Industry Category

Computer/Network Security

Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.

1048 threat reports
Page 85 of 88

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Computer/Network Security Threat Reports

Showing 10091020 / 1048 reports
AT&T 2023: How Salt Typhoon Changed the APT Playbook
Impact· medium

AT&T 2023: How Salt Typhoon Changed the APT Playbook

In 2023, the telecommunications giant AT&T was targeted by the advanced persistent threat group Salt Typhoon, which launched a sophisticated campaign exploiting unconventional vulnerabilities. Unlike conventional attacks, Salt Typhoon focused on endpoints lacking robust detection and response (EDR), hunted for network blind spots with minimal logging, and engaged in 'living off the land' attacks—leveraging legitimate administrative tools to evade detection and persist inside networks. This multi-pronged methodology enabled deep network infiltration before discovery, ultimately jeopardizing sensitive data and service availability across AT&T’s infrastructure. Following the breach, the company reported the threat group was successfully evicted from its systems. This incident has set a precedent, with numerous threat actors now adopting Salt Typhoon’s tactics to bypass traditional security controls. The breach highlights an urgent need for organizations to enhance monitoring, bolster endpoint visibility across all platforms, and adapt defenses for evolving attacker methodologies in critical infrastructure sectors.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fake Password Managers Spread AMOS Malware on Mac: The 2025 LastPass Incident
Impact· medium

Fake Password Managers Spread AMOS Malware on Mac: The 2025 LastPass Incident

In September 2025, LastPass reported an ongoing malware campaign targeting macOS users with fake password managers distributed through fraudulent GitHub repositories and deceptive SEO-optimized links. The attackers impersonated over 100 popular software products—including LastPass, 1Password, Dropbox, and others—using build-your-own repositories that redirected victims to install scripts containing the Atomic (AMOS) infostealer malware. Victims were instructed to run shell commands that downloaded backdoored payloads, risking credential theft, data exfiltration, and sustained system compromise. The campaign employed automated methods for rapid replication and evasive takedown resistance. This incident underscores a surge in supply chain and social engineering attacks using open platforms and SEO abuse, highlighting the persistent vulnerabilities in software distribution channels for macOS. It demonstrates attackers' growing sophistication in exploiting user trust and platform discoverability to deploy credential-stealing malware at scale.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
EDR-Freeze: Novel Windows WER Technique Suspends EDR and Antivirus Tools
Impact· medium

EDR-Freeze: Novel Windows WER Technique Suspends EDR and Antivirus Tools

In September 2025, a security researcher revealed a novel user-mode evasion technique leveraging Windows Error Reporting (WER) to suspend the operation of Endpoint Detection & Response (EDR) and antivirus software. The proof-of-concept tool, EDR-Freeze, exploits a race condition by combining the WerFaultSecure component with the MiniDumpWriteDump API. Attackers can indefinitely freeze security processes by suspending WerFaultSecure precisely as it is executing a memory dump of the target, effectively leaving EDR or AV tools inert without requiring kernel-level vulnerabilities. This design weakness bypasses typical Bring Your Own Vulnerable Driver (BYOVD) defences and leaves minimal forensic evidence. This incident underscores the increasing sophistication of EDR evasion by cyber adversaries, who are rapidly adopting stealthy, native Windows attack chains. Organizations must adapt detection and monitoring practices to keep pace as user-mode bypasses erode longstanding layers of endpoint protection. The wider prevalence of such techniques signals a strategic shift in attacker tradecraft and compels a reassessment of endpoint hardening and response automation.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
DPRK Leverages ClickFix Job Scams to Infest Crypto Firms with BeaverTail Infostealer
Impact· low

DPRK Leverages ClickFix Job Scams to Infest Crypto Firms with BeaverTail Infostealer

In September 2025, threat actors linked to North Korea (DPRK) orchestrated a targeted phishing campaign leveraging ClickFix-style lures against employees in the cryptocurrency and retail sectors. Masquerading as legitimate job opportunities for marketing and trader roles, attackers distributed malicious files leading to infection with BeaverTail and InvisibleFerret malware. This allowed adversaries to employ infostealing techniques, facilitating lateral movement and potential data exfiltration, while avoiding traditional security controls. The campaign highlights DPRK’s continued focus on crypto-enabled theft, using sophisticated social engineering, custom tooling, and industry-specific targeting. This incident underscores a recent surge in state-sponsored campaigns prioritizing non-technical roles and leveraging advanced lure techniques. Organizations in high-value verticals like crypto are increasingly attractive to financially motivated adversaries, elevating the urgency for zero trust defenses and robust internal traffic security controls.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Canada Seizes $40 Million in Historic Crackdown on TradeOgre Crypto Exchange
Impact· high

Canada Seizes $40 Million in Historic Crackdown on TradeOgre Crypto Exchange

In September 2025, the Royal Canadian Mounted Police (RCMP) dismantled the TradeOgre cryptocurrency exchange, seizing over $40 million in digital assets linked to alleged financial crimes. The operation was initiated following intelligence from Europol, leading to an investigation by the Money Laundering Investigative Team (MLIT) that uncovered the exchange's lack of regulatory compliance, such as evading Know Your Customer (KYC) protocols and failing to register with Canada's FINTRAC. The lack of oversight facilitated the laundering of cybercrime proceeds, particularly via privacy-focused cryptocurrencies like Monero, culminating in the country's largest-ever asset seizure. This incident underscores the growing scrutiny and regulatory pressure on privacy-centric platforms facilitating anonymous digital transactions. The enforcement action highlights heightened law enforcement capabilities targeting underground exchanges and reflects broader trends in global efforts to curb illicit finance within the crypto sector.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
MalTerminal: GPT-4-Powered Malware Signals New Era of AI Cyberattacks
Impact· high

MalTerminal: GPT-4-Powered Malware Signals New Era of AI Cyberattacks

In September 2025, SentinelOne’s SentinelLABS revealed the existence of 'MalTerminal,' the first documented malware leveraging GPT-4-powered Large Language Model (LLM) capabilities. Demonstrated at LABScon 2025, MalTerminal introduces LLM-driven automation within the malware lifecycle—enabling it to generate ransomware payloads, establish reverse shells, and craft social engineering content in real time. The attack method shows that malware authors are blending AI models directly into code to rapidly escalate privilege, automate lateral movement, and obfuscate command-and-control traffic. Business impact includes advanced, adaptive attacks that defeat legacy detection, heightening risks of data exfiltration, extended dwell time, and operational disruption. MalTerminal’s emergence is a bellwether for the rapid weaponization of generative AI technology by threat actors. This incident highlights the urgent need for organizations to re-evaluate traditional controls and accelerate adoption of cognitive security, visibility, and real-time policy enforcement frameworks to keep pace with evolving adversary techniques.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
LastPass Exposes macOS Atomic Infostealer Attack via Fake GitHub Repositories
Impact· high

LastPass Exposes macOS Atomic Infostealer Attack via Fake GitHub Repositories

In mid-2025, LastPass identified and warned users about a sophisticated information-stealing campaign targeting Apple macOS users. Attackers set up fraudulent GitHub repositories impersonating reputable projects, including LastPass, to distribute versions of the 'Atomic' infostealer malware. Unsuspecting users downloading these fake tools had their credentials, browser data, and sensitive files compromised. The campaign leveraged social engineering, search poisoning, and open-source developer trust to infiltrate victims’ systems, posing significant risk to both individual and enterprise security. The incident highlights continued abuse of trusted development platforms to target the software supply chain. This breach is noteworthy as it reflects the growing trend of attacker focus on macOS endpoints and the exploitation of open-source ecosystems. With supply chain attacks and infostealer campaigns rising sharply in 2025, organizations face increasing pressure to enhance their controls for code provenance, user awareness, and endpoint defense.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Gamaredon & Turla: Joint APT Campaign Strikes Ukraine in 2025
Impact· medium

Gamaredon & Turla: Joint APT Campaign Strikes Ukraine in 2025

In early 2025, a previously unseen collaboration between advanced persistent threat groups Gamaredon and Turla was discovered in Ukraine. Utilizing ESET telemetry, researchers identified co-compromises in which Gamaredon provided initial access using spearphishing and malicious PowerShell-based tools (such as PteroGraphin and PteroOdd), allowing Turla to deploy its exclusive Kazuar backdoor on select high-value targets. The attacks, attributed to Russian FSB-linked groups, targeted governmental entities and leveraged encrypted channels, PowerShell scripting, and multi-stage malware delivery via compromised web services and cloud platforms. Impact was mainly concentrated on the potential exfiltration of sensitive national intelligence. This incident underscores a growing trend of threat actor collaboration within nation-state cyber operations, blurring lines between operational roles and increasing attack efficiency. The overlapping TTPs and use of novel access and persistence mechanisms signal heightened complexity in the Eastern European threat landscape, demanding urgent operational and strategic defensive improvements.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
UNC1549: Iranian Cyber Espionage Breaches 11 European Telecoms Using LinkedIn Lures
Impact· medium

UNC1549: Iranian Cyber Espionage Breaches 11 European Telecoms Using LinkedIn Lures

In mid-2025, an Iran-affiliated cyber espionage group tracked as UNC1549 executed a coordinated attack targeting 11 European telecommunications firms. Using LinkedIn job recruitment lures and the custom MINIBIKE malware, the attackers successfully infiltrated 34 devices within these organizations, gaining persistent access to sensitive internal systems. The campaign, discovered by Swiss cybersecurity company PRODAFT, leveraged sophisticated social engineering alongside stealthy lateral movement, indicating considerable operational capability and intent to harvest confidential information potentially valuable for nation-state interests. This incident underscores a rising trend of strategic supply chain and telecom attacks using spear phishing and novel malware, highlighting the importance of strong east-west traffic controls and threat detection. It also reflects growing geopolitical tensions fueling state-sponsored cyber campaigns against critical infrastructure in Europe.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SonicWall 2024 Breach: Firewall Backup Data Compromised in MySonicWall Attack
Impact· high

SonicWall 2024 Breach: Firewall Backup Data Compromised in MySonicWall Attack

In June 2024, SonicWall confirmed that threat actors breached its MySonicWall portal and gained unauthorized access to a set of firewall backup configuration files. The attackers were able to obtain configuration data belonging to less than 5% of customers through this service, which could potentially reveal sensitive network information such as network structures, credentials, and policy configurations. SonicWall indicated that the breach was swiftly detected, affected accounts were notified, and the scope was limited, but details regarding the initial attack vector or threat actor remain undisclosed. This incident comes at a time of heightened targeting of network infrastructure management portals and supply chain entry points. As attackers increasingly look to exploit enterprise-grade device management platforms, organizations must reinforce segmentation, monitor lateral movements in east-west traffic, and continually validate zero trust architectures across all privileged network and cloud control panels.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
SonicWall MySonicWall Breach Puts Firewall Backups and Credentials at Risk
Impact· medium

SonicWall MySonicWall Breach Puts Firewall Backups and Credentials at Risk

In September 2025, SonicWall disclosed a security incident impacting its MySonicWall cloud platform, where firewall configuration backup files were accessed by threat actors following a series of brute-force attacks. The breach, affecting less than 5% of SonicWall firewalls, exposed configuration data that included encrypted passwords and sensitive information, potentially easing future exploitation of affected devices. SonicWall responded by disabling unauthorized access, notifying affected customers, and issuing urgent guidance to reset credentials, keys, and secrets for all related accounts and services. The vendor also coordinated with cybersecurity and law enforcement agencies as part of its investigation. This incident highlights a rising trend of attackers targeting cloud-based administrative services and configuration backups, exploiting brute-force methods and known vulnerabilities such as CVE-2024-40766. Organizations face increased pressure to secure not only device firmware but also backup repositories and credentials, underscoring the persistent threat of credential-based and configuration compromise attacks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Salesloft Drift Salesforce Breach 2025: OAuth Supply Chain Attack Exposes 1.5 Billion Records
Impact· high

Salesloft Drift Salesforce Breach 2025: OAuth Supply Chain Attack Exposes 1.5 Billion Records

In September 2025, the ShinyHunters extortion group, in collaboration with affiliates Scattered Spider and Lapsus$, claimed responsibility for a massive data breach targeting Salesforce via compromised OAuth tokens from Salesloft Drift integrations. By exploiting the tokens exposed in Salesloft's breached GitHub repository, the attackers accessed and exfiltrated approximately 1.5 billion records from 760 organizations, including sensitive CRM, support, and user data. The incident demonstrated sophisticated use of social engineering, malicious OAuth apps, and credential-harvesting across major cloud platforms, with the attackers leveraging the stolen information for extortion and potential lateral movement. This breach is emblematic of the growing threat from identity-based attacks and supply chain compromise targeting SaaS ecosystems. Attackers leveraging OAuth abuse, stolen developer secrets, and interconnected cloud services create highly scalable data theft risks, driving regulatory focus and pushing organizations to revisit zero trust and access management frameworks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports