✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Inside the GhostCall & GhostHire Malware Campaigns: BlueNoroff’s 2025 Cryptocurrency Heists
In October 2025, cybersecurity researchers uncovered new attack chains, GhostCall and GhostHire, attributed to BlueNoroff—a sub-group of North Korea's Lazarus Group—targeting the Web3 and blockchain sectors. The campaigns form part of SnatchCrypto, an ongoing operation active since 2017, characterized by sophisticated spear-phishing, malware-laden documents, and social engineering tactics to infiltrate cryptocurrency firms and financial technology startups. Once initial access is gained, attackers deploy custom malware, bypass defenses, and ultimately exfiltrate sensitive data and digital assets, resulting in significant cryptocurrency thefts and disruption across targeted organizations. This campaign is especially concerning amid a surge of advanced persistent threats exploiting trust gaps in rapidly evolving blockchain and cryptocurrency environments. Regulators and cybersecurity teams are on high alert as major financial losses and reputational impacts drive urgency for improved controls, detection, and Zero Trust strategies.
6 months ago
Kill Chain
Prompt Injection Flaw in ChatGPT Atlas Browser Enables Hidden Command Execution
In October 2025, security researchers at NeuralTrust identified a prompt injection vulnerability in the newly launched OpenAI ChatGPT Atlas Browser, allowing attackers to disguise malicious prompts as benign URLs in the omnibox. The attack exploits how the omnibox interprets user input, confusing it as either a navigation destination or a natural-language command to the agent. Malicious actors can craft deceptive URLs that bypass basic user scrutiny and trigger hidden commands, exposing users to unauthorized actions, potential data leaks, and unintended system manipulations. OpenAI was notified and subsequently began working on mitigations to address this risk. This incident underscores a rising wave of sophisticated prompt injection attacks targeting AI-powered web interfaces. As AI tools become widely integrated in everyday applications, the attack surface expands, making seamless human-computer interactions susceptible to exploitation from both classic and emerging attack vectors.
6 months ago
Kill Chain
First Wap's SS7 Exploit: How Altamides Changed Global Surveillance in 2025
In 2025, surveillance-technology firm First Wap, based in Jakarta, was revealed to have quietly built and operated the 'Altamides' system, a covert platform leveraging SS7 telecom vulnerabilities for global phone tracking. Unlike conventional spyware, Altamides enabled real-time location tracking of mobile devices across regions—from the Vatican to Silicon Valley—without requiring user interaction, installation, or leaving traces on targeted phones. The technology exploited legacy telecom protocols to access cell tower information, bypassing most modern mobile security defenses. As a result, sensitive locations and communications were exposed to persistent surveillance risk, with broad geopolitical and privacy implications. This incident underscores a worrying rise in the commercial proliferation of offensive surveillance tools exploiting underprotected telecom infrastructure. It highlights the urgent need for stronger regulatory action and zero trust defenses, as targeted espionage techniques move further away from traditional malware and towards systemic protocol abuse.
6 months ago
Kill Chain
Pwn2Own Ireland 2025: Researchers Unveil 73 Zero-Day Vulnerabilities
In June 2025, the Pwn2Own Ireland hacking competition saw security researchers successfully exploit 73 unique zero-day vulnerabilities across a variety of enterprise software and devices. Over $1,024,750 in rewards were awarded as teams identified and demonstrated live, working exploits, many targeting critical business platforms. These zero-days, by definition previously unknown to vendors, highlight the rapid pace at which vulnerabilities are discovered and the ongoing challenges organizations face in maintaining strong security posture against both sophisticated and opportunistic attackers. This event underscores the persistent risk of zero-day vulnerabilities and the growing sophistication of offensive security research. The scale and speed of exploit identification at Pwn2Own reflect broader industry trends, including increased investment in bug bounties and rising regulatory expectations for vulnerability management and disclosure.
6 months ago
Kill Chain
APT36 Exploits Golang-Based Malware to Compromise Indian Government in 2025
In August and September 2025, the state-sponsored hacking group APT36 (also known as Transparent Tribe) launched a spear-phishing campaign targeting Indian government entities. The campaign delivered a new variant of a Golang-based remote access trojan, DeskRAT, which allowed attackers to gain persistent access, conduct reconnaissance, and exfiltrate sensitive information. The phishing emails, likely crafted to impersonate trusted sources, succeeded in infecting victim networks, enabling APT36 to conduct espionage activities against high-profile targets, further compromising Indian national security interests. This incident underscores the persistent risk posed by well-resourced, nation-state threat actors using continuously evolving malware families and novel programming languages like Golang. The rise of such campaigns highlights an urgent need for improved east-west traffic monitoring, zero trust network segmentation, and advanced user awareness against targeted phishing techniques.
6 months ago
Kill Chain
Former L3Harris Executive Charged with Selling Cyber Trade Secrets to Russia
In August 2025, U.S. federal prosecutors charged Peter Williams, a former executive at L3Harris Technologies’ cyber division, with stealing and selling sensitive trade secrets to an undisclosed Russian buyer. Williams, the former general manager of specialized hacking group Trenchant, allegedly misappropriated eight proprietary technologies from two companies between April 2022 and August 2025, totaling $1.3 million in illicit gains. The Department of Justice seeks forfeiture of assets derived from the scheme. Neither L3Harris nor Trenchant is accused of direct wrongdoing. This incident underscores the growing threat posed by insiders with privileged access to highly sensitive cyber capabilities. As governments and critical industries bolster defenses, advanced techniques to detect, monitor, and mitigate insider risk are essential to prevent breaches that could have national security consequences.
6 months ago
Kill Chain
Lazarus APT Penetrates European Defense Firms with Fake Job Lures in 2024
In early 2024, the North Korean state-sponsored Lazarus Group orchestrated a targeted cyberattack against at least three European defense sector companies. Using a spear-phishing strategy known as 'Operation DreamJob,' attackers impersonated defense recruiters, luring employees with fake job offers and malicious documents. Once compromised, the attackers gained unauthorized access, moved laterally within victims' networks, and exfiltrated sensitive corporate and government data with minimal detection. The sophistication and persistence demonstrated in this operation highlight the evolving threat landscape posed by well-resourced APT actors. This campaign underscores the escalating risks facing critical industries from nation-state cyber espionage. As advanced phishing and lateral movement techniques proliferate, even mature security programs remain vulnerable to targeted, multi-stage attacks from groups like Lazarus.
6 months ago
Kill Chain
Over 100 Government Agencies Breached by Iranian MuddyWater APT with Phoenix Backdoor
In early 2024, the Iranian state-sponsored threat group MuddyWater executed widespread attacks leveraging the Phoenix backdoor (version 4), successfully targeting over 100 government entities worldwide. The campaign exploited spear-phishing and malicious document attachments to deliver the backdoor, enabling persistent access, lateral movement, and data exfiltration from compromised systems. This sophisticated intrusion allowed the attackers to maintain a long-term foothold within highly sensitive government networks, posing significant operational and intelligence risks across multiple regions. This incident underscores a sharp escalation in advanced persistent threat (APT) tactics targeting public sector organizations. It highlights both the evolving sophistication and relentless nature of nation-state cyber operations, amplifying regulatory and operational pressure on government organizations to strengthen east-west traffic security, anomaly detection, and Zero Trust segmentation strategies.
6 months ago
Kill Chain
BetterBank DeFi 2025: How a Reward Logic Flaw Led to a $5M Crypto Breach
From August 26 to 27, 2025, BetterBank, a DeFi protocol on PulseChain, suffered a major exploit in its ESTEEM reward logic, allowing an attacker to mint unlimited bonus tokens by abusing flaws in liquidity pool validation. The vulnerability enabled the creation of fake trading pairs and a recursive loop of reward minting, resulting in an initial $5 million loss. Notably, after open negotiations, $2.7 million of the pilfered assets were returned, but the net damage remained at approximately $1.4 million to users and the protocol. The breach highlights organizational and technical oversights, as a prior security audit flagged this very issue. This incident exemplifies the growing threat of sophisticated smart contract exploits targeting DeFi platforms. As similar attacks proliferate across decentralized protocols, regulators and security teams are intensifying scrutiny and demanding higher levels of design and audit rigor.
6 months ago
Kill Chain
MuddyWater's 2025 Global Espionage Campaign Targets 100+ Organizations
In late 2025, the Iranian nation-state threat group known as MuddyWater launched a sophisticated espionage campaign targeting over 100 organizations across the Middle East and North Africa (MENA) region. Leveraging a compromised email account as an entry point, the attackers distributed a custom backdoor named Phoenix to high-value government entities, enabling covert infiltration and sustained intelligence gathering. The operation involved methods designed to evade detection and facilitate ongoing access to sensitive data, underscoring the persistent risk posed by nation-state actors. This campaign highlights a continued escalation in advanced cyberespionage activities targeting governmental and critical infrastructure sectors. With threat actors increasingly exploiting social engineering and custom malware, organizations face intensified pressure to strengthen defenses and adhere to evolving security frameworks.
6 months ago
Kill Chain
WhatsApp Bans NSO Group: Landmark Legal Win Over Spyware Surveillance (2024)
In June 2024, WhatsApp achieved a legal victory against NSO Group following a six-year battle over the use of commercial spyware targeting WhatsApp users. NSO Group had exploited zero-day vulnerabilities to deploy its Pegasus spyware, surreptitiously compromising user devices for surveillance. As a result of the court decision, NSO Group is permanently banned from accessing or reverse-engineering WhatsApp and must pay $4 million in damages. The court's judgement underscores the broader risks posed by commercial surveillance tools, impacting end-user privacy and digital trust on a global scale. This incident comes amidst intensifying global scrutiny over spyware vendors and increasing pressure for technology companies to safeguard user data. The legal ruling sets a precedent for software platforms defending against targeted surveillance campaigns, emphasizing the role of legal strategy alongside technical security countermeasures.
6 months ago
Kill Chain
Canada Fines Cryptomus $176M Over Cybercrime Payment Networks
In October 2024, the Financial Transactions and Reports Analysis Center of Canada (FINTRAC) levied a record $176 million fine against Cryptomus, a digital payments platform, for violating Canada's anti-money laundering laws. Investigations uncovered that Cryptomus helped facilitate transactions for dozens of Russian cryptocurrency exchanges and cybercrime-related services without submitting suspicious transaction reports. Infractions were linked to money laundering for child sexual abuse material, fraud, ransomware, and sanctions evasion. The business used a Vancouver address also tied to numerous other questionable entities, none of which had any physical presence at the location. This enforcement action highlights intensifying global scrutiny on cryptocurrency payment processors and money service businesses (MSBs) operating as shadow facilitators for cybercriminals, particularly in regions facing heightened sanctions. As regulators ramp up pressure, organizations relying on cryptographic payment tools, or with exposure to digital currency ecosystems, must reassess their compliance, monitoring, and due diligence procedures in light of evolving financial crime threats.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports