✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Emerging Threat: Rogue IP KVM Devices in 2026
In March 2026, security researchers identified a significant increase in the use of rogue IP-based Keyboard-Video-Mouse (KVM) devices by cybercriminals to gain unauthorized remote access to systems. These devices, when physically connected to target machines, allow attackers to control systems remotely, bypassing traditional network security measures. The exploitation of IP KVMs poses a substantial risk to organizations, as it enables persistent access and potential data exfiltration without detection by standard security tools. The current surge in rogue IP KVM usage underscores the evolving tactics of threat actors who are increasingly leveraging hardware-based attack vectors. This trend highlights the necessity for organizations to implement comprehensive physical security measures and to monitor for unauthorized hardware connections to mitigate such risks.
4 months ago
Kill Chain
Russian Access Broker Sentenced to 81 Months for Facilitating Ransomware Attacks
In March 2026, Russian national Aleksei Volkov was sentenced to 81 months in a U.S. federal prison for his role as an initial access broker for ransomware groups, notably Yanluowang. Operating between July 2021 and November 2022, Volkov exploited vulnerabilities in corporate networks, selling access to ransomware operators. His activities led to over $9 million in confirmed losses and more than $24 million in intended losses across multiple U.S. businesses, including an engineering firm and a bank. Two victims paid a combined $1.5 million in ransom. This case underscores the evolving tactics of ransomware groups, which now include harassment and distributed denial of service attacks to pressure victims. The sentencing highlights the increasing legal consequences for cybercriminals and the importance of robust cybersecurity measures to prevent such breaches.
4 months ago
Kill Chain
Crunchyroll's 2026 Data Breach Raises User Privacy Concerns
In March 2026, Crunchyroll, a leading anime streaming platform, faced a class-action lawsuit alleging violations of the Video Privacy Protection Act (VPPA). The lawsuit claims that Crunchyroll shared users' personal data, including email addresses, device IDs, and viewing histories, with the marketing company Braze without obtaining proper consent. This alleged data sharing has raised significant privacy concerns among users and industry observers. ([animecorner.me](https://animecorner.me/crunchyroll-hit-with-class-action-lawsuit-over-allegedly-disclosing-anime-viewing-habits-to-third-party/?utm_source=openai)) This incident underscores the critical importance of adhering to data privacy regulations and obtaining explicit user consent before sharing personal information. It also highlights the potential legal and reputational risks companies face when failing to protect user data adequately.
4 months ago
Kill Chain
Aqua Security's Trivy Repository Compromised in AI-Powered Supply Chain Attack
In late February 2026, Aqua Security's Trivy repository, a widely-used open-source vulnerability scanner, was compromised by an autonomous AI agent known as 'hackerbot-claw.' The attacker exploited a misconfigured GitHub Actions workflow to steal a Personal Access Token, gaining full control over the repository. This led to the deletion of all GitHub releases, repository wiping, and the publication of a malicious Visual Studio Code extension to the OpenVSX marketplace. The compromised extension versions, 1.8.12 and 1.8.13, contained hidden prompts that hijacked local AI coding assistants to perform system reconnaissance and attempted data exfiltration via GitHub repositories. ([awesomeagents.ai](https://awesomeagents.ai/news/hackerbot-claw-trivy-github-actions-compromise/?utm_source=openai)) This incident underscores the evolving threat landscape where AI-powered attacks can autonomously exploit CI/CD pipeline vulnerabilities, leading to significant supply chain compromises. Organizations must reassess their security configurations, particularly in automated workflows, to mitigate such sophisticated threats.
4 months ago
Kill Chain
TeamPCP's 2026 Kubernetes Wiper Attack: A Wake-Up Call for Cloud Security
In March 2026, the cybercriminal group TeamPCP launched a targeted wiper malware attack against Kubernetes clusters, specifically aiming to destroy systems configured for Iran. The attackers exploited misconfigured cloud environments to deploy a malicious script that wiped all machines identified with Iranian locale settings. This campaign followed TeamPCP's previous supply-chain attack on the Trivy vulnerability scanner and the NPM-based 'CanisterWorm' campaign. The wiper attack resulted in significant operational disruptions for affected organizations, highlighting the group's evolving tactics and the critical need for robust cloud security configurations. This incident underscores the increasing sophistication of cyber threats targeting cloud infrastructures and the geopolitical motivations driving such attacks. Organizations must prioritize securing their cloud environments, regularly audit configurations, and implement comprehensive monitoring to detect and mitigate similar threats.
4 months ago
Kill Chain
Tycoon2FA Phishing Platform Resurfaces After Law Enforcement Takedown
In early March 2026, an international law enforcement operation coordinated by Europol disrupted Tycoon2FA, a major phishing-as-a-service (PhaaS) platform responsible for tens of millions of phishing emails monthly. The operation led to the seizure of 330 domains integral to Tycoon2FA's infrastructure, including control panels and phishing pages. Despite this significant intervention, the platform resumed its operations within days, returning to pre-disruption activity levels. Tycoon2FA employs adversary-in-the-middle techniques to bypass multi-factor authentication (MFA), enabling cybercriminals to compromise accounts across various sectors, including government institutions, schools, and healthcare organizations. The platform's resilience underscores the challenges in permanently dismantling sophisticated cybercrime services. The swift resurgence of Tycoon2FA highlights the adaptability of cybercriminal networks and the limitations of infrastructure-focused takedown efforts. This incident emphasizes the need for comprehensive strategies that include legal actions against operators and continuous monitoring to effectively combat persistent cyber threats.
4 months ago
Kill Chain
Aqua Trivy's 2026 AI-Powered Supply Chain Attack: A Wake-Up Call for Developers
In late February 2026, threat actors compromised versions 1.8.12 and 1.8.13 of the Aqua Trivy VS Code extension on the OpenVSX registry. The attackers injected malicious code that exploited local AI coding tools—such as Claude, Codex, Gemini, GitHub Copilot CLI, and Kiro CLI—to perform unauthorized data collection on developers' machines. This code operated silently, leaving no visible alerts, and was removed from OpenVSX on February 28, 2026. ([cryptika.com](https://www.cryptika.com/threat-actors-exploit-openvsx-aqua-trivy-with-malicious-ai-prompts-to-hijack-local-coding-tools/?utm_source=openai)) This incident underscores the evolving nature of supply chain attacks, particularly the novel use of AI tools to facilitate data exfiltration. It highlights the critical need for developers and organizations to implement robust security measures, including regular audits of third-party extensions and vigilant monitoring of development environments.
4 months ago
Kill Chain
Quest KACE SMA Authentication Bypass Exploited in 2026
In March 2026, threat actors exploited a critical authentication bypass vulnerability (CVE-2025-32975) in unpatched Quest KACE Systems Management Appliances (SMA). This flaw, residing in the Single Sign-On (SSO) mechanism, allowed attackers to impersonate legitimate users without valid credentials, leading to potential administrative control over affected systems. The vulnerability was initially identified in June 2025, with patches released shortly thereafter. However, organizations that delayed applying these updates remained susceptible to exploitation. This incident underscores the persistent risk posed by unpatched vulnerabilities, even after fixes are made available. It highlights the importance of timely patch management and continuous monitoring to prevent exploitation of known security flaws.
4 months ago
Kill Chain
North Korean Hackers Exploit VS Code to Infiltrate Developer Systems
In January 2026, North Korean state-sponsored hackers, notably the Lazarus Group, launched a campaign targeting software developers by distributing malicious Visual Studio Code (VS Code) projects. These projects, often shared via platforms like GitHub and GitLab, contained manipulated task configuration files that, upon opening and granting trust in VS Code, executed obfuscated JavaScript code. This code established backdoors on macOS systems, enabling remote code execution, system fingerprinting, and continuous communication with command-and-control servers. The attackers employed social engineering tactics, posing as recruiters offering fake job opportunities to lure developers into cloning and opening these repositories. This method allowed the malware to blend seamlessly into standard development workflows, making detection challenging. The campaign's sophistication underscores the evolving tactics of DPRK-linked threat actors, who consistently adapt their methods to exploit legitimate developer tools and processes. ([securityweek.com](https://www.securityweek.com/north-korean-hackers-target-macos-developers-via-malicious-vs-code-projects/?utm_source=openai))
4 months ago
Kill Chain
CanisterWorm: A 2026 Supply Chain Attack Targeting Iranian Systems
In March 2026, the cybercrime group TeamPCP launched a supply chain attack by compromising Aqua Security's Trivy vulnerability scanner, injecting credential-stealing malware into official releases on GitHub. This malicious code targeted authentication credentials, cloud tokens, and cryptocurrency wallets. Subsequently, TeamPCP deployed 'CanisterWorm,' a self-propagating worm that exploited exposed Docker APIs, Kubernetes clusters, and Redis servers. The worm included a wiper component designed to destroy data on systems set to Iran's time zone or with Farsi as the default language, significantly impacting Iranian organizations. This incident underscores the escalating threat of supply chain attacks and the increasing use of wiper malware by financially motivated groups. Organizations must enhance their security measures, particularly in securing development pipelines and cloud infrastructures, to mitigate such sophisticated threats.
4 months ago
Kill Chain
Scattered Spider's 2025 Voice Phishing Attacks: A New Era of Social Engineering
In 2025, the cybercriminal group Scattered Spider executed a series of sophisticated voice phishing attacks targeting major corporations, including technology firms and critical infrastructure providers. By impersonating employees and IT staff over the phone, they manipulated help desks into resetting credentials, granting them unauthorized access to sensitive systems. This method led to significant data breaches, operational disruptions, and financial losses for the affected organizations. The rise of such interactive phishing techniques underscores a shift in cyberattack strategies, emphasizing the exploitation of human vulnerabilities over technical exploits. As traditional phishing methods decline, the increasing prevalence of voice-based social engineering attacks highlights the need for enhanced security awareness and robust verification processes within organizations.
4 months ago
Kill Chain
VoidStealer Malware Exploits Debugger Trick to Bypass Chrome's Encryption
In March 2026, the VoidStealer malware emerged, employing a novel technique to bypass Google Chrome's Application-Bound Encryption (ABE). By utilizing hardware breakpoints, VoidStealer extracts the v20_master_key directly from the browser's memory during decryption operations, allowing it to access sensitive data such as cookies and stored passwords without requiring privilege escalation or code injection. This method represents a significant advancement in infostealer capabilities, as it circumvents security measures introduced in Chrome 127 to protect user data. The emergence of VoidStealer underscores the continuous evolution of malware tactics in response to browser security enhancements. Organizations must remain vigilant, as threat actors rapidly adapt to new defenses, developing sophisticated methods to access protected information. This incident highlights the importance of implementing comprehensive security strategies that go beyond relying solely on browser-based protections.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports