Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Understanding CVE-2026-0265: PAN-OS CAS Authentication Bypass
In May 2026, a critical authentication bypass vulnerability, CVE-2026-0265, was identified in Palo Alto Networks' PAN-OS software. This flaw allows unauthenticated attackers to forge JSON Web Tokens (JWTs) and gain unauthorized access to systems where the Cloud Authentication Service (CAS) is enabled. The vulnerability affects both GlobalProtect portals and management interfaces, potentially compromising VPN user sessions and administrative controls. Palo Alto Networks has released patches for affected versions, and organizations are urged to update to fixed versions or disable CAS to mitigate the risk. The discovery of CVE-2026-0265 underscores the ongoing challenges in securing authentication mechanisms within network infrastructure. As attackers continue to exploit such vulnerabilities, it is imperative for organizations to stay vigilant, apply timely patches, and adhere to best practices in access control to safeguard their systems against unauthorized access.
4 months ago
Kill Chain
Ghostwriter's Prometheus Phishing Campaign Targets Ukrainian Government
In May 2026, the Belarus-aligned threat actor known as Ghostwriter (also referred to as UAC-0057 and UNC1151) launched a phishing campaign targeting Ukrainian government entities. The attackers utilized compromised accounts to send emails containing PDF attachments that, when interacted with, led to the deployment of a multi-stage malware chain. This chain involved the execution of JavaScript files (OYSTERFRESH and OYSTERSHUCK) designed to install the OYSTERBLUES payload, which harvested system information and facilitated the deployment of Cobalt Strike, a tool commonly used for post-exploitation activities. The campaign exploited lures related to Prometheus, a Ukrainian online learning platform, to enhance the credibility of the phishing emails. ([thehackernews.com](https://thehackernews.com/2026/05/ghostwriter-targets-ukraine-government.html?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors employing sophisticated phishing techniques to infiltrate government networks. The use of legitimate platforms as lures and the deployment of multi-stage malware highlight the evolving tactics of such groups, emphasizing the need for robust cybersecurity measures and user awareness to mitigate these risks.
4 months ago
Kill Chain
Arrest of Kimwolf Botnet Operator Highlights IoT Security Risks
In May 2026, Canadian authorities arrested Jacob Butler, known online as "Dort," for allegedly creating and operating the Kimwolf botnet. This botnet infected millions of Internet-of-Things (IoT) devices, such as digital photo frames and web cameras, to execute massive distributed denial-of-service (DDoS) attacks. Some of these attacks reached nearly 30 terabits per second, causing financial losses exceeding one million dollars for certain victims. The U.S. Department of Justice has charged Butler with aiding and abetting computer intrusion, and he faces potential extradition to the United States. ([krebsonsecurity.com](https://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canada/?utm_source=openai)) The Kimwolf botnet's unprecedented scale and impact underscore the growing threat posed by IoT-based cyberattacks. This incident highlights the critical need for enhanced security measures in IoT devices and increased international cooperation to combat cybercrime effectively.
4 months ago
Kill Chain
CISA Contractor's GitHub Repository Exposes Sensitive Government Credentials
In May 2026, a contractor for the U.S. Cybersecurity and Infrastructure Security Agency (CISA) inadvertently exposed sensitive credentials by publishing them in a public GitHub repository named 'Private-CISA'. The repository contained plaintext passwords, AWS GovCloud keys, and internal documentation detailing CISA's software deployment processes. This exposure raised significant concerns about operational security and the potential for unauthorized access to critical government systems. ([techradar.com](https://www.techradar.com/pro/security/cisa-contractor-apparently-leaked-highly-sensitive-government-aws-keys-on-github?utm_source=openai)) This incident underscores the critical importance of stringent access controls and the need for robust monitoring of code repositories to prevent accidental exposure of sensitive information. It also highlights the necessity for organizations to implement comprehensive security training for all personnel, including contractors, to mitigate the risk of similar breaches.
4 months ago
Kill Chain
CISA Adds Two Known Exploited Vulnerabilities to Catalog
On May 21, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2025-34291, an origin validation error in Langflow, and CVE-2026-34926, a directory traversal flaw in Trend Micro Apex One (on-premise). Both vulnerabilities have been actively exploited, posing significant risks to affected systems. ([thehackernews.com](https://thehackernews.com/2026/05/cisa-adds-exploited-langflow-and-trend.html?utm_source=openai)) The inclusion of these vulnerabilities in the KEV Catalog underscores the ongoing threat posed by unpatched software flaws. Organizations are urged to prioritize remediation efforts to mitigate potential exploitation and safeguard their systems against emerging cyber threats.
4 months ago
Kill Chain
CISA Adds Langflow and Trend Micro Apex One Vulnerabilities to KEV Catalog
On May 21, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2025-34291, an origin validation error in Langflow with a CVSS score of 9.4, and CVE-2026-34926, a directory traversal flaw in on-premise versions of Trend Micro Apex One with a CVSS score of 6.7. Both vulnerabilities have been actively exploited, with CVE-2025-34291 being leveraged by the Iranian state-sponsored group MuddyWater to gain initial access to target networks. ([thehackernews.com](https://thehackernews.com/2026/05/cisa-adds-exploited-langflow-and-trend.html?utm_source=openai)) The inclusion of these vulnerabilities in the KEV catalog underscores the persistent threat posed by state-sponsored actors and the critical need for organizations to promptly address known security flaws. Federal agencies are mandated to apply necessary fixes by June 4, 2026, highlighting the urgency of mitigating these risks to protect sensitive systems and data. ([thehackernews.com](https://thehackernews.com/2026/05/cisa-adds-exploited-langflow-and-trend.html?utm_source=openai))
4 months ago
Kill Chain
Understanding the Risks of BYOVD: Exploiting Vulnerable Drivers Without Hardware
In May 2026, a detailed analysis titled 'Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective' was published, highlighting how attackers can exploit Windows kernel mode drivers without the associated hardware. This technique, known as Bring Your Own Vulnerable Driver (BYOVD), involves loading legitimate, signed drivers with known vulnerabilities to escalate privileges or disable security mechanisms. The research underscores that many drivers can be manipulated from user mode, even in the absence of the hardware they were designed for, thereby broadening the attack surface for potential exploits. The significance of this research lies in its exposure of the ease with which attackers can leverage vulnerable drivers to compromise systems. With the increasing sophistication of cyber threats, understanding and mitigating such vulnerabilities is crucial for maintaining robust security postures. Organizations must prioritize the identification and remediation of exploitable drivers to prevent potential breaches.
4 months ago
Kill Chain
Europol Dismantles 'First VPN' Used by Cybercriminals
In May 2026, a coordinated international operation led by French and Dutch authorities, with support from Europol and Eurojust, successfully dismantled 'First VPN,' a virtual private network service extensively utilized by cybercriminals to conceal their identities and illicit activities. The operation resulted in the seizure of 33 servers, the shutdown of multiple domains, and the identification of thousands of users linked to cybercrime, including ransomware attacks and data theft. ([europol.europa.eu](https://www.europol.europa.eu/media-press/newsroom/news/cybercriminal-vpn-used-ransomware-actors-dismantled-in-global-crackdown?utm_source=openai)) The takedown of 'First VPN' underscores the increasing effectiveness of international law enforcement collaboration in targeting cybercriminal infrastructure. This action not only disrupts a critical tool for cybercriminals but also provides authorities with valuable intelligence to pursue ongoing investigations into various cyber offenses. ([eurojust.europa.eu](https://www.eurojust.europa.eu/news/eurojust-coordinated-investigation-shuts-down-criminal-vpn-network?utm_source=openai))
4 months ago
Kill Chain
AI Uncovers Critical macOS Kernel Vulnerability in Record Time
In May 2026, cybersecurity firm Calif utilized Anthropic's advanced AI model, Mythos Preview, to identify and exploit a kernel memory corruption vulnerability in Apple's macOS 26.4.1 running on M5 silicon. This exploit enabled privilege escalation from an unprivileged user to root access by chaining two vulnerabilities, effectively bypassing Apple's Memory Integrity Enforcement (MIE) system, a hardware-assisted security feature introduced in 2025 to mitigate memory-based exploits. The discovery underscores the potential of AI in rapidly uncovering critical system vulnerabilities, as the exploit was developed within five days. ([9to5mac.com](https://9to5mac.com/2026/05/14/calif-team-details-how-anthropic-mythos-helped-build-a-working-macos-exploit-in-five-days/?utm_source=openai)) This incident highlights the evolving cybersecurity landscape where AI tools can both uncover and potentially exploit system vulnerabilities at unprecedented speeds. Organizations must reassess their security postures to address the dual-edged nature of AI in cybersecurity, balancing its defensive capabilities against the risks of adversarial use. ([techradar.com](https://www.techradar.com/pro/security/this-work-is-a-glimpse-of-what-is-coming-security-team-lays-out-how-anthropic-mythos-helped-build-a-working-macos-exploit-in-five-days?utm_source=openai))
4 months ago
Kill Chain
CISA Security Leak: A Wake-Up Call for Credential Management
In May 2026, a contractor for the U.S. Cybersecurity and Infrastructure Security Agency (CISA) inadvertently exposed highly sensitive credentials by maintaining a public GitHub repository named 'Private-CISA.' This repository contained plaintext passwords, AWS GovCloud keys, and internal documentation detailing CISA's software development and deployment processes. Security researcher Guillaume Valadon discovered the leak, describing it as the most severe government data exposure he had encountered. The repository had been publicly accessible since at least November 2025, raising significant concerns about operational security and potential unauthorized access to critical systems. This incident underscores the persistent risks associated with improper handling of sensitive credentials and the importance of stringent access controls. It highlights the need for organizations, especially those in critical infrastructure sectors, to enforce robust security practices, conduct regular audits, and ensure that contractors adhere to strict data protection protocols to prevent similar breaches.
4 months ago
Kill Chain
Critical Vulnerability in Cisco Secure Workload: CVE-2026-20223
In May 2026, Cisco disclosed a critical vulnerability (CVE-2026-20223) in its Secure Workload product, formerly known as Cisco Tetration. This flaw, due to insufficient validation and authentication in internal REST APIs, allowed unauthenticated remote attackers to gain Site Admin privileges by sending crafted API requests. Exploiting this vulnerability could enable attackers to access sensitive information and modify configurations across tenant boundaries. Cisco released software updates to address the issue and confirmed that, as of the advisory's publication, there was no evidence of exploitation in the wild. This incident underscores the critical importance of robust API security and timely patch management. Organizations are reminded to promptly apply security updates and review API access controls to mitigate risks associated with similar vulnerabilities.
4 months ago
Kill Chain
Chinese Hackers Deploy New Malware Targeting Telecom Providers
In mid-2022, the Chinese state-sponsored group Calypso, also known as Red Lamassu, initiated a cyber-espionage campaign targeting telecommunications providers across the Asia Pacific and parts of the Middle East. The attackers employed two newly discovered malware strains: Showboat, a modular Linux post-exploitation framework, and JMFBackdoor, a Windows-based espionage implant. Showboat facilitates long-term persistence, data exfiltration, and lateral movement within networks by acting as a SOCKS5 proxy. JMFBackdoor offers capabilities such as remote command execution, file management, and system manipulation. The initial infection vectors remain unknown, but the threat actors utilized telecom-themed domains to impersonate their targets. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/chinese-hackers-target-telcos-with-new-linux-windows-malware/amp/?utm_source=openai)) This incident underscores a growing trend of sophisticated cyber-espionage campaigns targeting critical infrastructure sectors, particularly telecommunications. The use of advanced malware like Showboat and JMFBackdoor highlights the evolving tactics of state-sponsored actors and the necessity for robust cybersecurity measures to protect sensitive information and maintain operational integrity.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports