Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
PhantomRaven: The AI-Generated Malware Infiltrating Developer Ecosystems
A financially motivated threat actor has been distributing PhantomRaven, a JavaScript-based information stealer, through malicious npm packages since November 2022. The attacker used slopsquatting and typosquatting techniques to upload over 100 malicious packages to the npm registry, targeting developers' authentication tokens, CI/CD secrets, and GitHub credentials. CrowdStrike analysis indicates the malware was likely generated using large language models, evidenced by verbose comments and placeholder code patterns. The threat actor claims to be a bug bounty hunter and uses stolen credentials to identify vulnerabilities for legitimate disclosure programs rather than selling data on criminal marketplaces. This incident highlights the growing trend of threat actors leveraging AI tools to accelerate malware development and the increasing sophistication of supply chain attacks targeting developer ecosystems. The use of remote dynamic dependencies to evade security detection represents an evolution in package-based attack methodologies.
2 days ago
Kill Chain
Critical Cisco ISE Zero-Day Highlights Identity Infrastructure Attack Trends
In September 2026, Cisco disclosed CVE-2026-76460, a maximum-severity authentication bypass vulnerability in Identity Services Engine (ISE) and ISE Passive Identity Connector being actively exploited by threat actors. The flaw allows remote attackers to bypass authentication on API endpoints through crafted requests, gaining unauthorized access to affected devices without any configuration requirements. Cisco's PSIRT confirmed active exploitation in the wild, prompting CISA to add the vulnerability to its Known Exploited Vulnerabilities catalog with a mandatory three-day patching deadline for federal agencies. This incident highlights the escalating targeting of identity and access management infrastructure, as threat actors increasingly focus on bypassing authentication controls to establish persistent network access and facilitate lateral movement in Zero Trust environments.
3 days ago
Kill Chain
FamousSparrow's SparroWocky Backdoor Targets Latin American Governments
The China-linked espionage group FamousSparrow has been conducting a sustained campaign against government organizations across Latin America using their new SparroWocky backdoor malware. From mid-2025 through 2026, the group targeted organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, replacing their previous SparrowDoor backdoor with this more advanced C++ malware. SparroWocky features sophisticated anti-analysis capabilities, modular architecture, and comprehensive data collection functions including screenshot capture, file manipulation, and proxy operations. The attacks aimed to gather intelligence on Latin American governments' responses to increasing U.S. pressure on Chinese economic interests, demonstrating China's strategic focus on regional geopolitical intelligence gathering. This campaign highlights the evolution of Chinese state-sponsored cyber espionage capabilities and their expanding focus on Latin American targets amid growing geopolitical tensions. The sophisticated evasion techniques and sustained operations demonstrate the increasing threat posed by well-resourced nation-state actors to regional government infrastructure and diplomatic communications.
3 days ago
Kill Chain
RatHat Malware: The Dawn of AI-Powered Android Banking Trojans
RatHat is a sophisticated Android banking trojan discovered in September 2026 that represents a significant evolution in mobile malware capabilities. Developed by Chinese threat actors, the malware combines traditional Android Remote Access Trojan (RAT) functionality with artificial intelligence-powered interface automation. RatHat spreads through malvertising campaigns, SMS phishing, and fraudulent APK downloads outside Google Play Store. The malware exploits Android's Accessibility permissions to enable Developer Options and Wireless Debugging, establishing persistent shell-level access through dual Go-based agents that provide mutual restoration capabilities. What makes RatHat particularly dangerous is its AI-powered navigation system that serializes Android's Accessibility tree into XML and leverages external AI assistants to intelligently navigate device interfaces, making remote control operations more adaptive than traditional script-based automation. The malware targets banking and cryptocurrency applications with HTML overlays, intercepts SMS messages and notifications for OTP theft, and employs sophisticated anti-removal mechanisms including fake Google Play error messages. This incident highlights the emerging convergence of AI technology with cybercriminal operations, representing a new paradigm where malware can adapt and respond to user interface changes in real-time without requiring constant operator intervention or frequent code updates.
3 days ago
Kill Chain
Critical Cisco ISE Zero-Day Exploited in Wild: CVE-2026-76460 Authentication Bypass
In September 2026, Cisco disclosed CVE-2026-76460, a maximum-severity zero-day vulnerability (CVSS 10.0) affecting Identity Services Engine (ISE) and ISE Passive Identity Connector. The flaw allows unauthenticated remote attackers to bypass authentication through insufficient controls on an API endpoint, granting unauthorized access to the web-based management interface and potentially root-level command execution. Cisco confirmed active exploitation in the wild, prompting CISA to add the vulnerability to its Known Exploited Vulnerabilities catalog with a mandatory patching deadline of September 19, 2026, for federal agencies. This incident highlights the escalating threat landscape targeting critical network infrastructure components, particularly identity and access management systems that serve as foundational security controls for enterprise zero trust architectures.
3 days ago
Kill Chain
NightmareStresser Takedown: How US Authorities Disrupted a Massive DDoS Empire
In September 2026, the U.S. Department of Justice seized two domains associated with NightmareStresser, a distributed denial-of-service (DDoS)-for-hire service that facilitated hundreds of thousands of attacks since 2022. The platform operated with over 566,000 registered users across 52 servers, targeting educational institutions, government agencies, gaming platforms, and millions of individuals worldwide. The service offered advanced Layer 4 and Layer 7 attack capabilities, cryptocurrency payment options, and claimed 24/7 availability over eight years of operation. This seizure represents a critical escalation in the ongoing battle against cybercrime-as-a-service platforms, highlighting the urgent need for organizations to implement comprehensive DDoS protection and network security measures as these attacks continue to evolve in sophistication and scale.
3 days ago
Kill Chain
Chinese APT FamousSparrow Targets Latin America with Advanced SparroWocky Backdoor
In August 2025, the China-aligned state-sponsored threat actor FamousSparrow began deploying a new backdoor called SparroWocky across multiple Latin American countries including Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The modular C++ backdoor replaced their previous SparrowDoor implant and targeted governmental entities through DLL sideloading techniques. SparroWocky features advanced capabilities including file execution, TCP proxy functionality, command execution, data exfiltration, screenshot capture, and self-deletion mechanisms while leveraging open-source tools like Mbed TLS for secure C2 communications. This campaign represents the evolving sophistication of Chinese APT groups who are increasingly integrating open-source offensive tools directly into custom malware rather than using them as separate utilities. The geographic focus on Latin America suggests either a formal mandate or opportunistic targeting based on current geopolitical circumstances, highlighting the global reach of state-sponsored cyber espionage operations.
3 days ago
Kill Chain
Critical Unbound DNS Vulnerability Exposes Organizations to Remote Code Execution
A critical heap overflow vulnerability (CVE-2026-81642) was discovered in the Unbound DNS resolver's DNSSEC validator, affecting all versions before 1.26.1. The flaw allows remote code execution when an attacker controls a malicious DNS zone and queries a vulnerable resolver. NLnet Labs released Unbound 1.26.1 on September 17, 2026, patching this critical vulnerability along with eight other security flaws. The vulnerability has a CVSS score of 9.1 and requires no user interaction or privileges to exploit. This incident highlights the growing sophistication of DNS-based attacks and the critical importance of maintaining up-to-date DNS infrastructure components. With DNS being foundational to internet operations, vulnerabilities in widely-deployed resolvers like Unbound pose significant risks to organizational security postures and can serve as initial compromise vectors for advanced persistent threats.
3 days ago
Kill Chain
Critical ScreenConnect Vulnerability CVE-2026-84869 Under Active Attack
In September 2026, CISA added ConnectWise ScreenConnect vulnerability CVE-2026-84869 to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The critical-severity flaw allows attackers with basic privileges to transfer and execute files through active remote sessions without authorization or host confirmation. The vulnerability affects ScreenConnect clients and enables low-complexity attacks requiring no user interaction, prompting CISA to order federal agencies to patch within three days. Over 1,000 vulnerable ScreenConnect instances remain exposed online according to Shadowserver tracking. This incident highlights the ongoing targeting of remote access tools by both ransomware groups and state-sponsored actors, with ScreenConnect facing its fourth CISA-flagged vulnerability since 2024. The exploitation underscores the critical security risks posed by widely-deployed MSP platforms that provide privileged access to thousands of customer environments.
4 days ago
Kill Chain
KREMLIN Banking Malware Exposes Critical Browser Security Gaps
The KREMLIN banking malware operation, active since mid-2025, has been deploying sophisticated techniques to bypass browser security mechanisms and forcibly install malicious Chrome and Edge extensions. The Brazilian-based threat actors use JavaScript files disguised as legitimate business documents to initiate infections, which then utilize Node.js persistence, Ethereum smart contracts for C2 communication, and advanced browser manipulation techniques. The malicious extensions, masquerading as AVSync, steal credentials, session tokens, and sensitive data while bypassing Chromium's integrity checks through cryptographic key manipulation. Elastic Security Labs confirmed 1,515 infected systems, primarily in Brazil, with the operation generating approximately $20,800 in cryptocurrency transactions. This campaign represents a significant evolution in banking malware tactics, demonstrating how threat actors are adapting to modern browser security controls while maintaining stealth and persistence across enterprise environments.
4 days ago
Kill Chain
Tajin Group Exposed: Inside China's Sophisticated Guarantee Marketplace Cybercrime Network
Tajin Group, a Chinese-speaking cybercriminal organization, operates as a third-party vendor on Telegram-based guarantee marketplaces, conducting extensive phishing campaigns, payment card theft, and money laundering operations. The group has demonstrated sophisticated financial crime capabilities by testing payment cards from twelve countries on platforms like CCAvenue and Geidea, while maintaining operations across multiple guarantee marketplaces including Dabai and Xinbi. Their activities target Chinese citizens and banks, with the group depositing over 208,000 USDT as operational stakes, indicating large-scale criminal enterprise operations that pose significant risks to global financial institutions and payment processors. This incident highlights the evolving sophistication of Chinese-language cybercriminal ecosystems and their increasing use of guarantee marketplaces as force multipliers for coordinated financial crimes. The emergence of these organized criminal networks represents a growing threat to international banking systems and demonstrates the need for enhanced cross-border cybersecurity cooperation and financial transaction monitoring.
5 days ago
Kill Chain
CISA Elevates Cisco Email Gateway SQL Injection to Critical Threat Status
CISA has added CVE-2026-76461, a critical SQL injection vulnerability in Cisco Secure Email Gateway, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. This vulnerability allows attackers to execute arbitrary SQL commands, potentially leading to unauthorized data access, system compromise, and lateral movement within enterprise networks. The addition to the KEV Catalog under Binding Operational Directive (BOD) 26-04 requires federal agencies to prioritize rapid remediation of this high-risk vulnerability on publicly exposed assets. This incident highlights the continued targeting of email security infrastructure by threat actors seeking initial access to enterprise environments. As organizations increasingly rely on cloud-based email security solutions, vulnerabilities in these critical gateway systems present attractive attack vectors for data exfiltration and ransomware deployment campaigns.
5 days ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports