✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Google Uncovers Rapidly Evolving COLDRIVER Malware Campaigns in 2025
In May 2025, Google’s Threat Intelligence Group (GTIG) identified a surge in new malware developed by the Russian state-sponsored hacking group COLDRIVER (also known as Callisto or SEABORGIUM). In rapid succession, three new malware families were discovered, each demonstrating increased sophistication and frequent code variations. The attackers leveraged targeted spear-phishing campaigns to compromise government, defense, and policy sector targets across Europe and North America. The swift adaptation and deployment of these malware strains highlight COLDRIVER’s evolving tradecraft and acceleration of offensive cyber operations, posing heightened risks to sensitive data and infrastructure. This campaign signals a broader trend of rapidly evolving Russian cyber-espionage efforts against Western entities. The increased pace, tooling variation, and focus on intelligence collection underline the critical need for organizations to upgrade monitoring, segmentation, and encryption controls across hybrid cloud and on-prem networks.
6 months ago
Kill Chain
GlassWorm Supply Chain Malware: VS Code & OpenVSX Infected in 2025
In October 2025, a highly sophisticated supply chain attack involving the GlassWorm malware targeted developers via the OpenVSX and Microsoft Visual Studio Code (VS Code) extension marketplaces. Malicious actors inserted invisible Unicode characters into multiple popular extensions, enabling self-spreading malware to infect users without detection during automatic updates. GlassWorm stole credentials for developer services and cryptocurrency wallets, established remote access, and transformed compromised workstations into nodes within a broader criminal infrastructure. The malware leveraged blockchain (Solana) transactions, Google Calendar events, and distributed Peer-to-Peer protocols for resilient command-and-control, impacting at least 35,800 installations and keeping several malicious extensions available before remediation. This incident highlights the growing threat of self-propagating malware in software supply chains, especially via extension ecosystems critical to development workflows. Its combination of advanced evasion tactics, automated propagation, and leveraging of decentralized infrastructure sets a new precedent, signaling broader risks for organizations relying on trusted code repositories and accelerating regulatory and industry scrutiny on supply chain security.
6 months ago
Kill Chain
Agentic AI's OODA Loop Vulnerability: Prompt Injection & Architecture Risks in 2025
In October 2025, a major vulnerability was revealed in agentic AI systems’ OODA (Observe, Orient, Decide, Act) decision loops, where adversaries exploited prompt injection, training data poisoning, and tool protocol confusion to compromise autonomous AI agents. Attackers planted triggers and malicious instructions in web-accessible content and tool descriptions, which were ingested by AI models, bypassing privilege separation and contaminating operational state and chat history. The incident resulted in persistent data leaks, unintentional tool actions, and the propagation of backdoors and compromised context across organizations deploying AI-driven automation and analytics. This exposure underscores a critical and growing risk: as organizations adopt increasingly autonomous AI, vulnerabilities related to data integrity, input trust, and OODA loop manipulation have escalated. Recent trends show surges in prompt injection exploits, AI-powered toolchain attacks, and regulatory focus on AI integrity controls, highlighting an urgent need for architectural reforms and robust zero trust measures.
6 months ago
Kill Chain
Iranian Nation-State Hackers Target John Bolton’s Email in 2021 Security Breach
In July 2021, former U.S. National Security Adviser John Bolton's personal email account was compromised by cyber actors believed to be linked to the Islamic Republic of Iran. The attackers gained unlawful access, extracted emails containing potentially sensitive information, and leveraged these materials to threaten and attempt to coerce Bolton, including by referencing classified content and threatening public disclosure. The FBI became aware when Bolton’s representative reported the intrusion and subsequent extortion attempts, with the threat actor referencing previous high-profile leaks to amplify pressure. It remains unclear if any sensitive materials were publicly disseminated, but the incident elevated concerns around the exposure of classified or sensitive government information through personal communication channels. This incident highlights a persistent risk from nation-state actors targeting senior government officials, leveraging cyber-intrusions for espionage and psychological operations. With the proliferation of similar tactics against political, governmental, and critical infrastructure targets globally, this attack reflects an urgent need for heightened security controls on personal communications of high-profile public figures.
6 months ago
Kill Chain
F5 Breach 2024: Nation-State Actors Steal Source Code and Vulnerabilities
In early 2024, F5 Networks suffered a significant security breach attributed to a sophisticated nation-state actor, which resulted in the theft of BIG-IP source code and undisclosed vulnerability details. The attackers leveraged targeted intrusion tactics, exploiting gaps in F5's internal protections to gain access to proprietary codebases and sensitive vulnerability information. This breach elevated the risk for F5’s enterprise and government customers, as the exposed vulnerabilities could facilitate future attacks on critical infrastructure globally. The incident highlights both supply chain implications and the heightened impact of intellectual property theft. This attack underscores a strategic shift where advanced threat actors seek not only data but also exploit software supply chains and zero-day vulnerabilities, raising urgent concerns for organizations dependent on key network infrastructure vendors. With regulatory scrutiny sharpening around supply chain risk and software assurance, incidents like this set new urgency for proactive defense and vendor risk management.
6 months ago
Kill Chain
Maverick: How WhatsApp Became the Gateway for Brazil’s Biggest Banking Trojan in 2024
In October 2024, a sophisticated banking Trojan dubbed Maverick was detected actively targeting Brazilian users. The malware was delivered via malicious ZIP files sent through WhatsApp, bypassing platform detection. Victims executed an LNK file that triggered a fully fileless, multi-stage infection chain, utilizing PowerShell, .NET, and encrypted shellcode. Maverick, which shares code similarities with the Coyote Trojan, leverages locale checks to target only Brazilians and uses WPPConnect to automate the spread through hijacked WhatsApp accounts. Once established, the Trojan provides attackers full remote access, including keylogging, screen control, and phishing overlays to harvest banking and cryptocurrency credentials. This incident is notable for its complex multi-stage deployment, worm-like propagation, and use of AI-aided code, reflecting a new evolution in financially motivated malware. The attack demonstrates the increasing convergence of social engineering, sophisticated fileless techniques, and abuse of popular messaging platforms, signaling urgent challenges for both enterprises and end users.
6 months ago
Kill Chain
Malicious VSCode Extensions: TigerJack’s 2025 Supply Chain Attack on OpenVSX
In October 2025, the threat actor known as TigerJack resurfaced with a sophisticated supply chain attack targeting developer environments by publishing malicious Visual Studio Code (VSCode) extensions to both the official marketplace and the OpenVSX registry. Despite removal from the VSCode marketplace after 17,000 downloads, the extensions remained accessible on OpenVSX and continued to proliferate through renamed and republished versions. These extensions exfiltrated source code, ran unauthorized cryptocurrency miners, and enabled arbitrary remote code execution, greatly increasing the risk to individual developers and organizations relying on open-source tools. This incident highlights a rising trend of supply chain attacks targeting developer tools and open-source ecosystems, where trust in community-maintained registries is frequently exploited. With minimal oversight and delayed response from registry maintainers, businesses face a persistent risk of compromise through their software development pipelines.
6 months ago
Kill Chain
SonicWall Cloud Backup Breach 2024: Firewall Configurations Exposed in Major Supply Chain Attack
In mid-2024, SonicWall suffered a significant security breach when an unauthorized party leveraged a brute-force attack against its customer-facing cloud backup platform, gaining access to all firewall configuration backup files stored on the service. The exposed data included sensitive firewall rules, encrypted credentials, and routing configurations for every customer utilizing SonicWall’s cloud backup, not just the initially cited 5% of their install base. While the credentials were encrypted, experts warned that weak passwords could be crackable, offering attackers expanded access. SonicWall worked with Mandiant to investigate, notified affected customers, hardened its infrastructure, and provided remediation tools. This incident highlights ongoing risks from cloud-based infrastructure and supply chain attacks, especially targeting security vendors. Attackers are increasingly exploiting weaknesses in API protections and infrastructure configurations, reinforcing the need for robust access controls and continuous monitoring as ransomware and targeted attacks against network security vendors persist.
6 months ago
Kill Chain
TwoNet Hacktivists Target Decoy Water Plant in Bold Critical Infrastructure Attack
In September 2025, the pro-Russian hacktivist group TwoNet targeted what they believed to be a vulnerable water treatment plant, unaware it was a decoy system (honeypot) operated by cybersecurity researchers. The attackers gained access using default credentials, escalated attacks through SQL enumeration, and exploited a known XSS vulnerability (CVE-2021-26829). Within 26 hours, they created new user accounts, manipulated PLC setpoints, disabled real-time updates, and attempted to disrupt both logs and alarms via the Human Machine Interface (HMI). Their tactics included data exfiltration and process disruption, signaling a shift toward operational technology (OT) attacks targeting critical infrastructure. This incident highlights a growing trend of hacktivist groups evolving from DDoS and defacement attacks to more sophisticated operations against OT and ICS targets. The rapid escalation and attempted sabotage observed in this breach emphasize the urgent need for robust segmentation, authentication, and real-time anomaly detection within critical infrastructure environments.
6 months ago
Kill Chain
SonicWall Cloud Backup Breach Exposes Firewall Configurations in 2024
In June 2024, SonicWall disclosed a significant data breach impacting all users of its cloud backup service. Attackers successfully gained unauthorized access and exfiltrated firewall configuration files belonging to these customers. The breach, which reportedly occurred in late May 2024, does not appear to have affected the core SonicWall services but poses considerable risk because leaked configurations may contain sensitive network information, VPN details, hashed passwords, and other operational data. SonicWall took immediate action by disabling the impacted service and advising affected clients to reset credentials and review their setups. This breach highlights increasing attacker focus on cloud-managed infrastructure, particularly targeting device configurations that can offer deep intelligence on enterprise environments. With threat actors exploiting misconfigurations and weak controls in supply chain and managed services, regulators and CISOs are under pressure to strengthen both preventative and responsive security postures.
6 months ago
Kill Chain
Inside the Qantas 2025 Ransomware Breach: Why Legal Measures Can’t Stop Data Leaks
In October 2025, Qantas, the Australian airline, suffered a ransomware attack attributed to the 'Scattered LAPSUS$ Hunters' group. Attackers claimed to have breached Qantas’ systems via a supply chain vulnerability, exfiltrating personal and loyalty program data of potentially hundreds of thousands of customers, including high-profile individuals. After initial extortion attempts, the stolen data—including names, emails, and frequent flyer records—was publicly leaked when Qantas refused to pay ransom. Qantas took legal steps, securing a court injunction to limit data dissemination, but these measures proved ineffective at curbing the spread among criminal and international actors. This breach highlights the ongoing threat of ransomware and data extortion campaigns targeting major brands, frequently leveraging supply-chain infiltration and cloud-based service weaknesses. The incident also underscores the limited real-world efficacy of legal remedies like injunctions, as well as evolving attacker strategies involving public shaming and mass data exposure.
6 months ago
Kill Chain
Apple Fixes Groundbreaking Pointer Infoleak in macOS/iOS Serialization (2025)
In March 2025, Apple patched a novel vulnerability in macOS and iOS after research by Google Project Zero revealed a pointer information leak in the way Apple's Foundation framework handled serialization and deserialization via NSKeyedArchiver and NSKeyedUnarchiver. The flaw allowed attackers to deduce memory address information—specifically, the address of the NSNull singleton—by crafting serialized data and analyzing the ordering of keys upon re-serialization, without exploiting any memory corruption or timing attacks. This potential leak could subvert Address Space Layout Randomization (ASLR), a key memory protection mechanism, if leveraged in real-world attack surfaces that allow roundtripping of attacker-supplied serialized objects. Although the direct impact was mitigated by Apple’s 31 March 2025 security update, the disclosure highlights an overlooked class of pointer leak vulnerabilities inherent in pointer-keyed data structures, especially where object addresses serve as hash values. This incident is significant in the context of a broader industry trend: attackers are increasingly pursuing remote and non-traditional side channels for ASLR bypasses and memory leaks, while defenders must contend with the residual risks of serialization and legacy data structure design. Regulatory and customer pressure continues to rise for organizations to ensure modern memory safety, especially as zero trust and data segmentation architectures rely on robust underlying primitives.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports