Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Aqua Trivy's 2026 AI-Powered Supply Chain Attack: A Wake-Up Call for Developers
In late February 2026, threat actors compromised versions 1.8.12 and 1.8.13 of the Aqua Trivy VS Code extension on the OpenVSX registry. The attackers injected malicious code that exploited local AI coding tools—such as Claude, Codex, Gemini, GitHub Copilot CLI, and Kiro CLI—to perform unauthorized data collection on developers' machines. This code operated silently, leaving no visible alerts, and was removed from OpenVSX on February 28, 2026. ([cryptika.com](https://www.cryptika.com/threat-actors-exploit-openvsx-aqua-trivy-with-malicious-ai-prompts-to-hijack-local-coding-tools/?utm_source=openai)) This incident underscores the evolving nature of supply chain attacks, particularly the novel use of AI tools to facilitate data exfiltration. It highlights the critical need for developers and organizations to implement robust security measures, including regular audits of third-party extensions and vigilant monitoring of development environments.
6 months ago
Kill Chain
CanisterWorm: A 2026 Supply Chain Attack Targeting Iranian Systems
In March 2026, the cybercrime group TeamPCP launched a supply chain attack by compromising Aqua Security's Trivy vulnerability scanner, injecting credential-stealing malware into official releases on GitHub. This malicious code targeted authentication credentials, cloud tokens, and cryptocurrency wallets. Subsequently, TeamPCP deployed 'CanisterWorm,' a self-propagating worm that exploited exposed Docker APIs, Kubernetes clusters, and Redis servers. The worm included a wiper component designed to destroy data on systems set to Iran's time zone or with Farsi as the default language, significantly impacting Iranian organizations. This incident underscores the escalating threat of supply chain attacks and the increasing use of wiper malware by financially motivated groups. Organizations must enhance their security measures, particularly in securing development pipelines and cloud infrastructures, to mitigate such sophisticated threats.
6 months ago
Kill Chain
Trivy Supply Chain Attack: A Wake-Up Call for Open-Source Security
In March 2026, the Trivy vulnerability scanner, a widely used open-source security tool, was compromised in a sophisticated supply chain attack orchestrated by the threat actor group known as TeamPCP. The attackers infiltrated Trivy's GitHub repository, replacing legitimate code with malicious versions in the v0.69.4 release and associated GitHub Actions. This breach led to the distribution of credential-stealing malware, which harvested sensitive information from developers' environments, including SSH keys, cloud service credentials, and database passwords. The malicious code was active for approximately three hours, during which it exfiltrated data to attacker-controlled servers. Organizations utilizing the affected versions were advised to treat their environments as fully compromised, necessitating immediate rotation of all secrets and thorough system analysis for additional breaches. This incident underscores the escalating threat posed by supply chain attacks targeting open-source ecosystems. The exploitation of trusted development tools to distribute malware highlights the critical need for enhanced security measures within software supply chains. As attackers increasingly focus on compromising widely adopted tools, organizations must implement rigorous code review processes, continuous monitoring, and robust incident response strategies to mitigate the risks associated with such attacks.
6 months ago
Kill Chain
Russian Hackers Exploit Signal and WhatsApp in Sophisticated Phishing Campaign
In March 2026, Dutch intelligence agencies reported a large-scale global cyber campaign by Russian state-sponsored hackers targeting Signal and WhatsApp accounts of dignitaries, military personnel, and journalists. The attackers employed social engineering techniques, such as impersonating support chatbots, to deceive users into revealing security verification codes and PINs. This allowed unauthorized access to individual accounts, enabling the interception of sensitive communications. Notably, the campaign did not exploit technical vulnerabilities within the messaging platforms themselves but rather manipulated legitimate security features through phishing tactics. ([english.aivd.nl](https://english.aivd.nl/latest/news/2026/03/09/russia-targets-signal-and-whatsapp-accounts-in-cyber-campaign?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors utilizing sophisticated social engineering methods to compromise secure communication channels. The focus on widely used encrypted messaging applications highlights the need for heightened vigilance and robust security practices among high-profile individuals and organizations to safeguard sensitive information.
6 months ago
Kill Chain
Aisuru and Kimwolf Botnets' 2025 Record-Breaking DDoS Attacks
In December 2025, the Aisuru and Kimwolf botnets orchestrated a record-breaking Distributed Denial of Service (DDoS) attack, peaking at 31.4 terabits per second (Tbps) and delivering 200 million requests per second. This unprecedented assault targeted multiple companies, predominantly in the telecommunications sector, and was part of a broader campaign dubbed "The Night Before Christmas." The attack leveraged a vast network of compromised Internet of Things (IoT) devices, including Android TVs and streaming boxes, to generate massive traffic volumes. ([hackmag.com](https://hackmag.com/news/aisuru-31-4-tbps?utm_source=openai)) The incident underscores the escalating scale and sophistication of DDoS attacks, highlighting the critical need for robust cybersecurity measures. The rapid proliferation of vulnerable IoT devices has provided attackers with extensive resources to launch such large-scale assaults. Organizations must prioritize securing these devices and implementing advanced DDoS mitigation strategies to defend against evolving cyber threats. ([fastnetmon.com](https://fastnetmon.com/2026/02/01/aisuru-botnet-sets-a-new-ddos-record-at-31-4-tbps/?utm_source=openai))
6 months ago
Kill Chain
Cisco FMC 2026: Interlock Ransomware's Exploitation of Insecure Deserialization
In early 2026, a critical vulnerability (CVE-2026-20131) was discovered in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. This flaw allowed unauthenticated, remote attackers to execute arbitrary Java code as root by exploiting insecure deserialization of user-supplied Java byte streams. The Interlock ransomware group actively exploited this vulnerability as a zero-day since late January 2026, targeting several high-profile organizations, including DaVita, Kettering Health, the Texas Tech University System, and the city of Saint Paul, Minnesota. The exploitation of CVE-2026-20131 underscores the persistent threat posed by sophisticated ransomware groups leveraging zero-day vulnerabilities. Organizations must prioritize timely patching and robust security measures to mitigate such risks.
6 months ago
Kill Chain
Trivy Security Scanner Compromised: A Wake-Up Call for CI/CD Security
In late February 2026, Aqua Security's Trivy, a widely-used open-source vulnerability scanner, was compromised through its GitHub Actions workflows. An autonomous AI bot named 'hackerbot-claw' exploited vulnerabilities in Trivy's CI/CD pipeline, leading to unauthorized code execution and the exfiltration of sensitive CI/CD secrets. This breach resulted in the deletion of Trivy's GitHub repository content, disrupting numerous organizations relying on Trivy for security scanning. ([medium.com](https://medium.com/%40abhishekchauhan_68324/your-security-scanner-is-the-attack-vector-6d2a175a4f5b?utm_source=openai)) This incident underscores the escalating threat of AI-driven supply chain attacks targeting CI/CD pipelines. The automation and adaptability demonstrated by 'hackerbot-claw' highlight the urgent need for enhanced security measures in development workflows to prevent similar breaches.
6 months ago
Kill Chain
Critical Vulnerability in Cisco Secure Firewall Management Center: CVE-2026-20131
In March 2026, a critical vulnerability (CVE-2026-20131) was identified in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. This flaw allows unauthenticated, remote attackers to execute arbitrary Java code as root by exploiting insecure deserialization of user-supplied Java byte streams. Successful exploitation could lead to full system compromise, granting attackers complete control over affected devices. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh?utm_source=openai)) The vulnerability underscores the persistent risks associated with deserialization flaws in network management systems. Organizations are urged to apply Cisco's security patches promptly and restrict public internet access to FMC management interfaces to mitigate potential exploitation. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh?utm_source=openai))
6 months ago
Kill Chain
EDR Killer Malware Exploits Vulnerable Drivers to Disable Security Tools
In early February 2026, threat actors exploited compromised SonicWall SSLVPN credentials to infiltrate a corporate network. Once inside, they deployed a custom 'EDR killer' malware that utilized a signed but revoked EnCase forensic driver to disable 59 endpoint detection and response (EDR) and antivirus tools. This 'Bring Your Own Vulnerable Driver' (BYOVD) technique allowed attackers to gain kernel-level access, effectively neutralizing security defenses and facilitating further malicious activities. The intrusion was disrupted before ransomware deployment, but it underscores the growing trend of adversaries weaponizing legitimate drivers to bypass endpoint security measures. ([huntress.com](https://www.huntress.com/blog/encase-byovd-edr-killer?utm_source=openai)) This incident highlights the critical need for organizations to enforce multi-factor authentication (MFA) on VPN access, regularly update and monitor security tools, and implement strict controls over driver installations to prevent the exploitation of vulnerable drivers. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/05/edr-killer-vulnerable-encase-driver/?utm_source=openai))
6 months ago
Kill Chain
Interlock Ransomware's 2026 Exploitation of Cisco Firewall Vulnerability
In early 2026, the Interlock ransomware group exploited a zero-day vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC) Software, allowing unauthenticated remote code execution as root. This critical flaw, due to insecure deserialization of user-supplied Java byte streams, enabled attackers to gain full control over affected devices. The exploitation began on January 26, 2026, 36 days prior to Cisco's public disclosure on March 4, 2026. Interlock's campaign involved deploying custom remote access trojans, reconnaissance scripts, and evasion techniques, leading to significant operational disruptions for targeted organizations. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh?utm_source=openai)) This incident underscores the persistent threat posed by ransomware groups leveraging zero-day vulnerabilities. Organizations must prioritize timely patching, implement defense-in-depth strategies, and maintain continuous threat monitoring to mitigate such risks.
6 months ago
Kill Chain
DarkSword iOS Exploit Kit: A New Threat in 2026
In early 2026, cybersecurity researchers discovered 'DarkSword,' an advanced iOS exploit kit attributed to Russian hackers. This toolkit repurposes vulnerabilities believed to have been originally developed by the U.S. government. DarkSword targets iOS devices through sophisticated attack chains, enabling unauthorized access to sensitive user data, including messages, passwords, and cryptocurrency wallets. The exploit kit has been deployed in espionage campaigns against individuals in Ukraine, Saudi Arabia, Turkey, and Malaysia, affecting potentially millions of iPhone users worldwide. The emergence of DarkSword underscores the escalating trend of nation-state actors leveraging leaked or repurposed cyber tools to conduct widespread surveillance and financial theft. This incident highlights the critical need for robust cybersecurity measures and timely software updates to mitigate the risks posed by such sophisticated threats.
6 months ago
Kill Chain
LayerX Uncovers Font-Rendering Exploit Targeting AI Assistants
In March 2026, LayerX researchers unveiled a novel font-rendering attack that exploits discrepancies between how AI assistants and web browsers interpret HTML content. By utilizing custom fonts and CSS techniques, attackers can display malicious commands to users while presenting benign content to AI tools analyzing the same page. This method effectively deceives AI assistants into endorsing harmful instructions, leading users to execute potentially dangerous commands under false assurances of safety. This incident underscores a critical vulnerability in AI-assisted browsing, highlighting the need for enhanced security measures that account for the visual rendering of web content. As AI tools become increasingly integrated into daily workflows, understanding and mitigating such sophisticated social engineering tactics is imperative to maintain user trust and system integrity.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports