Industry Category

Computer/Network Security

Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.

1048 threat reports
Page 72 of 88

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Computer/Network Security Threat Reports

Showing 853864 / 1048 reports
Major Insider Attack Wipes 96 US Government Databases: Lessons for 2024
Impact· high

Major Insider Attack Wipes 96 US Government Databases: Lessons for 2024

In June 2024, two Virginia-based former federal contractors were accused of orchestrating a significant insider attack after being terminated from their government roles. Prosecutors allege the brothers conspired to steal sensitive information and deliberately wiped 96 critical government databases, severely disrupting several agencies' operations. The attack exploited their privileged access, allowing them to bypass existing controls and inflict lasting operational and data loss consequences. This incident highlights how trusted insiders with sufficient technical skills and unresolved grievances can weaponize their access against public-sector organizations, exposing gaps in monitoring and segmentation. Insider-powered destructive attacks are on the rise globally, targeting both public and private sectors with increasing sophistication. In a climate of heightened regulatory expectations and increasing adoption of zero trust models, this incident demonstrates the urgency to strengthen monitoring, privileged access controls, and anomaly detection to detect and prevent similar threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Intellexa 2024: Spyware Supply Chains Now Targeting Executives Worldwide
Impact· medium

Intellexa 2024: Spyware Supply Chains Now Targeting Executives Worldwide

In 2024, investigators identified a sprawling global network linked to Intellexa, a major commercial spyware developer behind the Predator malware platform. Entities across multiple countries—including the Czech Republic, Kazakhstan, and the Philippines—were found facilitating the shipment and deployment of Intellexa’s surveillance products to government and private sector customers. Notably, targeting expanded beyond civil society to include executives and high-value private sector individuals, with infection vectors leveraging ad-based mechanisms such as the 'Aladdin' platform. This growing balkanized ecosystem enables strategic intelligence gathering, while obfuscating operator and client identities. This incident reflects intensifying arms-race dynamics in the mercenary spyware market, characterized by increased secrecy, proliferation to jurisdictions with weak oversight, and exposure of private sector leaders. The expanding reach and impact have raised urgent concerns over regulatory gaps, legal liability, and escalating risks to both individual privacy and organizational resilience.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical React Flaw Puts Cloud Supply Chains at Immediate Risk
Impact· low

Critical React Flaw Puts Cloud Supply Chains at Immediate Risk

In June 2024, multiple severe vulnerabilities (CVSS 10.0) were discovered in the React JavaScript library, widely used by more than a third of cloud service providers. The flaws, which have been assigned two CVEs, could enable supply-chain attacks by allowing attackers to execute unauthorized code through compromised package updates or dependencies. If exploited, these vulnerabilities may lead to credential theft, lateral movement, and unauthorized access to sensitive cloud workloads, severely impacting the confidentiality and integrity of customer data. Cloud providers were urged to apply emergency patches and audit their environments for suspicious activity. This incident exemplifies the increasing risk posed by software supply-chain vulnerabilities, particularly as critical open-source components underpin cloud and enterprise infrastructures. The speed and scale of exploitation have raised concerns with regulators and CISOs, highlighting escalating threats to core cloud services and compliance programs.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Student Breach: Compromised Gov't and University Access Sold to Chinese Actors (2024)
Impact· medium

Student Breach: Compromised Gov't and University Access Sold to Chinese Actors (2024)

In early 2024, cyber investigators uncovered a scheme in which a student was selling fully compromised access to high-value government and university websites, predominantly to Chinese threat actors. The access, peddled through underground forums for several hundred dollars apiece, enabled buyers to exploit web server vulnerabilities, deploy malware, and potentially exfiltrate sensitive institutional and personal data. These breaches highlighted significant weaknesses in internal access controls and malware detection at academic and government institutions, risking the integrity of core systems, sensitive research, and regulated personal information. The incident underscores ongoing operational and reputational risks for public sector organizations, particularly where student employees or contractors bypass internal protections. This breach is emblematic of an emerging trend—threat actors leveraging insiders or poorly vetted contractors to facilitate lateral movement targeting valuable educational and governmental data. As ransomware groups and state-sponsored adversaries shift toward supply chain and identity-driven compromise, robust zero trust controls and network segmentation are becoming essential to preempt similar attacks.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
PRC State Actors Compromise Public Sector with BRICKSTORM Malware
Impact· medium

PRC State Actors Compromise Public Sector with BRICKSTORM Malware

In late 2025, PRC state-sponsored cyber actors launched a sophisticated espionage campaign using the BRICKSTORM malware, targeting government and information technology sectors. The threat actors gained initial access via a compromised web server in victim DMZs, progressed laterally to internal VMware vCenter servers, and deployed BRICKSTORM to maintain deep persistence in both VMware vSphere and Windows environments. Leveraging advanced encrypted communication channels, stolen credentials, and techniques such as DNS-over-HTTPS and rogue virtual machines, the actors exfiltrated sensitive data while evading detection for extended periods. This incident underscores the evolving tactics of nation-state adversaries, who now frequently employ modular, stealthy malware to attack critical infrastructure. The widespread use of cloud and virtualization platforms in public sector IT environments makes these organizations particularly vulnerable to such persistent threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Insider Threat at Opexus: Twin Contractors Breach US Federal Agency Data in 2024
Impact· high

Insider Threat at Opexus: Twin Contractors Breach US Federal Agency Data in 2024

In February 2024, twin brothers Muneeb and Sohaib Akhter exploited their privileged positions as contractors at Opexus, a government IT provider, to compromise, steal, and destroy sensitive data belonging to more than 45 federal agencies, including the Department of Homeland Security, IRS, and EEOC. The attack occurred minutes after the brothers were terminated, leveraging insider access to delete 96 critical databases, extract personally identifiable information, and disrupt ongoing investigations. Their methods reportedly included using AI to cover their tracks by clearing system and audit logs. The incident triggered a major federal investigation and prompted urgent responses from affected agencies, highlighting the impact of trusted insider abuse on national operations. This breach exemplifies a growing trend of insider threats exploiting technical know-how and elevated access during termination events, intensified by the use of generative AI tools to evade detection. The case underscores the critical need for organizations handling sensitive federal data to implement rigorous access controls, continuous monitoring, and rapid offboarding processes to mitigate potential insider-driven damage.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Supply Chain Attack: Malicious Rust Crate Targets Web3 Developer Ecosystems
Impact· medium

Supply Chain Attack: Malicious Rust Crate Targets Web3 Developer Ecosystems

In April 2025, cybersecurity researchers identified a malicious Rust package named "evm-units" that was uploaded to crates.io, the central Rust package registry. Disguised as an Ethereum Virtual Machine (EVM) helper tool, the crate targeted developers working in Web3 environments across Windows, macOS, and Linux systems. Once installed, the package stealthily executed OS-specific malware to compromise developer endpoints, enabling threat actors to potentially gain access to sensitive credentials and project intellectual property. The incident underscores sophisticated, hard-to-detect supply chain tactics exploiting trusted ecosystems and automated developer workflows. This attack highlights the increasing prevalence of supply chain threats targeting open source development pipelines and blockchain ecosystems. Recent trends show attackers adapting to security controls by embedding malware into widely used software components, pressuring organizations to enhance package vetting, anomaly detection, and Zero Trust strategies.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Raptor Framework: AI-Powered Exploit and Patch Creation Disrupts Vulnerability Management
Impact· low

Raptor Framework: AI-Powered Exploit and Patch Creation Disrupts Vulnerability Management

In June 2024, security researchers publicly released the Raptor Framework, an open source AI-powered toolkit capable of autonomously generating both exploit code for software vulnerabilities and their corresponding security patches. Leveraging large language models (LLMs) and novel prompting techniques, the framework orchestrates agentic AI workflows to iterate, test, and refine functional exploit and remediation code at scale. While initially intended for defensive and research use, the dual-use nature of Raptor means malicious actors could similarly employ it to accelerate exploit development or enable broader, automated vulnerability discovery across cloud and on-prem environments. The release of the Raptor Framework highlights urgent concerns around weaponized AI and the rapid democratization of advanced cyber capabilities. Security leaders must act now, as similar agentic LLM tools could fuel faster attack cycles, strain patching processes, and escalate regulatory scrutiny around software security and responsible AI use.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
GlassWorm Returns: 2025 Supply Chain Attack on Developer Tool Extensions
Impact· low

GlassWorm Returns: 2025 Supply Chain Attack on Developer Tool Extensions

In late 2025, the malicious campaign known as GlassWorm reemerged, infiltrating the Microsoft Visual Studio Marketplace and Open VSX with 24 rogue extensions disguised as legitimate developer tools such as Flutter, React, Tailwind, Vim, and Vue. By impersonating trusted tools, GlassWorm tricked developers into installing compromised extensions containing hidden payloads. Once embedded, these extensions established command-and-control communication over the Solana blockchain and enabled threat actors to perform code exfiltration, credential harvesting, and potentially insert backdoors into enterprise codebases, causing major risks for organizations leveraging these tools in their software supply chain. This incident underscores the ongoing and evolving risk of supply chain attacks targeting popular software development ecosystems. With developers as high-value targets, adversaries are increasingly sophisticated in exploiting marketplaces and open-source repositories to distribute malicious code, highlighting the urgent need for stronger validation, monitoring, and zero trust controls in software development lifecycles.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Law Enforcement Dismantles Cryptomixer, Deals Major Blow to Ransomware Laundering Networks
Impact· medium

Law Enforcement Dismantles Cryptomixer, Deals Major Blow to Ransomware Laundering Networks

In June 2024, a coalition of European law enforcement agencies successfully disrupted Cryptomixer, a cryptocurrency mixing service allegedly used to launder proceeds from ransomware and cybercrime. Authorities seized infrastructure and millions in digital assets linked to illicit transactions, following months of cross-border investigation and digital forensics. Cryptomixer was reportedly favored by ransomware groups to obfuscate the trail of stolen funds, complicating recovery efforts and hampering international financial tracking of illicit operations. This incident underscores the escalation of law enforcement action against cryptographic financial laundering tools, which remain instrumental to cybercriminal operations. Increasing scrutiny and regulatory collaboration highlight a growing intolerance for shadow financial ecosystems enabling ransomware and cyber extortion.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Tomiris Unleashes 'Havoc': 2024 CIS Government Cyber-Espionage Explained
Impact· medium

Tomiris Unleashes 'Havoc': 2024 CIS Government Cyber-Espionage Explained

In early 2024, the Russian-speaking APT group Tomiris launched a sophisticated cyber-espionage campaign targeting government and diplomatic organizations in several CIS nations and Central Asia. Attackers leveraged new malware tools and refined tactics, initially gaining access via spear-phishing and malicious email attachments designed to exploit trust within diplomatic correspondence chains. Once inside, the group deployed covert tools for lateral movement, maintained persistence, and exfiltrated sensitive diplomatic communications and internal documents. The breach had significant operational security implications, exposing strategic discussions and potentially undermining ongoing government initiatives. This incident exemplifies the ongoing risk posed by advanced persistent threats in geopolitical hotspots, with Tomiris demonstrating evolving tradecraft and adaptability. Organizations are urged to review east-west security, segmentation, and monitoring practices as similar espionage campaigns are increasingly targeting public sector networks.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
North Korea’s ‘Contagious Interview’ npm Supply Chain Attack Disrupts Developer Ecosystem
Impact· medium

North Korea’s ‘Contagious Interview’ npm Supply Chain Attack Disrupts Developer Ecosystem

In October 2023, North Korean state-sponsored threat actors launched an extensive supply chain attack by distributing over 197 malicious npm packages, collectively accumulating more than 31,000 downloads. These attackers, using tactics known as the 'Contagious Interview,' targeted software developers, especially those active in open-source environments, by delivering trojanized code through compromised npm modules. The campaign aimed to infiltrate developer systems, steal sensitive information, and establish persistent access to downstream enterprise networks, significantly raising the risk to downstream software supply chains and CI/CD pipelines. This incident is especially notable for its scale, rapid spread, and focus on highly trusted open-source ecosystems, underscoring an alarming trend in software supply chain attacks. Organizations are urged to strengthen controls around package management, implement zero trust principles, and increase monitoring of development infrastructure to defend against similar threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports