattack—Exports Disrupted in 2024 Incident
Impact· medium

Venezuelan Oil Giant PDVSA Hit by Cyberattack—Exports Disrupted in 2024 Incident

In June 2024, Petróleos de Venezuela S.A. (PDVSA), Venezuela’s state-owned oil giant, suffered a major cyberattack that disrupted its oil export operations. Attackers reportedly targeted IT infrastructure critical to the export scheduling and operational logistics of PDVSA, forcing the company to revert to manual processes while systems were restored. Although the precise entry vector and threat actor remain unconfirmed, preliminary indications suggest ransomware or disruptive malware may have played a role, leading to significant business interruption and delayed global shipments. This incident underscores the persistent risks facing critical infrastructure sectors worldwide, with cyberattacks increasingly targeting essential energy supply chains. With ransomware and nation-state threats evolving in sophistication, organizations must urgently prioritize segmentation, threat detection, and resilient network architectures.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Inside the 2025 KPop Malware Hunter Takedowns: Exposing Cloud Attack Trends
Impact· medium

Inside the 2025 KPop Malware Hunter Takedowns: Exposing Cloud Attack Trends

In 2025, a coordinated intelligence operation led by an international alliance of cybersecurity researchers, dubbed the KPop Malware Hunters, dismantled several prolific malware campaigns targeting global cloud and data center environments. Threat actors, including the group Salt Typhoon, exploited east-west traffic routes and unencrypted data in transit to achieve lateral movement post-compromise. Using advanced encrypted traffic analytics and inline IPS, defenders identified high-volume command-and-control exchanges masked within routine inter-region traffic. The operation led to significant disruption of adversary infrastructure, restoration of business operations, and improved threat visibility for impacted organizations worldwide. This takedown is highly relevant amid heightened attacks on hybrid and multicloud architectures, where sophisticated adversaries increasingly exploit internal cloud pathways and vulnerable segmentation. 2025’s events spotlight the urgent need for zero trust, inline threat detection, and rigorous compliance alignment as attackers leverage AI-driven evasion and cloud-native persistence.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports