✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
How a Vulnerable AI Plugin in Figma MCP Opened the Door for Remote Code Attacks
In early 2025, a critical vulnerability (CVE-2025-53967) was discovered in a third-party connector integrating agentic AI capabilities with Figma’s Multi-Cloud Platform (MCP) server. This supply-chain flaw enabled remote code execution (RCE), allowing attackers to exploit the connection to infiltrate organizational environments using the affected plugin. Threat actors leveraged the unsanctioned plugin to gain unauthorized access to internal systems, potentially exposing sensitive design data, intellectual property, and user information. The compromise highlighted risks associated with insufficient east-west security controls, lack of zero trust segmentation, and inadequate traffic visibility, ultimately impacting business continuity and trust in the collaboration platform. This incident exemplifies the growing threat of supply-chain vulnerabilities targeting enterprise SaaS applications, amid increasing adoption of AI integrations. Organizations are re-evaluating their third-party risk, agentic AI governance, and internal segmentation postures as regulatory scrutiny and attacker sophistication intensify.
6 months ago
Kill Chain
Red Hat Consulting Breach 2024: Crimson Collective Launches Major Supply Chain Attack
In April 2024, the Crimson Collective, in collaboration with elements of the Lapsus$ group, executed a supply chain attack targeting Red Hat Consulting by breaching its GitLab instance. The attackers gained unauthorized access through credential compromise and lateral movement across internal infrastructure, successfully exfiltrating sensitive source code and internal communications. The breach, which remained undetected for several days, raised concerns over east-west traffic security, lack of segmentation, and insufficient anomaly detection within Red Hat Consulting’s cloud development supply chain. This incident highlights the increasing prevalence of supply chain attacks leveraging lateral movement and sophisticated alliance between threat groups. Its relevance is underscored by renewed regulatory scrutiny, the growing risk posed by collaborative cybercriminal operations, and heightened demand for zero trust architecture and cloud-native threat mitigation strategies.
6 months ago
Kill Chain
SonicWall 2024: Every Cloud Firewall Backup Breached in Major Supply Chain Attack
In June 2024, SonicWall confirmed that the previously disclosed breach of its cloud backup service was far more extensive than initially announced. The attack resulted in unauthorized access to firewall configuration backups for 100% of customers using SonicWall's cloud backup platform, rather than the 5% originally estimated. The compromise exposed sensitive customer network data, including credentials and VPN configurations, after attackers exploited vulnerabilities in SonicWall’s systems. This breach underscores significant supply chain risks, as attackers targeted third-party-managed infrastructure to circumvent perimeter defenses. This incident highlights the rising threat of supply chain attacks targeting security vendors themselves, which can expose downstream customer environments. With increasing regulatory scrutiny and heightened awareness of lateral movement risks across managed services, organizations must revisit both technical and vendor controls to ensure comprehensive zero trust segmentation and backup protection.
6 months ago
Kill Chain
Inside the 2025 Mysterious Elephant Cyber-Espionage Attacks Across South Asia
In early 2025, the cyber-espionage group known as "Mysterious Elephant" conducted a sophisticated campaign targeting government and diplomatic agencies across South Asia. Exploiting previously unseen custom tools, the threat actors gained initial access through spear-phishing and deployed a combination of new malware and legacy techniques to maintain persistence and facilitate covert lateral movement. The attackers exfiltrated sensitive communications and state documents while evading traditional detection mechanisms, resulting in significant exposure of confidential information and escalating regional tensions. This incident highlights the evolution of state-sponsored threat actors beyond recycled malware toward bespoke toolkits and advanced TTPs. Security leaders should note the rapid escalation of intelligence-driven attacks against public sector targets, an indicator of rising geopolitical cyber conflict and regulatory scrutiny.
6 months ago
Kill Chain
GlassWorm: A Self-Propagating Supply Chain Worm Targets VS Code Developers
In early 2024, a sophisticated supply chain attack targeting the Visual Studio Code (VS Code) developer ecosystem was uncovered, leveraging a self-propagating worm dubbed 'GlassWorm.' The attack exploited weaknesses in package distribution and dependency validation, spreading rapidly via malicious code hidden in open-source extensions and packages. Once executed on developer machines, GlassWorm covertly harvested credentials and turned compromised systems into nodes for broader criminal infrastructure, affecting nearly 36,000 endpoints globally. The incident illuminated the risks posed by highly automated, invisible code propagation through trusted development tools, impacting developer productivity and increasing the potential for downstream compromise across organizations that rely on shared code repositories. This breach is emblematic of the accelerating trend of supply chain attacks against development environments, with threat actors increasingly leveraging automation and legitimate software to undermine trust. The GlassWorm incident underscores the urgency for enhanced visibility, stringent code validation, and zero trust controls in modern software supply chains to counter evolving adversary tactics.
6 months ago
Kill Chain
ColdRiver Malware Surge: 2024 Espionage Attack Analysis
In early 2024, the Russia-linked threat group ColdRiver launched a fresh cyber espionage campaign targeting Western government entities, research institutions, and non-governmental organizations. Exploiting spear-phishing emails laden with custom-designed malware, the attackers accessed sensitive emails and files by leveraging well-crafted lures and technical evasion methods. The operation showcased ColdRiver’s rapid adaptation: when prior campaign tactics were exposed, the group swiftly pivoted to deploy new malware strains and infrastructure, signifying a high level of technical agility. The impact included unauthorized data access, intelligence gathering, and operational disruptions for targeted organizations. This incident stands out due to its demonstration of how quickly sophisticated espionage actors can update their tactics in response to detection. With global instability rising and state-aligned groups escalating campaigns, the rapid agility in threat activity puts extra pressure on organizations to strengthen detection and incident response protocols.
6 months ago
Kill Chain
Velociraptor Misused: LockBit Ransomware & Storm-2603 Weaponize DFIR Tools in 2025 Attacks
In October 2025, cybersecurity researchers uncovered that threat actors associated with Storm-2603 (also known as Gold Salem or CL-CRI-1040) leveraged Velociraptor, a legitimate open-source digital forensics and incident response (DFIR) tool, to facilitate a series of LockBit ransomware attacks. Adversaries exploited Velociraptor’s capabilities to gather intelligence and move laterally within target environments, evading detection by blending in with regular security operations. The attacks led to significant data encryption events and operational disruptions, primarily impacting organizations with insufficient internal security segmentation and monitoring. This incident marks a significant evolution in attacker tradecraft, as it demonstrates that widely trusted security tools—often present for defensive use—can be repurposed as offensive weapons. Increased regulatory scrutiny and the recurrent rise of double extortion ransomware attacks highlight the urgent need for organizations to monitor tool usage and improve east-west visibility.
6 months ago
Kill Chain
Pwn2Own Ireland 2025: Security Researchers Expose 34 Zero-Day Vulnerabilities
On the first day of Pwn2Own Ireland 2025, security researchers successfully exploited 34 unique zero-day vulnerabilities across a range of enterprise technologies, earning $522,500 in awards. The event, renowned for responsible disclosure and sponsored by leading vendors, demonstrated both the speed and sophistication with which zero-day flaws can be discovered and exploited in widely used software and hardware platforms. While no criminal group was involved (these are sanctioned research efforts), the findings underscore prevailing vulnerabilities in enterprise defenses and often result in rapid product updates and critical security advisories. This incident highlights the ongoing arms race between researchers and vendors to identify and remediate unknown security gaps. The large number of zero-days found in a single day signals both the growing complexity of attack surfaces and the pressing need for automated detection and proactive patching mechanisms across the digital ecosystem.
6 months ago
Kill Chain
How UNC5142 Hijacked WordPress & Blockchain for Next-Gen Stealer Attacks (2025)
In October 2025, threat actor UNC5142 leveraged compromised WordPress sites to distribute a wave of information-stealing malware using an innovative attack method dubbed 'EtherHiding.' The adversaries abused blockchain-based smart contracts to conceal malicious code, enabling malware such as Atomic Stealer, Lumma, Rhadamanthys, and Vidar to infect both Windows and macOS endpoints. This technique allowed attackers to rapidly update payloads beyond the reach of static blocklists and frequently evade traditional security controls. Victims included a variety of enterprises and individuals, with attackers capitalizing on the popularity and trust of infected WordPress content management platforms. This incident highlights an emerging TTP where blockchain infrastructure is repurposed to enhance delivery persistence and obfuscation for criminal campaigns. The rapid uptake of such blockchain-based methods demonstrates the need for organizations to evolve threat detection and response strategies as attackers diversify beyond conventional web infrastructure.
6 months ago
Kill Chain
North Korean Hackers Employ EtherHiding for Unprecedented Cryptocurrency Heist
In October 2025, threat group UNC5342—attributed to North Korea—executed an advanced cryptocurrency theft operation by leveraging the novel EtherHiding technique. Attackers embedded malicious code within blockchain smart contracts to distribute malware, evading conventional detection mechanisms. Google Threat Intelligence Group (GTIG) identified this as the first known use of EtherHiding by a state-sponsored actor, resulting in the covert compromise of multiple cryptocurrency platforms and significant asset loss. The incident underscores an evolving trend: nation-state actors are adopting increasingly sophisticated blockchain-based attack methods. With rising blockchain adoption, such TTPs present serious risks for organizations involved in digital assets, regulation, and financial technology.
6 months ago
Kill Chain
Europol Busts Global SIM Farm Fueling Industrial-Scale Fake Accounts and Cybercrime
In October 2025, Europol led Operation SIMCARTEL to dismantle a sophisticated cybercrime-as-a-service (CaaS) organization running an extensive SIM farm network. This criminal service provisioned more than 49 million SIM cards to cybercriminals worldwide, enabling the rapid creation and management of fake online accounts. Threat actors leveraged the infrastructure for phishing campaigns, investment fraud, impersonation, and large-scale social engineering schemes, causing substantial financial and reputational harm to both individuals and businesses. The coordinated law enforcement operation involved 26 property searches, resulted in seven arrests, and the seizure of equipment and digital assets tied to the illicit platform. This incident highlights the growing industrialization of cybercrime, where turnkey services significantly lower the barrier to entry and accelerate threat actor operations. Law enforcement and the security industry face increasing challenges as cybercriminals exploit scalable CaaS platforms, requiring organizations to modernize their defenses and policy enforcement.
6 months ago
Kill Chain
Salt Typhoon Breaches European Telecom via Citrix Flaw and Snappybee Malware
In July 2025, a major European telecommunications provider suffered a targeted cyber espionage breach attributed to Salt Typhoon (aka Earth Estries), a suspected China-nexus group. Attackers exploited a vulnerability in a Citrix NetScaler Gateway appliance to gain initial access, then deployed the custom Snappybee malware for persistent network infiltration and surveillance. The operation allowed lateral movement across critical systems, putting sensitive customer and infrastructure data at risk. Timely detection by Darktrace helped contain the breach, but the incident highlights the telecom industry's growing exposure to sophisticated APT tactics and advanced malware. This breach exemplifies how state-aligned actors are exploiting enterprise VPN and appliance vulnerabilities for initial access, a recurring trend influencing regulatory scrutiny and CISO priorities. Telecom providers remain high-value targets due to their access to critical national infrastructure and vast troves of sensitive data.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports