✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Critical Security Vulnerabilities in LangChain and LangGraph: Immediate Action Required
In early 2026, multiple security vulnerabilities were identified in LangChain and LangGraph, two widely used open-source frameworks for building applications powered by Large Language Models (LLMs). These vulnerabilities include Server-Side Request Forgery (SSRF) in LangChain versions prior to 1.2.11, Regular Expression Denial-of-Service (ReDoS) in versions up to 0.3.1, and a critical Remote Code Execution (RCE) flaw in LangGraph's caching layer before version 4.0.0. Exploitation of these vulnerabilities could lead to unauthorized access to sensitive data, execution of arbitrary code, and potential system compromise. ([stack.watch](https://stack.watch/product/langchain-ai/langchain/?utm_source=openai)) The discovery of these vulnerabilities underscores the importance of rigorous security practices in the development and maintenance of AI frameworks. As LLM-powered applications become increasingly prevalent, ensuring the security of underlying frameworks is crucial to prevent potential exploitation by malicious actors.
4 months ago
Kill Chain
Open VSX Registry's 2026 GlassWorm Supply Chain Attack: A Wake-Up Call for Extension Security
In January 2026, the Open VSX Registry, a vendor-neutral extension marketplace for Visual Studio Code, experienced a significant supply chain attack. Threat actors compromised a legitimate publisher's account to distribute malicious updates to four popular extensions, collectively downloaded over 22,000 times. These updates deployed the GlassWorm malware, specifically targeting macOS users by exfiltrating sensitive data such as browser cookies, cryptocurrency wallets, and developer credentials. The malware utilized sophisticated evasion techniques, including locale checks and blockchain-based command-and-control mechanisms, to avoid detection and dynamically manage its infrastructure. ([securityweek.com](https://www.securityweek.com/open-vsx-publisher-account-hijacked-in-fresh-glassworm-attack/?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks within open-source ecosystems, highlighting the critical need for robust security measures in extension marketplaces. In response, the Eclipse Foundation, which maintains the Open VSX Registry, has announced plans to implement pre-publication security checks to proactively identify and mitigate malicious extensions before they reach users. ([thehackernews.com](https://thehackernews.com/2026/02/eclipse-foundation-mandates-pre-publish.html?utm_source=openai))
4 months ago
Kill Chain
TeamPCP's Malicious 'telnyx' PyPI Attack Exposes Supply Chain Vulnerabilities
In March 2026, the threat actor group TeamPCP executed a supply chain attack by uploading two malicious versions (4.87.1 and 4.87.2) of the 'telnyx' Python package to the Python Package Index (PyPI). These versions concealed credential-stealing malware within .WAV files, enabling the exfiltration of sensitive data from compromised systems. The attack underscores the vulnerability of open-source repositories to sophisticated supply chain compromises. This incident highlights the escalating trend of attackers targeting widely used open-source packages to distribute malware, emphasizing the need for enhanced vigilance and security measures in software supply chains.
4 months ago
Kill Chain
Coruna iOS Exploit Framework: Evolution from Espionage to Cybercrime
In 2025, the Coruna exploit kit emerged as a sophisticated tool targeting iPhones running iOS versions 13.0 through 17.2.1. Initially observed in February 2025, it was used by a surveillance vendor's client, later appearing in attacks by Russian espionage groups against Ukrainian users, and subsequently by financially motivated Chinese hackers. Coruna comprises five full iOS exploit chains leveraging 23 vulnerabilities, including CVE-2023-32434 and CVE-2023-38606, previously exploited in Operation Triangulation. The kit's evolution suggests a continuous development from earlier frameworks, now capable of compromising modern hardware, including Apple's A17 and M3 chips. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/03/03/coruna-ios-exploit-kit/?utm_source=openai)) The proliferation of Coruna underscores the escalating risk of advanced exploit kits transitioning from state-sponsored espionage to widespread cybercrime. This trend highlights the urgent need for organizations to implement robust security measures, including timely software updates and advanced threat detection systems, to mitigate the risks posed by such sophisticated tools.
4 months ago
Kill Chain
International Operation Dismantles LeakBase Cybercrime Forum in 2026
In early March 2026, an international law enforcement operation led by the FBI and Europol dismantled LeakBase, one of the world's largest cybercrime forums. Established in 2021, LeakBase had over 142,000 members and facilitated the trade of stolen data, including account credentials and financial information. The coordinated effort spanned 14 countries, resulting in the seizure of the forum's domains and databases, as well as multiple arrests and searches targeting the platform's most active users. This operation underscores the growing global collaboration in combating cybercrime and highlights the increasing focus on dismantling platforms that facilitate the sale of stolen data. The takedown of LeakBase serves as a significant deterrent to cybercriminals and emphasizes the importance of international cooperation in addressing the evolving cyber threat landscape.
4 months ago
Kill Chain
Critical Langflow RCE Vulnerability (CVE-2026-33017) Exploited in the Wild
In March 2026, a critical remote code execution (RCE) vulnerability, identified as CVE-2026-33017, was discovered in Langflow, an open-source framework for building AI workflows. This flaw allows unauthenticated attackers to execute arbitrary Python code on affected servers by sending crafted HTTP requests to the unsandboxed flow execution endpoint. The vulnerability affects Langflow versions 1.8.1 and earlier, potentially leading to full system compromise, data theft, and unauthorized access to sensitive information. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-27966/?utm_source=openai)) The rapid exploitation of this vulnerability underscores the increasing targeting of AI development tools by threat actors. Organizations utilizing Langflow are urged to upgrade to version 1.9.0 or later, which addresses this security issue. Additionally, it is recommended to disable or restrict access to the vulnerable endpoint, monitor for suspicious activity, and rotate API keys and credentials to mitigate potential risks. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-27966/?utm_source=openai))
4 months ago
Kill Chain
LiteLLM Supply Chain Attack: A Wake-Up Call for Open-Source Security
In March 2026, the widely used Python library LiteLLM was compromised in a supply chain attack. Threat actors, identified as TeamPCP, gained access to the LiteLLM account and released malicious versions 1.82.7 and 1.82.8 on the PyPI repository. These versions contained backdoors that harvested sensitive data, including SSH keys, cloud tokens, Kubernetes secrets, and crypto wallets. The malware also attempted lateral movement across Kubernetes clusters by deploying privileged pods and established persistence via systemd backdoors. ([techradar.com](https://www.techradar.com/pro/security/top-llm-pypl-package-compromised-to-steal-user-details-heres-what-we-know?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting open-source software repositories. The compromise of LiteLLM, a tool integral to AI model management, highlights the critical need for enhanced security measures in software development pipelines to prevent similar breaches.
4 months ago
Kill Chain
Critical Vulnerability in Anthropic's Claude Chrome Extension Highlights AI Security Risks
In March 2026, a critical vulnerability was discovered in Anthropic's Claude Chrome Extension, allowing malicious actors to inject prompts into the assistant without user interaction. This zero-click cross-site scripting (XSS) flaw enabled attackers to execute arbitrary commands by embedding malicious code into web pages, leading to potential data exfiltration and unauthorized actions. The vulnerability was promptly addressed by Anthropic through an emergency patch, mitigating the risk to users. This incident underscores the growing threat landscape associated with AI-powered browser extensions. As these tools become more integrated into daily workflows, they present new vectors for exploitation. Organizations must remain vigilant, ensuring that such extensions are regularly updated and monitored for security vulnerabilities to prevent similar attacks.
4 months ago
Kill Chain
Unveiling Red Menshen's 2026 BPFDoor Espionage in Telecom Networks
In 2026, the China-linked threat actor Red Menshen, also known as Earth Bluecrow, conducted a prolonged cyber espionage campaign targeting telecommunications networks across the Middle East and Asia. Utilizing the stealthy Linux backdoor BPFDoor, the group infiltrated critical infrastructure, including Home Subscriber Servers (HSS), to exfiltrate sensitive subscriber data. BPFDoor's advanced evasion techniques allowed it to bypass traditional security measures, enabling Red Menshen to maintain persistent access and conduct surveillance undetected for extended periods. This incident underscores the increasing sophistication of nation-state cyber threats targeting telecom infrastructure. The use of kernel-level implants and passive backdoors like BPFDoor highlights the need for enhanced detection capabilities and proactive security measures to protect critical communication networks from such covert operations.
4 months ago
Kill Chain
Unveiling the Scarlet Goldfinch 2025 ClickFix Malware Campaign
In 2025, the Scarlet Goldfinch threat actor launched a sophisticated malware campaign utilizing the ClickFix social engineering technique. This method deceived users into executing malicious commands under the guise of routine system verifications, leading to the installation of NetSupport Manager, a remote access tool. The campaign primarily targeted Windows systems, exploiting compromised websites to display fake browser update prompts, which, when acted upon, initiated the malware download and execution process. ([redcanary.com](https://redcanary.com/threat-detection-report/threats/scarlet-goldfinch/?utm_source=openai)) The significance of this incident lies in the evolution of social engineering tactics, highlighting the increasing sophistication of threat actors in bypassing traditional security measures. The widespread use of ClickFix underscores the necessity for enhanced user education and the implementation of robust security protocols to mitigate such deceptive attack vectors.
4 months ago
Kill Chain
RedLine Infostealer Developer Extradited to US in 2026
In March 2026, international law enforcement agencies successfully extradited Hambardzum Minasyan, an Armenian national, to the United States for his alleged involvement in the development and administration of the RedLine infostealer malware. RedLine, active since 2020, has been one of the most prevalent data-stealing malware variants, responsible for compromising millions of devices worldwide. Minasyan faces charges including conspiracy to commit access device fraud, conspiracy to violate the Computer Fraud and Abuse Act, and conspiracy to commit money laundering. The indictment alleges that he registered virtual private servers to host RedLine, established repositories for distributing the malware, and managed cryptocurrency accounts to receive payments from affiliates. This extradition marks a significant step in the ongoing efforts to dismantle cybercriminal networks operating on a global scale. The arrest and extradition of Minasyan underscore the persistent threat posed by infostealer malware like RedLine. Despite previous takedown operations, such as Operation Magnus in 2024, which targeted RedLine's infrastructure, the malware continues to be a tool for cybercriminals to steal sensitive information, including login credentials, financial data, and cryptocurrency wallets. Organizations must remain vigilant, as the convergence of infostealers and other cyber threats, like ransomware, has led to rapid extortion chains, emphasizing the need for robust cybersecurity measures and international cooperation to combat these evolving threats.
4 months ago
Kill Chain
TA551 Botnet Manager Sentenced for Ransomware Attacks
In March 2026, Ilya Angelov, a Russian national and co-manager of the cybercriminal group TA551 (also known as Shathak or GOLD CABIN), was sentenced to two years in prison. Angelov's group operated a massive botnet that distributed malware through large-scale phishing campaigns, leading to ransomware attacks on 72 U.S. companies between 2018 and 2019. These attacks resulted in over $14 million in extortion payments. The botnet infected approximately 3,000 computers daily at its peak, facilitating the deployment of ransomware such as BitPaymer. This sentencing underscores the persistent threat posed by sophisticated cybercriminal organizations like TA551, which have been active since at least 2018. Their use of phishing campaigns to distribute malware highlights the critical need for organizations to implement robust email security measures and user awareness training to mitigate such risks.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports