Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Anthropic's Claude Mythos AI: A Game-Changer in Cybersecurity
In March 2026, Anthropic's AI model, Claude Mythos, identified thousands of zero-day vulnerabilities across major operating systems and web browsers. This unprecedented discovery included a 27-year-old bug in OpenBSD and a critical flaw in FFmpeg. Due to the model's potential for misuse, Anthropic restricted access to select organizations under Project Glasswing to facilitate responsible vulnerability remediation. ([techcrunch.com](https://techcrunch.com/2026/04/07/anthropic-mythos-ai-model-preview-security/?utm_source=openai)) The incident underscores the dual-use nature of advanced AI in cybersecurity, highlighting the need for stringent access controls and collaborative efforts to mitigate risks associated with powerful AI tools.
5 months ago
Kill Chain
New macOS Malware Campaign Exploits Script Editor in ClickFix Attack
In April 2026, a new macOS malware campaign emerged, leveraging the Script Editor application to deliver the Atomic Stealer (AMOS) malware. Attackers employed a variation of the ClickFix technique, directing users to malicious websites that prompted them to open Script Editor via the 'applescript://' URL scheme. This method executed obfuscated commands to download and run AMOS, which exfiltrated sensitive data including Keychain information, browser credentials, and cryptocurrency wallets. This incident underscores the evolving tactics of threat actors targeting macOS systems, particularly through trusted applications like Script Editor. The shift from Terminal-based to Script Editor-based ClickFix attacks highlights the need for continuous vigilance and user education to recognize and avoid such sophisticated social engineering schemes.
5 months ago
Kill Chain
North Korean Hackers Deploy 1,700 Malicious Packages in Unprecedented Supply Chain Attack
In early April 2026, North Korean state-sponsored hackers, identified as the Contagious Interview group, executed a sophisticated supply chain attack by publishing over 1,700 malicious packages across multiple open-source ecosystems, including npm, PyPI, Go, Rust, and PHP. These packages impersonated legitimate developer tools but functioned as malware loaders, deploying platform-specific payloads capable of data theft and remote access. The attack underscores the persistent threat to software supply chains and the need for vigilant security practices among developers and organizations. ([thehackernews.com](https://thehackernews.com/2026/04/n-korean-hackers-spread-1700-malicious.html?utm_source=openai)) This incident highlights a concerning trend of state-sponsored actors targeting open-source ecosystems to infiltrate developer environments. The scale and coordination of this attack demonstrate the evolving tactics of threat actors and the critical importance of securing software supply chains to prevent widespread compromise.
5 months ago
Kill Chain
Anthropic's Claude Mythos AI Model Uncovers Critical Software Vulnerabilities
In April 2026, Anthropic unveiled its advanced AI model, Claude Mythos, which autonomously identified thousands of high-severity vulnerabilities across major operating systems and web browsers. This unprecedented capability led to the launch of Project Glasswing, a collaborative initiative with tech giants like Amazon, Apple, and Microsoft, aiming to address these security flaws before potential exploitation. The discovery of such extensive vulnerabilities underscores the critical need for proactive cybersecurity measures in the face of rapidly advancing AI technologies. As AI models become more sophisticated, they present both opportunities for enhancing security and risks of being weaponized by malicious actors. Organizations must stay vigilant and adapt their defenses to counteract these evolving threats.
5 months ago
Kill Chain
AI-Assisted Cyberattack Compromises 600+ FortiGate Firewalls Globally
In early 2026, a sophisticated cyberattack leveraging artificial intelligence (AI) tools compromised over 600 FortiGate firewalls across 55 countries. The attackers utilized AI to automate reconnaissance, vulnerability scanning, and exploitation processes, significantly accelerating the attack timeline and reducing the need for human intervention. By exploiting weak security configurations and exposed management interfaces, the threat actors gained unauthorized access to critical network infrastructure, leading to potential data breaches and operational disruptions. This incident underscores the escalating threat posed by AI-enhanced cyberattacks, which enable adversaries to conduct large-scale operations with unprecedented speed and efficiency. Organizations must recognize the evolving capabilities of AI in the cyber threat landscape and implement robust security measures to defend against such advanced attacks.
5 months ago
Kill Chain
Flowise 2026 RCE Vulnerability Exploitation
In April 2026, security researchers identified active exploitation of a critical remote code execution (RCE) vulnerability, CVE-2025-59528, in Flowise, an open-source platform for building AI agents and large language model (LLM) workflows. This flaw, residing in the CustomMCP node, allows attackers to execute arbitrary JavaScript code without security validation, leading to potential full system compromise. Despite a patch being available since September 2025, many instances remain unpatched, exposing organizations to significant risks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/max-severity-flowise-rce-vulnerability-now-exploited-in-attacks/?utm_source=openai)) The exploitation of this vulnerability underscores the persistent threat posed by unpatched software in widely used AI development tools. Organizations leveraging Flowise must prioritize immediate updates to mitigate potential breaches and safeguard sensitive data. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/max-severity-flowise-rce-vulnerability-now-exploited-in-attacks/?utm_source=openai))
5 months ago
Kill Chain
APT28's 2025 DNS Hijacking Campaign: A Wake-Up Call for Network Security
In 2025, the Russian state-sponsored cyber group APT28, also known as Fancy Bear, exploited vulnerabilities in MikroTik and TP-Link routers to conduct a large-scale DNS hijacking campaign. By compromising these routers, APT28 redirected internet traffic through attacker-controlled servers, enabling adversary-in-the-middle attacks that harvested credentials from web and email services. This operation targeted a broad range of victims, including organizations linked to the UK Ministry of Defence and NATO logistics contractors, posing significant risks of credential theft, data manipulation, and broader network compromise. ([ncsc.gov.uk](https://www.ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dns-hijacking-operations?utm_source=openai)) This incident underscores the critical importance of securing network infrastructure against sophisticated state-sponsored threats. The exploitation of widely used routers highlights the need for organizations to implement robust security measures, including regular firmware updates, strong authentication protocols, and continuous monitoring to detect and mitigate such attacks.
5 months ago
Kill Chain
Fortinet's 2026 Unauthenticated API Access Bypass: A Critical Security Alert
In April 2026, Fortinet disclosed a critical vulnerability (CVE-2026-35616) in its FortiClient Endpoint Management Server (EMS) versions 7.4.5 and 7.4.6. This improper access control flaw allowed unauthenticated attackers to execute unauthorized code or commands via crafted API requests. The vulnerability was actively exploited in the wild, prompting Fortinet to release emergency hotfixes and advise customers to apply them immediately. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/?utm_source=openai)) The incident underscores the persistent targeting of Fortinet products by threat actors, highlighting the importance of timely patch management and vigilant monitoring of security advisories to mitigate risks associated with zero-day vulnerabilities. ([tenable.com](https://www.tenable.com/blog/cve-2026-35616-fortinet-forticlientems-improper-access-control-vulnerability-exploited-in-the?utm_source=openai))
5 months ago
Kill Chain
Fortinet FortiClientEMS 2026 Improper Access Control Vulnerability
In April 2026, Fortinet disclosed a critical improper access control vulnerability (CVE-2026-35616) in FortiClient Endpoint Management Server (EMS) versions 7.4.5 and 7.4.6. This flaw allows unauthenticated attackers to execute unauthorized code or commands via crafted requests, leading to potential remote code execution and privilege escalation. The vulnerability has been actively exploited in the wild, prompting Fortinet to release emergency hotfixes and advise immediate patching to mitigate the risk. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/?utm_source=openai)) The exploitation of CVE-2026-35616 underscores the persistent targeting of Fortinet products by threat actors. Organizations are urged to apply the provided hotfixes promptly and monitor their systems for any signs of compromise to maintain robust security postures. ([tenable.com](https://www.tenable.com/blog/cve-2026-35616-fortinet-forticlientems-improper-access-control-vulnerability-exploited-in-the?utm_source=openai))
5 months ago
Kill Chain
Fortinet's FortiClient EMS Zero-Day Vulnerability Exploited in 2026
In early April 2026, Fortinet disclosed a critical zero-day vulnerability (CVE-2026-35616) in its FortiClient Endpoint Management Server (EMS), which was actively exploited in the wild. This improper access control flaw allowed unauthenticated attackers to execute unauthorized code or commands via crafted requests. Fortinet released an emergency hotfix for versions 7.4.5 and 7.4.6, with plans for a comprehensive patch in version 7.4.7. The vulnerability was added to CISA's known exploited vulnerability catalog, highlighting its severity and widespread impact. The rapid exploitation of CVE-2026-35616 underscores a growing trend of attackers targeting zero-day vulnerabilities in widely used security solutions. Organizations must remain vigilant, ensuring timely application of patches and hotfixes to mitigate such threats. This incident also emphasizes the importance of robust access controls and continuous monitoring to detect and respond to unauthorized activities promptly.
5 months ago
Kill Chain
pcTattletale's 2024 Data Breach: A Cautionary Tale in Cybersecurity
In May 2024, pcTattletale, a U.S.-based spyware application, suffered a significant data breach when a hacker infiltrated its servers, defaced its website, and exposed sensitive data, including customer information and victim data. The breach was facilitated by exploiting vulnerabilities that allowed unauthorized access to the company's Amazon Web Services account, leading to the exposure of over 300 million screenshots captured from victims' devices. Following the incident, pcTattletale's founder, Bryan Fleming, announced the company's immediate shutdown, stating that all data had been deleted to prevent further exposure. This breach underscores the inherent risks associated with spyware applications, particularly their potential to compromise user privacy and security. The incident also highlights the growing scrutiny and legal actions against developers and distributors of such software, emphasizing the need for robust security measures and ethical considerations in software development.
5 months ago
Kill Chain
Fortinet EMS Vulnerability CVE-2026-35616: Immediate Action Required
In April 2026, a critical vulnerability (CVE-2026-35616) was discovered in Fortinet's FortiClient Enterprise Management Server (EMS). This flaw allowed unauthenticated attackers to bypass authentication controls and execute arbitrary code via specially crafted requests. Fortinet released emergency hotfixes to address the issue, urging immediate application to prevent exploitation. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) mandated federal agencies to patch affected systems by April 9, 2026, highlighting the significant risk posed by this vulnerability. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-fortinet-flaw-exploited-in-attacks-by-friday/?utm_source=openai)) The exploitation of CVE-2026-35616 underscores the persistent threat of zero-day vulnerabilities in widely used enterprise solutions. Organizations are reminded of the critical importance of timely patch management and proactive security measures to mitigate such risks.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports