Industry Category

Computer/Network Security

Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.

1048 threat reports
Page 71 of 88

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Computer/Network Security Threat Reports

Showing 841852 / 1048 reports
Fake OSINT and GPT GitHub Repos Used to Spread PyStoreRAT in Supply Chain Attack
Impact· medium

Fake OSINT and GPT GitHub Repos Used to Spread PyStoreRAT in Supply Chain Attack

In late 2025, cybersecurity researchers uncovered a supply chain attack involving malicious repositories on GitHub impersonating open-source Python utilities themed around OSINT and GPT automation. These repos covertly delivered a previously unseen JavaScript-based Remote Access Trojan dubbed PyStoreRAT, using minimal code to retrieve and execute a remote HTA file. Unsuspecting developers and security professionals, lured by the project's legitimate appearance, risked compromise when cloning or running the code, resulting in unauthorized remote access and potential data exfiltration. The campaign highlights the growing sophistication of attacks abusing trusted developer platforms and open-source supply chains. This incident underscores the urgent need for organizations to audit third-party code sources, bolster code supply chain security, and monitor for emerging malware targeting developer ecosystems. The tactic reflects broader trends in social engineering, weaponized open-source projects, and the exploitation of generative AI themes by threat actors.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Hamas Espionage Malware Hits Middle East Diplomats: 2024 Breach Analysis
Impact· medium

Hamas Espionage Malware Hits Middle East Diplomats: 2024 Breach Analysis

In early 2024, state-sponsored threat actors linked to Hamas intensified cyber-espionage campaigns targeting Middle Eastern diplomatic entities. Attackers leveraged tailored malware and advanced phishing schemes to infiltrate networks, harvest intelligence, and gain persistent access to government communications. The campaign utilized unpatched vulnerabilities, abused encrypted and lateral east-west traffic, and bypassed conventional perimeter defenses. These intrusions aimed to gather political intelligence and undermine regional security, impacting the operational confidentiality of affected governments and creating heightened diplomatic tensions. This incident reflects a broader escalation in politically motivated cyber-espionage across the region, as Hamas and allied groups continue to innovate with more sophisticated tooling and tactics. The evolving threat landscape underscores the urgency for robust east-west segmentation, encrypted traffic controls, and real-time threat detection among critical infrastructure and state agencies.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
WIRTE’s 2025 Espionage Campaign: Middle East Governments Breached via AshenLoader and AshTag
Impact· medium

WIRTE’s 2025 Espionage Campaign: Middle East Governments Breached via AshenLoader and AshTag

In late 2025, the advanced persistent threat group WIRTE, linked to Gaza Cyber Gang, launched a far-reaching espionage campaign against government and diplomatic entities across the Middle East using a new malware suite known as AshTag. Attackers used phishing emails with geopolitical lures to entice targets into downloading malicious archives, resulting in the sideloading of AshenLoader and the deployment of AshTag. This modular .NET backdoor enabled remote command execution, persistence, and document exfiltration, specifically targeting sensitive diplomatic materials. Notably, attacks persisted throughout the Israel-Hamas conflict and continued after the Gaza ceasefire, highlighting the threat actors' sustained operational tempo. This campaign is a potent reminder of the increasing sophistication of state-linked espionage operations, including the adoption of advanced malware delivery and in-memory execution tactics designed to evade detection. With attackers broadening their target geography and refining their methods, regional governments and strategic organizations must urgently review and upgrade their defenses.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Ashen Lepus Strikes: 2025 APT Breach Unveils Advanced Espionage Across Middle Eastern Diplomatic Targets
Impact· medium

Ashen Lepus Strikes: 2025 APT Breach Unveils Advanced Espionage Across Middle Eastern Diplomatic Targets

In late 2025, a Hamas-affiliated APT group known as Ashen Lepus (also referred to as WIRTE) executed a sophisticated cyber-espionage campaign targeting governmental and diplomatic organizations across multiple Middle Eastern countries. The attackers leveraged a novel modular malware suite called AshTag, delivered through decoy documents, DLL sideloading, and a carefully staged infection chain. The campaign made extensive use of in-memory payload delivery, advanced encryption, legitimate-themed subdomains for C2 communications, and the abuse of widely used file transfer tools like Rclone to exfiltrate sensitive, often diplomacy-related data. This incident marks a notable evolution in the operational security and technical sophistication of Middle Eastern espionage campaigns. It highlights the rising use of modular malware, infrastructure blending, and legitimate protocol abuse by regionally motivated threat actors, underscoring a trend where state-linked groups continue cyber operations despite geopolitical turmoil or ceasefires.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Ukrainian Hacker Charged: Russian Hacktivist Attacks Underscore U.S. Critical Infrastructure Risks
Impact· high

Ukrainian Hacker Charged: Russian Hacktivist Attacks Underscore U.S. Critical Infrastructure Risks

In 2024, U.S. authorities charged a Ukrainian national for collaborating with Russian state-sponsored hacktivist groups in a series of high-profile cyberattacks against critical infrastructure. The targeted sectors included U.S. water systems, election infrastructure, and nuclear facilities. Leveraging advanced intrusion tools and lateral movement tactics, the attacker contributed to sophisticated campaigns aimed at espionage, disruption, and potential sabotage. These efforts underscore the persistent threat posed by coordinated state-aligned cyber actors and the increasing risk to essential public services worldwide. This case highlights how modern threat actors are expanding their focus from traditional targets to critical infrastructure with geo-political motives. The intersection of hacktivism, nation-state support, and escalating global tensions demands greater cyber defense readiness and robust compliance from both private and public sectors.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Google Chrome 2025: AI Browsing Defenses Raise the Bar Against Indirect Prompt Injection
Impact· medium

Google Chrome 2025: AI Browsing Defenses Raise the Bar Against Indirect Prompt Injection

In December 2025, Google implemented new layered defenses in the Chrome browser to counter indirect prompt injection attacks following the introduction of agentic AI features. Attackers exploited weaknesses inherent in large language model-powered browser agents, attempting to override user intent, exfiltrate data from other sites, or execute rogue actions by injecting malicious prompts via untrusted web content. Google's updated architecture introduced components like the User Alignment Critic and Agent Origin Sets, isolating agent actions from attacker-controlled data and enforcing origin-based access controls. These measures aim to prevent data leaks and unauthorized automation that could compromise user accounts, sensitive information, or browser integrity. This incident highlights the rising risk of AI-driven browsing, where automated agents interacting with multiple web origins are exposed to sophisticated prompt-based attacks. The move reflects a broader industry push for deterministic (non-LLM) safeguards and ongoing regulatory and organizational scrutiny over rapidly evolving AI systems in end-user applications.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Storm-0249 Orchestrates Precision Ransomware Attacks with ClickFix and Advanced Endpoint Exploits
Impact· high

Storm-0249 Orchestrates Precision Ransomware Attacks with ClickFix and Advanced Endpoint Exploits

In December 2025, threat actors identified as Storm-0249 escalated their cybercriminal operations, shifting from initial access brokerage to hands-on ransomware deployment using advanced techniques. Leveraging the ClickFix social engineering tactic, they convinced victims to execute malicious commands via spoofed domains leading to fileless PowerShell execution and DLL side-loading attacks. The attackers exploited legitimate security software processes to deploy trojanized DLLs, establish persistent and encrypted communications, and use living-off-the-land binaries to evade detection. These sophisticated methods enabled Storm-0249 to lay the groundwork for ransomware payloads tied to unique system identifiers, bolstering their ability to monetize enterprise footholds with minimal exposure. This incident reflects a broader trend toward precision, low-noise endpoint exploitation using fileless methods and trusted process abuse. Cybersecurity teams must adapt quickly to shifting tactics that exploit endpoint trust, social engineering, and advanced lateral movement, as similar methodologies are rapidly proliferating among ransomware and initial access threat groups.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Spiderman Phishing Service: A 2024 Wakeup Call for European Banks
Impact· medium

Spiderman Phishing Service: A 2024 Wakeup Call for European Banks

In early 2024, a sophisticated phishing-as-a-service platform known as Spiderman emerged, targeting customers of more than 50 European banks and cryptocurrency holders. The perpetrators leveraged pixel-perfect cloned websites and credential harvesting techniques to deceive users into divulging sensitive financial information. Attackers used advanced phishing kits capable of bypassing two-factor authentication and dynamically generating legitimate-looking web pages, resulting in significant financial losses and heightened concern among European financial institutions. This incident underscores a growing trend of increasingly accessible and effective phishing services, enabling even low-skill cybercriminals to launch large-scale, targeted attacks. Regulatory scrutiny and the evolving threat landscape demand that organizations bolster defenses against phishing service operations leveraging social engineering and real-time site cloning.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Ransomware Reimagined: Attackers Deploy Their Own QEMU VM for Stealth and Persistence
Impact· medium

Ransomware Reimagined: Attackers Deploy Their Own QEMU VM for Stealth and Persistence

In early 2025, a sophisticated ransomware incident was revealed by Red Canary Intelligence when an adversary launched a coordinated attack combining email bombing, social engineering, and abuse of legitimate remote access tools. Initially, victims endured email inundation designed to cause confusion and open the door to a convincing technical support ruse. Leveraging remote assistance software, attackers deployed a custom QEMU virtual machine (VM) into the compromised environment—a novel method for persistent access. Within this VM, tools such as Sliver C2, QDoor backdoor, and ScreenConnect enabled internal reconnaissance, lateral movement, and external command and control, all while evading conventional endpoint security controls. This incident is noteworthy for both its multi-layered attack chain and the adversary’s use of their own pre-configured VM for persistence, representing a shift toward virtualization-based evasion and resilience. The detection highlights a rise in blended attacks using social engineering, legitimate tools, and bespoke infrastructure, stressing the importance of defense-in-depth and advanced anomaly detection capabilities.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Malicious VSCode Extensions Breach Puts Developer Supply Chains at Risk
Impact· high

Malicious VSCode Extensions Breach Puts Developer Supply Chains at Risk

In December 2025, two malicious Visual Studio Code extensions—Bitcoin Black and Codo AI—were uncovered on Microsoft’s official VSCode Marketplace, executing a supply chain attack that targeted developers. Published by an entity named 'BigBlack', these extensions installed information-stealing malware by abusing extension privileges. The malware leveraged DLL hijacking and covert batch scripts to steal credentials, browser session cookies, cryptocurrency wallet data, and system information from infected developer machines, storing exfiltrated data for later retrieval. The incident highlights how even widely trusted software platforms can host weaponized add-ons capable of compromising sensitive environments. This breach exemplifies the growing risks posed by open-source and third-party software supply chain compromises, especially targeting developer tools. The ease with which unvetted code can be distributed through official registries underscores the need for rigorous extension security and policy enforcement in enterprise environments.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
AI Agent Prompt Injection Turns GitHub Actions Into Supply Chain Backdoor
Impact· medium

AI Agent Prompt Injection Turns GitHub Actions Into Supply Chain Backdoor

In early 2024, cybersecurity researchers at Aikido disclosed a critical supply-chain vulnerability affecting major AI coding tools such as Google Gemini, Claude Code, OpenAI Codex, and GitHub AI Inference. The flaw enables attackers to inject malicious prompts into software automation workflows like GitHub Actions, causing integrated AI agents with elevated privileges to execute unauthorized commands. Cunning use of crafted commit messages and pull requests can trick large language models into treating these inputs as actionable instructions, leading to code modifications, shell command execution, and privilege escalation within software repositories. The vulnerability, reported via responsible disclosure, has prompted urgent fixes in some tools, but similar weaknesses remain present in other platforms. This incident highlights the expanding risks of AI-powered automation in the software development supply chain. With organizations increasingly relying on LLM integrations, the potential for prompt injection and privilege abuse creates new avenues for compromise, underscoring the urgency for robust controls, regular audit, and architectural safeguards around agentic AI workflows.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Issues Stark Warning on Ongoing Brickstorm Backdoor Attacks
Impact· medium

CISA Issues Stark Warning on Ongoing Brickstorm Backdoor Attacks

In early 2024, the Cybersecurity and Infrastructure Security Agency (CISA) issued a warning regarding sustained state-sponsored attacks targeting VMware vSphere environments, attributed to China-linked advanced persistent threat (APT) groups. These actors deployed the 'Brickstorm' backdoor to compromise government and technology sector organizations, exploiting vulnerabilities to achieve persistence and lateral movement within affected networks. The intrusion enabled attackers to bypass security controls, maintain privileged access, and exfiltrate sensitive information, highlighting a persistent threat targeting virtualization infrastructure. This incident is notable as it reflects a concerning evolution in attacker tactics, specifically the abuse of virtualization platforms as an entry vector for espionage. The ongoing campaign underscores the urgent need for enhanced detection, segmentation, and defense against stealthy operations in hybrid and cloud environments.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports