✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Spain Arrests Suspected Member of Pro-Russian Hacktivist Groups
In March 2026, Spain's National Police, in collaboration with the FBI, arrested a 34-year-old Italian man in Palencia for his alleged involvement with pro-Russian hacktivist groups, including CyberArmy of Russia Reborn (CARR) and Z-Pentest. The suspect is accused of providing logistical support to a Ukrainian hacker affiliated with CARR, facilitating their escape to Russia via Poland and Belarus. Authorities seized computers and cryptocurrency storage devices during the operation. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/spain-arrests-suspected-member-of-pro-russian-hacktivist-groups/?utm_source=openai)) This arrest underscores the ongoing threat posed by pro-Russian hacktivist groups targeting critical infrastructure in the U.S. and Europe. The collaboration between international law enforcement agencies highlights the importance of coordinated efforts to combat cyber threats that exploit geopolitical tensions. ([nsa.gov](https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4355881/nsa-fbi-and-others-call-out-pro-russia-hacktivist-groups-targeting-critical-inf/?utm_source=openai))
2 weeks ago
Kill Chain
Armored Likho's 2026 Cyber-Espionage Campaign: BusySnake Infostealer Targets Critical Infrastructure
In July 2026, the previously unknown APT group 'Armored Likho' launched sophisticated cyber-espionage campaigns targeting government agencies and electric power entities in Russia, Brazil, and Kazakhstan. Utilizing spear-phishing emails disguised as official communications, they deployed the Python-based 'BusySnake' infostealer to exfiltrate sensitive data, including credentials and cryptographic keys. The malware's advanced obfuscation techniques and modular architecture enabled persistent access and evasion of detection mechanisms. This incident underscores the escalating threat posed by APT groups leveraging AI-generated malware to target critical infrastructure. Organizations must enhance their cybersecurity posture to defend against such evolving tactics.
2 weeks ago
Kill Chain
FreeBSD Kernel Vulnerability CVE-2026-3038: A Critical Security Flaw
In March 2026, a critical vulnerability identified as CVE-2026-3038 was discovered in the FreeBSD kernel's rtsock_msg_buffer() function. This flaw allows unprivileged users to trigger a 127-byte stack buffer overflow, leading to immediate kernel panics by overwriting stack canaries. The vulnerability arises from improper validation of the sockaddr length field, enabling attackers to craft malicious requests that exploit this weakness. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-3038/?utm_source=openai)) The discovery of CVE-2026-3038 underscores the persistent challenges in kernel security, particularly concerning input validation and memory management. This incident highlights the necessity for continuous vigilance and prompt patching to mitigate potential exploits that could lead to system crashes or privilege escalation.
2 weeks ago
Kill Chain
Iranian Hackers Deploy Cavern C2 Framework Against Israeli Sectors
In early 2026, an Iranian state-sponsored hacking group known as Cavern Manticore targeted Israeli government and IT sectors using a sophisticated modular command-and-control (C2) framework called Cavern. This framework, built on a .NET foundation with multiple compilation formats, enabled the attackers to execute DLL side-loading through SysAid's software update feature, leading to the deployment of various modules for reconnaissance, data theft, and lateral movement. The attack chain involved the execution of a trojanized DLL ('uxtheme.dll') containing the Cavern Agent, which then loaded additional modules to contact the C2 server and fetch further post-exploitation tools. ([research.checkpoint.com](https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/?utm_source=openai)) The incident underscores the evolving tactics of Iranian threat actors, who are increasingly leveraging modular and adaptable toolsets to enhance their cyber espionage capabilities. The use of such frameworks allows for tailored deployments based on victim profiles, reducing forensic visibility and ensuring persistent access. Organizations must remain vigilant and implement robust security measures to defend against these sophisticated threats.
2 weeks ago
Kill Chain
SkillCloak: Unveiling the Evasion of Malicious AI Skills
In July 2026, researchers from the Hong Kong University of Science and Technology unveiled 'SkillCloak,' a technique enabling malicious AI agent skills to evade static scanners through self-extracting packing methods. By embedding malicious payloads within directories typically ignored by scanners, such as .git/, and reconstructing them during execution, SkillCloak achieved over 90% evasion rates across eight tested scanners. This method allows attackers to distribute harmful skills that can steal credentials, exfiltrate source code, or install backdoors, all while appearing benign during initial scans. ([thehackernews.com](https://thehackernews.com/2026/07/new-skillcloak-technique-lets-malicious.html?utm_source=openai)) The study underscores a critical vulnerability in current AI agent ecosystems, where static analysis tools fail to detect dynamically concealed threats. This highlights the urgent need for enhanced runtime behavior monitoring and the development of more robust detection mechanisms to safeguard against sophisticated evasion tactics. ([thehackernews.com](https://thehackernews.com/2026/07/new-skillcloak-technique-lets-malicious.html?utm_source=openai))
3 weeks ago
Kill Chain
North Korean Malicious npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
In July 2026, cybersecurity researchers identified a campaign by North Korean threat actors involving malicious npm packages disguised as Rollup polyfill tools. These packages, including 'rollup-packages-polyfill-core' and 'rollup-runtime-polyfill-core,' closely mimicked legitimate projects to deceive developers. Upon installation, they executed hidden scripts that established remote access and exfiltrated sensitive data such as credentials for AWS, Azure, and cryptocurrency wallets. The attack leveraged a multi-stage delivery mechanism, with initial packages installing secondary payloads that fetched and executed malicious code from external servers. This approach enabled the attackers to evade detection and maintain persistence on compromised systems. ([thehackernews.com](https://thehackernews.com/2026/07/north-korea-linked-npm-packages-mimic.html?utm_source=openai)) This incident underscores a growing trend of sophisticated supply chain attacks targeting open-source ecosystems. By compromising widely used development tools, attackers can infiltrate numerous organizations, highlighting the critical need for enhanced vigilance and security measures in software development practices.
3 weeks ago
Kill Chain
FortiBleed Campaign's Link to Inc and Lynx Ransomware Groups Unveiled
In July 2026, the FortiBleed campaign, initially identified as a credential-harvesting operation targeting Fortinet FortiGate firewalls, was linked to ransomware-as-a-service groups Inc Ransom and Lynx. SOCRadar researchers discovered that an operator within the FortiBleed infrastructure was actively engaged in ransom negotiations for both groups, indicating that credentials obtained through FortiBleed were being utilized for ransomware deployment. The campaign compromised approximately 12,000 FortiGate devices, with at least 12 confirmed ransomware deployments resulting in hundreds of encrypted endpoints across affected organizations. ([darkreading.com](https://www.darkreading.com/threat-intelligence/fortibleed-actors-inc-lynx-ransomware-gangs?utm_source=openai)) This incident underscores the evolving threat landscape where initial access brokers collaborate with ransomware operators, amplifying the risk to organizations. The exploitation of network security devices as entry points highlights the critical need for robust perimeter defenses and vigilant monitoring to prevent unauthorized access and subsequent ransomware attacks.
3 weeks ago
Kill Chain
Chinese AI Models Redefine Cybersecurity Landscape
In June 2026, Chinese companies Zhipu AI and 360 Security Technology released advanced AI models—GLM-5.2 and Tulongfeng, respectively—that significantly enhance vulnerability discovery capabilities. GLM-5.2, an open-weight model, demonstrated performance on par with leading U.S. models like Anthropic's Mythos in identifying software vulnerabilities. Tulongfeng, described as China's version of Mythos, reportedly identified over 3,400 vulnerabilities, with 105 acknowledged by the Chinese government. These developments underscore a rapid advancement in AI-driven cybersecurity tools within China, potentially altering the global cybersecurity landscape. ([techradar.com](https://www.techradar.com/pro/security/chinese-cybersecurity-company-360-unveils-chinas-version-of-mythos-and-yitianzhen-to-automate-cyber-defense?utm_source=openai)) The emergence of these models highlights the increasing accessibility of sophisticated AI tools for both defenders and attackers. The open-source nature of GLM-5.2 raises concerns about potential misuse by malicious actors, as it allows for modification and deployment without restrictions. This trend necessitates a reassessment of current cybersecurity strategies to address the evolving threat landscape posed by AI-enhanced capabilities. ([axios.com](https://www.axios.com/2026/06/25/china-glm-52-open-source-hackers?utm_source=openai))
3 weeks ago
Kill Chain
European Parliament Member Targeted with Pegasus Spyware During Investigation
In October 2022 and March 2023, former Member of the European Parliament (MEP) Stelios Kouloglou's mobile device was infiltrated with Pegasus spyware while he was serving on the PEGA committee, which was investigating the misuse of such surveillance tools within the European Union. The Citizen Lab's forensic analysis confirmed these infections, indicating that attackers potentially accessed confidential committee documents and deliberations. The specific government or entity responsible for these attacks remains unidentified. ([citizenlab.ca](https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus/?utm_source=openai)) This incident underscores the escalating threat of sophisticated spyware targeting high-profile individuals, including those involved in oversight and investigative roles. It highlights the urgent need for robust cybersecurity measures and regulatory frameworks to protect sensitive information and uphold democratic processes. ([theguardian.com](https://www.theguardian.com/world/2026/jul/03/spyware-used-against-mep-investigating-pegasus-abuses-report-finds?utm_source=openai))
3 weeks ago
Kill Chain
Armored Likho's BusySnake Stealer Targets Government and Energy Sectors
In July 2026, a previously undocumented threat actor known as Armored Likho launched cyber attacks targeting government agencies and the electric power sector in Russia, Brazil, and Kazakhstan. The group employed spear-phishing emails with lures related to official government notices or social programs, distributing RAR archives containing EXE binaries that served as droppers for additional payloads retrieved from a GitHub repository. These payloads included a newly identified Python-based information stealer named BusySnake Stealer, which is capable of stealing browser passwords, cookies, clipboard contents, screenshots, documents, Telegram session data, OTP secrets, and cryptocurrency wallet files. The malware establishes persistence through a combination of VBScript files and scheduled tasks, allowing the attackers to maintain prolonged access to compromised systems. This incident underscores the evolving tactics of cyber espionage groups, highlighting their ability to blend financially motivated campaigns with targeted attacks on critical infrastructure. The use of AI-generated first-stage loaders and obfuscated, modular remote access trojans (RATs) and infostealers specifically engineered to bypass dynamic analysis demonstrates a significant advancement in their capabilities. Organizations must remain vigilant and adapt their cybersecurity measures to counter these sophisticated threats.
3 weeks ago
Kill Chain
Anthropic's Mythos AI Breach: A Wake-Up Call for AI Security
In April 2026, unauthorized users gained access to Anthropic's restricted AI cybersecurity tool, Mythos, through a third-party vendor environment. Mythos, designed for enterprise security, was considered too powerful for public release due to its potential to identify vulnerabilities and simulate cyberattacks autonomously. The breach raised significant concerns about the security of advanced AI tools and the potential misuse of such technologies. This incident underscores the critical need for robust security measures when handling powerful AI tools, especially those capable of autonomous actions. It highlights the importance of securing third-party vendor environments to prevent unauthorized access to sensitive technologies.
3 weeks ago
Kill Chain
Pegasus Spyware Targets PEGA Committee Member Amid Investigations
In 2022 and 2023, the European Parliament's PEGA Committee, established to investigate the misuse of surveillance spyware like NSO Group's Pegasus, faced an ironic security breach. Greek journalist and substitute committee member Stelios Kouloglou's phone was infected with Pegasus spyware twice: first around October 2022 and again in March 2023. These infections coincided with critical phases of the committee's work, including the drafting of its final report. The infections were confirmed by the University of Toronto's Citizen Lab, highlighting the persistent threat posed by sophisticated spyware even to those tasked with investigating its misuse. This incident underscores the ongoing challenges in protecting sensitive information from advanced surveillance tools. It also emphasizes the need for robust cybersecurity measures within governmental bodies and the urgency of implementing the PEGA Committee's recommendations to prevent future abuses of spyware technologies.
3 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports