Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
US ATM Jackpotting: Tren de Aragua's Ploutus Malware Heist Exposed
In late 2025 and early 2026, US law enforcement charged 31 additional suspects in a major campaign of ATM jackpotting attacks attributed to the Venezuelan criminal gang Tren de Aragua. The attackers breached numerous ATMs across the United States, installing Ploutus malware by physically accessing internal components and deploying malware to force the machines to dispense large quantities of cash. The sophisticated attacks leveraged swapped hard drives or infected USB devices and allowed the perpetrators to launder stolen funds internationally, inflicting millions of dollars in losses on banks and credit unions. To date, over 87 individuals have been charged in this transnational criminal scheme. This incident highlights the evolving tactics of financially motivated threat groups combining physical access and technical expertise. The designation of Tren de Aragua as a Foreign Terrorist Organization underscores law enforcement’s recognition of cyber-enabled financial crime as a national security threat and signals intensified global scrutiny on such operations.
7 months ago
Kill Chain
Mustang Panda’s CoolClient Infostealer: 2026 Global Espionage Campaign Unveiled
In January 2026, Chinese state-sponsored group Mustang Panda leveraged an updated version of its CoolClient backdoor to conduct targeted espionage campaigns against government organizations in Myanmar, Mongolia, Malaysia, Russia, and Pakistan. The attackers used legitimate Sangfor software for initial infection and subsequently deployed tailored infostealers that extracted login credentials from major browsers, monitored clipboard data, and profiled compromised systems. The operation featured advanced tactics such as DLL side-loading, remote shell plugins, encrypted multi-stage payloads, and the use of public cloud services (via hardcoded tokens) for stealthy data exfiltration. This breach highlights the rapid advancement and operational innovation among state-backed APT actors, particularly regarding infostealer deployment and C2 evasion using legitimate cloud infrastructure. Organizations in APAC, government, and critical infrastructure sectors remain top targets as attacker toolsets evolve to bypass both endpoint and network security controls.
7 months ago
Kill Chain
2026 Fortinet Zero-Day SSO Breach: How Authentication Bypass Exposed Critical Devices
In January 2026, Fortinet disclosed a critical zero-day vulnerability (CVE-2026-24858) in its FortiCloud SSO authentication mechanism that allowed attackers to bypass security controls and gain unauthorized administrative access to FortiOS, FortiManager, and FortiAnalyzer devices. By leveraging rogue FortiCloud accounts, threat actors exploited an alternate authentication path—even on fully patched systems—to create new local admin and VPN-enabled accounts, exfiltrating firewall configuration data from customer environments within seconds. Fortinet mitigated active attacks by disabling vulnerable FortiCloud SSO connections and initiating global blocks before a patch was available, but over 25,000 devices were at risk during the attack window. This incident is highly relevant due to the growing sophistication and automation of supply chain and SSO-based attacks, with adversaries increasingly targeting trusted cloud management platforms. The event underscores the need for stricter access controls, rapid incident response capabilities, and heightened vigilance around identity infrastructure, especially as SAML and SSO adoption expands in modern enterprises.
7 months ago
Kill Chain
Pakistan-Linked APT Launches Gopher Strike & Sheet Attack Against Indian Government in 2025
In September 2025, cybersecurity researchers uncovered coordinated cyber campaigns—dubbed Gopher Strike and Sheet Attack—targeting Indian government entities. Attributed to a Pakistan-linked Advanced Persistent Threat (APT) group, the operations leveraged novel, undocumented tactics involving phishing and multi-stage malware to compromise government networks. Attackers exploited existing security gaps, conducted lateral movement, and exfiltrated sensitive data, threatening the confidentiality and integrity of official communications. The campaigns remained undetected for an extended period, highlighting the advanced tradecraft and persistent nature of the threat actor. These incidents underscore the growing risk posed by state-aligned actors employing increasingly sophisticated tactics to target critical government infrastructure. The discovery of new tools and techniques in these attacks signals an escalation in South Asian regional cyber conflict and emphasizes the need for updated security controls and rapid detection capabilities.
7 months ago
Kill Chain
Sandworm Wiper Campaign Frustrated at Poland Power Grid
In May 2024, cyber researchers reported a high-profile attack attempt targeting Poland’s power grid infrastructure. The operation was attributed to Sandworm, a Russian APT group notorious for wiper malware and sabotage against critical national infrastructure. Attackers leveraged custom malware designed to disrupt grid operations, but strong detection and security controls reportedly thwarted the attempt, preventing widespread outages. The incident highlighted Sandworm’s persistent focus on critical infrastructure in Central Europe and their evolving tactics for sabotaging operational technology environments. This case underscores a larger trend of state-aligned threat actors targeting energy and critical infrastructure in Europe, leveraging specialized wiper tools and lateral movement techniques. It also emphasizes increasing cross-border cyber risk as geopolitical tensions escalate and underscores new regulatory scrutiny for critical sectors.
7 months ago
Kill Chain
Konni APT Leverages AI-Generated PowerShell to Breach Blockchain Developers
In January 2026, the North Korean-linked APT group Konni conducted a sophisticated phishing campaign targeting blockchain developers and engineering teams in Japan, Australia, and India. Using AI-generated PowerShell malware, attackers successfully penetrated targeted organizations by delivering malicious payloads through convincing spear-phishing emails. Once inside, the adversaries leveraged lateral movement and exfiltration techniques to access sensitive intellectual property and digital assets, expanding their historical targeting beyond South Korea and parts of Europe. The breach underscores the evolution of attacker tradecraft—adopting AI to evade traditional defenses and efficiently craft malicious code. This incident is highly relevant as it marks a notable surge in both AI-driven malware and the targeting of the blockchain sector. With threat actors broadening their geographic reach and operational sophistication, organizations must urgently re-evaluate their security controls, specifically around code execution, endpoint monitoring, and identity access management, to defend against emerging threats.
7 months ago
Kill Chain
DPRK's Konni: AI-Generated Backdoor Hits Blockchain Developers in 2024
In early 2024, the North Korean threat group Konni launched a sophisticated supply-chain attack targeting blockchain developers by deploying an AI-generated PowerShell backdoor within compromised development environments. The operation exploited development tools to surreptitiously gain access to cryptocurrency assets, leveraging advanced evasion techniques and encrypted communications to avoid detection. Victims faced risks of cryptocurrency theft, business disruption, and potential regulatory exposure, with the attackers demonstrating a deep understanding of both blockchain technologies and modern security controls. This incident highlights the growing convergence of AI-generated malware and targeted supply-chain attacks, especially against financially lucrative industries like cryptocurrency. As threat actors increasingly leverage custom malware and automated tools, organizations with high-value digital assets face mounting pressure to improve internal visibility, zero-trust enforcement, and incident response capabilities.
7 months ago
Kill Chain
Sandworm’s Failed DynoWiper Attack on Poland’s Energy Grid: A 2025 Nation-State Case Study
In late December 2025, Polish energy infrastructure was targeted in a sophisticated cyberattack attributed to Sandworm, a notorious Russian state-sponsored hacking group. The attackers attempted to deploy 'DynoWiper', a destructive data-wiping malware, against two combined heat and power facilities and key management systems for renewable energy assets. Although the wiper aimed to erase files and render systems inoperable, Polish officials confirmed the attack was detected and mitigated before operational disruption occurred. Attribution to Sandworm, linked to Russia’s GRU, underscores continued targeting of critical infrastructure by advanced persistent threats. This incident is highly relevant given the continued escalation of cyber operations against national infrastructure, particularly in Europe. It highlights the evolving use of destructive malware by state-backed actors and signals the necessity for robust cross-sector cyber defenses and detection mechanisms.
7 months ago
Kill Chain
Sandworm’s DynoWiper Attack on Poland’s Power Grid: How Cyberdefenders Stopped a Nation-State Threat
In late December 2025, Poland’s power sector faced the largest cyberattack in its history, attributed to the notorious Russian state-backed Sandworm group. The attackers deployed a new destructive malware strain dubbed DynoWiper, attempting to disrupt critical energy operations by wiping systems within operational networks. Polish cyber defense teams identified the attack early through advanced threat monitoring and contained the threat before any operational damage occurred. No loss of service or data was reported, and authorities confirmed that core infrastructure remained uncompromised. The incident has intensified scrutiny of nation-state threats to Europe’s energy grid, reinforcing calls for resilient cybersecurity postures across all critical infrastructure assets. Sandworm’s use of a novel wiper malware and focus on lateral movement echo a sharp uptick in high-impact, geopolitically motivated attacks targeting EU utilities. This case highlights the growing sophistication and persistence of nation-state cyber operations, raising fresh challenges for defenders in the energy sector and beyond.
7 months ago
Kill Chain
Konni Deploys AI-Built Malware Against Blockchain Engineers in 2026 Cyber Campaign
In January 2026, the North Korean-linked Konni APT (also known as Opal Sleet or TA406) launched a targeted cyber campaign against blockchain developers and engineers in the Asia-Pacific region, deploying bespoke PowerShell malware suspected of being generated using AI tools. Attackers lured victims with Discord-hosted ZIP files containing malicious shortcut links that, when launched, initiated a multi-stage infection chain. This included staged extraction of obfuscated PowerShell backdoors, privilege detection, scheduled task creation for persistence, and hourly beaconing to a remote command-and-control server. The malware focused on extracting sensitive development environment credentials, API keys, and potentially cryptocurrency wallet access, posing significant risks to both individuals and organizations handling blockchain assets. This incident exemplifies a sharp escalation in attacker sophistication, particularly the operational use of AI-powered malware, accelerating the pace at which advanced persistent threats can scale, adapt, and evade detection. As malicious actors increasingly leverage generative AI to develop modular, well-commented, and evasive code, organizations in crypto and other high-value sectors face a heightened need for adaptive security controls and rapid incident detection to keep defenses aligned with evolving attack techniques.
7 months ago
Kill Chain
Researchers Disclose Widespread Automotive and EV Vulnerabilities at Pwn2Own 2026
In January 2026, security researchers at the Pwn2Own Automotive World competition uncovered and exploited dozens of critical vulnerabilities in modern vehicle infotainment systems and EV (electric vehicle) chargers from multiple manufacturers. By chaining flaws across network interfaces and poorly secured APIs, attackers demonstrated the ability to remotely compromise vehicle systems, extract sensitive data, and gain unauthorized control over critical vehicle functions. While these attacks were conducted in a controlled, ethical hacking contest, they highlighted the substantial risks posed by connected automotive platforms, which often lack robust segmentation and encryption for internal and external communications. This incident underscores the rapidly escalating threat landscape facing the automotive industry as vehicles integrate more digital and cloud-connected components. The research-driven breach foreshadows what real-world adversaries may attempt, making it urgent for OEMs and suppliers to adopt zero trust, comprehensive monitoring, and proactive vulnerability management.
7 months ago
Kill Chain
Fortinet FortiCloud Auth Bypass: Patched Firewalls Remain at Risk in 2026
In January 2026, Fortinet confirmed the existence of a critical authentication bypass (CVE-2025-59718) affecting its FortiCloud SSO feature, leaving fully patched devices vulnerable to compromise. Attackers exploited a patch bypass to gain administrative access, quickly creating VPN-enabled accounts and exfiltrating firewall configurations. Despite an earlier advisory, threat actors continued to exploit an unaddressed attack path, with the campaign becoming automated and impacting organizations globally. Evidence included unauthorized logins and suspect account creation, prompting urgent investigation and forensic response from network teams. This breach illustrates the growing risk posed by incomplete patches and the relentless pursuit by attackers of residual vulnerabilities, particularly in widely deployed network security products. It underscores the critical need for continuous monitoring, rapid patch validation, and limiting administrative access to sensitive management interfaces.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports