✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
npm Package Supply Chain Compromise: 2023’s Maintainer Phishing Attacks
In mid-2023, a significant wave of supply chain attacks targeted the npm JavaScript ecosystem, compromising maintainer accounts through highly sophisticated phishing campaigns and credential theft. Adversaries delivered convincing emails impersonating npmjs.org, tricking developers into revealing login credentials and two-factor authentication secrets. Stolen publishing tokens and, in some cases, hijacked email domains enabled attackers to inject malicious code into popular packages such as 'prettier', 'chalk', and 'debug'. This resulted in malware propagation to thousands of downstream applications, facilitating widespread credential theft, cryptocurrency manipulation, and exfiltration risks within user environments. Organizations and end users faced significant exposure due to the trust placed on these foundational open-source dependencies. The incident remains highly relevant as npm and the broader open-source software community continue to see an uptick in targeted supply chain attacks. Threat actors are evolving their techniques, leveraging both technical exploits and sophisticated social engineering, raising the urgency for robust package vetting, stronger identity controls, and supply chain transparency.
6 months ago
Kill Chain
NPM Supply Chain: Shai-Hulud Attack Compromises 700+ Packages
In September 2024, researchers identified a large-scale supply chain attack leveraging malicious NPM packages weaponized with the "Shai-Hulud" malware. Attackers trojanized over 700 NPM packages—including popular and widely-used ones such as CrowdStrike's—compromising developer systems and creating persistent, unauthorized GitHub Actions workflows in code repositories. The attack targeted both Windows and Linux environments, harvesting developer credentials, CI/CD tokens, and secrets, then exfiltrating the data via webhooks to attacker-controlled servers. The worm-like propagation enabled ongoing data theft and espionage, raising substantial risks for any organization dependent on NPM or continuous integration workflows. This incident underscores growing risks in software supply chains, as modern attacks increasingly target developer tools and automation infrastructure. Self-propagating, persistent attacks such as Shai-Hulud highlight the need for stronger code provenance controls, real-time threat detection, and updated development pipeline security to counter evolving adversary tactics.
6 months ago
Kill Chain
Brazilian Military Breach: Zimbra Zero-Day Exploited via Libyan Navy Impersonation
In early 2024, cyber attackers posing as representatives of the Libyan Navy’s Office of Protocol targeted the Brazilian military using a sophisticated spear-phishing campaign. By leveraging a previously unknown zero-day vulnerability in Zimbra Collaboration Suite and delivering malicious emails through compromised inter-country secure communications channels (ICS), the threat actors successfully bypassed traditional perimeter defenses. The attackers' advanced persistent techniques enabled them to gain unauthorized access, exploit sensitive data, and risk critical communications infrastructure for the Brazilian defense sector, with potential exposure of mission-critical information. This incident highlights the escalating risks posed by zero-day vulnerabilities and state-linked or impersonation-driven threat actors, particularly against government and defense organizations. The unusual attack vector via ICS demonstrates evolving tactics beyond routine phishing, reinforcing the necessity for layered security, real-time threat detection, and robust segmentation controls.
6 months ago
Kill Chain
Zeroday Cloud 2025: Cloud and AI Security in the Spotlight
In December 2025, the inaugural Zeroday Cloud hacking contest was announced, offering $4.5 million in bug bounties for security researchers able to compromise open-source cloud and AI technologies. Organized by cloud security firm Wiz with major cloud providers Google Cloud, AWS, and Microsoft, the event is set to coincide with Black Hat Europe in London. Categories span AI platforms, Kubernetes, virtualization, web servers, databases, and DevOps tools, with cash rewards reaching as high as $300,000 for critical exploits that achieve remote code execution or full container escapes. The competition’s rules encourage demonstration of high-impact vulnerabilities in default configurations, drawing attention from the research and bug bounty community worldwide. This contest stands out as the largest ever focused exclusively on cloud-native and AI environments. It highlights industry-wide concerns about tooling security as organizations accelerate public cloud and AI adoption. The timing reflects both the proliferation of adversaries targeting these attack surfaces and coordinated industry efforts to crowdsource vulnerability discovery in critical platforms.
6 months ago
Kill Chain
How a Zimbra Zero-Day Breach Exposed the Brazilian Military: Lessons for Secure Collaboration
In early 2025, a zero-day vulnerability in Zimbra Collaboration (CVE-2025-27915), a widely used email and collaboration platform, was exploited to target the Brazilian military. Attackers used malicious ICS calendar files containing unsanitized HTML and JavaScript to trigger stored cross-site scripting (XSS) within Zimbra's Classic Web Client. This entry vector effectively bypassed standard security controls and provided attackers the ability to execute malicious code in users' browsers, potentially enabling credential theft, session hijacking, and further movement inside the organization before the vulnerability was patched. The campaign underscores how attackers are increasingly leveraging vulnerabilities in collaborative and communication tools to gain a foothold in targeted organizations and critical infrastructure. This breach is particularly relevant today given the ongoing surge in zero-day exploits against widely deployed business applications, especially in sectors such as government and defense. The rapid weaponization of collaboration-tool vulnerabilities highlights the need for timely patch management, robust segmentation, and vigilant threat detection to combat sophisticated phishing and XSS-based initial access.
6 months ago
Kill Chain
How Chinese Front Organizations Exploited Western Research to Advance State Cyber Capabilities
In early 2024, coordinated investigations revealed that Chinese government-linked academic and research institutions were covertly collaborating with Western organizations and researchers. Operating under seemingly neutral fronts, these entities facilitated the transfer of advanced cyber technologies and expertise, ultimately benefitting the intelligence apparatus of the People’s Republic of China (PRC). The campaign included joint projects, academic exchanges, and technology partnerships that enabled the PRC to sidestep export controls and gain access to cutting-edge cyber defense and offensive capabilities. The outcome potentially undermines intellectual property protections and heightens risks to network and national security within targeted Western sectors. This incident underscores a marked escalation in supply chain and technology transfer tactics used by nation-state actors. As the global competition for cyber advantage intensifies, regulators and organizations must heighten vigilance around academic, research, and cross-border tech collaborations to mitigate risks of inadvertent technology leakage.
6 months ago
Kill Chain
Palo Alto Networks Faces Massive Surge in Login Portal Recon Scans
In early October 2025, cybersecurity firm GreyNoise detected a sharp 500% spike in reconnaissance scans targeting Palo Alto Networks GlobalProtect and PAN-OS login portals. Over 1,285 unique suspicious IP addresses, predominantly from the U.S., but also from the UK, Canada, the Netherlands, and Russia, launched automated probes against these authentication portals. The campaign appeared targeted, leveraging data from public scanning platforms like Shodan and Censys. No verified exploit or compromise has been confirmed, with Palo Alto Networks asserting their systems remain secure and attributing much of the observed activity to external fingerprinting, not internal breach. This incident highlights a broader escalation in focused reconnaissance tactics against major infrastructure platforms, often preceding attempts to weaponize new vulnerabilities. Organizations should remain vigilant about emerging threats, monitor authentication endpoints, and proactively patch known and zero-day-related risks.
6 months ago
Kill Chain
Palo Alto Networks Portals Targeted by 500% Surge in Reconnaissance Scanning
On October 3, 2025, cybersecurity researchers at GreyNoise detected an unprecedented 500% spike in scanning activity targeting Palo Alto Networks login portals, marking the highest volume observed over a three-month period. The scanning involved a surge of IP addresses systematically probing these portals, suggesting highly targeted reconnaissance efforts by unknown threat actors. While no direct exploitation or breach was reported, such coordinated scanning is often the precursor to exploitation attempts against potential vulnerabilities in security infrastructure, especially as targeted technologies are foundational for enterprise security postures. This incident exemplifies the growing trend of automated reconnaissance on high-value network assets as adversaries aim to map attack surfaces for later campaigns. Organizations relying on exposed management interfaces must bolster detection, segmentation, and access controls to address these evolving reconnaissance tactics.
6 months ago
Kill Chain
Salesforce Breach 2024: Scattered Lapsus$ Hunters' Massive Data Extortion Campaign
In October 2024, the cybercriminal collective Scattered Lapsus$ Hunters resurfaced with a dedicated leak site, threatening to publish stolen data related to Salesforce customers if their extortion demands were not met. This group, an alliance of threat actors including Scattered Spider, Lapsus$, and ShinyHunters, allegedly compromised Salesforce environments through social engineering—specifically vishing IT support personnel to obtain credentials and, in parallel campaigns, exploiting OAuth token theft. The attackers claimed to possess approximately one billion records from 39 prominent organizations, including sensitive personally identifiable information (PII) like Social Security and driver’s license numbers. This incident underscores the increased targeting of SaaS platforms via identity and access manipulation, as well as the growing sophistication of multinational threat actor collaborations. It signals elevated risk for organizations relying on cloud applications and highlights the necessity of enforcing multi-factor authentication and vigilant third-party access controls.
6 months ago
Kill Chain
Dutch Teens Arrested for Wi-Fi Sniffer Recon in 2024 Russian Espionage Case
In June 2024, Dutch law enforcement arrested two 17-year-olds suspected of conducting cyber-espionage for Russian-backed threat actors. The teens reportedly canvassed high-profile locations in The Hague, including several embassies and European law enforcement headquarters, using a Wi-Fi sniffer to gather network intelligence. Authorities allege they were recruited via Telegram and that state-sponsored Russian actors utilized the pair for reconnaissance, leveraging youth engagement to mask attribution. The operation came to light after a tip-off from Dutch intelligence, resulting in swift arrests and raising significant policy concerns. This incident underscores a rising trend of nation-states outsourcing early reconnaissance to foreign youth via social media, reducing their risk of direct detection. The use of simple yet effective tools for physical/digital hybrid espionage highlights growing operational sophistication—and creates new urgency for organizations to shore up network perimeter and monitoring controls.
6 months ago
Kill Chain
Israeli-Linked AI Disinformation Campaign Targets Iran Amid Evin Prison Strike
In June 2023, a coordinated network linked to the Israeli government, dubbed PRISONBREAK, used AI-generated deepfake content and social media manipulation to incite unrest in Iran amid escalating regional tensions and real-world airstrikes. Researchers at Citizen Lab and Clemson University uncovered how this sophisticated influence campaign leveraged newly created accounts on X to disseminate doctored videos and imagery—often timed with kinetic events such as an Israeli strike on Tehran’s Evin Prison. The operation successfully tricked news outlets and amassed significant engagement, specifically pushing calls for uprisings against the Iranian government. This incident spotlights the growing use of state-backed AI-enabled disinformation as a tool of hybrid warfare, bridging digital and physical attacks to maximize psychological impact. It exemplifies the broadening threat landscape, where credible-seeming content can intensify volatility and erode trust in open information ecosystems.
6 months ago
Kill Chain
Cavalry Werewolf APT Hits Russian Agencies with FoalShell and StallionRAT in 2025
In October 2025, a sophisticated threat actor known as Cavalry Werewolf, believed to share links with the YoroTrooper group, orchestrated targeted cyber attacks against Russian public sector agencies. Utilizing custom malware families FoalShell and StallionRAT, the attackers infiltrated key government systems, establishing covert access for potential espionage and data theft. Security firm BI.ZONE detected the activity, noting operational overlaps with other known clusters such as SturgeonPhisher and Comrade Saiga. The cyber-espionage campaign leveraged a mix of spear-phishing, credential theft, and advanced persistence techniques to evade detection and conduct lateral movement within critical infrastructure environments. This incident highlights a continuing trend of state-aligned espionage campaigns that exploit zero trust gaps, advanced malware, and blended tactics to compromise sensitive government data. The increasing frequency and sophistication of such attacks elevate the urgency for robust segmentation and monitoring strategies within public sector networks.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports