Validated Containment Architectures are here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2671 threat reports
Page 102 of 223

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 12131224 / 2671 reports
Critical Code Injection Vulnerability in Langflow's CSV Agent Node
Impact· CRITICAL

Critical Code Injection Vulnerability in Langflow's CSV Agent Node

In February 2026, a critical Remote Code Execution (RCE) vulnerability, identified as CVE-2026-27966, was discovered in Langflow, an open-source platform for building AI-powered agents and workflows. This flaw resides in the CSV Agent node, which, prior to version 1.8.0, hardcoded the parameter `allow_dangerous_code=True`, inadvertently exposing LangChain’s Python REPL tool (`python_repl_ast`). This misconfiguration allows unauthenticated attackers to execute arbitrary Python and OS commands on the server via prompt injection, leading to full system compromise. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-27966/?utm_source=openai)) The rapid exploitation of this vulnerability underscores the critical need for organizations to promptly address security flaws in AI development tools. As AI platforms become integral to business operations, ensuring their security is paramount to prevent potential data breaches and operational disruptions.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
TeamPCP's Supply Chain Attack: Unveiling the Telnyx SDK Compromise and Ransomware Expansion
Impact· HIGH

TeamPCP's Supply Chain Attack: Unveiling the Telnyx SDK Compromise and Ransomware Expansion

In March 2026, the threat actor TeamPCP executed a sophisticated supply chain attack by compromising the Telnyx Python SDK on the Python Package Index (PyPI). Malicious versions 4.87.1 and 4.87.2 were published, embedding payloads within WAV audio files—a novel steganography technique. These payloads targeted Windows systems by dropping a persistent binary named 'msbuild.exe' into the Startup folder, while Linux and macOS systems faced credential harvesting similar to previous LiteLLM compromises. Forensic analyses confirmed the use of RSA-4096 encryption and specific exfiltration patterns consistent with TeamPCP's tactics. The compromised versions were promptly quarantined by PyPI. Concurrently, TeamPCP partnered with the Vect ransomware-as-a-service operation and BreachForums, distributing affiliate keys to approximately 300,000 users, potentially enabling one of the largest coordinated ransomware deployments observed. Additionally, the LAPSUS$ group claimed a 3GB data breach of AstraZeneca, allegedly using credentials obtained through TeamPCP's activities. This breach reportedly includes internal code repositories, cloud infrastructure configurations, and employee data. Organizations affected by any phase of the TeamPCP campaign are urged to rotate credentials immediately and monitor for indicators of compromise.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
CitrixBleed 2: A Critical Vulnerability in NetScaler Appliances
Impact· CRITICAL

CitrixBleed 2: A Critical Vulnerability in NetScaler Appliances

In June 2025, Citrix disclosed a critical vulnerability (CVE-2025-5777), dubbed 'CitrixBleed 2,' affecting NetScaler ADC and Gateway appliances configured as Gateways or AAA virtual servers. This flaw allows unauthenticated attackers to perform out-of-bounds memory reads, potentially leading to session hijacking and bypassing multifactor authentication. Despite the release of patches, over 100 organizations have been compromised, and thousands of instances remain unpatched, exposing sensitive data and critical systems to unauthorized access. The rapid exploitation of CitrixBleed 2 underscores a growing trend of attackers targeting network infrastructure vulnerabilities to gain initial access. This incident highlights the urgent need for organizations to prioritize timely patch management and enhance monitoring of network appliances to mitigate the risk of similar exploits.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Bubble AI App Builder Exploited in Sophisticated Phishing Scheme
Impact· HIGH

Bubble AI App Builder Exploited in Sophisticated Phishing Scheme

In March 2026, threat actors exploited the no-code platform Bubble to create and host malicious web applications designed to steal Microsoft account credentials. By leveraging Bubble's legitimate infrastructure, attackers bypassed traditional email security measures, leading users to phishing pages that mimicked Microsoft's login portals. Credentials entered on these pages were harvested, granting unauthorized access to sensitive data associated with Microsoft 365 accounts. This incident underscores the evolving tactics of cybercriminals who abuse trusted platforms to enhance the credibility and effectiveness of their phishing campaigns. The use of AI-powered app builders in such attacks highlights the need for heightened vigilance and adaptive security measures to counteract sophisticated social engineering techniques.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Kaspersky's 2026 Security Bulletin: Navigating Persistent and Emerging Cyber Threats in Telecommunications
Impact· CRITICAL

Kaspersky's 2026 Security Bulletin: Navigating Persistent and Emerging Cyber Threats in Telecommunications

In December 2025, Kaspersky released its Security Bulletin highlighting persistent and emerging cybersecurity threats in the telecommunications sector. The report identifies four primary threat categories: Advanced Persistent Threats (APTs) aiming for long-term espionage, supply chain vulnerabilities exploiting interconnected vendor ecosystems, Distributed Denial-of-Service (DDoS) attacks affecting service availability, and SIM-enabled fraud targeting mobile networks. Additionally, the integration of new technologies such as AI-driven network management, post-quantum cryptography, and 5G-to-satellite connectivity introduces new operational risks. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/kaspersky-warns-telecom-threats-from-2025-will-carry-into-2026-as-new-technology-adds-new-risk?utm_source=openai)) The relevance of this report is underscored by the continuous evolution of cyber threats in the telecom industry. As operators adopt advanced technologies, they must address both existing and emerging risks to maintain network security and service reliability. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/kaspersky-warns-telecom-threats-from-2025-will-carry-into-2026-as-new-technology-adds-new-risk?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
TA551 2026: Russian Hacker Sentenced for Botnet-Driven Ransomware Attacks
Impact· HIGH

TA551 2026: Russian Hacker Sentenced for Botnet-Driven Ransomware Attacks

In March 2026, the U.S. Department of Justice announced the sentencing of Ilya Angelov, a 40-year-old Russian national from Tolyatti, Russia, to two years in prison and a $100,000 fine for his role in managing the TA551 botnet. Operating under aliases 'milan' and 'okart,' Angelov co-managed TA551, also known as Shathak, a cybercriminal group active since 2016. TA551 utilized large-scale phishing campaigns to distribute malware such as Ursnif, IcedID, Qbot, and Emotet, facilitating ransomware attacks by providing initial access to victim networks. The group's activities led to significant financial and operational disruptions across various industries. ([redcanary.com](https://redcanary.com/threat-detection-report/threats/ta551/?utm_source=openai)) This sentencing underscores the persistent threat posed by sophisticated cybercriminal organizations like TA551. Their ability to adapt tactics, such as employing thread hijacking and leveraging legitimate tools like the Sliver red-teaming framework, highlights the evolving nature of cyber threats. Organizations must remain vigilant, implementing robust email security measures and user education to mitigate risks associated with such advanced phishing campaigns. ([proofpoint.com](https://www.proofpoint.com/us/blog/security-briefs/ta551-uses-sliver-red-team-tool-new-activity?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Device Code Phishing: A New Threat to Microsoft 365 Security in 2026
Impact· HIGH

Device Code Phishing: A New Threat to Microsoft 365 Security in 2026

In early 2026, a sophisticated phishing campaign exploited Microsoft's OAuth 2.0 Device Authorization Grant flow to compromise Microsoft 365 accounts across over 340 organizations in the U.S., Canada, Australia, New Zealand, and Germany. Attackers tricked users into entering device codes on legitimate Microsoft authentication pages, granting unauthorized access without stealing passwords or bypassing multi-factor authentication. This method allowed threat actors to maintain persistent access to compromised accounts, leading to data breaches and potential financial losses. ([cryptika.com](https://www.cryptika.com/attackers-hijack-microsoft-365-accounts-through-oauth-device-code-abuse-without-stealing-passwords/?utm_source=openai)) The incident underscores a significant shift in phishing tactics, with attackers increasingly abusing legitimate authentication workflows to evade detection. Organizations must enhance their security measures to address these evolving threats, including educating users about such sophisticated phishing techniques and implementing stricter controls over device code authentication. ([securitybrief.com.au](https://securitybrief.com.au/story/proofpoint-warns-of-surge-in-microsoft-device-code-phishing?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
GlassWorm Malware Exploits Open VSX Extensions to Target macOS Systems
Impact· HIGH

GlassWorm Malware Exploits Open VSX Extensions to Target macOS Systems

In late January 2026, a sophisticated supply chain attack compromised the Open VSX Registry, a platform for Visual Studio Code extensions. Threat actors gained unauthorized access to the developer account 'oorzc' and published malicious updates to four widely used extensions, collectively downloaded over 22,000 times. These updates embedded the GlassWorm malware loader, which, upon installation, targeted macOS systems to steal credentials, browser data, and cryptocurrency wallet information. The malware employed advanced evasion techniques, including locale-based profiling and utilizing the Solana blockchain for command-and-control communication, complicating detection and mitigation efforts. ([socket.dev](https://socket.dev/blog/glassworm-loader-hits-open-vsx-via-suspected-developer-account-compromise?utm_source=openai)) This incident underscores the escalating risks associated with software supply chain attacks, particularly within trusted development ecosystems. The use of blockchain technology for command-and-control highlights the evolving sophistication of threat actors, necessitating enhanced vigilance and robust security measures in software development and distribution processes.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Checkmarx KICS Supply Chain Attack: A 2026 Cybersecurity Wake-Up Call
Impact· MEDIUM

Checkmarx KICS Supply Chain Attack: A 2026 Cybersecurity Wake-Up Call

In early 2026, Checkmarx's KICS code scanner was targeted in a sophisticated supply chain attack attributed to the cyber threat group TeamPCP. The attackers exploited vulnerabilities in the software's update mechanism to inject malicious code, compromising the integrity of the tool and potentially exposing users to further exploits. This incident underscores the growing trend of threat actors focusing on software supply chains to distribute malware and gain unauthorized access to systems. Organizations relying on KICS were advised to verify the integrity of their installations and apply security patches promptly to mitigate potential risks. The attack highlights the critical need for robust supply chain security measures and continuous monitoring of software dependencies to prevent similar incidents in the future.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Palo Alto Networks' 2025 Data Breach: A Supply Chain Attack via Salesloft Drift
Impact· MEDIUM

Palo Alto Networks' 2025 Data Breach: A Supply Chain Attack via Salesloft Drift

In August 2025, Palo Alto Networks experienced a significant data breach resulting from a supply chain attack targeting the Salesloft Drift platform. Attackers exploited stolen OAuth tokens to gain unauthorized access to Salesforce environments, leading to the exfiltration of sensitive data, including business contacts, internal sales records, and support case information. The breach affected hundreds of organizations globally, with Palo Alto Networks among the impacted entities. ([techradar.com](https://www.techradar.com/pro/security/palo-alto-networks-becomes-the-latest-to-confirm-it-was-hit-by-salesloft-drift-attack?utm_source=openai)) This incident underscores the escalating risks associated with third-party integrations and the critical need for robust supply chain security measures. The attack highlights the importance of vigilant monitoring and rapid response strategies to mitigate potential vulnerabilities in interconnected systems. ([breached.company](https://breached.company/major-supply-chain-attack-palo-alto-networks-and-zscaler-hit-by-salesloft-drift-breach/?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
AI-Generated Phishing Attacks Surge in 2025
Impact· HIGH

AI-Generated Phishing Attacks Surge in 2025

In 2025, cybercriminals significantly escalated their use of AI-generated phishing attacks, with 83% of phishing emails containing AI-generated content. This shift led to a 54% click rate on these emails, compared to 12% for traditional phishing attempts. The enhanced realism and personalization of these AI-driven attacks resulted in a 275% increase in phishing-related losses, totaling $70 billion annually, with small and medium-sized businesses being the primary targets. ([itpro.com](https://www.itpro.com/security/phishing/ai-generated-phishing-became-the-baseline-for-hackers-last-year-kaseya-warns-its-going-to-get-worse-in-2026?utm_source=openai)) The widespread adoption of AI in phishing campaigns underscores the urgent need for organizations to implement advanced, AI-driven email security solutions to detect and mitigate these sophisticated threats effectively.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Palo Alto Networks 2026 Recruiter Phishing Scam: A Cautionary Tale
Impact· MEDIUM

Palo Alto Networks 2026 Recruiter Phishing Scam: A Cautionary Tale

Since August 2025, a series of sophisticated phishing campaigns have targeted senior-level professionals by impersonating Palo Alto Networks' talent acquisition staff. Attackers utilized scraped LinkedIn data to craft highly personalized emails, falsely claiming that the recipient's resume failed to meet applicant tracking system (ATS) requirements. They then offered paid services to 'correct' these issues, charging fees ranging from $400 to $800. This social engineering tactic exploited victims' career aspirations and trust in reputable companies. This incident underscores a growing trend of cybercriminals leveraging social engineering and impersonation tactics to exploit individuals' trust and professional ambitions. As remote work and digital communication become more prevalent, such personalized phishing schemes are likely to increase, highlighting the need for heightened vigilance and robust verification processes.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports