Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
GoSerpent Malware: A Persistent Threat to Southeast Asian Governments
In late 2025, cybersecurity researchers identified a new malware strain named GoSerpent, actively targeting government and diplomatic entities in Southeast Asia. Discovered by Kaspersky in February 2026, GoSerpent is designed to establish long-term access for intelligence gathering by connecting to external servers and deploying secondary payloads for data collection and credential dumping. The malware's capabilities include setting up SOCKS5 proxy servers, enabling attackers to route traffic through compromised hosts and mask their true IP addresses. Additional tools such as ThumbcacheService for file collection and Mimikatz for credential extraction have been employed to facilitate data exfiltration through network shared drives. ([thehackernews.com](https://thehackernews.com/2026/07/new-goserpent-malware-targets-southeast.html?utm_source=openai)) The resurgence of GoSerpent in May 2026, with evolved tools like the Stowaway RAT and enhanced data exfiltration methods, underscores the persistent and adaptive nature of cyber threats targeting sensitive government information. This incident highlights the critical need for robust cybersecurity measures and continuous monitoring to detect and mitigate sophisticated espionage campaigns. ([thehackernews.com](https://thehackernews.com/2026/07/new-goserpent-malware-targets-southeast.html?utm_source=openai))
2 months ago
Kill Chain
Armenia Detains Russian Tourist Mistaken for REvil Hacker
In June 2026, Armenian authorities detained Russian tourist Aleksandr Yuryevich Ermakov at Yerevan's Zvartnots airport, acting on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Gennadievich Ermakov. The U.S. alleges that the wanted individual participated in Sodinokibi/REvil attacks from April 2019 to July 2021, affecting over 1,000 victims, including entities in the Northern District of Texas. However, the detained man's lawyers assert that he is not the individual sought by the U.S., highlighting discrepancies in personal details and emphasizing that the actual suspect is serving a sentence in Russia, restricting his travel. This incident underscores the complexities and potential misidentifications in international cybercrime enforcement efforts, especially when dealing with common names and limited identifying information. It also highlights the ongoing global pursuit of REvil affiliates, reflecting the persistent threat posed by ransomware groups and the challenges in dismantling their networks.
2 months ago
Kill Chain
OkoBot Malware: A New Threat to Cryptocurrency Security
In July 2026, cybersecurity researchers identified OkoBot, a sophisticated malware framework comprising over 20 modules designed to steal cryptocurrency wallet seed phrases, credentials, and other sensitive data. OkoBot infiltrates systems through deceptive ClickFix attacks and malicious GitHub repositories masquerading as legitimate software tools. Once installed, it deploys various payloads, including browser injectors and keyloggers, to harvest user information and monitor activities. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-okobot-framework-deploys-20-payloads-to-steal-data-crypto/?utm_source=openai)) The emergence of OkoBot underscores a growing trend of targeted attacks on cryptocurrency users, highlighting the need for enhanced vigilance and robust security measures within the crypto community. As the malware continues to evolve, staying informed about such threats is crucial for safeguarding digital assets.
2 months ago
Kill Chain
ClickLock: The New macOS Malware Exploiting User Trust
In July 2026, cybersecurity researchers identified a new macOS malware named ClickLock, which employs social engineering tactics to deceive users into revealing their system login passwords. The malware initiates by presenting a fake Cloudflare 'human verification' prompt, leading users to execute a command in the Terminal. This action triggers the download of malicious modules that disable keyboard interrupts and suppress system notifications. Subsequently, ClickLock displays a counterfeit macOS password dialog, coercing users into entering their credentials. Upon obtaining the password, the malware exfiltrates sensitive data, including login credentials, cryptocurrency assets, and browser information, to the attackers via Telegram. Additionally, it installs a persistent backdoor, granting ongoing remote access to the compromised systems. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-clicklock-macos-malware-traps-users-into-revealing-login-password/?utm_source=openai)) The emergence of ClickLock underscores a growing trend in macOS-targeted malware leveraging sophisticated social engineering techniques. This incident highlights the necessity for heightened user awareness and the implementation of robust security measures to counteract such deceptive attacks.
2 months ago
Kill Chain
GoSerpent Backdoor: A Persistent Threat to Southeast Asian Governments
The GoSerpent campaign is a sophisticated, multi-stage attack targeting government and diplomatic entities in Southeast Asia since at least 2021, with evolved variants deployed through 2026. The Go-based GoSerpent backdoor establishes persistent access and deploys ThumbcacheService for document collection, Mimikatz and QuarksDumpLocalHash for credential dumping, and later stages use Stowaway RAT and TmcLoader/TmcPayload to exfiltrate collected data via network shares using stolen credentials. The tight integration between collection, credential theft, and exfiltration components demonstrates advanced operational planning and long-term intelligence gathering objectives.
2 months ago
Kill Chain
Iran's AI-Enhanced Asymmetric Warfare in 2026
Between January and June 2026, Iran leveraged artificial intelligence (AI) to enhance its longstanding hybrid warfare model, blending asymmetric military operations, cyber operations, information warfare, proxy attacks, and coercive state control. AI acted as a force multiplier, increasing the speed, scale, and effectiveness of Iranian operations. This strategic use of AI enabled Iran to compensate for conventional military and economic disadvantages, improving its cyber capabilities, accelerating propaganda production, and expanding the reach of information campaigns. ([intelligentciso.com](https://www.intelligentciso.com/2026/07/16/recorded-future-examines-irans-growing-use-of-ai-in-cyber-operations/?utm_source=openai)) The integration of AI into Iran's asymmetric tactics underscores the evolving nature of cyber threats, highlighting the need for organizations to bolster defenses against AI-enhanced operations. This development reflects a broader trend of state actors utilizing AI to amplify their cyber and information warfare capabilities, posing elevated risks to critical infrastructure and vital industries. ([intelligentciso.com](https://www.intelligentciso.com/2026/07/16/recorded-future-examines-irans-growing-use-of-ai-in-cyber-operations/?utm_source=openai))
2 months ago
Kill Chain
OpenAI's GPT-Red: Revolutionizing AI Security with Automated Prompt Injection Testing
In July 2026, OpenAI unveiled GPT-Red, an internal AI model designed to autonomously identify and exploit prompt injection vulnerabilities within its own AI systems. This initiative aims to proactively detect and mitigate security flaws before deployment. GPT-Red demonstrated a remarkable success rate, identifying vulnerabilities in 84% of test scenarios, significantly outperforming human red-teamers who achieved a 13% success rate. The model employs self-play reinforcement learning, continuously refining its attack strategies to uncover weaknesses that might be overlooked by human testers. This proactive approach underscores OpenAI's commitment to enhancing the robustness and security of its AI models. The introduction of GPT-Red highlights the escalating sophistication of AI-driven security testing. As AI systems become more integrated into critical applications, the ability to autonomously identify and address vulnerabilities is crucial. This development also reflects a broader industry trend towards leveraging AI for cybersecurity, emphasizing the need for continuous innovation to stay ahead of emerging threats.
2 months ago
Kill Chain
Critical Unpatched Flaw in Shark Vacuums Highlights IoT Security Risks
In July 2026, a critical security vulnerability was discovered in Shark RV2320EDUS robot vacuums, allowing attackers to remotely execute commands on other Shark vacuums within the same AWS region. By extracting the device certificate from the vacuum's flash storage, an attacker could gain root access to other devices, enabling actions such as controlling the vacuum's movements, accessing onboard cameras, retrieving home maps, and obtaining Wi-Fi credentials in plaintext. The flaw was reported to SharkNinja in March 2026 but remained unpatched as of the disclosure. This incident underscores the escalating risks associated with IoT devices, particularly those with inadequate security configurations. The ability to exploit a single device to compromise an entire network of similar devices highlights the urgent need for robust security measures in IoT device design and deployment.
2 months ago
Kill Chain
Daxin and Stupig Malware Resurface in Taiwan Manufacturing Firm
In May 2026, Symantec's Threat Hunter Team identified the re-emergence of Backdoor.Daxin, a sophisticated kernel-mode rootkit previously linked to China-based threat actors, on a compromised host within a Taiwan-based subsidiary of a multinational high-tech manufacturer. Alongside Daxin, researchers discovered a novel backdoor named Stupig, which exploits a trojanized keyboard-layout DLL to execute commands with SYSTEM privileges directly from the Windows logon screen, bypassing standard authentication mechanisms. Both malware samples carry compile timestamps from early 2013, suggesting a prolonged undetected presence of up to 13 years within the victim's network. This incident underscores the persistent and evolving nature of cyber threats targeting critical infrastructure and high-tech industries. The discovery of Stupig's unique pre-authentication execution method highlights the need for continuous vigilance and advanced detection capabilities to identify and mitigate such stealthy intrusions.
2 months ago
Kill Chain
PhantomEnigma: Cyberattack Compromises Brazilian Government Websites
In July 2026, cybersecurity analysts uncovered a campaign named PhantomEnigma, which exploited over 20 Brazilian government websites to distribute malware targeting banking and public-sector organizations. Attackers compromised legitimate .gov.br domains and email accounts, enabling them to bypass security protocols and deliver malicious payloads through trusted channels. This operation utilized modular malware and frequently rotated infrastructure, complicating detection and mitigation efforts. The campaign's sophistication underscores the critical need for robust cybersecurity measures to protect sensitive government and financial data. The PhantomEnigma incident highlights a growing trend of cybercriminals leveraging trusted government infrastructure to conduct attacks, increasing the difficulty of detection and response. This case serves as a stark reminder for organizations to enhance their security postures, particularly in monitoring and securing official digital platforms against such sophisticated threats.
2 months ago
Kill Chain
Cato Networks' 2026 Research Highlights the Importance of AI Harnesses in Cybersecurity
In July 2026, Cato Networks conducted research demonstrating the significant impact of integrating Large Language Models (LLMs) with bespoke cybersecurity harnesses. By pairing OpenAI's ChatGPT 5.5 and GPT 5.5-Cyber models with their proprietary tool, Cato Networks achieved complete end-to-end attack chains, including domain administrator privileges and Active Directory access, in as little as 40 minutes. This research underscores the critical role of technical harnesses in guiding LLMs to perform complex cybersecurity tasks autonomously. The findings highlight the necessity for organizations to develop and implement tailored AI harnesses to effectively manage and direct LLMs in cybersecurity operations. As AI-enabled hacking becomes more prevalent, the ability to control and optimize these models through specialized harnesses is essential for maintaining robust security postures.
2 months ago
Kill Chain
AI Tools in Cyberattacks: The Misuse of Google's Gemini CLI
In mid-2026, a Russian-speaking threat actor known as "bandcampro" exploited Google's open-source Gemini CLI AI tool to orchestrate a small-scale botnet targeting a dental clinic's systems. Over approximately two months, the attacker utilized the AI agent to deploy and manage infrastructure controlling eight systems, gaining unauthorized access to the OpenDental database. The AI facilitated tasks such as troubleshooting, operational improvements, and command-and-control (C2) migration, demonstrating advanced capabilities in automating cyberattack processes. This incident underscores the evolving landscape of cyber threats, where adversaries increasingly leverage AI tools to enhance the efficiency and sophistication of their operations. The misuse of AI in cyberattacks highlights the urgent need for robust security measures and vigilant monitoring to detect and mitigate such advanced threats.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports