Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Bybit's 2025 Security Breach: A Deep Dive into the $1.4 Billion Ethereum Theft
In February 2025, Dubai-based cryptocurrency exchange Bybit suffered a significant security breach, resulting in the theft of approximately 401,000 Ethereum (ETH), valued at over $1.4 billion. The attackers exploited vulnerabilities in Bybit's multi-signature cold wallet system, facilitated by compromised infrastructure at Safe{Wallet}, a third-party provider. This incident stands as the largest cryptocurrency exchange hack to date. ([en.wikipedia.org](https://en.wikipedia.org/wiki/Bybit?utm_source=openai)) The breach was attributed to the North Korean state-sponsored Lazarus Group, known for their sophisticated cyber operations targeting financial institutions. The stolen funds were laundered through various channels, including privacy-focused platforms, complicating recovery efforts. ([en.wikipedia.org](https://en.wikipedia.org/wiki/Lazarus_Group?utm_source=openai))
7 months ago
Kill Chain
Safeguarding AI Assets: Lessons from the 2025 Model Extraction Attack
In 2025, a significant AI model extraction attack was identified, where adversaries systematically queried a proprietary machine learning model's API to replicate its functionality. By sending carefully crafted inputs and analyzing the outputs, attackers reconstructed a substitute model that closely mirrored the original's behavior. This breach exposed the model's intellectual property, leading to potential competitive disadvantages and financial losses for the organization. The incident underscores the vulnerabilities inherent in exposing AI models through APIs without adequate security measures. ([techtarget.com](https://www.techtarget.com/searchsecurity/tip/AI-model-theft-Risk-and-mitigation-in-the-digital-era?utm_source=openai)) The rise of such model extraction attacks highlights the urgent need for organizations to implement robust defenses, including rate limiting, output perturbation, and behavioral monitoring, to protect their AI assets from unauthorized replication and misuse. ([snyk.io](https://snyk.io/articles/ai-model-theft/?utm_source=openai))
7 months ago
Kill Chain
Swarmer Tool: Exploiting Windows Legacy Features for Stealthy Registry Persistence
In February 2025, Praetorian Inc. introduced 'Swarmer,' a tool designed to achieve stealthy Windows registry persistence without triggering Endpoint Detection and Response (EDR) systems. By exploiting legacy Windows features such as mandatory user profiles and the Offline Registry API, Swarmer allows low-privilege users to modify the NTUSER hive covertly. This method bypasses standard registry APIs monitored by EDR solutions, enabling attackers to establish persistence without detection. The release of Swarmer underscores the ongoing challenges in cybersecurity, particularly the exploitation of overlooked system functionalities. As attackers continue to innovate, it is imperative for organizations to reassess and fortify their security postures against such sophisticated techniques.
7 months ago
Kill Chain
Fortinet’s 2024 Zero-Day SSO Breach: Key Lessons in Cloud Identity Security
In June 2024, Fortinet disclosed a critical zero-day vulnerability that was actively exploited by threat actors to compromise FortiCloud single sign-on (SSO) authentication, enabling unauthorized access to customer devices. Attackers leveraged the flaw to perform malicious SSO logins, bypassing authentication controls and potentially moving laterally within affected network environments. In response, Fortinet took the unprecedented step of disabling FortiCloud SSO services temporarily for all users while investigating and developing a fix. This incident underscores significant risks associated with identity and access management in cloud-delivered network security platforms. This breach highlights the growing prevalence of zero-day exploitation targeting authentication mechanisms and cloud infrastructure. As attackers increasingly focus on SSO and federated identity systems, organizations must reassess their reliance on third-party authentication, strengthen monitoring, and accelerate adoption of zero trust strategies.
7 months ago
Kill Chain
Fake Dating App Used to Deliver Android Spyware in Pakistan
In early 2024, an Android spyware campaign was uncovered by ESET researchers targeting users in Pakistan via a fraudulent dating app masquerading as a legitimate platform. The attackers lured victims using romance scam tactics, convincing users to download the malicious app outside of trusted marketplaces. Once installed, the spyware harvested sensitive data including call logs, messages, and device information, forwarding it to remote command-and-control servers linked to an ongoing espionage operation. The threat actors exhibited targeted behavior, indicating a capability for victim profiling and data exfiltration on mobile devices. This incident underscores a broader cybersecurity trend: growing use of socially engineered lures and repurposed surveillance tooling in region-specific espionage. Mobile attack vectors are increasingly leveraged for targeted intelligence gathering, amplifying urgency for robust defenses and heightened awareness of app distribution risks.
7 months ago
Kill Chain
Fortinet’s 2026 Zero-Day: Attackers Bypass FortiCloud SSO to Compromise Firewalls
In January 2026, Fortinet disclosed a critical zero-day vulnerability (CVE-2026-24858) affecting FortiCloud’s single sign-on authentication, enabling attackers with a FortiCloud account and a registered device to bypass authentication controls and gain privileged access to FortiGate firewalls and other products. Malicious actors leveraged the flaw in the wild, making unauthorized configuration changes, creating unauthorized accounts, and manipulating VPN settings across exposed management interfaces. Fortinet responded by disabling FortiCloud SSO, blocking the known malicious accounts, and issuing mitigations, though patches for multiple affected products remained unavailable at disclosure. This incident highlights the persistent targeting of network infrastructure devices by threat actors seeking initial access and lateral movement. With thousands of Fortinet instances exposed globally and repeated inclusion of Fortinet CVEs in known exploited vulnerabilities catalogs, organizations face increased regulatory scrutiny and pressure to rapidly address vulnerabilities affecting critical network management infrastructure.
7 months ago
Kill Chain
Kingdom Market Darknet Takedown: How Law Enforcement Disrupted a Global Cybercrime Hub (2021–2023)
Between March 2021 and December 2023, the Kingdom Market darknet platform operated as a large-scale cybercrime marketplace facilitating the sale of narcotics, cybercrime tools, stolen personal information, and fraudulent documents. Slovakian national Alan Bill, also known as "Vend0r" or "KingdomOfficial," admitted in January 2026 to administering the illicit platform, handling site infrastructure, and orchestrating anonymous cryptocurrency payments. The marketplace boasted over 42,000 illegal listings and tens of thousands of customer accounts. Its takedown culminated in coordinated law enforcement actions, domain seizures, and Bill's arrest in the U.S., where evidence linked him directly to site operations. This case highlights the persistent challenge of global, darknet-enabled cybercrime, the evolution of anonymous payment technologies, and the international scope of enforcement efforts. Cybercrime marketplaces remain a top concern for regulators and enterprises alike, with attackers rapidly adapting business models and operational security to evade detection.
7 months ago
Kill Chain
Enterprise AI at Risk: Hackers Hijack Exposed LLM Endpoints in Bizarre Bazaar Operation
In early June 2024, security researchers revealed an active campaign—dubbed the Bizarre Bazaar operation—where threat actors systematically scanned for and exploited publicly exposed Large Language Model (LLM) service endpoints. Attackers hijacked these AI/ML endpoints by bypassing inadequate API controls and leveraging unsecured cloud configurations, enabling unauthorized access to advanced AI resources. Compromised infrastructure became part of an underground market offering illicit AI compute power, leading to business risks ranging from intellectual property leakage to tool misuse and service disruption for impacted organizations. This incident spotlights the growing exploitation of AI infrastructure, with attackers rapidly adopting novel tactics as organizations rush to deploy LLMs. Weak segmentation, lack of egress controls, and poor visibility have left many organizations vulnerable to sophisticated abuse, elevating urgency for robust enterprise AI security and compliance measures.
7 months ago
Kill Chain
Empire Market Dark Web Takedown: Owner Pleads Guilty in $430M Cybercrime Plot
In January 2026, U.S. authorities announced that Raheim Hamilton (“Sydney”/“ZeroAngel”), a co-founder of the notorious Empire Market, pleaded guilty to federal drug conspiracy charges. From 2018 to 2020, Empire Market operated as a large-scale dark web marketplace accessible via TOR, facilitating over $430 million in illegal transactions, primarily enabling drug sales but also distributing stolen credentials, hacking tools, and counterfeit currency. Hamilton and partner Thomas Pavey laundered illicit proceeds through cryptocurrency and designed the site to evade law enforcement, directly overseeing vendor disputes and operational security. This prosecution underscores the ongoing threat and operational sophistication of dark web cybercrime marketplaces, even after earlier takedowns. As digital criminal platforms persistently adapt, law enforcement and organizations must address the evolving risks involving anonymized markets, cryptocurrency transactions, and the proliferation of illicit digital goods and services.
7 months ago
Kill Chain
MicroWorld eScan Update Server Breach Exposes Supply Chain Risks
In June 2024, MicroWorld Technologies, developers of eScan antivirus, experienced a breach where attackers compromised one of its update servers. The intruders leveraged this access to push a malicious software update to a limited subset of customers, effectively deploying unauthorized code via the trusted antivirus delivery mechanism. MicroWorld quickly detected the incident, notified impacted users, and began forensic analysis with assistance from cybersecurity experts. The compromised update posed potential risks including malware infection and lateral network movement. This incident is part of a growing trend of supply chain attacks, where adversaries exploit trusted update channels to infiltrate enterprise environments. As organizations increasingly rely on third-party software, vigilance and layered security controls around update infrastructures have become a pressing necessity.
7 months ago
Kill Chain
Mustang Panda’s 2025 Cyber Espionage: Updated COOLCLIENT Backdoor Hits Government
In late 2025, cyber espionage group Mustang Panda (also known as Earth Preta and Twill Typhoon) launched a series of targeted attacks against government entities, deploying an updated version of the COOLCLIENT backdoor. These intrusions leveraged spear-phishing and custom malware to establish persistent access, exfiltrate sensitive government data, and conduct surveillance. The campaign relied on advanced command-and-control infrastructure and encrypted traffic to evade detection, demonstrating the group’s evolving tactics and technical sophistication. The breach resulted in notable data theft and highlighted vulnerabilities in governmental East-West network security and policy enforcement. This incident underscores a rising trend of state-sponsored attackers continuously updating malware toolsets and intensifying operations against government organizations. The sophistication and stealth of these campaigns demand enhanced data protection, visibility, and zero trust network controls to meet regulatory and operational requirements.
7 months ago
Kill Chain
Russian ELECTRUM APT Strikes Polish Power Grid with Coordinated December 2025 Attack
In December 2025, a coordinated cyber attack disrupted multiple sites within Poland's national power grid, marking the first significant compromise of distributed energy operational technology in the region. The campaign, attributed with medium confidence to Russian state-sponsored APT group ELECTRUM, leveraged supply chain vulnerabilities and advanced lateral movement techniques to infiltrate the grid's OT networks. Attackers exploited unencrypted east-west traffic and segmentation gaps, enabling persistent access and operational disruption that triggered brief power outages and forced manual intervention by Polish operators. The incident showcased a notable escalation in critical infrastructure targeting methods by highly skilled actors. This incident highlights the increasing risk of state-sponsored attacks on energy infrastructure, especially in the context of rising geopolitical tensions and adversarial use of sophisticated supply chain compromise and network segmentation evasion. Organizations should reassess their visibility and controls for east-west and encrypted traffic to mitigate similar risks.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports