The Containment Era is here. →Explore

Industry Category

Computer/Network Security

Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.

860 threat reports
Page 60 of 72

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer/Network Security Threat Reports

Showing 709720 / 860 reports
Coyote & Maverick Banking Trojans: 2024 Banking Attacks Sweep Brazil
Impact· medium

Coyote & Maverick Banking Trojans: 2024 Banking Attacks Sweep Brazil

In 2024, cybersecurity researchers observed a surge in banking Trojan activity in Brazil, notably from two malware strains named Coyote and Maverick. These Trojans specifically target financial institutions and individual banking customers by using advanced phishing campaigns, malicious email attachments, and fake banking apps to infiltrate devices. Once installed, they deploy credential-stealing modules, monitor browser activity, and intercept authentication data, often leveraging encrypted and east-west network traffic to evade security controls. Maverick is engineered to self-terminate if it detects a target located outside Brazil, indicating a strong geo-targeting component. The campaign’s impact includes stolen banking credentials, financial fraud, and operational disruption for affected users and banks in the region. The continued advancement and targeted nature of these Brazilian banking Trojans demonstrate a significant evolution in threat actor sophistication, especially toward region-specific attacks. Organizations need to heighten their defenses and monitor emerging tactics as financially motivated cybercrime rises across Latin America.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Amazon Detects APT Group Exploiting Cisco & Citrix Zero-Days in 2024
Impact· medium

Amazon Detects APT Group Exploiting Cisco & Citrix Zero-Days in 2024

In summer 2024, Amazon’s threat intelligence team identified that an advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (CVE-2025-20337) and Citrix NetScaler (CVE-2025-5777), months before official patches were released. The attackers leveraged custom malware with advanced evasion capabilities, demonstrating a deep understanding of enterprise Java and network edge products. Exploitation was detected as early as May, prior to vendor disclosure, allowing the threat actor prolonged access to target environments for likely espionage purposes. Massive exploitation attempts followed public disclosure, impacting thousands of organizations globally. This incident underscores the increased speed and sophistication with which threat groups are identifying and weaponizing zero-day vulnerabilities in critical network and identity infrastructure. The trend poses escalating risks for organizations relying on edge devices, making timely patching and layered defenses more crucial than ever.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Synnovis 2024 Ransomware Breach: UK Healthcare Services and Patient Data Exposed
Impact· high

Synnovis 2024 Ransomware Breach: UK Healthcare Services and Patient Data Exposed

In June 2024, Synnovis, a leading UK pathology services provider, suffered a significant ransomware attack that led to operational disruption and the exposure of sensitive patient data. The attack, attributed to Russian-speaking threat actor group Qilin, resulted in widespread IT outages across London hospitals, delaying critical healthcare procedures and temporarily halting diagnostic services. Investigations revealed that attackers were able to steal files containing patient information before encrypting core systems, underscoring the vulnerability of healthcare organizations to ransomware campaigns targeting their critical infrastructure. This incident is emblematic of a surge in highly targeted ransomware attacks against the healthcare sector globally. With a marked increase in double-extortion tactics and operationally disruptive attacks, this event highlights escalating cyber risk, increasing regulatory oversight, and the urgent need for robust cyber-resilience in healthcare.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Cisco ASA & Firepower Exploits: 2025 Emergency Directive and Breach Analysis
Impact· low

Cisco ASA & Firepower Exploits: 2025 Emergency Directive and Breach Analysis

In September 2025, critical vulnerabilities (CVE-2025-20333 and CVE-2025-20362) in Cisco Adaptive Security Appliance (ASA) and Firepower devices were actively exploited by unidentified threat actors. The initial compromise stemmed from unpatched or insufficiently updated devices, enabling attackers to bypass security controls, conduct lateral movement, and potentially gain persistent access to affected networks. CISA responded by issuing Emergency Directive 25-03, requiring federal agencies to verify patch levels, perform core dump analyses with RayDetect, and execute urgent remediation steps. Numerous organizations that assumed their systems were protected were found to be running outdated software, escalating operational risks and exposing sensitive data. This incident underscores a growing trend of attackers targeting critical network infrastructure devices leveraging newly discovered or previously unpatched vulnerabilities. With increasing regulatory scrutiny, immediate and robust vulnerability management is required across all sectors to prevent exploitation of supply chain and edge network technologies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
ClickFix Phishing Hits Hospitality: Hotel Credentials Compromised via PureRAT
Impact· medium

ClickFix Phishing Hits Hospitality: Hotel Credentials Compromised via PureRAT

In late 2025, the hospitality sector was targeted by a sophisticated, large-scale phishing campaign involving ClickFix-style lures that tricked hotel managers into revealing their credentials. Attackers leveraged compromised email accounts to distribute malicious links to numerous hotel establishments, leading victims to phishing sites that mimicked familiar workflow tools. Credential theft enabled deployment of PureRAT malware, which provided remote access to internal hotel systems and enabled lateral movement, resulting in compromised operations and data exposure for multiple organizations. This incident demonstrates the increasing use of advanced social engineering in credential-focused attacks against the hospitality industry. With phishing campaigns growing more convincing and commodity RATs like PureRAT widely available, organizations in high-turnover sectors face mounting risk from credential-based breaches and follow-on malware infections.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
TEE.fail: 2025 Hardware Attack Cracks Latest Secure Enclaves
Impact· medium

TEE.fail: 2025 Hardware Attack Cracks Latest Secure Enclaves

In November 2025, researchers disclosed a critical hardware attack known as TEE.fail, which compromised secure enclaves (trusted execution environments or TEEs) across Intel, AMD, and ARM chips. By placing a small hardware device between a DDR5 memory chip and the motherboard, and leveraging kernel-level privileges, attackers were able to bypass the most advanced TEE protections including Confidential Compute, SEV-SNP, and TDX/SDX. Once exploited, these secure enclaves could no longer be trusted to protect sensitive data in-use, raising major concerns for cloud providers, enterprises, and users reliant on confidential computing. The attack’s low cost, simplicity, and applicability to modern hardware make it a significant development, reflecting growing sophistication in hardware-level threats. Regulatory scrutiny and industry attention have intensified as organizations reevaluate their trust assumptions and risk models for sensitive workloads.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Yanluowang Ransomware & Access Broker Target U.S. Firms: Volkov Convicted
Impact· high

Yanluowang Ransomware & Access Broker Target U.S. Firms: Volkov Convicted

Between July 2021 and November 2022, multiple U.S. businesses—including an engineering firm and a bank—were targeted by the Yanluowang ransomware group, using access broker Aleksei Olegovich Volkov to gain initial entry. Volkov, operating as “chubaka.kor,” exploited vulnerabilities in victim networks, facilitated data theft and encryption, and coordinated ransom payments, some of which totaled $1.5 million. Victims suffered operational disruption, including temporary shutdowns and extortion attempts such as DDoS attacks and executive harassment. Forensic analysis linked the activities to Volkov via cryptocurrency tracing and communication evidence; $24 million in ransoms was demanded in total. This case highlights growing cooperation among cybercriminals, where access brokers sell or share footholds with ransomware operators, fueling larger-scale, multi-faceted cyber-extortion campaigns. The high-profile prosecution also sets precedent for international arrests and restitution, amid increasingly aggressive ransomware trends and evolving attack tactics.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
SonicWall 2024 Breach: Nation-State Actor Steals Firewall Backups in Supply Chain Attack
Impact· medium

SonicWall 2024 Breach: Nation-State Actor Steals Firewall Backups in Supply Chain Attack

In early 2024, SonicWall, a prominent network security vendor, disclosed that a sophisticated nation-state threat actor had gained unauthorized access to its systems and exfiltrated firewall backup configurations. The breach exploited the MySonicWall cloud portal as an entry vector, allowing attackers to obtain sensitive backup files from certain customers. While SonicWall emphasized that no customer credentials or direct device access occurred, the compromised backup data could potentially aid attackers in mapping internal customer network topologies, exposing configurations, or enabling tailored downstream attacks. The breach was unrelated to the recent Akira ransomware campaign targeting SonicWall appliances. This incident underscores the increasing targeting of security infrastructure suppliers in supply chain attacks. With nation-state actors focusing on backup and configuration theft, the breach highlights emergent risks to organizations relying on third-party network security providers for confidentiality and resilience.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SonicWall 2024 Cloud Backup Breach: Nation-State Attack Exposes Supply Chain Risks
Impact· high

SonicWall 2024 Cloud Backup Breach: Nation-State Attack Exposes Supply Chain Risks

In 2024, SonicWall disclosed a major supply-chain security incident where a state-sponsored threat actor exploited an API flaw to access the company's firewall cloud backup service. This breach, initially downplayed, resulted in the exposure and exfiltration of firewall configuration files for all customers leveraging SonicWall’s cloud backup. These files contained sensitive data such as firewall rules, encrypted credentials, and routing details, representing a significant risk for impacted organizations. An investigation by Mandiant confirmed the full scale of the compromise, though the specific country or threat group responsible remains undisclosed. This attack is especially relevant due to increasing targeting of security vendors and the potential for cascading risk across the customer base. The incident underscores persistent concerns over supply-chain vulnerabilities and the sophistication of nation-state actors focusing on critical infrastructure providers.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
SonicWall Cloud Backup Breach: How State-Sponsored Attackers Exploited API Weaknesses in 2025
Impact· medium

SonicWall Cloud Backup Breach: How State-Sponsored Attackers Exploited API Weaknesses in 2025

In September 2025, SonicWall confirmed that state-sponsored threat actors orchestrated a security breach targeting its cloud backup environment. The attackers exploited an API vulnerability to gain unauthorized access to firewall configuration backup files stored in a specific cloud deployment. SonicWall's investigation determined the breach was limited to the exposure of these configuration files, with no evidence of lateral movement or impact to production systems. The breach prompted immediate containment actions, disclosure to affected customers, and a global review of cloud access controls and incident response procedures. This incident underscores the increasing risk posed by sophisticated, nation-state adversaries targeting cloud environments and API endpoints. It highlights how misconfigurations and insufficient segmentation in cloud infrastructure can facilitate data exposure, driving industry-wide reassessment of cloud-native security and compliance practices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Phishing Attack Delivers Kalambur Backdoor via Trojanized ESET Installers in Ukraine
Impact· low

Phishing Attack Delivers Kalambur Backdoor via Trojanized ESET Installers in Ukraine

In May 2025, a Russia-aligned threat group tracked as InedibleOchotense conducted a spear-phishing campaign targeting Ukrainian organizations. Attackers impersonated Slovak security company ESET, delivering phishing emails and Signal messages containing malicious links to trojanized ESET installers. When unsuspecting victims executed these files, a previously undocumented backdoor named Kalambur was installed, granting attackers covert access to compromised systems and enabling persistent network reconnaissance, command execution, and data exfiltration. The impersonation of a well-known cybersecurity firm lent the campaign added credibility, elevating its success rate and risk to targeted entities. This incident is a stark illustration of evolving phishing TTPs that exploit software supply chain trust and employ realistic impersonation. The campaign highlights the enduring threat posed by nation-state actors employing sophisticated lures, and underscores the urgent need for vigilant software validation, phishing awareness, and robust protective controls across organizations operating in high-risk geopolitical regions.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
US Sanctions North Korean Banks for Cryptocurrency Cybercrime in 2024
Impact· medium

US Sanctions North Korean Banks for Cryptocurrency Cybercrime in 2024

In May 2024, the U.S. Treasury sanctioned two North Korean banks and eight individuals believed to be heavily involved in high-profile cryptocurrency laundering operations linked to state-sponsored cybercrime. The sanctioned parties allegedly laundered millions of dollars in digital assets stolen through cyberattacks and IT worker fraud, often hiding illicit proceeds to evade international detection. North Korean operatives reportedly posed as legitimate IT contractors for Western firms to gain unauthorized access to sensitive systems and divert funds, fueling further malicious operations and funding government programs in Pyongyang. This incident exemplifies shifting tactics in cyber-enabled financial crime, where attackers exploit advanced laundering techniques and foggy compliance areas around cryptocurrency. The urgency of improved detection and policy enforcement is fueled by growing international regulatory pressure and the adaptation of state-sponsored groups to exploit digital infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports