✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
State-Sponsored Attackers Breach SonicWall Firewall Backups in 2023
In September 2023, SonicWall disclosed a security breach where state-sponsored threat actors gained unauthorized access to systems containing customer firewall configuration backup files. The incident was investigated thoroughly, and SonicWall determined that sophisticated attackers exploited vulnerabilities, allowing access to backup files with potentially sensitive customer information. The breach did not involve ransomware or financial extortion but had the potential to expose operational details and configurations of deployed firewalls, raising concerns over further lateral movement or exploitation. Attacks like these underscore the growing threat posed by well-resourced, nation-state actors directly targeting technology vendors and supply chain components. As attackers prioritize exploiting configuration data, the security of infrastructure suppliers is under renewed scrutiny and regulatory interest, emphasizing the need for robust data encryption, segmentation, and incident response.
6 months ago
Kill Chain
U.S. Cybersecurity Insiders Indicted for BlackCat Ransomware Attacks (2023)
Between May and November 2023, a trio of U.S.-based individuals—including two named suspects and an unnamed co-conspirator—compromised the networks of five American companies using BlackCat (ALPHV) ransomware. Prosecutors allege that the attackers, all cybersecurity insiders, leveraged privileged access and technical expertise to deploy ransomware on a range of targets, including a medical organization, resulting in considerable financial losses and data encryption. The conspirators used advanced methods to extort payments, disrupt operations, and evade detection. This incident highlights the growing risk posed by insider threats and the increasing sophistication of ransomware groups like BlackCat/ALPHV. Such attacks are driving regulatory calls for enhanced east-west network controls, granular segmentation, and robust anomaly detection as ransomware tactics continue to evolve.
6 months ago
Kill Chain
Operation SkyCloak: Tor-Enabled OpenSSH Backdoor Infiltrates Defense Networks
In November 2025, a sophisticated cyber campaign dubbed 'Operation SkyCloak' was uncovered, targeting Russian and Belarusian defense sectors. Attackers distributed weaponized attachments via phishing emails, successfully implanting a persistent OpenSSH-based backdoor on compromised hosts. To conceal its activity, the malware leverages a customized Tor hidden service with obfs4 protocol, facilitating covert command-and-control and persistent unauthorized access. This campaign demonstrates advanced threat actor operational security, targeting high-value government and defense assets to enable espionage and data exfiltration. The use of Tor-enabled backdoors in defense-related attacks is surging, marking a shift towards more covert, untraceable threat tactics. This incident exemplifies the growing adoption of anonymized infrastructure by attackers to evade detection, highlighting urgent requirements for east-west traffic inspection, advanced threat detection, and zero trust segmentation for critical sectors.
6 months ago
Kill Chain
European Authorities Bust €600M Crypto Fraud Network in Pan-European Operation
In late October 2025, European authorities led by Europol and Eurojust dismantled a sophisticated cryptocurrency money laundering network responsible for stealing €600 million (around $688 million) through large-scale crypto fraud schemes. The coordinated operation spanned Cyprus, Spain, and Germany, resulting in the arrest of nine suspects linked to elaborate investment scams, phishing, and online fraud. The network leveraged complex cross-border laundering methods, making use of encrypted digital transactions and a web of services to obfuscate stolen funds, ultimately victimizing thousands of individuals across multiple nations. The case spotlights the emergence of organized crime groups exploiting cryptocurrency platforms for large-scale financial fraud and money laundering. It underscores the urgent need for robust regulatory frameworks and advanced monitoring tools, as law enforcement agencies worldwide face growing challenges combating tech-enabled fraud tied to the volatile, largely unregulated crypto sector.
6 months ago
Kill Chain
IDIS ICM Viewer 2025: Critical Application Vulnerability Risk Exposed
In November 2025, IDIS disclosed a critical vulnerability (CVE-2025-12556) in its ICM Viewer application, enabling remote attackers to execute arbitrary code via improper neutralization of argument delimiters—a classic argument injection flaw. The vulnerability, scored CVSS v4 8.7, affected version 1.6.0.10 and allowed exploitation through low-complexity attacks requiring only limited privileges. The flaw could provide adversaries with broad control over vulnerable systems, directly impacting critical communications infrastructure deployed worldwide and potentially undermining operational continuity and data integrity. This incident highlights the growing risk posed by supply chain and application-layer vulnerabilities in industrial and communications networks. The prevalence of remote, low-complexity exploits underscores the urgent need for robust patch management and defense-in-depth approaches, especially as regulators intensify scrutiny of critical infrastructure cybersecurity.
6 months ago
Kill Chain
Pixel KASLR Bypass: Linear Map Non-Randomization Threatens Android Kernel Security
In November 2025, security researchers from Google Project Zero disclosed a significant design flaw in the Linux kernel’s implementation of Kernel Address Space Layout Randomization (KASLR) on modern Android devices, specifically Google Pixel phones. The weakness stems from the lack of randomization in both the linear kernel mapping and the physical memory loading address of the kernel itself. As a result, attackers with an arbitrary read/write primitive could derive static kernel virtual addresses, bypassing KASLR protections without leaks—thereby making exploitation significantly easier and increasing the risk of privilege escalation and persistence. This incident underscores a broader industry challenge where operating system mitigations lag behind evolving attacker techniques. The exposure of predictable kernel virtual addresses on widely deployed Android devices highlights the urgency for stronger kernel randomization and renewed attention to memory safety for mobile platforms.
6 months ago
Kill Chain
Rogue Incident Responders Deploy ALPHV/BlackCat Ransomware Against US Companies
In 2023, three US-based cybersecurity professionals, including an incident response manager from Sygnia and a ransomware negotiator from DigitalMint, were indicted after orchestrating a wave of ransomware attacks using the ALPHV/BlackCat strain. Beginning in May 2023, the group compromised five US organizations spanning healthcare, pharmaceuticals, engineering, and tech, deploying ransomware to encrypt critical data and extort payments. Only a Florida medical company paid, sending nearly $1.3 million in ransom; the other four victims did not make payments. The attacks were uncovered through joint law enforcement efforts, leading to arrests and criminal charges for the conspirators. This case is significant as it highlights the ongoing risk of insider threats even among trusted cybersecurity professionals. The exploitation of privileged insider knowledge paired with advanced ransomware-as-a-service tooling demonstrates how internal actors can subvert security postures, fueling industry concerns about vigilance, vetting, and zero trust principles within security teams.
6 months ago
Kill Chain
Insiders Indicted: BlackCat Ransomware Attacks Orchestrated by US Cybersecurity Experts (2023)
Between May and November 2023, three former employees of DigitalMint and Sygnia—both incident response firms—were indicted following allegations that they leveraged insider knowledge to facilitate BlackCat (ALPHV) ransomware attacks on five U.S. companies. These individuals reportedly gained unauthorized access to sensitive networks, deployed BlackCat ransomware, and demanded significant payouts, resulting in operational disruptions, data encryption, and potential data exposure for affected organizations. The attackers’ technical expertise made detection difficult, and their actions exploited gaps in internal network security, east-west monitoring, and threat detection protocols. This incident highlights the evolving threat posed by malicious insiders and the intersection of human risk with sophisticated ransomware-as-a-service operations. The case underscores the urgency for organizations to enhance identity-based segmentation, rigorous monitoring of internal activity, and to adapt cybersecurity policies to counter both external and internal threats.
6 months ago
Kill Chain
Fake Solidity VSCode Extension Backdoors Developers in 2024 Supply Chain Attack
In early 2024, a malicious Visual Studio Code extension impersonating the popular Solidity plugin was discovered on the Open VSX Registry, a prominent open-source extension marketplace. The extension secretly installed the SleepyDuck remote access trojan. Threat actors leveraged an Ethereum smart contract to covertly communicate with infected developer environments, establishing a covert command and control channel. Dozens of unsuspecting developers who installed the fake extension were exposed to potential source code theft, workspace compromise, and broader supply chain risk for any software subsequently produced on affected systems. This incident highlights the escalating threat posed by supply chain attacks via open-source repositories and package registries, particularly those targeting development toolchains. Increasingly, attackers are exploiting trust in popular extensions, emphasizing the urgent need for organizations to bolster code integrity controls and enforce zero trust principles for their build environments.
6 months ago
Kill Chain
SleepyDuck Supply Chain Attack: Malicious VSX Extension Exposes Developers via Ethereum C2
In late October and early November 2025, cybersecurity researchers uncovered a malicious Visual Studio Code extension, 'juan-bianco.solidity-vlang', uploaded to the Open VSX registry. Originally benign, the extension was updated within days to include a remote access trojan called SleepyDuck, which leveraged Ethereum smart contracts to dynamically maintain connectivity with its command-and-control (C2) servers. By exploiting the trust inherent in open-source software supply chains and masquerading as a development tool, attackers enabled remote access and possible data exfiltration from developer environments, posing significant risks to organizations reliant on open-source packages. This breach highlights the persistent threat of supply chain attacks targeting developer tools and marketplaces, a rapidly growing vector as attackers seek to compromise software upstream. It also demonstrates the adoption of blockchain infrastructure for resilient, hard-to-takedown C2 mechanisms, forcing defenders to adapt to increasingly complex threat ecosystems.
6 months ago
Kill Chain
Arrest of 764 Group Leader Signals Crackdown on Online Child Exploitation and Extremism
In December 2023, Baron Cain Martin, alleged leader of the violent extremist group 764, was arrested in Tucson, Arizona, following an extensive federal investigation. Unsealed in June 2024, the indictment charges Martin with 29 counts, including producing and distributing child sexual abuse material (CSAM), cyberstalking, conspiracy to commit wire fraud, animal cruelty, and providing material support to terrorists. Federal law enforcement alleges that Martin not only led the illicit collective but also created detailed guides for grooming and exploiting minors. The operation exploited online anonymity, targeting vulnerable young individuals across the globe. At least nine victims, primarily minors, have been identified, with the group's activities linked to broader networks such as The Com. The Martin case spotlights alarming trends in cyber-enabled abuse and violent extremism, highlighting law enforcement’s ongoing efforts to dismantle depraved online collectives. The prosecution’s severity underscores rising societal and regulatory pressure to address digital child exploitation, encrypted criminal coordination, and psychologically manipulative methods used by such groups.
6 months ago
Kill Chain
Windows Zero-Day Attack Exposes European Diplomats in 2024 Espionage Campaign
In early 2024, a threat group with links to China launched a targeted espionage campaign exploiting a previously unknown Windows zero-day vulnerability. The attackers aimed at European diplomats and associated governmental entities in countries including Hungary and Belgium. Armed with this zero-day, threat actors gained initial access, moved laterally within the network, and exfiltrated sensitive data from diplomatic communications and systems. The sophistication of the operation allowed them to evade traditional signature-based defenses, resulting in significant potential exposure of confidential state-level information and disruption of diplomatic activities. This incident underscores the ongoing shift towards advanced, nation-state–backed cyber-espionage using zero-day exploits. The rise of targeted attacks against governmental and diplomatic institutions highlights the necessity for modern threat detection, east-west traffic security, and proactive zero trust strategies to stay ahead of rapidly evolving adversary techniques.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports