The Containment Era is here. →Explore

Industry Category

Computer/Network Security

Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.

860 threat reports
Page 55 of 72

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer/Network Security Threat Reports

Showing 649660 / 860 reports
French Interior Ministry 2024 Email Server Breach: What Happened & Key Lessons
Impact· high

French Interior Ministry 2024 Email Server Breach: What Happened & Key Lessons

In June 2024, the French Interior Ministry confirmed a significant cyberattack that targeted its internal email servers. Threat actors conducted a sophisticated intrusion into the ministry's IT infrastructure, accessing and potentially exfiltrating sensitive email communications. The breach was detected after suspicious activity was found on the email systems. While no citizen data has reportedly been compromised, the attack forced authorities to rapidly isolate affected servers and implement remedial security protocols, causing temporary disruption to some official communications and raising concerns about government data confidentiality and resilience. This incident is emblematic of an increasing trend of targeted attacks on government email and communication systems. With attackers becoming more adept at breaching core administrative platforms, nations are under heightened pressure to bolster segmentation, encryption in transit, and detection capabilities to safeguard critical infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
ShadyPanda’s Browser Extension Supply-Chain Attack Exposes Millions in 2025
Impact· medium

ShadyPanda’s Browser Extension Supply-Chain Attack Exposes Millions in 2025

In December 2025, security researchers uncovered a widespread supply-chain attack perpetrated by the threat group ShadyPanda, which had silently compromised several popular Chrome and Edge browser extensions. Over the course of seven years, ShadyPanda either published or acquired seemingly innocuous extensions, allowed them to build credibility and large user bases, and then weaponized them through malicious updates. The attackers exploited the implicit trust in browser extension ecosystems to exfiltrate user data and potentially inject hostile code into millions of browsers worldwide, impacting individuals and organizations alike. This incident underscores persistent risks in software supply chains, as threat actors increasingly target trusted application ecosystems to achieve broad access. As browser extensions remain integral to productivity and daily workflows, the event highlights the urgency for organizations to monitor third-party components and reassess extension management, especially amid evolving regulatory scrutiny and attacker sophistication.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
10 Critical November 2025 CVEs: Quality Over Quantity in Exploitation Trends
Impact· low

10 Critical November 2025 CVEs: Quality Over Quantity in Exploitation Trends

In November 2025, a sharp 69% drop in reported critical vulnerabilities masked a surge in the intensity of exploitation campaigns. Threat intelligence from Recorded Future revealed 10 high-risk CVEs—including two critical Fortinet FortiWeb flaws—actively targeted by threat actors. Notably, the LANDFALL spyware campaign weaponized Samsung's image processing vulnerability for zero-click remote attacks, while seven of ten vulnerabilities had public proof-of-concept code released. Vulnerabilities included OS command injection, out-of-bounds writes, access control failures, and issues affecting major vendors such as Microsoft, Oracle, and Google. This incident highlights how attackers are shifting to fewer but far more impactful vulnerabilities, emphasizing quality over quantity in their exploitation. Security teams must adapt, maintaining vigilance even during perceived lulls and prioritizing fast patching, advanced monitoring, and comprehensive exposure management to counter rapidly evolving threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Mesa County's 2021 Election System Data Breach: The Insider Threat Exposed
Impact· high

Mesa County's 2021 Election System Data Breach: The Insider Threat Exposed

In 2021, Mesa County, Colorado experienced a significant breach of its election system data, orchestrated by then-county election clerk Tina Peters. Unauthorized copies of sensitive voting-system hard drives were made following the 2020 U.S. Presidential election and leaked to the public, purportedly to expose alleged voter fraud. The breach, which did not reveal any evidence of fraud, exposed highly confidential election infrastructure information, leading to criminal charges against Peters. The incident is widely recognized as one of the most impactful attacks on U.S. election security in recent years and undermined trust within the local community and beyond. This case highlights the ongoing risks to election system integrity posed by insider threats and emphasizes the importance of robust access controls, encryption, and segmentation. It is particularly relevant today as the U.S. prepares for upcoming elections amid heightened scrutiny of both technical and human vulnerabilities in election infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Fake OSINT and GPT GitHub Repos Used to Spread PyStoreRAT in Supply Chain Attack
Impact· medium

Fake OSINT and GPT GitHub Repos Used to Spread PyStoreRAT in Supply Chain Attack

In late 2025, cybersecurity researchers uncovered a supply chain attack involving malicious repositories on GitHub impersonating open-source Python utilities themed around OSINT and GPT automation. These repos covertly delivered a previously unseen JavaScript-based Remote Access Trojan dubbed PyStoreRAT, using minimal code to retrieve and execute a remote HTA file. Unsuspecting developers and security professionals, lured by the project's legitimate appearance, risked compromise when cloning or running the code, resulting in unauthorized remote access and potential data exfiltration. The campaign highlights the growing sophistication of attacks abusing trusted developer platforms and open-source supply chains. This incident underscores the urgent need for organizations to audit third-party code sources, bolster code supply chain security, and monitor for emerging malware targeting developer ecosystems. The tactic reflects broader trends in social engineering, weaponized open-source projects, and the exploitation of generative AI themes by threat actors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Hamas Espionage Malware Hits Middle East Diplomats: 2024 Breach Analysis
Impact· medium

Hamas Espionage Malware Hits Middle East Diplomats: 2024 Breach Analysis

In early 2024, state-sponsored threat actors linked to Hamas intensified cyber-espionage campaigns targeting Middle Eastern diplomatic entities. Attackers leveraged tailored malware and advanced phishing schemes to infiltrate networks, harvest intelligence, and gain persistent access to government communications. The campaign utilized unpatched vulnerabilities, abused encrypted and lateral east-west traffic, and bypassed conventional perimeter defenses. These intrusions aimed to gather political intelligence and undermine regional security, impacting the operational confidentiality of affected governments and creating heightened diplomatic tensions. This incident reflects a broader escalation in politically motivated cyber-espionage across the region, as Hamas and allied groups continue to innovate with more sophisticated tooling and tactics. The evolving threat landscape underscores the urgency for robust east-west segmentation, encrypted traffic controls, and real-time threat detection among critical infrastructure and state agencies.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
WIRTE’s 2025 Espionage Campaign: Middle East Governments Breached via AshenLoader and AshTag
Impact· medium

WIRTE’s 2025 Espionage Campaign: Middle East Governments Breached via AshenLoader and AshTag

In late 2025, the advanced persistent threat group WIRTE, linked to Gaza Cyber Gang, launched a far-reaching espionage campaign against government and diplomatic entities across the Middle East using a new malware suite known as AshTag. Attackers used phishing emails with geopolitical lures to entice targets into downloading malicious archives, resulting in the sideloading of AshenLoader and the deployment of AshTag. This modular .NET backdoor enabled remote command execution, persistence, and document exfiltration, specifically targeting sensitive diplomatic materials. Notably, attacks persisted throughout the Israel-Hamas conflict and continued after the Gaza ceasefire, highlighting the threat actors' sustained operational tempo. This campaign is a potent reminder of the increasing sophistication of state-linked espionage operations, including the adoption of advanced malware delivery and in-memory execution tactics designed to evade detection. With attackers broadening their target geography and refining their methods, regional governments and strategic organizations must urgently review and upgrade their defenses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Ashen Lepus Strikes: 2025 APT Breach Unveils Advanced Espionage Across Middle Eastern Diplomatic Targets
Impact· medium

Ashen Lepus Strikes: 2025 APT Breach Unveils Advanced Espionage Across Middle Eastern Diplomatic Targets

In late 2025, a Hamas-affiliated APT group known as Ashen Lepus (also referred to as WIRTE) executed a sophisticated cyber-espionage campaign targeting governmental and diplomatic organizations across multiple Middle Eastern countries. The attackers leveraged a novel modular malware suite called AshTag, delivered through decoy documents, DLL sideloading, and a carefully staged infection chain. The campaign made extensive use of in-memory payload delivery, advanced encryption, legitimate-themed subdomains for C2 communications, and the abuse of widely used file transfer tools like Rclone to exfiltrate sensitive, often diplomacy-related data. This incident marks a notable evolution in the operational security and technical sophistication of Middle Eastern espionage campaigns. It highlights the rising use of modular malware, infrastructure blending, and legitimate protocol abuse by regionally motivated threat actors, underscoring a trend where state-linked groups continue cyber operations despite geopolitical turmoil or ceasefires.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Ukrainian Hacker Charged: Russian Hacktivist Attacks Underscore U.S. Critical Infrastructure Risks
Impact· high

Ukrainian Hacker Charged: Russian Hacktivist Attacks Underscore U.S. Critical Infrastructure Risks

In 2024, U.S. authorities charged a Ukrainian national for collaborating with Russian state-sponsored hacktivist groups in a series of high-profile cyberattacks against critical infrastructure. The targeted sectors included U.S. water systems, election infrastructure, and nuclear facilities. Leveraging advanced intrusion tools and lateral movement tactics, the attacker contributed to sophisticated campaigns aimed at espionage, disruption, and potential sabotage. These efforts underscore the persistent threat posed by coordinated state-aligned cyber actors and the increasing risk to essential public services worldwide. This case highlights how modern threat actors are expanding their focus from traditional targets to critical infrastructure with geo-political motives. The intersection of hacktivism, nation-state support, and escalating global tensions demands greater cyber defense readiness and robust compliance from both private and public sectors.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Google Chrome 2025: AI Browsing Defenses Raise the Bar Against Indirect Prompt Injection
Impact· medium

Google Chrome 2025: AI Browsing Defenses Raise the Bar Against Indirect Prompt Injection

In December 2025, Google implemented new layered defenses in the Chrome browser to counter indirect prompt injection attacks following the introduction of agentic AI features. Attackers exploited weaknesses inherent in large language model-powered browser agents, attempting to override user intent, exfiltrate data from other sites, or execute rogue actions by injecting malicious prompts via untrusted web content. Google's updated architecture introduced components like the User Alignment Critic and Agent Origin Sets, isolating agent actions from attacker-controlled data and enforcing origin-based access controls. These measures aim to prevent data leaks and unauthorized automation that could compromise user accounts, sensitive information, or browser integrity. This incident highlights the rising risk of AI-driven browsing, where automated agents interacting with multiple web origins are exposed to sophisticated prompt-based attacks. The move reflects a broader industry push for deterministic (non-LLM) safeguards and ongoing regulatory and organizational scrutiny over rapidly evolving AI systems in end-user applications.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Storm-0249 Orchestrates Precision Ransomware Attacks with ClickFix and Advanced Endpoint Exploits
Impact· high

Storm-0249 Orchestrates Precision Ransomware Attacks with ClickFix and Advanced Endpoint Exploits

In December 2025, threat actors identified as Storm-0249 escalated their cybercriminal operations, shifting from initial access brokerage to hands-on ransomware deployment using advanced techniques. Leveraging the ClickFix social engineering tactic, they convinced victims to execute malicious commands via spoofed domains leading to fileless PowerShell execution and DLL side-loading attacks. The attackers exploited legitimate security software processes to deploy trojanized DLLs, establish persistent and encrypted communications, and use living-off-the-land binaries to evade detection. These sophisticated methods enabled Storm-0249 to lay the groundwork for ransomware payloads tied to unique system identifiers, bolstering their ability to monetize enterprise footholds with minimal exposure. This incident reflects a broader trend toward precision, low-noise endpoint exploitation using fileless methods and trusted process abuse. Cybersecurity teams must adapt quickly to shifting tactics that exploit endpoint trust, social engineering, and advanced lateral movement, as similar methodologies are rapidly proliferating among ransomware and initial access threat groups.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Spiderman Phishing Service: A 2024 Wakeup Call for European Banks
Impact· medium

Spiderman Phishing Service: A 2024 Wakeup Call for European Banks

In early 2024, a sophisticated phishing-as-a-service platform known as Spiderman emerged, targeting customers of more than 50 European banks and cryptocurrency holders. The perpetrators leveraged pixel-perfect cloned websites and credential harvesting techniques to deceive users into divulging sensitive financial information. Attackers used advanced phishing kits capable of bypassing two-factor authentication and dynamically generating legitimate-looking web pages, resulting in significant financial losses and heightened concern among European financial institutions. This incident underscores a growing trend of increasingly accessible and effective phishing services, enabling even low-skill cybercriminals to launch large-scale, targeted attacks. Regulatory scrutiny and the evolving threat landscape demand that organizations bolster defenses against phishing service operations leveraging social engineering and real-time site cloning.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports