The Containment Era is here. →Explore

Industry Category

Computer/Network Security

Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.

860 threat reports
Page 71 of 72

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer/Network Security Threat Reports

Showing 841852 / 860 reports
KillSec Ransomware Campaign Targets Brazilian Healthcare Supply Chain
Impact· high

KillSec Ransomware Campaign Targets Brazilian Healthcare Supply Chain

In April 2024, the KillSec ransomware group orchestrated a cyberattack against a major Brazilian healthcare software provider, targeting a core element of the nation’s healthcare technology supply chain. According to cybersecurity researchers, the attackers leveraged sophisticated ransomware tactics to breach the provider’s environment, exfiltrate sensitive patient data, and subsequently encrypt vital systems, disrupting normal operations. The breach involved the theft of confidential healthcare records, potentially exposing personally identifiable information (PII) as well as critical medical data, raising alarms across Brazil’s healthcare sector. As a result, provider services experienced significant operational delays and financial impact, and the wider ecosystem faces cascading risks from the exposed data. This incident is particularly noteworthy due to the healthcare sector’s growing vulnerability to ransomware attacks, with supply chain vectors increasingly exploited by threat actors like KillSec. The event reflects a concerning trend of ransomware groups shifting toward critical infrastructure and service-provider targets, amplifying regulatory, compliance, and patient safety pressures.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Shai-Hulud Worm: Self-Propagating Malware Hits 180+ NPM Packages in Major Supply Chain Breach
Impact· high

Shai-Hulud Worm: Self-Propagating Malware Hits 180+ NPM Packages in Major Supply Chain Breach

In September 2025, a novel self-replicating worm, dubbed 'Shai-Hulud,' targeted the JavaScript NPM ecosystem by infecting over 180 code packages. The malware exploited developer authentication tokens found on Linux and macOS devices, replicating itself into the top 20 packages accessible to the compromised account and rapidly publishing malicious package versions. Stolen credentials were published in new, public GitHub repositories, compounding the supply chain risk. Though the initial infection included several packages managed by CrowdStrike, the company quickly removed the compromised code and rotated secrets, preventing wider impact to its flagship products. This incident highlights the increasing sophistication and automation of supply chain compromise, especially in open-source software development. The self-propagating nature of Shai-Hulud, combined with credential harvesting and public exposure, represents a growing risk trend for organizations relying on software registries.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
2024 Shai-hulud Worm: Major Supply Chain Attack Strikes NPM
Impact· medium

2024 Shai-hulud Worm: Major Supply Chain Attack Strikes NPM

In September 2024, a self-replicating malware dubbed "Shai-hulud" infiltrated the open source ecosystem by targeting hundreds of NPM (Node Package Manager) packages. The worm initiates its campaign by compromising a single software component, and automatically harvests secrets, tokens, and credentials present in affected developers' environments. By leveraging compromised NPM accounts, Shai-hulud spreads itself through subsequent package uploads, injecting malicious payloads into new releases and perpetuating a chain reaction across software supply chains. Impacted parties range from individual developers to prominent tech companies and security vendors. This incident highlights a concerning escalation in supply chain threats, demonstrating advanced automation in malware propagation and the weaponization of interconnected open source dependencies. The attack underscores the rising prevalence of highly automated, lateral-moving malware and the systemic risks posed by compromised development ecosystems.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
K2 Think AI Model Jailbroken Within Hours of 2024 Release
Impact· medium

K2 Think AI Model Jailbroken Within Hours of 2024 Release

On September 9, 2024, the UAE-backed 'K2 Think' large language model (LLM) was released with the goal of industry-leading transparent reasoning. Within hours, however, cybersecurity researchers discovered a critical vulnerability known as Partial Prompt Leakage. This flaw allowed adversaries to observe the model's internal logic in plain text, making it easier to methodically bypass safeguards and jailbreak the AI system. The exploit was demonstrated by researcher Alex Polyakov, who publicly documented how attackers could uncover and iterate against the model’s defenses, enabling harmful behaviors such as malware generation. The breach did not result in immediate large-scale misuse, but it revealed a key tradeoff between transparency and security in modern LLM development. This incident is emblematic of new AI security risks emerging as open, auditable models grow in popularity. It underscores the urgency for vendors to balance transparency with robust protection, as attackers quickly adapt to and exploit unique model features. With increased regulatory scrutiny and rising enthusiasm for open-source AI, safeguarding model reasoning is now a critical surface organizations cannot ignore.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Lies-in-the-Loop: When AI Coding Agents Become Supply Chain Threats
Impact· high

Lies-in-the-Loop: When AI Coding Agents Become Supply Chain Threats

In June 2024, researchers at Checkmarx Zero demonstrated a novel supply chain attack called 'Lies-in-the-Loop' (LITL) targeting AI-assisted coding agents, specifically Anthropic's Claude Code. By leveraging prompt injection, attackers manipulated the AI into concealing malicious code execution behind benign prompts, effectively tricking human operators into approving dangerous actions. The attack exploited trust in the 'human-in-the-loop' workflow, showing that malicious context within public resources like GitHub issues could hide remote code execution triggers. Successful exploitation enabled attackers to deploy arbitrary commands and potentially introduce malicious packages into software repositories, increasing the risk of downstream supply chain compromise. This incident highlights a concerning trend: as AI coding agents are rapidly adopted, their interfaces become a ripe target for adversaries using social engineering and prompt manipulation. The attack underscores the evolving sophistication of supply chain threats, especially those that blur the lines between human fallibility and machine autonomy in development environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
North Korean Kimsuky Leverages Deepfake Military IDs in Sophisticated Social Engineering Attack
Impact· low

North Korean Kimsuky Leverages Deepfake Military IDs in Sophisticated Social Engineering Attack

In April 2024, threat group Kimsuky, attributed to North Korea, launched a cyberattack campaign targeting South Korean organizations using advanced social engineering tactics. The attackers exploited ChatGPT to generate sophisticated deepfake military ID documents, which were then used as bait to compromise targets via phishing emails and messaging apps. By mimicking authentic credentials, Kimsuky aimed to breach sensitive military and governmental networks, potentially facilitating credential harvesting and further lateral movement within critical infrastructures. This incident highlights the increasing convergence of generative AI and cyberattack techniques, making impersonation and credential-based attacks far more convincing and widespread. It underscores rising urgency for organizations to strengthen verification processes and stay vigilant against emerging deepfake-enabled attack vectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
SXVM Ransomware PoC Reveals Next-Gen DLL Unhooking to Bypass EDR
Impact· high

SXVM Ransomware PoC Reveals Next-Gen DLL Unhooking to Bypass EDR

In September 2024, a novel ransomware proof-of-concept dubbed 'SXVM' showcased advanced defensive evasion capabilities through DLL unhooking, enabling it to bypass traditional endpoint detection and response (EDR) tools. The threat leverages in-memory manipulation to restore .text sections of key system DLLs—effectively undoing any hooks or software breakpoints set by debuggers and security products. This approach allows ransomware operators to conceal malicious actions and access powerful Windows APIs unchecked. While initial analysis points to a low detection rate and proof-of-concept status, the technique underscores an escalating trend in ransomware sophistication and anti-forensic tactics. This incident is especially relevant as ransomware variants increasingly adopt anti-debugging and anti-EDR methods. The widespread use of DLL unhooking signals a maturing threat landscape, where attackers are continuously innovating to defeat security controls and leverage memory-based evasion techniques.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
npm’s Largest Supply Chain Compromise: Phishing and the Fragility of Open Source Security
Impact· medium

npm’s Largest Supply Chain Compromise: Phishing and the Fragility of Open Source Security

In June 2024, a major npm supply chain compromise saw attackers inject malicious code into 18 highly popular JavaScript packages, including chalk and debug, which together accounted for over 2.6 billion weekly downloads. The breach began with a successful phishing attack targeting a package maintainer, resulting in the theft of two-factor authentication credentials. Threat actors quickly published backdoored versions of affected packages, which were downloaded millions of times in minutes before rapid detection and disclosure limited the fallout. The immediate financial losses were low, with only minimal amounts of cryptocurrency stolen, but the operational impact included widespread remediation efforts across thousands of organizations dependent on these open-source assets. This incident exemplifies the growing risk and frequency of supply chain attacks leveraging compromised maintainers and rapid malware propagation in software registries. It highlights the urgent need for enhanced account security, ecosystem-level safeguards, and improved transparency, as such compromises are increasingly targeted by sophisticated actors and threaten the core trust mechanisms of modern digital infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
npm Supply-Chain Attack Exposes Open-Source Dependencies: 2024 Incident Analysis
Impact· high

npm Supply-Chain Attack Exposes Open-Source Dependencies: 2024 Incident Analysis

In June 2024, a supply-chain attack struck the widely used npm ecosystem when a threat actor compromised developer Josh Junon's account via a phishing-enabled two-factor reset. The attacker injected malicious code into 18 high-download open-source JavaScript packages, including 'ansi-styles', 'chalk', and 'debug', targeting cryptocurrency transactions. Although the incident caused significant alarm due to the downloads’ reach (>2 billion/week), rapid detection by the open-source community and immediate takedown by npm limited the impact. The injected packages were removed within hours, and the attacker ultimately stole just over $1,000 in cryptocurrency. This incident highlights the growing sophistication of supply-chain and social engineering attacks on open-source platforms. As attackers target developer credentials and critical project maintainers, organizations face renewed urgency to reassess their software supply chain controls and dependency management.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
KazMunayGas Penetration Test Mistaken for Russian Cyberattack: Lessons From a Simulated Incident
Impact· low

KazMunayGas Penetration Test Mistaken for Russian Cyberattack: Lessons From a Simulated Incident

In early 2024, Kazakhstan's largest oil company, KazMunayGas, was mistakenly believed to have suffered a cyberattack attributed to a Russian Advanced Persistent Threat (APT) group using a compromised employee email account. Initial reports claimed that attackers breached internal systems, raising alarm over possible business disruption and data compromise. However, after internal review, the company clarified the activity was actually part of an authorized penetration testing exercise, not a malicious breach, and no operational impact or data loss occurred. This incident comes amid heightened concern about cyberthreats targeting energy companies, particularly in regions where geopolitical tensions and state-sponsored actors are active. It demonstrates the confusion that can arise when security drills mimic genuine adversary tactics, highlighting the necessity for robust communication around cybersecurity validation activities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Global NPM Phishing Breach Exposes Billions to Supply Chain Malware
Impact· high

Global NPM Phishing Breach Exposes Billions to Supply Chain Malware

In September 2023, threat actors compromised the NPM account of Qix, a well-known developer, through a phishing attack and used the access to publish malicious updates to 18 highly popular open-source packages. These tainted packages, which collectively garnered over 2 billion weekly downloads, included 'ansi-styles', 'debug', 'chalk', and 'supports-color'. The inserted malware aimed to steal cryptocurrency by tampering with API calls and redirecting wallet transactions. The attack window was brief—about two hours—before the breach was discovered, the malicious versions withdrawn, and further spread prevented. While technical fallout was limited and the attackers profited minimally, the incident exposed significant vulnerabilities in the open-source software ecosystem and generated substantial remediation efforts globally. This episode highlights urgent risks inherent in software supply chains and the dependency of modern development on a small number of package maintainers. Public attention to supply chain defense, rapid incident response, and robust dependency vetting is rising as organizations face the reality of widespread reliance on community-maintained resources.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Jaguar Land Rover Ransomware Breach Disrupts Global Operations in 2024
Impact· high

Jaguar Land Rover Ransomware Breach Disrupts Global Operations in 2024

In June 2024, Jaguar Land Rover (JLR), the renowned luxury automotive manufacturer, experienced a major ransomware-related cyber incident that forced the company to shut down vital portions of its IT infrastructure. The disruption, which began on a Sunday and quickly affected production and retail activities globally, resulted in assembly line stoppages at key UK plants including Halewood and Solihull. JLR responded by disabling systems to prevent further attacker movement and data loss, launching an internal investigation with forensics partners to determine entry vectors, potential data exposure, and persistent threats. While the company stated there was no evidence of customer data being compromised, the operational and financial impacts were significant. This incident underscores the ongoing trend of ransomware actors targeting critical manufacturing and supply chain operations, where downtime can rapidly translate into massive losses. The event serves as a stark reminder that even mature organizations face evolving threats that can bypass traditional security controls, highlighting the urgent need for zero trust segmentation, enhanced network monitoring, and rapid anomaly detection.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports