Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Critical Vulnerabilities in Acer Wave 7 Routers: CVE-2026-49200 and CVE-2026-49201
In May 2026, security researcher Gergo Pap identified two critical vulnerabilities in Acer's Wave 7 mesh routers running firmware version T7c_GBL_1.01.000055 or earlier. The first vulnerability (CVE-2026-49200) allows unauthenticated remote access to the 'acer_cgi.log' file via the web interface, exposing cleartext login credentials and enabling unauthorized system access. The second vulnerability (CVE-2026-49201) involves a hardcoded AES encryption key in the 'upload.cgi' binary, permitting attackers to decrypt, modify, and re-encrypt system backups, potentially injecting persistent backdoors into the router. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/acer-warns-of-max-severity-zero-days-affecting-wave-7-routers/?utm_source=openai)) These vulnerabilities underscore the critical importance of securing network infrastructure devices, as they can serve as entry points for attackers to infiltrate organizational networks. The incident highlights the necessity for manufacturers to implement robust security measures, including proper access controls and secure cryptographic practices, to prevent such exposures.
3 months ago
Kill Chain
U.S. Treasury Sanctions Nobitex for IRGC-Linked Transactions
In June 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned Nobitex, Iran's largest cryptocurrency exchange, for facilitating transactions linked to the Islamic Revolutionary Guard Corps (IRGC), including those associated with IRGC-affiliated ransomware actors. Nobitex processed over 50% of Iran's digital asset inflows in 2025 and assisted the Central Bank of Iran in accessing hundreds of millions of dollars in stablecoins to support the Iranian rial. This action is part of the U.S. government's "Economic Fury" campaign targeting financial networks supporting terrorism and sanctions evasion. The sanctions underscore the increasing scrutiny of cryptocurrency platforms used to circumvent international sanctions and finance illicit activities. Organizations must enhance their compliance measures to prevent inadvertent involvement in such networks, as regulatory bodies intensify efforts to disrupt financial channels linked to state-sponsored cyber threats.
3 months ago
Kill Chain
Microsoft's Legal Threats Over Zero-Day Disclosures Spark Backlash
In early April 2026, a security researcher known as 'Nightmare-Eclipse' publicly disclosed multiple zero-day vulnerabilities affecting Microsoft products, including 'BlueHammer' (CVE-2026-33825), 'RedSun,' and 'Undefend.' These disclosures were made without prior coordination with Microsoft, leading to active exploitation by threat actors. Microsoft responded by condemning the uncoordinated disclosures and indicated potential legal action against the researcher, citing risks to customer security. This incident underscores the ongoing tension between security researchers and software vendors regarding vulnerability disclosure practices. The situation highlights the critical need for clear and cooperative communication channels to balance the prompt identification of security flaws with the protection of users from potential exploits.
3 months ago
Kill Chain
Spain Arrests Minor for Leaking Sensitive Government Data
In May 2026, Spanish authorities arrested a minor in Granada for leaking sensitive personal data of members from critical state institutions, including the National Cybersecurity Institute (INCIBE), the State Attorney General's Office, the National Police, the Civil Guard, and the National Security Council. The individual disseminated this information online, posing significant national security risks. The arrest followed an urgent investigation initiated after the mass dissemination of this data was detected, leading to a search of the suspect's residence and the seizure of electronic devices for forensic analysis. This incident underscores the growing threat of doxing, where personal information is maliciously published online, targeting government officials and institutions. The case highlights the need for robust cybersecurity measures and the importance of protecting sensitive data to prevent potential threats to national security.
3 months ago
Kill Chain
Red Hat npm Packages Compromised in 2026 Supply Chain Attack
In June 2026, Red Hat's '@redhat-cloud-services' npm namespace was compromised, leading to the distribution of over 30 backdoored packages containing the 'Miasma' malware. This supply chain attack targeted developer credentials, cloud secrets, SSH keys, and CI/CD tokens. The attackers allegedly gained access through a compromised Red Hat employee's GitHub account, injecting malicious code into multiple repositories. Red Hat promptly removed the affected packages and reported no impact on customer or partner environments. This incident underscores the escalating threat of supply chain attacks in the software development ecosystem. The use of sophisticated malware like 'Miasma' highlights the need for enhanced security measures in CI/CD pipelines and vigilant monitoring of open-source dependencies to prevent unauthorized access and data breaches.
3 months ago
Kill Chain
CISA Adds CVE-2026-0257 to Known Exploited Vulnerabilities Catalog
In May 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability affects the GlobalProtect portal and gateway components of Palo Alto Networks' PAN-OS software, allowing unauthenticated attackers to bypass security restrictions and establish unauthorized VPN connections. The flaw is present in multiple versions of PAN-OS, with patches available for affected systems. Organizations using vulnerable versions are urged to apply the necessary updates promptly to mitigate potential risks. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0257?utm_source=openai)) The inclusion of CVE-2026-0257 in the KEV Catalog underscores the ongoing threat posed by authentication bypass vulnerabilities in widely used network security products. As attackers continue to exploit such flaws, it is imperative for organizations to maintain vigilant patch management practices and monitor for emerging threats to safeguard their networks.
3 months ago
Kill Chain
Dutch Authorities Dismantle Massive 17 Million-Device Botnet
In May 2026, Dutch authorities dismantled a massive botnet comprising 17 million infected devices, including computers, tablets, and smartphones. The operation involved seizing over 200 servers located in the Netherlands that controlled the botnet's infrastructure. This network was utilized for various cyberattacks, such as distributed denial-of-service (DDoS) attacks and malicious traffic proxying. The botnet was linked to a service called Asocks, which offered proxy services using compromised devices without the owners' knowledge. This incident underscores the growing threat posed by botnets leveraging residential devices, highlighting the need for enhanced security measures to protect consumer hardware from unauthorized exploitation.
3 months ago
Kill Chain
Major Supply Chain Attacks Target Nx Console and GitHub Repositories in 2026
In May 2026, two significant supply chain attacks targeted the developer ecosystem. The first involved a compromised version of the Nx Console Visual Studio Code extension (v18.95.0), which was live for approximately 18 minutes on May 18, 2026. This malicious extension exfiltrated credentials from developer machines, leading to unauthorized access and exfiltration of approximately 3,800 internal GitHub repositories. The second attack, dubbed 'Megalodon,' occurred on the same day and compromised over 5,500 GitHub repositories by injecting malicious GitHub Actions workflows designed to harvest CI/CD secrets and cloud credentials. These incidents underscore the escalating threat landscape targeting software development pipelines and the critical need for robust security measures in CI/CD environments. The rapid execution and widespread impact of these attacks highlight the urgency for organizations to implement stringent supply chain security practices and continuous monitoring to detect and mitigate such threats promptly.
3 months ago
Kill Chain
Kimsuky's Advanced Cyber Attacks: A New Era of AI-Driven Threats
In March and April 2026, the North Korean state-sponsored threat actor Kimsuky launched sophisticated cyber attacks targeting South Korean military and corporate entities. Utilizing advanced social engineering tactics, they spoofed security software installation pages and crafted fake Webex meeting pages to distribute malware. These campaigns delivered variants of the HTTPSpy remote access trojan, enabling extensive control over compromised systems, including command execution, file manipulation, and data exfiltration. Notably, Kimsuky employed legitimate tools like Visual Studio Code's remote tunneling feature and DWAgent for post-exploitation activities, enhancing their ability to evade detection. The increasing integration of artificial intelligence in cyber attack methodologies, as demonstrated by Kimsuky's use of large language models to develop malware like HelloDoor, signifies a significant evolution in threat actor capabilities. This trend underscores the urgent need for organizations to adopt advanced, behavior-based detection systems and regularly update threat intelligence to effectively counter these sophisticated and rapidly evolving cyber threats.
3 months ago
Kill Chain
Harnessing AI: LLMs in EDR Evasion Techniques
In May 2026, Praetorian published a blog post titled 'Adversarial Oracles: LLM-Guided EDR Signature Reduction,' detailing the use of Large Language Models (LLMs) to automate the evasion of Endpoint Detection and Response (EDR) signatures. The post describes a methodology where LLMs analyze detection patterns from services like VirusTotal, identify specific triggers in offensive security tools, and suggest code modifications to reduce detection rates. This approach was applied to tools like 'goffloader,' resulting in a significant decrease in antivirus detections without altering the tools' core functionalities. This development is significant as it highlights the evolving arms race between offensive and defensive cybersecurity measures. The use of AI to circumvent EDR systems underscores the need for adaptive defense strategies and raises ethical considerations regarding the deployment of AI in cybersecurity.
3 months ago
Kill Chain
FortiClient EMS Vulnerability Leads to EKZ Infostealer Deployment
In May 2026, threat actors exploited a critical authentication bypass vulnerability (CVE-2026-35616) in Fortinet's FortiClient Enterprise Management Server (EMS) versions 7.4.5 and 7.4.6. This flaw allowed unauthenticated remote attackers to execute arbitrary code via specially crafted requests. Leveraging this vulnerability, attackers delivered the EKZ infostealer malware, disguised as a legitimate Fortinet endpoint update, through FortiClient-managed VPN scripting workflows. The malware targeted credentials and sensitive data stored in web browsers, exfiltrating them to attacker-controlled servers. Fortinet released emergency patches to address this issue, and organizations were urged to apply them promptly to mitigate the risk of compromise. This incident underscores the critical importance of timely patch management and vigilance against sophisticated social engineering tactics. The exploitation of trusted security infrastructure highlights the evolving strategies of threat actors, emphasizing the need for organizations to adopt a proactive and layered security approach to protect against such vulnerabilities.
3 months ago
Kill Chain
Exploitation of FortiClient EMS Vulnerability Leads to Credential Theft
In May 2026, threat actors exploited a critical vulnerability (CVE-2026-35616) in Fortinet's FortiClient Endpoint Management Server (EMS) to deploy credential-stealing malware across managed endpoints. By abusing the trusted endpoint management infrastructure, attackers disguised the malicious payload as a legitimate Fortinet update, executing it via PowerShell. This allowed them to harvest sensitive data, including passwords and autofill details from web browsers, and exfiltrate the information to attacker-controlled servers. The exploitation of this vulnerability underscores the risks associated with unpatched management systems and the potential for widespread compromise through centralized infrastructure. Organizations are urged to apply the latest patches and review endpoint management configurations to mitigate such threats.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports