The Containment Era is here. →Explore

Industry Category

Computer/Network Security

Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.

860 threat reports
Page 69 of 72

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer/Network Security Threat Reports

Showing 817828 / 860 reports
UNC6148 Rootkit Attack on SonicWall SMA100 Devices in 2025
Impact· high

UNC6148 Rootkit Attack on SonicWall SMA100 Devices in 2025

In September 2025, SonicWall released a critical firmware update for its SMA 100 series products in response to a sophisticated attack campaign orchestrated by threat actor UNC6148. This incident involved the deployment of the OVERSTEP user-mode rootkit on end-of-life SMA 100 devices, providing persistent unauthorized access, stealing sensitive configuration and certificate data, and enabling lateral movement. Attackers exploited vulnerabilities in legacy firmware to maintain remote access—even post firmware upgrades—compromising credentials, OTP seeds, and digital certificates, with notable overlaps to prior Abyss ransomware operations. The incident underscores the growing threat posed by ransomware groups leveraging supply chain devices and persistent malware in network appliances. With a surge in rootkit-enabled persistence and a rise in zero-day exploitations targeting network edge devices, organizations must prioritize timely patching and end-of-life device management to curb risk exposure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
US Secret Service Seizes Massive SIM Server Network Threatening Government Officials
Impact· high

US Secret Service Seizes Massive SIM Server Network Threatening Government Officials

In September 2025, the U.S. Secret Service announced it had dismantled a large-scale illicit telecommunications infrastructure across the New York tri-state area, seizing over 300 SIM servers and 100,000 SIM cards. These devices, co-located at multiple sites, were used by unknown malicious actors to facilitate threats against U.S. government officials, particularly near the United Nations. Investigators discovered that this network enabled covert communications and potentially enabled bypasses of monitoring controls, raising national security concerns. The takedown required coordinated federal action to secure the assets, neutralize the risk, and support ongoing intelligence operations. This incident highlights the ongoing evolution and physical sophistication of threat actor infrastructure, especially targeting high-profile government personnel. The scale and automation facilitated by such hardware underline the growing intersection of physical and cyber threats and serve as a wake-up call for risk teams facing advanced, hybrid attack models.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Fake GitHub Pages Used to Deliver Atomic Stealer to Mac Users in 2024
Impact· medium

Fake GitHub Pages Used to Deliver Atomic Stealer to Mac Users in 2024

In early 2024, cybercriminals launched a large-scale campaign targeting macOS users by leveraging SEO poisoning, fraudulent GitHub repositories, and fake GitHub Pages to distribute the Atomic (AMOS) infostealer malware. Attackers lured users searching for popular software with malicious websites that mimicked legitimate download portals, redirecting victims to GitHub-hosted payloads. Once executed, the malware exfiltrated critical information such as credentials, browser data, cryptocurrency wallets, and system details, putting both individuals and organizations at serious risk. The campaign’s scope and reliance on open-source infrastructure enabled the threat actors to infect a wide swathe of Mac users with relative ease. This incident is particularly relevant due to the increasing prevalence of infostealer malware targeting macOS, the cunning use of SEO manipulation for initial access, and the abuse of trusted development platforms like GitHub. Security teams must be vigilant as these multi-vector attacks blend social engineering, supply chain compromise, and cloud service misuse to evade traditional defenses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
SANS Honeypot 2024: SYN Flood Distraction Amplifies Network Reconnaissance Threat
Impact· high

SANS Honeypot 2024: SYN Flood Distraction Amplifies Network Reconnaissance Threat

Between March 31 and April 20, 2024, the SANS Internet Storm Center's honeypot experienced a persistent barrage of over 2.3 million TCP SYN packets in three distinct waves, mimicking a distributed denial of service (DDoS) campaign. Traffic originated from thousands of hosts—mostly within Bangladeshi and Iraqi ISPs—leveraging spoofed and potentially compromised IPs to generate low-rate, highly patterned SYN floods targeting port 443. Despite the scale, the attack's volume and packet rates were insufficient to disrupt modern services and instead appeared to serve as a diversionary tactic. This incident highlights emerging trends in network reconnaissance and distraction techniques, where attackers intentionally generate noisy traffic to mislead analysts and mask parallel or future activities. As SYN flood patterns evolve and attackers increasingly use crafted packets and IP spoofing, traditional DDoS detection and response strategies must adapt to avoid misallocation of resources or missing stealthier threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
AT&T 2023: How Salt Typhoon Changed the APT Playbook
Impact· medium

AT&T 2023: How Salt Typhoon Changed the APT Playbook

In 2023, the telecommunications giant AT&T was targeted by the advanced persistent threat group Salt Typhoon, which launched a sophisticated campaign exploiting unconventional vulnerabilities. Unlike conventional attacks, Salt Typhoon focused on endpoints lacking robust detection and response (EDR), hunted for network blind spots with minimal logging, and engaged in 'living off the land' attacks—leveraging legitimate administrative tools to evade detection and persist inside networks. This multi-pronged methodology enabled deep network infiltration before discovery, ultimately jeopardizing sensitive data and service availability across AT&T’s infrastructure. Following the breach, the company reported the threat group was successfully evicted from its systems. This incident has set a precedent, with numerous threat actors now adopting Salt Typhoon’s tactics to bypass traditional security controls. The breach highlights an urgent need for organizations to enhance monitoring, bolster endpoint visibility across all platforms, and adapt defenses for evolving attacker methodologies in critical infrastructure sectors.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fake Password Managers Spread AMOS Malware on Mac: The 2025 LastPass Incident
Impact· medium

Fake Password Managers Spread AMOS Malware on Mac: The 2025 LastPass Incident

In September 2025, LastPass reported an ongoing malware campaign targeting macOS users with fake password managers distributed through fraudulent GitHub repositories and deceptive SEO-optimized links. The attackers impersonated over 100 popular software products—including LastPass, 1Password, Dropbox, and others—using build-your-own repositories that redirected victims to install scripts containing the Atomic (AMOS) infostealer malware. Victims were instructed to run shell commands that downloaded backdoored payloads, risking credential theft, data exfiltration, and sustained system compromise. The campaign employed automated methods for rapid replication and evasive takedown resistance. This incident underscores a surge in supply chain and social engineering attacks using open platforms and SEO abuse, highlighting the persistent vulnerabilities in software distribution channels for macOS. It demonstrates attackers' growing sophistication in exploiting user trust and platform discoverability to deploy credential-stealing malware at scale.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
EDR-Freeze: Novel Windows WER Technique Suspends EDR and Antivirus Tools
Impact· medium

EDR-Freeze: Novel Windows WER Technique Suspends EDR and Antivirus Tools

In September 2025, a security researcher revealed a novel user-mode evasion technique leveraging Windows Error Reporting (WER) to suspend the operation of Endpoint Detection & Response (EDR) and antivirus software. The proof-of-concept tool, EDR-Freeze, exploits a race condition by combining the WerFaultSecure component with the MiniDumpWriteDump API. Attackers can indefinitely freeze security processes by suspending WerFaultSecure precisely as it is executing a memory dump of the target, effectively leaving EDR or AV tools inert without requiring kernel-level vulnerabilities. This design weakness bypasses typical Bring Your Own Vulnerable Driver (BYOVD) defences and leaves minimal forensic evidence. This incident underscores the increasing sophistication of EDR evasion by cyber adversaries, who are rapidly adopting stealthy, native Windows attack chains. Organizations must adapt detection and monitoring practices to keep pace as user-mode bypasses erode longstanding layers of endpoint protection. The wider prevalence of such techniques signals a strategic shift in attacker tradecraft and compels a reassessment of endpoint hardening and response automation.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
DPRK Leverages ClickFix Job Scams to Infest Crypto Firms with BeaverTail Infostealer
Impact· low

DPRK Leverages ClickFix Job Scams to Infest Crypto Firms with BeaverTail Infostealer

In September 2025, threat actors linked to North Korea (DPRK) orchestrated a targeted phishing campaign leveraging ClickFix-style lures against employees in the cryptocurrency and retail sectors. Masquerading as legitimate job opportunities for marketing and trader roles, attackers distributed malicious files leading to infection with BeaverTail and InvisibleFerret malware. This allowed adversaries to employ infostealing techniques, facilitating lateral movement and potential data exfiltration, while avoiding traditional security controls. The campaign highlights DPRK’s continued focus on crypto-enabled theft, using sophisticated social engineering, custom tooling, and industry-specific targeting. This incident underscores a recent surge in state-sponsored campaigns prioritizing non-technical roles and leveraging advanced lure techniques. Organizations in high-value verticals like crypto are increasingly attractive to financially motivated adversaries, elevating the urgency for zero trust defenses and robust internal traffic security controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Canada Seizes $40 Million in Historic Crackdown on TradeOgre Crypto Exchange
Impact· high

Canada Seizes $40 Million in Historic Crackdown on TradeOgre Crypto Exchange

In September 2025, the Royal Canadian Mounted Police (RCMP) dismantled the TradeOgre cryptocurrency exchange, seizing over $40 million in digital assets linked to alleged financial crimes. The operation was initiated following intelligence from Europol, leading to an investigation by the Money Laundering Investigative Team (MLIT) that uncovered the exchange's lack of regulatory compliance, such as evading Know Your Customer (KYC) protocols and failing to register with Canada's FINTRAC. The lack of oversight facilitated the laundering of cybercrime proceeds, particularly via privacy-focused cryptocurrencies like Monero, culminating in the country's largest-ever asset seizure. This incident underscores the growing scrutiny and regulatory pressure on privacy-centric platforms facilitating anonymous digital transactions. The enforcement action highlights heightened law enforcement capabilities targeting underground exchanges and reflects broader trends in global efforts to curb illicit finance within the crypto sector.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
MalTerminal: GPT-4-Powered Malware Signals New Era of AI Cyberattacks
Impact· high

MalTerminal: GPT-4-Powered Malware Signals New Era of AI Cyberattacks

In September 2025, SentinelOne’s SentinelLABS revealed the existence of 'MalTerminal,' the first documented malware leveraging GPT-4-powered Large Language Model (LLM) capabilities. Demonstrated at LABScon 2025, MalTerminal introduces LLM-driven automation within the malware lifecycle—enabling it to generate ransomware payloads, establish reverse shells, and craft social engineering content in real time. The attack method shows that malware authors are blending AI models directly into code to rapidly escalate privilege, automate lateral movement, and obfuscate command-and-control traffic. Business impact includes advanced, adaptive attacks that defeat legacy detection, heightening risks of data exfiltration, extended dwell time, and operational disruption. MalTerminal’s emergence is a bellwether for the rapid weaponization of generative AI technology by threat actors. This incident highlights the urgent need for organizations to re-evaluate traditional controls and accelerate adoption of cognitive security, visibility, and real-time policy enforcement frameworks to keep pace with evolving adversary techniques.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
LastPass Exposes macOS Atomic Infostealer Attack via Fake GitHub Repositories
Impact· high

LastPass Exposes macOS Atomic Infostealer Attack via Fake GitHub Repositories

In mid-2025, LastPass identified and warned users about a sophisticated information-stealing campaign targeting Apple macOS users. Attackers set up fraudulent GitHub repositories impersonating reputable projects, including LastPass, to distribute versions of the 'Atomic' infostealer malware. Unsuspecting users downloading these fake tools had their credentials, browser data, and sensitive files compromised. The campaign leveraged social engineering, search poisoning, and open-source developer trust to infiltrate victims’ systems, posing significant risk to both individual and enterprise security. The incident highlights continued abuse of trusted development platforms to target the software supply chain. This breach is noteworthy as it reflects the growing trend of attacker focus on macOS endpoints and the exploitation of open-source ecosystems. With supply chain attacks and infostealer campaigns rising sharply in 2025, organizations face increasing pressure to enhance their controls for code provenance, user awareness, and endpoint defense.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Gamaredon & Turla: Joint APT Campaign Strikes Ukraine in 2025
Impact· medium

Gamaredon & Turla: Joint APT Campaign Strikes Ukraine in 2025

In early 2025, a previously unseen collaboration between advanced persistent threat groups Gamaredon and Turla was discovered in Ukraine. Utilizing ESET telemetry, researchers identified co-compromises in which Gamaredon provided initial access using spearphishing and malicious PowerShell-based tools (such as PteroGraphin and PteroOdd), allowing Turla to deploy its exclusive Kazuar backdoor on select high-value targets. The attacks, attributed to Russian FSB-linked groups, targeted governmental entities and leveraged encrypted channels, PowerShell scripting, and multi-stage malware delivery via compromised web services and cloud platforms. Impact was mainly concentrated on the potential exfiltration of sensitive national intelligence. This incident underscores a growing trend of threat actor collaboration within nation-state cyber operations, blurring lines between operational roles and increasing attack efficiency. The overlapping TTPs and use of novel access and persistence mechanisms signal heightened complexity in the Eastern European threat landscape, demanding urgent operational and strategic defensive improvements.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports