Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
TuxBot v3 Evolution: Unveiling the AI-Assisted IoT Botnet Threat
In early 2026, cybersecurity researchers uncovered TuxBot v3 Evolution, a sophisticated modular IoT botnet framework. This malware targets a wide range of IoT devices by exploiting known vulnerabilities and employing extensive Telnet brute-force attacks. Notably, the development of TuxBot v3 Evolution involved assistance from a large language model (LLM), resulting in both functional components and critical errors due to unreviewed AI-generated code. The botnet's capabilities include multi-architecture support, encrypted command-and-control communications, and a variety of fallback mechanisms, posing a significant threat to IoT security. The discovery of TuxBot v3 Evolution underscores the evolving landscape of cyber threats, where adversaries leverage AI technologies to enhance malware development. This trend highlights the urgent need for robust security measures and continuous monitoring to protect IoT ecosystems from increasingly sophisticated attacks.
2 months ago
Kill Chain
OkoBot Malware Exploits Ledger and Trezor Apps to Steal Seed Phrases
In April 2025, the OkoBot malware framework emerged, targeting Windows users by infiltrating legitimate cryptocurrency hardware wallet applications such as Trezor Suite and Ledger Live. The malware's 'SeedHunter' module monitors for the launch of these applications, injecting malicious code that prompts users to enter their recovery seed phrases. This deceptive tactic enables attackers to gain unauthorized access to victims' cryptocurrency assets. Kaspersky's GReAT team reported that OkoBot has affected hundreds of users across more than 25 countries, with significant concentrations in Brazil, Vietnam, Canada, Mexico, and Turkey. The malware remains active as of July 2026, continually evolving its methods to exploit hardware wallet users. The persistence and adaptability of OkoBot underscore a broader trend of increasingly sophisticated attacks targeting cryptocurrency holders. This incident highlights the critical need for users to remain vigilant against phishing attempts and to adhere strictly to security protocols, such as never entering recovery phrases into software interfaces. The ongoing evolution of such malware emphasizes the importance of continuous security education and the implementation of robust protective measures within the cryptocurrency community.
2 months ago
Kill Chain
ADPathFinder: Comprehensive Attack Path Mapping for Enhanced Security Assessments
ADPathFinder is a cybersecurity tool designed to enhance internal assessments by mapping privilege escalation paths across Active Directory (AD), Active Directory Certificate Services (ADCS), Microsoft SQL Server (MSSQL), and System Center Configuration Manager (SCCM) environments. By integrating data from SharpHound with OpenGraph collectors like MSSQLHound and ConfigManBearPig, ADPathFinder provides a unified view of attack paths, enabling security professionals to identify and address vulnerabilities more efficiently. Additionally, it offers password auditing capabilities, tying cracked NTDS/hashcat results back to group memberships and account risks, thereby providing a comprehensive security analysis. As organizations increasingly rely on complex and interconnected systems, tools like ADPathFinder become essential in proactively identifying and mitigating potential security threats. Its ability to consolidate data from multiple sources and present a cohesive analysis allows for more effective prioritization of remediation efforts, ensuring that critical vulnerabilities are addressed promptly.
2 months ago
Kill Chain
Unveiling TuxBot v3 Evolution: The AI-Assisted IoT Botnet Threat
In early 2026, security researchers identified TuxBot v3 Evolution, a sophisticated modular IoT botnet framework. This malware targets a wide range of IoT devices by exploiting known vulnerabilities and employing extensive Telnet brute-force attacks. Notably, the developers utilized large language models (LLMs) to assist in code development, resulting in a mix of functional and flawed components. The botnet's capabilities include cross-compilation for multiple architectures, encrypted command-and-control (C2) communications, and a DDoS-for-hire panel. Despite some non-functional features due to development oversights, the framework's modularity and adaptability pose a significant threat to IoT security. The emergence of TuxBot v3 Evolution underscores a concerning trend: the integration of AI tools in malware development, which can accelerate the creation of complex and adaptable threats. This incident highlights the urgent need for enhanced security measures in IoT devices and the importance of monitoring AI-assisted developments in the cyber threat landscape.
2 months ago
Kill Chain
U.S. Treasury Sanctions 1VPNS for Facilitating Ransomware Attacks
In July 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) sanctioned First VPN Service (1VPNS) and its administrator, Ukrainian national Dmytro Rashevskyi, for providing services to ransomware operators. 1VPNS, operational since 2014, advertised its refusal to cooperate with law enforcement and offered anonymity services that were exploited by cybercriminals to conceal attack origins, deploy malware, and manage exfiltrated data. Victims included U.S. businesses, financial services companies, hospitals, and municipal governments. Additionally, Belarusian national Yegeniy Vladimirovich Silayev was sanctioned for selling 'cryptors'—tools designed to disguise ransomware and other malware as harmless files—to ransomware operators. These actions underscore the critical role that infrastructure providers play in facilitating cybercriminal activities and the necessity of targeting such enablers to disrupt the ransomware ecosystem. The sanctions highlight the ongoing efforts by international law enforcement to dismantle networks that support ransomware operations, emphasizing the importance of vigilance and proactive measures in cybersecurity.
2 months ago
Kill Chain
US Sanctions 1VPNS and Affiliates for Enabling Ransomware Attacks
In July 2026, the U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian national Yegeniy Vladimirovich Silayev for facilitating ransomware attacks against U.S. organizations. 1VPNS provided anonymizing services to cybercriminals, while Silayev sold cryptors that helped malware evade detection. These services enabled ransomware groups to conduct attacks resulting in billions of dollars in losses to U.S. businesses and critical infrastructure. The sanctions followed a May 2026 law enforcement operation that dismantled 1VPNS's infrastructure and arrested Rashevskyi. This incident underscores the critical role that service providers play in the cybercriminal ecosystem. By targeting these enablers, authorities aim to disrupt the infrastructure supporting ransomware operations. Organizations should be aware of the evolving threat landscape and the importance of securing their networks against such indirect threats.
2 months ago
Kill Chain
Uncovering the BoryptGrab Infostealer: Nearly 300 Fake GitHub Repositories Distribute Malware
In July 2026, a sophisticated cyber campaign was uncovered involving nearly 300 fraudulent GitHub repositories that impersonated legitimate software projects to distribute the BoryptGrab infostealer malware. These repositories targeted users searching for security tools, cryptocurrency services, financial applications, developer utilities, secure email providers, macOS utilities, and gaming software. The malware was capable of harvesting data from over 19 web browsers, extracting information from 32 cryptocurrency wallets, and exfiltrating sensitive details from messaging and social media applications. The campaign utilized deceptive landing pages with trust-inducing elements to lure victims into downloading malicious ZIP archives containing trojanized DLL files and legitimate executables, which, when executed, loaded the infostealer into memory. This incident underscores a growing trend where threat actors exploit trusted platforms like GitHub to disseminate malware, leveraging search engine optimization (SEO) techniques to enhance the visibility of malicious repositories. The use of legitimate-looking repositories and sophisticated social engineering tactics highlights the evolving nature of cyber threats and the need for heightened vigilance when downloading software from online sources.
2 months ago
Kill Chain
CISA Issues Urgent Alert on Joomla RCE Vulnerabilities
In July 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning about active exploitation of critical remote code execution (RCE) vulnerabilities in Joomla extensions, specifically iCagenda and Balbooa Forms. These vulnerabilities, identified as CVE-2026-48939 and CVE-2026-56291 respectively, allow unauthenticated attackers to upload arbitrary files, including malicious PHP scripts, leading to full website compromise. The flaws were exploited in automated attacks before patches were released, prompting CISA to mandate immediate remediation for federal agencies. This incident underscores the persistent threat posed by web application vulnerabilities, particularly in widely used content management systems like Joomla. The rapid exploitation of these flaws highlights the importance of timely patching and proactive security measures to protect web assets from emerging threats.
2 months ago
Kill Chain
Jscrambler npm Package Compromise: A Wake-Up Call for Supply Chain Security
In July 2026, Jscrambler's npm package was compromised, leading to the publication of malicious versions (8.14, 8.16, 8.17, and 8.20) containing an infostealer malware executed during the 'preinstall' hook. This breach resulted in approximately 1,500 downloads within a two-hour window before the issue was addressed. The malware targeted sensitive data, including source code, developer credentials, cloud service keys, and cryptocurrency wallets. Jscrambler promptly deprecated the affected versions and released a secure version 8.22. This incident underscores the critical importance of securing software supply chains, as attackers increasingly exploit trusted development tools to distribute malware. Organizations must implement stringent security measures, such as code integrity checks and continuous monitoring, to prevent similar supply chain attacks.
2 months ago
Kill Chain
Yellow Teams: Defining the Future of AI Security
In 2026, organizations like Anthropic and OpenAI initiated projects such as Project Glasswing and Daybreak, respectively, to explore the integration of advanced AI models like Claude Mythos and GPT-5.5 into cybersecurity operations. These initiatives led to the formation of 'yellow teams'—engineering groups dedicated to developing both offensive and defensive AI tools. These teams collaborated with red (offensive) and blue (defensive) teams to harness AI capabilities for identifying vulnerabilities and enhancing security measures. The collaboration resulted in the discovery of numerous vulnerabilities, including some longstanding ones, and emphasized the necessity of integrating AI into the software development life cycle to proactively mitigate future threats. The emergence of yellow teams underscores a significant shift in cybersecurity strategies, highlighting the critical role of AI in both offensive and defensive operations. As AI technologies continue to evolve, the integration of such teams is essential for organizations aiming to stay ahead of sophisticated cyber threats and to adapt to the rapidly changing threat landscape.
2 months ago
Kill Chain
CISA's 2026 GitHub Credential Leak: Lessons in Security Oversight
In May 2026, the Cybersecurity and Infrastructure Security Agency (CISA) experienced a significant security lapse when a contractor inadvertently exposed sensitive credentials on a public GitHub repository named 'Private-CISA.' This repository, maintained by an employee of Nightwing—a contractor for CISA—contained approximately 844 MB of internal data, including administrative AWS GovCloud keys, plaintext passwords for internal systems, SSH keys, and SAML certificates. The repository was publicly accessible from November 2025 until its discovery in May 2026 by security researcher Guillaume Valadon of GitGuardian. Upon notification, CISA took steps to remove the repository and revoke the exposed credentials. ([techcrunch.com](https://techcrunch.com/2026/05/19/us-cyber-agency-cisa-exposed-reams-of-passwords-and-cloud-keys-to-the-open-web/?utm_source=openai)) This incident underscores the critical importance of stringent credential management and the need for continuous monitoring of public code repositories to prevent unauthorized data exposure. It also highlights the necessity for organizations, especially those responsible for national cybersecurity, to enforce robust security protocols and ensure that contractors adhere to the same standards to mitigate potential risks.
2 months ago
Kill Chain
ScamBuster: Revolutionizing Phishing Defense with AI
In July 2026, cybersecurity researcher Laurent Giovannoni introduced ScamBuster, an AI-driven system designed to counteract phishing attacks by engaging scammers with human-like personas. By simulating potential victims, ScamBuster collects critical data on cybercriminal operations, including financial details and infrastructure insights, which can be utilized by organizations and law enforcement to disrupt fraudulent activities. This proactive approach not only wastes scammers' time but also provides valuable intelligence to prevent future attacks. The emergence of ScamBuster highlights a significant shift towards offensive cybersecurity measures, leveraging artificial intelligence to turn the tables on cybercriminals. As phishing tactics become increasingly sophisticated, tools like ScamBuster offer a novel method to gather actionable intelligence, emphasizing the importance of adaptive and proactive defense strategies in the evolving threat landscape.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports