Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Trezor Data Breach 2026: Lessons in Supply Chain Security
In August 2026, Trezor, a leading cryptocurrency hardware wallet manufacturer, disclosed a data breach affecting nearly 14,000 customers. The breach occurred through their shipping and logistics provider, ShipMonk, whose systems were compromised via a vulnerability in the third-party analytics platform Metabase. This incident exposed customers' full names, shipping addresses, email addresses, and phone numbers. Trezor's internal systems and devices remained secure, but the exposed personal information heightened the risk of targeted phishing attacks against affected individuals. This breach underscores the critical importance of securing third-party service providers, as vulnerabilities in external platforms can directly impact primary organizations and their customers. The incident also highlights the evolving tactics of cybercriminals, who exploit supply chain weaknesses to access sensitive data, emphasizing the need for comprehensive security measures across all operational facets.
1 month ago
Kill Chain
City-Forum Campaign: A Wake-Up Call for SaaS Security
Since at least March 2025, an unidentified threat actor has been conducting a prolonged data theft campaign, dubbed "City-Forum," targeting organizations across various sectors by exploiting overly permissive guest access in Salesforce and ServiceNow platforms. The attacker developed custom tools to interact with less-documented interfaces, such as Salesforce's Lightning Web Runtime and ServiceNow's Service Portal search endpoint, enabling unauthorized access to sensitive data including customer information, support tickets, and internal communications. This incident underscores the evolving sophistication of cyber threats, highlighting the need for organizations to reassess and fortify their security configurations, especially concerning third-party integrations and guest access permissions. The campaign's duration and the attacker's ability to exploit undocumented interfaces emphasize the importance of continuous monitoring and proactive security measures.
1 month ago
Kill Chain
Critical Vulnerabilities in Belgium's eID System Expose Citizens to Remote Code Execution
In August 2026, severe vulnerabilities were discovered in Belgium's eID authentication system, specifically within the 'Connective' browser extension. These flaws allowed attackers to steal citizens' identities, payment information, and execute remote code on users' machines. The extension, used by over 2 million individuals, failed to verify the origin of activation tokens, enabling malicious websites to impersonate legitimate services and interact with users' eID systems. Additionally, the native host application could be exploited to load arbitrary DLL files, leading to remote code execution without user interaction. This incident underscores the critical need for rigorous security assessments of browser extensions, especially those integral to national identity and financial systems. It highlights the broader risks associated with browser extension vulnerabilities and the potential for widespread exploitation if not promptly addressed.
1 month ago
Kill Chain
Bleeding Llama: Critical Memory Leak in Ollama (CVE-2026-7482)
In May 2026, a critical vulnerability known as 'Bleeding Llama' (CVE-2026-7482) was disclosed in Ollama, a widely used framework for running large language models locally. This unauthenticated heap out-of-bounds read flaw allows remote attackers to exfiltrate sensitive data—including API keys, user conversations, and system prompts—from any internet-exposed Ollama server with minimal effort. The vulnerability affects versions up to 0.17.0, with an estimated 300,000 servers exposed at the time of disclosure. Ollama addressed the issue in version 0.17.1, but many instances remain unpatched, leaving organizations vulnerable to data breaches and unauthorized access. ([lyrie.ai](https://lyrie.ai/research/research/2026-05-08-bleeding-llama-ollama-cve-2026-7482?utm_source=openai)) The 'Bleeding Llama' incident underscores the critical importance of timely patch management and robust security practices in AI infrastructure. As AI models become integral to business operations, ensuring their security is paramount to prevent data leaks and maintain trust in AI-driven systems.
1 month ago
Kill Chain
Near-Autonomous AI Cyberattack on Taiwanese Government in 2026
In August 2026, a sophisticated cyberattack targeted the Taiwanese government, marking the first publicly known instance of a near-autonomous AI-driven breach against a state entity. Suspected Chinese hackers employed open-source AI frameworks, Hermes and OpenClaw, to orchestrate the attack, which led to the exfiltration of over 2,500 personnel records. The AI system autonomously adapted during the operation, conducting 'Learning Cycles' to identify vulnerabilities and expanding its reach to government IT supply chain vendors, a nuclear safety agency, and multiple energy sector companies. This incident underscores the escalating use of AI in cyber warfare, highlighting the need for enhanced defensive measures against autonomous threats. The attack's ability to self-correct and adapt without human intervention signifies a paradigm shift in cyberattack methodologies, necessitating a reevaluation of current cybersecurity strategies to address AI-driven threats.
1 month ago
Kill Chain
Unveiling 'ShieldBreak': A New Zero-Day Threat in Microsoft Defender
In August 2026, security researcher Nightmare Eclipse disclosed a zero-day vulnerability named 'ShieldBreak' in Microsoft Defender, allowing attackers to escalate privileges to SYSTEM level on fully patched Windows 10, Windows 11, and Windows Server systems. This exploit leverages a user-mode callback hook during a Defender cloud-hydration scan via the Cloud Filter API (cfapi), effectively bypassing the previous 'RoguePlanet' patch (CVE-2026-50656). The proof-of-concept demonstrated a 100% success rate on tested systems. This incident underscores the persistent challenges in securing endpoint protection platforms and highlights the need for continuous vigilance and rapid response to emerging threats. Organizations must reassess their security postures, especially concerning privilege escalation vulnerabilities, to mitigate potential risks associated with such exploits.
1 month ago
Kill Chain
Signal Introduces Automatic Key Verification to Strengthen Chat Security
In August 2026, Signal introduced Automatic Key Verification, a feature designed to enhance user security by automatically verifying the integrity of encrypted conversations. This system employs trusted third-party auditors to ensure that public encryption keys associated with user accounts remain consistent and unaltered, thereby mitigating the risk of man-in-the-middle attacks. Users can enable this feature through the app's privacy settings, providing a seamless method to confirm secure communications without manual safety number verification. The implementation of Automatic Key Verification addresses the growing concern over sophisticated interception techniques targeting encrypted messaging platforms. By automating the verification process, Signal aims to bolster user confidence and maintain the platform's reputation for robust security in an era where digital communication threats are increasingly prevalent.
1 month ago
Kill Chain
ShieldBreak Zero-Day PoC Exposes Microsoft Defender Patch Bypass
In August 2026, security researcher Chaotic Eclipse released a proof-of-concept (PoC) for a new Microsoft zero-day vulnerability named ShieldBreak. This vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656, also known as RoguePlanet. RoguePlanet is a race condition that, if exploited, allows an attacker to spawn a shell with SYSTEM-level privileges, enabling the execution of arbitrary code or unauthorized actions. Despite Microsoft's release of a patch in July 2026 to address RoguePlanet, the ShieldBreak PoC indicates that the patch is ineffective, as it can be fully bypassed, maintaining a 100% success rate in tests on Windows 11 25H2 and Windows Server 2025. The release of ShieldBreak underscores the persistent challenges in effectively patching critical vulnerabilities. It highlights the need for organizations to adopt comprehensive security measures beyond relying solely on vendor patches. This incident also emphasizes the importance of continuous monitoring and rapid response strategies to mitigate potential exploits that can arise even after patches are applied.
1 month ago
Kill Chain
Critical Vulnerability in Pulsetto Vagus Nerve Stimulator: CVE-2026-18844
In August 2026, a critical vulnerability (CVE-2026-18844) was identified in the Pulsetto Vagus Nerve Stimulator, a device widely used for non-invasive wellness applications. The flaw allows unauthenticated commands to be sent over its Bluetooth Low Energy (BLE) interface, enabling attackers to disable safety mechanisms or alter stimulation settings. Pulsetto has not responded to mitigation requests, leaving users exposed to potential exploitation. This incident underscores the growing security risks associated with IoT medical devices, emphasizing the need for robust security measures and prompt vendor responses to vulnerabilities to protect patient safety and device integrity.
1 month ago
Kill Chain
Context Bombing: Turning Prompt Injections into Defensive Weapons
In July 2026, cybersecurity researchers at Tracebit introduced a defensive technique called 'context bombing' to counteract AI-driven cyberattacks. This method involves embedding specific prompt injections within sensitive data stored on platforms like Amazon Web Services (AWS). When AI hacking agents encounter these prompts, they are directed to perform actions that violate their built-in safety protocols, leading to their immediate shutdown. This proactive approach effectively neutralizes potential threats before they can cause harm. ([arstechnica.com](https://arstechnica.com/security/2026/07/now-defenders-are-embracing-the-prompt-injection-too/?utm_source=openai)) The significance of this development lies in its innovative use of offensive tactics for defense. By leveraging prompt injections—a tool traditionally used by attackers—defenders can now preemptively disrupt AI-driven attacks. This strategy highlights a shift towards more adaptive and proactive cybersecurity measures in response to the evolving landscape of AI threats.
1 month ago
Kill Chain
Delta Airlines Flight 591 Wi-Fi Spoofing Incident: A Wake-Up Call for In-Flight Cybersecurity
In August 2026, during Delta Airlines flight 591 from Las Vegas to Atlanta, a passenger reportedly deployed a rogue Wi-Fi network named 'Delta WiFi Fast,' mimicking the airline's legitimate in-flight Wi-Fi. This 'evil twin' attack aimed to deceive passengers into connecting to the fraudulent network, potentially exposing their sensitive data. Upon detection, the flight crew promptly disabled the aircraft's Wi-Fi for approximately 30 minutes to mitigate the threat. The incident did not compromise flight safety or aircraft systems. Delta is collaborating with federal authorities, including the FBI and FAA, to thoroughly investigate the event. This incident underscores the growing cybersecurity risks associated with public Wi-Fi networks, especially in confined environments like aircraft cabins. The timing, coinciding with the conclusion of the DEF CON cybersecurity conference, highlights the need for heightened vigilance against sophisticated attacks targeting unsuspecting users in transit.
1 month ago
Kill Chain
Cisco ClamAV Vulnerabilities: Immediate Action Required
In August 2026, Cisco disclosed two high-severity vulnerabilities (CVE-2026-20337 and CVE-2026-20338) in ClamAV's ZIP archive parser, affecting versions 1.5.0 through 1.5.3. These flaws, due to improper boundary checks and memory handling, allow unauthenticated remote attackers to crash the ClamAV scanning process, leading to denial-of-service (DoS) conditions. Proof-of-concept exploit code is publicly available, though no active exploitation has been reported. The vulnerabilities are particularly critical on Windows platforms, where ClamAV operates with elevated privileges. The disclosure underscores the persistent risk of DoS attacks targeting antivirus solutions. Organizations relying on ClamAV should promptly update to version 1.5.4 to mitigate potential threats. This incident highlights the importance of timely patch management and the need for continuous monitoring of security advisories to protect against emerging vulnerabilities.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports