The Containment Era is here. →Explore

Industry Category

Computer/Network Security

Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.

850 threat reports
Page 8 of 71

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer/Network Security Threat Reports

Showing 8596 / 850 reports
Pegasus Spyware Targets PEGA Committee Member Amid Investigations
Impact· HIGH

Pegasus Spyware Targets PEGA Committee Member Amid Investigations

In 2022 and 2023, the European Parliament's PEGA Committee, established to investigate the misuse of surveillance spyware like NSO Group's Pegasus, faced an ironic security breach. Greek journalist and substitute committee member Stelios Kouloglou's phone was infected with Pegasus spyware twice: first around October 2022 and again in March 2023. These infections coincided with critical phases of the committee's work, including the drafting of its final report. The infections were confirmed by the University of Toronto's Citizen Lab, highlighting the persistent threat posed by sophisticated spyware even to those tasked with investigating its misuse. This incident underscores the ongoing challenges in protecting sensitive information from advanced surveillance tools. It also emphasizes the need for robust cybersecurity measures within governmental bodies and the urgency of implementing the PEGA Committee's recommendations to prevent future abuses of spyware technologies.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Opera's 'Paste Protect' Feature: A New Defense Against 'ClickFix' Attacks
Impact· MEDIUM

Opera's 'Paste Protect' Feature: A New Defense Against 'ClickFix' Attacks

In July 2026, Opera introduced 'Paste Protect,' a security feature designed to combat 'ClickFix' attacks—a social engineering technique where users are deceived into copying and executing malicious commands via their system's command-line interface. These attacks often masquerade as legitimate verification processes or problem-solving instructions, leading to the execution of harmful commands with the user's privileges, potentially resulting in malware installation or data theft. 'Paste Protect' proactively scans clipboard content for patterns associated with malicious scripts across Windows, macOS, and Linux platforms. Upon detecting suspicious content, it blocks the copy operation, alerts the user with a warning, and displays a red security indicator in the browser's address bar. This feature aims to prevent users from inadvertently executing harmful commands, thereby enhancing overall system security. The introduction of 'Paste Protect' underscores the growing prevalence of 'ClickFix' attacks and the necessity for proactive security measures. As threat actors increasingly exploit human behavior through sophisticated social engineering tactics, it becomes imperative for both software developers and users to adopt and maintain robust security practices to mitigate such evolving threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Google's 2026 Takedown of NetNut Residential Proxy Network
Impact· MEDIUM

Google's 2026 Takedown of NetNut Residential Proxy Network

In July 2026, Google, in collaboration with the FBI and Lumen, significantly disrupted the NetNut residential proxy network, also known as Popa. This network, comprising at least 2 million home devices worldwide, was exploited by cybercriminals and espionage groups to mask malicious activities and conduct password-guessing attacks. Google's actions included disabling accounts and services associated with NetNut's command-and-control operations, leading to a substantial reduction in the network's operational capacity. ([thehackernews.com](https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html?utm_source=openai)) The takedown of NetNut underscores the growing threat posed by residential proxy networks, which can be co-opted by malicious actors to obscure their activities. This incident highlights the critical need for enhanced security measures and vigilance among consumers and organizations to prevent their devices from being exploited in such networks.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
ChocoPoC RAT: A New Threat Targeting Vulnerability Researchers
Impact· HIGH

ChocoPoC RAT: A New Threat Targeting Vulnerability Researchers

In July 2026, cybersecurity researchers uncovered a campaign distributing a Python-based remote access trojan (RAT) named ChocoPoC. Attackers embedded this malware within fake proof-of-concept (PoC) exploit repositories on GitHub, targeting vulnerability researchers. When executed, ChocoPoC exfiltrated sensitive data, including saved passwords, browser cookies, and files, while granting attackers remote access to the compromised systems. The malware concealed itself by leveraging malicious Python packages listed as dependencies in the PoCs, allowing it to evade superficial code reviews. ([thehackernews.com](https://thehackernews.com/2026/07/new-chocopoc-rat-targets-vulnerability.html?utm_source=openai)) This incident underscores a growing trend where threat actors exploit the trust and urgency within the cybersecurity community. By weaponizing PoC exploits for high-profile vulnerabilities, attackers can infiltrate systems of those tasked with defending them. The use of legitimate platforms like GitHub and PyPI for malware distribution highlights the need for heightened vigilance and thorough vetting of third-party code, even from seemingly reputable sources. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits/?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
FortiBleed Credential Theft: A Gateway to Ransomware Attacks
Impact· CRITICAL

FortiBleed Credential Theft: A Gateway to Ransomware Attacks

In early 2026, the FortiBleed campaign emerged as a large-scale credential-harvesting operation targeting over 430,000 FortiGate firewalls across more than 150 countries. Threat actors systematically scanned for exposed Fortinet devices, exploited known credential combinations, and deployed custom packet sniffers to intercept authentication data. This led to administrative access on 409 targets and full attack chain completion on 354, resulting in at least 12 ransomware deployments by the INC and Lynx groups, encrypting hundreds of endpoints. ([thehackernews.com](https://thehackernews.com/2026/07/fortibleed-credential-theft-linked-to.html?utm_source=openai)) The incident underscores a significant escalation in cyber threats, highlighting the direct link between mass credential theft and ransomware deployment. Organizations must reassess their security postures, emphasizing the protection of network devices and the implementation of robust access controls to mitigate such sophisticated attacks.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
DHS HSIN Breach 2026: Cyberattack on Information-Sharing Platform
Impact· MEDIUM

DHS HSIN Breach 2026: Cyberattack on Information-Sharing Platform

In late May to early June 2026, the Department of Homeland Security (DHS) experienced a cyberattack on the Homeland Security Information Network (HSIN), a platform for sharing sensitive but unclassified information among federal, state, local, and private-sector partners. An unknown threat actor accessed HSIN servers and a SharePoint system used for collaboration. DHS is investigating the breach to determine the extent of the intrusion and whether any documents were stolen. The department has not attributed the attack to any specific threat actor or foreign government. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform/amp/?utm_source=openai)) This incident underscores the persistent threats to government information-sharing platforms and highlights the need for robust cybersecurity measures. As the United States oversees security for major events like the World Cup, ensuring the integrity of such systems is paramount to national security. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform/amp/?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
FortiBleed Credential Theft Campaign Exposes Over 73,000 Fortinet Devices
Impact· CRITICAL

FortiBleed Credential Theft Campaign Exposes Over 73,000 Fortinet Devices

In July 2026, the 'FortiBleed' campaign was uncovered, revealing a massive credential theft operation targeting over 73,000 Fortinet devices. Attackers utilized a custom tool named 'FortiGate Sniffer' to intercept VPN credentials directly from network traffic. Subsequent investigations linked this operation to the INC and Lynx ransomware groups, indicating that the stolen credentials were intended to facilitate future network intrusions. This incident underscores the evolving tactics of ransomware groups, highlighting their focus on exploiting network infrastructure vulnerabilities to gain unauthorized access. Organizations must prioritize securing their network devices and monitoring for unusual activities to mitigate such threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
ChocoPoC Malware: A New Threat Targeting Cybersecurity Researchers
Impact· CRITICAL

ChocoPoC Malware: A New Threat Targeting Cybersecurity Researchers

In July 2026, cybersecurity researchers identified a campaign distributing a Python-based remote access trojan (RAT) named ChocoPoC through trojanized proof-of-concept (PoC) exploits on GitHub. Unlike previous incidents where malware was embedded directly in exploit files, this campaign introduced malicious Python packages into the PoC's dependency list. When victims cloned these repositories, a trojanized package named 'frint' was automatically installed, which subsequently fetched another malicious package, 'skytext.' This package contained a compiled Python extension that decrypted and executed additional code, ultimately downloading the ChocoPoC RAT from a Mapbox dataset. The RAT possessed capabilities such as executing arbitrary commands, uploading files, and collecting sensitive data, including browser credentials and network configurations. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits/?utm_source=openai)) This incident underscores a growing trend where threat actors exploit trusted platforms like GitHub to distribute malware, targeting professionals who frequently utilize PoC exploits for research and testing. The sophisticated method of embedding malicious code within dependency packages highlights the need for heightened vigilance when sourcing code from public repositories. As attackers continue to refine their techniques, the cybersecurity community must adapt by implementing stricter code verification processes and promoting awareness about the risks associated with unverified code. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits/?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Iran-Nexus TAG-182 Deploys MarkiRAT Malware in Surveillance Campaign
Impact· HIGH

Iran-Nexus TAG-182 Deploys MarkiRAT Malware in Surveillance Campaign

In early 2026, the Iranian-linked threat group TAG-182 initiated a cyber espionage campaign deploying MarkiRAT malware via counterfeit Android applications, including fake VPNs and media tools, to surveil Iranian citizens domestically and abroad. This operation aligns with Iran's intensified digital surveillance efforts following the partial restoration of internet access on May 26, 2026, targeting perceived dissidents and foreign collaborators. The MarkiRAT samples exhibit tradecraft overlaps with previous variants used by Ferocious Kitten, suggesting a potential operational connection, though further evidence is required to confirm organizational links. ([staging.hawk-eye.io](https://staging.hawk-eye.io/iran-apt-threat-advisory/?utm_source=openai)) The resurgence of TAG-182's activities underscores the persistent threat posed by Iranian state-sponsored cyber operations, particularly in the realm of surveillance and intelligence gathering. Organizations and individuals, especially those involved in human rights advocacy or opposition activities, should remain vigilant against sophisticated social engineering tactics and ensure robust cybersecurity measures are in place to mitigate the risks associated with such targeted campaigns.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Securing AI Endpoints: Lessons from Recent Exploits
Impact· CRITICAL

Securing AI Endpoints: Lessons from Recent Exploits

Between March and May 2026, Zenity researchers identified three distinct campaigns where threat actors exploited exposed AI inference endpoints, such as those of Ollama and LiteLLM, to conduct offensive operations. These attacks did not require full system compromises; attackers merely needed knowledge of the exposed endpoints to leverage them for activities like autonomous penetration testing and web reverse-engineering. The incidents underscore the critical need for securing AI infrastructure against unauthorized access. This trend highlights a growing tactic among cyber adversaries: exploiting misconfigured or exposed AI endpoints to amplify their offensive capabilities. As organizations increasingly integrate AI into their operations, ensuring the security of these systems becomes paramount to prevent their misuse in cyberattacks.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
BioShocking Attack: A New Threat to AI Browser Security
Impact· MEDIUM

BioShocking Attack: A New Threat to AI Browser Security

In June 2026, researchers at LayerX identified a novel prompt injection attack named 'BioShocking' targeting AI-powered browsers. The attack involves a malicious webpage presenting a BioShock-themed puzzle game that rewards incorrect answers, conditioning the browser's control agent to disregard standard safety protocols. In the final stage, the agent is directed to access a GitHub repository and extract sensitive data, such as passwords. This proof-of-concept was tested against six mainstream agentic browsers, with only OpenAI's ChatGPT Atlas implementing an effective fix after disclosure. The BioShocking attack underscores the critical need for robust security measures in AI-driven applications. As AI agents become more integrated into daily tasks, their susceptibility to manipulation poses significant risks. This incident highlights the urgency for developers to implement explicit user confirmations for sensitive actions, enhance context checks, and establish strict boundaries for agentic sessions to prevent similar exploits.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
RustDuck Botnet's Evolution: A New Era of DDoS Threats
Impact· CRITICAL

RustDuck Botnet's Evolution: A New Era of DDoS Threats

Since February 2026, the RustDuck botnet has been actively compromising home routers, IP cameras, Android devices, and poorly secured servers to orchestrate large-scale Distributed Denial-of-Service (DDoS) attacks. Researchers at QiAnXin's XLab have observed its rapid evolution, notably transitioning its core codebase from C to Rust, enhancing its adaptability and resistance to analysis. The malware propagates through weak password brute-forcing on Telnet/SSH services and exploits various remote code execution vulnerabilities in devices from manufacturers like TVT, Ruijie, TP-Link, and ZTE, as well as web applications such as ThinkPHP, Jenkins, and Hadoop YARN. ([thehackernews.com](https://thehackernews.com/2026/06/rustduck-botnet-rebuilds-in-rust-to.html?utm_source=openai)) The emergence of RustDuck underscores a concerning trend in botnet development, where threat actors adopt modern programming languages like Rust to create more resilient and evasive malware. This shift complicates detection and mitigation efforts, highlighting the need for continuous adaptation in cybersecurity defenses. ([thehackernews.com](https://thehackernews.com/2026/06/rustduck-botnet-rebuilds-in-rust-to.html?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports