Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Teen Hacker, Scattered Spider, and the 2023 Vegas Casino Ransomware Crisis
In late summer and early fall 2023, Las Vegas casinos MGM Resorts and Caesars Entertainment suffered major cyberattacks conducted by the Scattered Spider threat group, including at least one 17-year-old suspect. Attackers gained network access via social engineering and lateral movement, ultimately deploying BlackCat/ALPHV ransomware. The incidents led to severe operational disruption, significant financial losses exceeding $100 million for MGM, a $15 million ransom paid by Caesars, and exposure of sensitive customer and employee data. Law enforcement identified and apprehended one teenage perpetrator, who was later released to parental custody pending trial. This high-profile case highlights the growing trend of sophisticated, identity-driven ransomware attacks launched by younger, tech-savvy threat actors and hacking collectives. It underscores the urgent need for organizations to close internal security gaps, improve zero trust posture, and address the challenges of compliance amid increasingly aggressive and disruptive ransomware campaigns.
8 months ago
Kill Chain
Malicious Rust Crates on Crates.io Compromise Developer Crypto Wallets in 2025
In September 2025, security researchers uncovered two malicious Rust packages, 'faster_log' and 'async_println', uploaded to the official Crates.io repository. These packages, downloaded nearly 8,500 times, masqueraded as legitimate logging libraries but secretly scanned developers' machines for cryptocurrency wallet private keys and other sensitive secrets. The attackers used cloned documentation and authentic functionality to evade suspicion, while an embedded payload exfiltrated discovered secrets to a hardcoded Cloudflare Worker endpoint controlled by the threat actors. Upon discovery, Crates.io removed the packages and banned the associated users, mitigating the immediate threat. This incident demonstrates the persistent risk posed by supply chain attacks targeting open-source repositories and the increasing focus of cybercriminals on cryptocurrency theft. It underscores the need for rigorous vetting, enhanced code scanning, and heightened awareness among developers regarding open-source dependencies.
8 months ago
Kill Chain
APT Campaign Exploits Cisco ASA Zero-Days: Persistent Threats to Government Devices in 2025
In September 2025, U.S. federal agencies were ordered by CISA to urgently patch Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices after two critical zero-day vulnerabilities (CVE-2025-20333, CVE-2025-20362) were exploited by the APT group UAT4356 (STORM-1849). Attackers achieved unauthenticated remote code execution and persistent control by manipulating device ROMMON, deploying malware such as LINE VIPER and the RayInitiator bootkit to facilitate malware implants, command execution, and possible data exfiltration. The campaign, linked to the larger ArcaneDoor operation, threatened essential government and global infrastructure by allowing full device compromise, evasion of detection, and resistance to conventional remediation steps. This incident highlights an escalating trend in sophisticated, state-linked attacks targeting edge infrastructure, often leveraging supply-chain weaknesses and persistent malware able to survive reboots and firmware updates. It also underscores renewed regulatory pressure for timely vulnerability mitigation and increased focus on Zero Trust architectures for critical sectors.
8 months ago
Kill Chain
Massive npm Supply Chain Attack: Shai-Hulud Worm Infects Hundreds of Packages
In September 2025, a major supply chain compromise hit the npm ecosystem with the discovery of the Shai-Hulud worm. Attackers leveraged malicious npm packages to propagate self-replicating malware, which spread by abusing developer credentials and update permissions across over 500 packages—including widely used libraries from organizations such as CrowdStrike. Malicious code executed on install harvested secrets, exfiltrated sensitive GitHub and cloud data, and published infected releases to additional packages, resulting in widespread risk of source code leaks, credential theft, and downstream infections. This incident typifies the escalating trend of highly automated supply chain attacks targeting open-source repositories. Such events highlight the vulnerabilities of complex dependency networks and reinforce the necessity for robust controls, automated monitoring, and zero trust policies for development and CI/CD ecosystems.
8 months ago
Kill Chain
North Korean AkdoorTea Supply Chain Attack Hits Global Crypto Developers
In September 2025, a sophisticated supply chain attack targeting the global cryptocurrency development sector was uncovered, orchestrated by North Korea-linked threat actors associated with the Contagious Interview campaign. Leveraging a newly identified backdoor named AkdoorTea—as well as tools like TsunamiKit and Tropidoor—the adversaries compromised software development environments across all major operating systems, including Windows. According to research from ESET, tracked as part of the DeceptiveDevelopment group, attackers used trojanized developer tools and social engineering tactics to infiltrate their targets and facilitate lateral movement, data theft, and potential deployment of further malware within sensitive crypto-related projects. This incident highlights the rising trend of nation-state attackers exploiting software supply chains to infiltrate innovative sectors such as cryptocurrency. It underscores the urgent need for improved east-west traffic visibility, zero trust segmentation, and threat detection controls, as organizations increasingly become targets for persistent, highly resourced adversaries.
8 months ago
Kill Chain
State-Sponsored Actors Breach Libraesva ESG via Command Injection Vulnerability
In September 2025, Libraesva disclosed a command injection vulnerability (CVE-2025-59689, CVSS 6.1) affecting its Email Security Gateway (ESG) platform, which was actively exploited by state-sponsored threat actors. Attackers leveraged maliciously-crafted email payloads to trigger remote command execution, bypassing ESG protections and potentially gaining persistent access to targeted networks. The intrusion method allowed attackers to move laterally and exfiltrate sensitive data, underscoring the risks posed by the exploitation of security appliances themselves. Libraesva released emergency patches and urged customers to upgrade immediately, as evidence emerged of ongoing targeted campaigns against critical sectors. This incident highlights the increasing use of email gateway exploits by sophisticated adversaries, aligning with a wider trend of targeting security infrastructure for initial access. With command injection flaws on the rise and ransomware operators adopting similar approaches, organizations face escalating pressure to rapidly patch vulnerabilities and reinforce segmentation and anomaly detection across their environments.
8 months ago
Kill Chain
Brickstorm: The Next-Level Chinese APT Breach Impacting SaaS & Legal Sectors in 2025
In 2025, a highly sophisticated cyberespionage campaign attributed to a suspected Chinese advanced persistent threat (APT), utilizing malware later dubbed 'Brickstorm,' successfully infiltrated multiple US legal services and tech supply chain organizations. The attackers leveraged undisclosed zero-day vulnerabilities to gain initial access, maintain exceptional stealth with average dwell times of over 400 days, and move laterally into downstream customers. Their campaign targeted proprietary source code and sensitive trade/national security intelligence, making detection challenging through advanced cleanup techniques and non-overlapping infrastructure. This incident is particularly significant as it represents a new echelon of APT supply chain intrusions, echoing a rise in strategic, multi-year campaigns focusing on SaaS and cloud intermediaries. It highlights the growing need for robust east-west visibility, zero trust segmentation, and supply chain security amid evolving TTPs that routinely outpace traditional detection and response capabilities.
8 months ago
Kill Chain
NPM Package 'Fezbox' Abused QR Codes in Sophisticated 2025 Supply Chain Attack
In September 2025, a malicious npm package named 'fezbox' was discovered utilizing QR codes as a novel delivery mechanism for cookie-stealing malware. Masquerading as a legitimate utility library on npmjs.com, the package was downloaded at least 327 times before its removal. The attack involved the package embedding a reversed URL to evade detection, which, once decoded, retrieved a dense QR code image containing obfuscated, second-stage payload code. The malware specifically targeted credentials by harvesting cookies and sending harvested credentials to a command-and-control server via HTTPS POST, only proceeding if valid username and password data were detected. This incident highlights the increasing creativity of supply-chain attackers, leveraging steganography within QR codes to bypass traditional static security tools. As QR codes become more commonplace and attackers innovate their use beyond social engineering, organizations must strengthen package vetting, threat detection, and response for open-source dependencies within their development ecosystems.
8 months ago
Kill Chain
UNC6148 Rootkit Attack on SonicWall SMA100 Devices in 2025
In September 2025, SonicWall released a critical firmware update for its SMA 100 series products in response to a sophisticated attack campaign orchestrated by threat actor UNC6148. This incident involved the deployment of the OVERSTEP user-mode rootkit on end-of-life SMA 100 devices, providing persistent unauthorized access, stealing sensitive configuration and certificate data, and enabling lateral movement. Attackers exploited vulnerabilities in legacy firmware to maintain remote access—even post firmware upgrades—compromising credentials, OTP seeds, and digital certificates, with notable overlaps to prior Abyss ransomware operations. The incident underscores the growing threat posed by ransomware groups leveraging supply chain devices and persistent malware in network appliances. With a surge in rootkit-enabled persistence and a rise in zero-day exploitations targeting network edge devices, organizations must prioritize timely patching and end-of-life device management to curb risk exposure.
8 months ago
Kill Chain
US Secret Service Seizes Massive SIM Server Network Threatening Government Officials
In September 2025, the U.S. Secret Service announced it had dismantled a large-scale illicit telecommunications infrastructure across the New York tri-state area, seizing over 300 SIM servers and 100,000 SIM cards. These devices, co-located at multiple sites, were used by unknown malicious actors to facilitate threats against U.S. government officials, particularly near the United Nations. Investigators discovered that this network enabled covert communications and potentially enabled bypasses of monitoring controls, raising national security concerns. The takedown required coordinated federal action to secure the assets, neutralize the risk, and support ongoing intelligence operations. This incident highlights the ongoing evolution and physical sophistication of threat actor infrastructure, especially targeting high-profile government personnel. The scale and automation facilitated by such hardware underline the growing intersection of physical and cyber threats and serve as a wake-up call for risk teams facing advanced, hybrid attack models.
8 months ago
Kill Chain
Fake GitHub Pages Used to Deliver Atomic Stealer to Mac Users in 2024
In early 2024, cybercriminals launched a large-scale campaign targeting macOS users by leveraging SEO poisoning, fraudulent GitHub repositories, and fake GitHub Pages to distribute the Atomic (AMOS) infostealer malware. Attackers lured users searching for popular software with malicious websites that mimicked legitimate download portals, redirecting victims to GitHub-hosted payloads. Once executed, the malware exfiltrated critical information such as credentials, browser data, cryptocurrency wallets, and system details, putting both individuals and organizations at serious risk. The campaign’s scope and reliance on open-source infrastructure enabled the threat actors to infect a wide swathe of Mac users with relative ease. This incident is particularly relevant due to the increasing prevalence of infostealer malware targeting macOS, the cunning use of SEO manipulation for initial access, and the abuse of trusted development platforms like GitHub. Security teams must be vigilant as these multi-vector attacks blend social engineering, supply chain compromise, and cloud service misuse to evade traditional defenses.
8 months ago
Kill Chain
SANS Honeypot 2024: SYN Flood Distraction Amplifies Network Reconnaissance Threat
Between March 31 and April 20, 2024, the SANS Internet Storm Center's honeypot experienced a persistent barrage of over 2.3 million TCP SYN packets in three distinct waves, mimicking a distributed denial of service (DDoS) campaign. Traffic originated from thousands of hosts—mostly within Bangladeshi and Iraqi ISPs—leveraging spoofed and potentially compromised IPs to generate low-rate, highly patterned SYN floods targeting port 443. Despite the scale, the attack's volume and packet rates were insufficient to disrupt modern services and instead appeared to serve as a diversionary tactic. This incident highlights emerging trends in network reconnaissance and distraction techniques, where attackers intentionally generate noisy traffic to mislead analysts and mask parallel or future activities. As SYN flood patterns evolve and attackers increasingly use crafted packets and IP spoofing, traditional DDoS detection and response strategies must adapt to avoid misallocation of resources or missing stealthier threats.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports