Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
North Korean Malicious npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
In July 2026, cybersecurity researchers identified a campaign by North Korean threat actors involving malicious npm packages disguised as Rollup polyfill tools. These packages, including 'rollup-packages-polyfill-core' and 'rollup-runtime-polyfill-core,' closely mimicked legitimate projects to deceive developers. Upon installation, they executed hidden scripts that established remote access and exfiltrated sensitive data such as credentials for AWS, Azure, and cryptocurrency wallets. The attack leveraged a multi-stage delivery mechanism, with initial packages installing secondary payloads that fetched and executed malicious code from external servers. This approach enabled the attackers to evade detection and maintain persistence on compromised systems. ([thehackernews.com](https://thehackernews.com/2026/07/north-korea-linked-npm-packages-mimic.html?utm_source=openai)) This incident underscores a growing trend of sophisticated supply chain attacks targeting open-source ecosystems. By compromising widely used development tools, attackers can infiltrate numerous organizations, highlighting the critical need for enhanced vigilance and security measures in software development practices.
2 months ago
Kill Chain
FortiBleed Campaign's Link to Inc and Lynx Ransomware Groups Unveiled
In July 2026, the FortiBleed campaign, initially identified as a credential-harvesting operation targeting Fortinet FortiGate firewalls, was linked to ransomware-as-a-service groups Inc Ransom and Lynx. SOCRadar researchers discovered that an operator within the FortiBleed infrastructure was actively engaged in ransom negotiations for both groups, indicating that credentials obtained through FortiBleed were being utilized for ransomware deployment. The campaign compromised approximately 12,000 FortiGate devices, with at least 12 confirmed ransomware deployments resulting in hundreds of encrypted endpoints across affected organizations. ([darkreading.com](https://www.darkreading.com/threat-intelligence/fortibleed-actors-inc-lynx-ransomware-gangs?utm_source=openai)) This incident underscores the evolving threat landscape where initial access brokers collaborate with ransomware operators, amplifying the risk to organizations. The exploitation of network security devices as entry points highlights the critical need for robust perimeter defenses and vigilant monitoring to prevent unauthorized access and subsequent ransomware attacks.
2 months ago
Kill Chain
Chinese AI Models Redefine Cybersecurity Landscape
In June 2026, Chinese companies Zhipu AI and 360 Security Technology released advanced AI models—GLM-5.2 and Tulongfeng, respectively—that significantly enhance vulnerability discovery capabilities. GLM-5.2, an open-weight model, demonstrated performance on par with leading U.S. models like Anthropic's Mythos in identifying software vulnerabilities. Tulongfeng, described as China's version of Mythos, reportedly identified over 3,400 vulnerabilities, with 105 acknowledged by the Chinese government. These developments underscore a rapid advancement in AI-driven cybersecurity tools within China, potentially altering the global cybersecurity landscape. ([techradar.com](https://www.techradar.com/pro/security/chinese-cybersecurity-company-360-unveils-chinas-version-of-mythos-and-yitianzhen-to-automate-cyber-defense?utm_source=openai)) The emergence of these models highlights the increasing accessibility of sophisticated AI tools for both defenders and attackers. The open-source nature of GLM-5.2 raises concerns about potential misuse by malicious actors, as it allows for modification and deployment without restrictions. This trend necessitates a reassessment of current cybersecurity strategies to address the evolving threat landscape posed by AI-enhanced capabilities. ([axios.com](https://www.axios.com/2026/06/25/china-glm-52-open-source-hackers?utm_source=openai))
2 months ago
Kill Chain
European Parliament Member Targeted with Pegasus Spyware During Investigation
In October 2022 and March 2023, former Member of the European Parliament (MEP) Stelios Kouloglou's mobile device was infiltrated with Pegasus spyware while he was serving on the PEGA committee, which was investigating the misuse of such surveillance tools within the European Union. The Citizen Lab's forensic analysis confirmed these infections, indicating that attackers potentially accessed confidential committee documents and deliberations. The specific government or entity responsible for these attacks remains unidentified. ([citizenlab.ca](https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus/?utm_source=openai)) This incident underscores the escalating threat of sophisticated spyware targeting high-profile individuals, including those involved in oversight and investigative roles. It highlights the urgent need for robust cybersecurity measures and regulatory frameworks to protect sensitive information and uphold democratic processes. ([theguardian.com](https://www.theguardian.com/world/2026/jul/03/spyware-used-against-mep-investigating-pegasus-abuses-report-finds?utm_source=openai))
2 months ago
Kill Chain
Armored Likho's BusySnake Stealer Targets Government and Energy Sectors
In July 2026, a previously undocumented threat actor known as Armored Likho launched cyber attacks targeting government agencies and the electric power sector in Russia, Brazil, and Kazakhstan. The group employed spear-phishing emails with lures related to official government notices or social programs, distributing RAR archives containing EXE binaries that served as droppers for additional payloads retrieved from a GitHub repository. These payloads included a newly identified Python-based information stealer named BusySnake Stealer, which is capable of stealing browser passwords, cookies, clipboard contents, screenshots, documents, Telegram session data, OTP secrets, and cryptocurrency wallet files. The malware establishes persistence through a combination of VBScript files and scheduled tasks, allowing the attackers to maintain prolonged access to compromised systems. This incident underscores the evolving tactics of cyber espionage groups, highlighting their ability to blend financially motivated campaigns with targeted attacks on critical infrastructure. The use of AI-generated first-stage loaders and obfuscated, modular remote access trojans (RATs) and infostealers specifically engineered to bypass dynamic analysis demonstrates a significant advancement in their capabilities. Organizations must remain vigilant and adapt their cybersecurity measures to counter these sophisticated threats.
2 months ago
Kill Chain
Anthropic's Mythos AI Breach: A Wake-Up Call for AI Security
In April 2026, unauthorized users gained access to Anthropic's restricted AI cybersecurity tool, Mythos, through a third-party vendor environment. Mythos, designed for enterprise security, was considered too powerful for public release due to its potential to identify vulnerabilities and simulate cyberattacks autonomously. The breach raised significant concerns about the security of advanced AI tools and the potential misuse of such technologies. This incident underscores the critical need for robust security measures when handling powerful AI tools, especially those capable of autonomous actions. It highlights the importance of securing third-party vendor environments to prevent unauthorized access to sensitive technologies.
2 months ago
Kill Chain
Pegasus Spyware Targets PEGA Committee Member Amid Investigations
In 2022 and 2023, the European Parliament's PEGA Committee, established to investigate the misuse of surveillance spyware like NSO Group's Pegasus, faced an ironic security breach. Greek journalist and substitute committee member Stelios Kouloglou's phone was infected with Pegasus spyware twice: first around October 2022 and again in March 2023. These infections coincided with critical phases of the committee's work, including the drafting of its final report. The infections were confirmed by the University of Toronto's Citizen Lab, highlighting the persistent threat posed by sophisticated spyware even to those tasked with investigating its misuse. This incident underscores the ongoing challenges in protecting sensitive information from advanced surveillance tools. It also emphasizes the need for robust cybersecurity measures within governmental bodies and the urgency of implementing the PEGA Committee's recommendations to prevent future abuses of spyware technologies.
2 months ago
Kill Chain
Opera's 'Paste Protect' Feature: A New Defense Against 'ClickFix' Attacks
In July 2026, Opera introduced 'Paste Protect,' a security feature designed to combat 'ClickFix' attacks—a social engineering technique where users are deceived into copying and executing malicious commands via their system's command-line interface. These attacks often masquerade as legitimate verification processes or problem-solving instructions, leading to the execution of harmful commands with the user's privileges, potentially resulting in malware installation or data theft. 'Paste Protect' proactively scans clipboard content for patterns associated with malicious scripts across Windows, macOS, and Linux platforms. Upon detecting suspicious content, it blocks the copy operation, alerts the user with a warning, and displays a red security indicator in the browser's address bar. This feature aims to prevent users from inadvertently executing harmful commands, thereby enhancing overall system security. The introduction of 'Paste Protect' underscores the growing prevalence of 'ClickFix' attacks and the necessity for proactive security measures. As threat actors increasingly exploit human behavior through sophisticated social engineering tactics, it becomes imperative for both software developers and users to adopt and maintain robust security practices to mitigate such evolving threats.
2 months ago
Kill Chain
Google's 2026 Takedown of NetNut Residential Proxy Network
In July 2026, Google, in collaboration with the FBI and Lumen, significantly disrupted the NetNut residential proxy network, also known as Popa. This network, comprising at least 2 million home devices worldwide, was exploited by cybercriminals and espionage groups to mask malicious activities and conduct password-guessing attacks. Google's actions included disabling accounts and services associated with NetNut's command-and-control operations, leading to a substantial reduction in the network's operational capacity. ([thehackernews.com](https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html?utm_source=openai)) The takedown of NetNut underscores the growing threat posed by residential proxy networks, which can be co-opted by malicious actors to obscure their activities. This incident highlights the critical need for enhanced security measures and vigilance among consumers and organizations to prevent their devices from being exploited in such networks.
2 months ago
Kill Chain
ChocoPoC RAT: A New Threat Targeting Vulnerability Researchers
In July 2026, cybersecurity researchers uncovered a campaign distributing a Python-based remote access trojan (RAT) named ChocoPoC. Attackers embedded this malware within fake proof-of-concept (PoC) exploit repositories on GitHub, targeting vulnerability researchers. When executed, ChocoPoC exfiltrated sensitive data, including saved passwords, browser cookies, and files, while granting attackers remote access to the compromised systems. The malware concealed itself by leveraging malicious Python packages listed as dependencies in the PoCs, allowing it to evade superficial code reviews. ([thehackernews.com](https://thehackernews.com/2026/07/new-chocopoc-rat-targets-vulnerability.html?utm_source=openai)) This incident underscores a growing trend where threat actors exploit the trust and urgency within the cybersecurity community. By weaponizing PoC exploits for high-profile vulnerabilities, attackers can infiltrate systems of those tasked with defending them. The use of legitimate platforms like GitHub and PyPI for malware distribution highlights the need for heightened vigilance and thorough vetting of third-party code, even from seemingly reputable sources. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits/?utm_source=openai))
2 months ago
Kill Chain
FortiBleed Credential Theft: A Gateway to Ransomware Attacks
In early 2026, the FortiBleed campaign emerged as a large-scale credential-harvesting operation targeting over 430,000 FortiGate firewalls across more than 150 countries. Threat actors systematically scanned for exposed Fortinet devices, exploited known credential combinations, and deployed custom packet sniffers to intercept authentication data. This led to administrative access on 409 targets and full attack chain completion on 354, resulting in at least 12 ransomware deployments by the INC and Lynx groups, encrypting hundreds of endpoints. ([thehackernews.com](https://thehackernews.com/2026/07/fortibleed-credential-theft-linked-to.html?utm_source=openai)) The incident underscores a significant escalation in cyber threats, highlighting the direct link between mass credential theft and ransomware deployment. Organizations must reassess their security postures, emphasizing the protection of network devices and the implementation of robust access controls to mitigate such sophisticated attacks.
2 months ago
Kill Chain
DHS HSIN Breach 2026: Cyberattack on Information-Sharing Platform
In late May to early June 2026, the Department of Homeland Security (DHS) experienced a cyberattack on the Homeland Security Information Network (HSIN), a platform for sharing sensitive but unclassified information among federal, state, local, and private-sector partners. An unknown threat actor accessed HSIN servers and a SharePoint system used for collaboration. DHS is investigating the breach to determine the extent of the intrusion and whether any documents were stolen. The department has not attributed the attack to any specific threat actor or foreign government. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform/amp/?utm_source=openai)) This incident underscores the persistent threats to government information-sharing platforms and highlights the need for robust cybersecurity measures. As the United States oversees security for major events like the World Cup, ensuring the integrity of such systems is paramount to national security. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform/amp/?utm_source=openai))
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports