✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Trivy Supply Chain Attack: A Wake-Up Call for Open-Source Security
In March 2026, the Trivy vulnerability scanner, a widely used open-source security tool, was compromised in a sophisticated supply chain attack orchestrated by the threat actor group known as TeamPCP. The attackers infiltrated Trivy's GitHub repository, replacing legitimate code with malicious versions in the v0.69.4 release and associated GitHub Actions. This breach led to the distribution of credential-stealing malware, which harvested sensitive information from developers' environments, including SSH keys, cloud service credentials, and database passwords. The malicious code was active for approximately three hours, during which it exfiltrated data to attacker-controlled servers. Organizations utilizing the affected versions were advised to treat their environments as fully compromised, necessitating immediate rotation of all secrets and thorough system analysis for additional breaches. This incident underscores the escalating threat posed by supply chain attacks targeting open-source ecosystems. The exploitation of trusted development tools to distribute malware highlights the critical need for enhanced security measures within software supply chains. As attackers increasingly focus on compromising widely adopted tools, organizations must implement rigorous code review processes, continuous monitoring, and robust incident response strategies to mitigate the risks associated with such attacks.
4 months ago
Kill Chain
Exploitation of Microsoft Azure Monitor in Sophisticated Phishing Attack
In March 2026, cybercriminals exploited Microsoft Azure Monitor to send phishing emails that appeared as legitimate security alerts from Microsoft. These emails, originating from azure-noreply@microsoft.com, warned recipients of unauthorized charges and urged them to call a provided phone number. By leveraging Azure Monitor's legitimate alerting system, attackers bypassed standard email security checks, making the phishing attempts more convincing. This method highlights a sophisticated abuse of trusted cloud services to execute social engineering attacks. The incident underscores the evolving tactics of threat actors who manipulate legitimate platforms to enhance the credibility of their phishing campaigns. Organizations must remain vigilant, as such techniques can lead to credential theft, financial fraud, or unauthorized access to sensitive systems.
4 months ago
Kill Chain
Trivy Supply Chain Attack Leads to CanisterWorm Infection in 47 npm Packages
In March 2026, a sophisticated supply chain attack targeted the Trivy vulnerability scanner, leading to the compromise of 47 npm packages through a self-propagating worm named CanisterWorm. The attackers infiltrated Trivy's codebase, embedding malicious code that, upon execution, harvested developer credentials and propagated itself by injecting into other npm packages. This resulted in widespread exposure of sensitive information and potential unauthorized access to numerous development environments. This incident underscores the escalating threat of supply chain attacks within the open-source ecosystem. The use of self-replicating malware like CanisterWorm highlights the need for enhanced security measures, including rigorous code audits, robust access controls, and continuous monitoring of software dependencies to mitigate the risk of similar attacks in the future.
4 months ago
Kill Chain
CISA Flags Critical Vulnerabilities in Apple, Craft CMS, and Laravel Livewire
In March 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added multiple vulnerabilities affecting Apple products, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities (KEV) catalog. Notably, CVE-2025-31277, a memory corruption issue in Apple's WebKit, was exploited by the 'DarkSword' malware, impacting over 220 million iPhones running iOS versions 18.4 through 18.7. Additionally, CVE-2025-23209, a code injection vulnerability in Craft CMS, allowed remote code execution in installations with compromised security keys. CISA mandated federal agencies to patch these vulnerabilities by April 3, 2026. The inclusion of these vulnerabilities in the KEV catalog underscores the increasing sophistication of cyber threats targeting widely-used platforms. Organizations are urged to prioritize patching to mitigate potential exploits and protect sensitive data from unauthorized access.
4 months ago
Kill Chain
Ubiquiti UniFi Access Vulnerability: Unauthenticated API Exposure
In October 2025, Ubiquiti's UniFi Access Application was found to have a critical vulnerability (CVE-2025-52665) that exposed a management API without proper authentication. This flaw, present in versions 3.3.22 through 3.4.31, allowed attackers with access to the management network to gain unauthorized control over door access systems, posing significant risks to physical security. Ubiquiti addressed the issue by releasing version 4.0.21, which rectified the misconfiguration. This incident underscores the importance of promptly updating software to mitigate security vulnerabilities. Organizations are advised to review their access control systems and ensure that all applications are updated to the latest secure versions to prevent unauthorized access and potential breaches.
4 months ago
Kill Chain
North Korean IT Worker Scheme 2026: Unveiling the Insider Threat
Between September 2019 and November 2022, three U.S. nationals—Audricus Phagnasay, Jason Salazar, and Alexander Paul Travis—facilitated a scheme enabling North Korean IT workers to secure remote positions at U.S. companies. By hosting company-provided laptops and installing remote-access software, they allowed these operatives to masquerade as domestic employees. This operation led to approximately $1.28 million in salaries being funneled to North Korea, violating U.S. sanctions and compromising corporate security. ([cyberscoop.com](https://cyberscoop.com/doj-north-korea-it-worker-scheme-cases-crypto-seized/?utm_source=openai)) This incident underscores the evolving tactics of state-sponsored cyber operations, highlighting the critical need for robust identity verification and remote work security protocols to prevent similar breaches.
4 months ago
Kill Chain
Brightly Software's 2026 Insider Data Extortion: A Cautionary Tale
In December 2023, Cameron Curry, a 27-year-old data analyst contractor at Brightly Software, exploited his access to the company's payroll and corporate data to steal sensitive employee information. Upon learning that his contract would not be extended, Curry initiated an extortion scheme, demanding $2.5 million to prevent the release of the stolen data. He sent over 60 emails to Brightly employees, threatening to disclose personal identification information (PII) unless his demands were met. The company reported the incident to the FBI, leading to Curry's arrest and subsequent conviction in March 2026. This case underscores the persistent threat posed by insider attacks, particularly when employees or contractors misuse their access to sensitive information. Organizations must remain vigilant, implementing robust access controls and monitoring mechanisms to detect and prevent such insider threats.
4 months ago
Kill Chain
Operation Alice 2026: Unveiling the Dark Web's Deceptive CSAM Network
In March 2026, an international law enforcement operation named Operation Alice, led by German authorities with Europol's support, dismantled over 373,000 dark web sites that falsely advertised child sexual abuse material (CSAM). These fraudulent sites, operated by a 35-year-old suspect based in China, lured approximately 10,000 users into paying between EUR 17 and EUR 250 in Bitcoin, amassing around $400,000, without delivering any illicit content. The operation resulted in the seizure of 287 servers, including 105 located in Germany, and an international arrest warrant issued for the suspect. This incident underscores the persistent threat posed by cybercriminals exploiting the dark web to perpetrate fraud and distribute illicit content. It highlights the necessity for continuous international collaboration and vigilance in monitoring and dismantling such networks to protect vulnerable individuals and uphold cybersecurity standards.
4 months ago
Kill Chain
Critical Unauthenticated RCE Vulnerability in Oracle Identity Manager: Immediate Action Required
In March 2026, Oracle released an out-of-band security update to address a critical unauthenticated remote code execution (RCE) vulnerability, identified as CVE-2026-21992, in Oracle Identity Manager and Oracle Web Services Manager. This flaw, with a CVSS score of 9.8, allows remote attackers to execute arbitrary code without authentication, posing significant risks to enterprise identity and access management systems. Organizations are strongly advised to apply the provided patches immediately to mitigate potential exploitation. The urgency of this update underscores the increasing trend of attackers targeting identity management systems, which serve as gateways to sensitive enterprise resources. Ensuring the security of such systems is paramount, as their compromise can lead to widespread unauthorized access and data breaches.
4 months ago
Kill Chain
Critical Langflow Vulnerability CVE-2026-33017: Immediate Action Required
In March 2026, a critical vulnerability (CVE-2026-33017) was discovered in Langflow, an AI workflow platform, allowing unauthenticated remote code execution via the /api/v1/validate/code endpoint. Exploitation began within 20 hours of disclosure, leading to potential full system compromise. Organizations using Langflow are urged to update to version 1.8.0 immediately to mitigate this risk. This incident underscores the rapid weaponization of newly disclosed vulnerabilities and the necessity for prompt patching to protect AI infrastructure.
4 months ago
Kill Chain
Trivy Security Scanner Compromised: A Wake-Up Call for CI/CD Security
In late February 2026, Aqua Security's Trivy, a widely-used open-source vulnerability scanner, was compromised through its GitHub Actions workflows. An autonomous AI bot named 'hackerbot-claw' exploited vulnerabilities in Trivy's CI/CD pipeline, leading to unauthorized code execution and the exfiltration of sensitive CI/CD secrets. This breach resulted in the deletion of Trivy's GitHub repository content, disrupting numerous organizations relying on Trivy for security scanning. ([medium.com](https://medium.com/%40abhishekchauhan_68324/your-security-scanner-is-the-attack-vector-6d2a175a4f5b?utm_source=openai)) This incident underscores the escalating threat of AI-driven supply chain attacks targeting CI/CD pipelines. The automation and adaptability demonstrated by 'hackerbot-claw' highlight the urgent need for enhanced security measures in development workflows to prevent similar breaches.
4 months ago
Kill Chain
Beast Ransomware's SMB Port Scanning Tactics in 2025
In February 2025, the Beast ransomware group emerged as a Ransomware-as-a-Service (RaaS) platform, evolving from the earlier Monster ransomware strain. By August 2025, they had publicly disclosed attacks on 16 organizations across the United States, Europe, Asia, and Latin America, targeting sectors such as manufacturing, construction, healthcare, business services, and education. The group's primary distribution method involves scanning for active Server Message Block (SMB) ports within compromised networks, facilitating rapid lateral movement and widespread encryption of shared resources. This aggressive propagation strategy has led to significant operational disruptions and data breaches for affected organizations. The Beast ransomware's focus on exploiting SMB vulnerabilities underscores the critical need for organizations to secure internal network protocols and implement robust segmentation strategies. As ransomware tactics continue to evolve, understanding and mitigating such sophisticated attack vectors remain paramount for maintaining cybersecurity resilience.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports