The Containment Era is here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2619 threat reports
Page 11 of 219

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 121132 / 2619 reports
Urgent: SonicWall SMA1000 Zero-Day Vulnerabilities Under Active Exploitation
Impact· CRITICAL

Urgent: SonicWall SMA1000 Zero-Day Vulnerabilities Under Active Exploitation

In July 2026, SonicWall disclosed two critical zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances: CVE-2026-15409 and CVE-2026-15410. CVE-2026-15409 is a server-side request forgery (SSRF) vulnerability allowing unauthenticated attackers to make the appliance send requests to unintended locations. CVE-2026-15410 is a code injection flaw enabling authenticated administrators to execute arbitrary operating system commands. Both vulnerabilities have been actively exploited in the wild, potentially leading to unauthorized access and control over affected systems. SonicWall has released patches to address these issues and urges immediate updates to mitigate risks. ([sonicwall.com](https://www.sonicwall.com/ja-jp/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities/kA1VN000001nv6D0AQ?utm_source=openai)) The exploitation of these vulnerabilities underscores a growing trend of attackers targeting remote access solutions to gain initial footholds into organizational networks. This incident highlights the critical importance of promptly applying security patches and maintaining vigilant monitoring of network appliances to prevent unauthorized access and potential data breaches.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Security Researcher Releases 'LegacyHive' Windows Zero-Day Exploit Post Patch Tuesday
Impact· HIGH

Security Researcher Releases 'LegacyHive' Windows Zero-Day Exploit Post Patch Tuesday

On July 15, 2026, security researcher Chaotic Eclipse, also known as Nightmare-Eclipse, released a proof-of-concept (PoC) exploit named 'LegacyHive.' This exploit targets a vulnerability in the Windows User Profile Service (ProfSvc), allowing an authenticated attacker to load registry hives associated with other user accounts, potentially leading to privilege escalation. The PoC requires another standard user credential and a third username, which can be an administrator account. If successful, it mounts the target user hive in the current user's classes root. Notably, this vulnerability affects all supported desktop and server versions of Windows, including those running the latest July 2026 Patch Tuesday update. The release of 'LegacyHive' underscores the ongoing tensions between independent security researchers and major software vendors regarding vulnerability disclosure practices. This incident highlights the critical need for organizations to implement robust privilege escalation defenses and to stay vigilant about applying security updates promptly to mitigate potential exploitation risks.

1 week ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Adds Four Known Exploited Vulnerabilities to Catalog
Impact· CRITICAL

CISA Adds Four Known Exploited Vulnerabilities to Catalog

On July 14, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. The vulnerabilities include CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA1000 Appliances, CVE-2026-56155 impacting Microsoft Active Directory Federation Services, and CVE-2026-56164 related to Microsoft SharePoint Server. These vulnerabilities are commonly exploited by malicious actors and pose significant risks to federal enterprises. CISA's Binding Operational Directive (BOD) 26-04 emphasizes the importance of promptly addressing such high-risk vulnerabilities to protect federal networks. While BOD 26-04 is mandatory for Federal Civilian Executive Branch agencies, CISA encourages all organizations to adopt risk-based vulnerability management practices and prioritize remediation of vulnerabilities listed in the KEV Catalog. This proactive approach is crucial in mitigating potential threats and enhancing overall cybersecurity resilience.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
ServiceNow's June 2026 Data Exposure: A Wake-Up Call for Cloud Security
Impact· HIGH

ServiceNow's June 2026 Data Exposure: A Wake-Up Call for Cloud Security

In early June 2026, ServiceNow identified a security vulnerability within its REST API that permitted unauthenticated users to access customer instance data. The flaw, present in the ‘Australia’ platform release and certain earlier versions with specific configurations, allowed unauthorized queries to sensitive data, including IT support tickets and employee records. ServiceNow applied a security update on June 5, 2026, to rectify the issue and notified affected customers directly. The incident underscores the critical importance of robust access controls and timely vulnerability management in cloud-based platforms. This event highlights the ongoing challenges in securing API endpoints against unauthorized access. As enterprises increasingly rely on cloud services for core operations, ensuring the integrity and confidentiality of data through stringent security measures becomes paramount. Organizations must remain vigilant, regularly audit their systems, and promptly address identified vulnerabilities to mitigate potential risks.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Microsoft's July 2026 Patch Tuesday: A Record-Breaking 622 Vulnerabilities Addressed
Impact· CRITICAL

Microsoft's July 2026 Patch Tuesday: A Record-Breaking 622 Vulnerabilities Addressed

In July 2026, Microsoft released its largest Patch Tuesday update to date, addressing 622 vulnerabilities across its product suite. This unprecedented volume includes two zero-day vulnerabilities: CVE-2026-56155, a privilege escalation flaw in Active Directory Federation Services, and CVE-2026-56164, a similar flaw in Microsoft SharePoint Server. Both vulnerabilities were actively exploited in the wild, posing significant security risks to organizations. The surge in identified vulnerabilities is attributed to Microsoft's deployment of its multi-model agentic scanning harness (MDASH), an AI-driven tool designed to accelerate the discovery and remediation of software defects. This development underscores the growing role of artificial intelligence in cybersecurity, enabling faster identification and patching of vulnerabilities but also highlighting the increasing complexity and volume of potential security issues that organizations must manage.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SAP's July 2026 Security Updates: Addressing Critical Vulnerabilities in NetWeaver and Commerce Cloud
Impact· CRITICAL

SAP's July 2026 Security Updates: Addressing Critical Vulnerabilities in NetWeaver and Commerce Cloud

In July 2026, SAP released security updates addressing 16 vulnerabilities across multiple products, including three critical flaws in NetWeaver, Commerce Cloud, and Approuter. The most severe, CVE-2026-44747, is a memory corruption issue in NetWeaver Application Server ABAP, potentially leading to unauthorized data access and system unavailability. CVE-2026-27690, an HTTP request smuggling vulnerability in SAP Approuter, could allow unauthenticated attackers to access user responses and trigger denial-of-service attacks. CVE-2026-44761 in SAP Commerce Cloud involves default credentials that enable attackers to obtain valid access tokens and manipulate data via certain APIs. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/sap-warns-of-critical-flaws-in-netweaver-and-commerce-cloud/?utm_source=openai)) These vulnerabilities underscore the critical need for organizations to promptly apply security patches to prevent potential exploitation. The increasing complexity and integration of enterprise software systems make timely updates essential to maintain system integrity and protect sensitive data.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Phishing Alert: LastPass and Bitwarden Users Targeted in July 2026
Impact· HIGH

Phishing Alert: LastPass and Bitwarden Users Targeted in July 2026

In July 2026, a sophisticated phishing campaign targeted users of LastPass and Bitwarden, two prominent password management services. Attackers sent emails from addresses like 'hello@lastpassnewsletter.com' and 'hello@bitwardennewsletter.com', falsely notifying recipients of updated security policies. These emails directed users to fraudulent websites impersonating DocuSign, prompting them to download malicious files purportedly compatible with both Windows and macOS systems. The domains used, such as 'lastpasscompliance[.]com' and 'bitwardencompliance[.]com', were flagged as malicious by security services. LastPass confirmed that its systems remained uncompromised and that the phishing emails did not originate from its infrastructure. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/lastpass-bitwarden-users-targeted-with-fake-security-alerts/?utm_source=openai)) This incident underscores a growing trend of cybercriminals targeting password manager users through sophisticated phishing tactics. The use of legitimate-looking emails and websites to deceive users highlights the need for heightened vigilance and robust security measures. Organizations and individuals must remain alert to such evolving threats to safeguard sensitive information.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Windows 11 July 2026 Patch Tuesday: Critical Updates and New Features
Impact· LOW

Windows 11 July 2026 Patch Tuesday: Critical Updates and New Features

On July 14, 2026, Microsoft released cumulative updates KB5101650 and KB5099414 for Windows 11 versions 25H2/24H2 and 23H2, respectively. These mandatory updates addressed 571 security vulnerabilities, including three zero-day exploits, and introduced new features such as improved Bluetooth reliability, enhanced Widgets experience, and Point-in-Time restore functionality. The updates also included various performance and reliability improvements across system components, including File Explorer, networking, printing, and accessibility. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5101650-and-kb5099414-cumulative-updates-released/amp/?utm_source=openai)) The release of these updates underscores the ongoing need for organizations to prioritize timely patch management. With the increasing complexity and volume of vulnerabilities, staying current with security updates is essential to protect systems against potential exploits and maintain operational integrity.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
SonicWall SMA1000 Zero-Day Vulnerabilities: Immediate Action Required
Impact· CRITICAL

SonicWall SMA1000 Zero-Day Vulnerabilities: Immediate Action Required

In July 2026, SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances: CVE-2026-15409, a server-side request forgery flaw, and CVE-2026-15410, a post-authentication code injection vulnerability. These flaws allowed unauthenticated attackers to make unauthorized requests and authenticated administrators to execute arbitrary OS commands, respectively. Both vulnerabilities were actively exploited in zero-day attacks, prompting SonicWall to release urgent security patches. Organizations utilizing affected SMA1000 models were advised to upgrade to the latest firmware versions immediately and to inspect their systems for indicators of compromise. This incident underscores the persistent targeting of remote access solutions by threat actors, highlighting the necessity for continuous monitoring, timely patching, and comprehensive security measures to protect against evolving cyber threats.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft's Unprecedented Patch Tuesday: 622 Vulnerabilities Addressed
Impact· CRITICAL

Microsoft's Unprecedented Patch Tuesday: 622 Vulnerabilities Addressed

On July 14, 2026, Microsoft released patches for a record-breaking 622 vulnerabilities across its product suite, including Windows, Office, Azure, Defender, and SQL Server. Notably, two zero-day vulnerabilities were actively exploited: CVE-2026-56155 in Active Directory Federation Services, allowing local privilege escalation to administrator, and CVE-2026-56164 in SharePoint Server, enabling network-based privilege escalation without authentication. Additionally, a BitLocker security feature bypass (CVE-2026-50661) was publicly disclosed prior to the patch release. ([securityweek.com](https://www.securityweek.com/microsoft-patches-record-622-vulnerabilities-including-two-exploited-zero-days/?utm_source=openai)) This unprecedented volume of patches underscores the increasing complexity of Microsoft's ecosystem and the growing sophistication of threat actors. Organizations are urged to prioritize applying these updates promptly to mitigate potential risks associated with these vulnerabilities.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in Cursor IDE: Automatic Execution of Malicious Code in Compromised Repositories
Impact· CRITICAL

Critical Vulnerability in Cursor IDE: Automatic Execution of Malicious Code in Compromised Repositories

In July 2026, a critical vulnerability was discovered in Cursor IDE, an AI-powered coding platform. This flaw allows attackers to embed a malicious 'git.exe' file within a repository. When a developer opens such a compromised project, Cursor automatically executes the malicious binary without any warnings or prompts, leading to potential unauthorized code execution on the developer's machine. Despite being reported to Cursor in December 2025, the vulnerability remains unpatched, posing significant risks to developers using the platform. This incident underscores the growing security challenges associated with AI-assisted development tools. As these platforms become more integrated into software development workflows, they present new attack vectors that can be exploited by threat actors. The lack of prompt remediation highlights the need for developers and organizations to remain vigilant, implement robust security measures, and advocate for timely patches from software vendors to mitigate emerging threats.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ClickFix Malware Campaign: A 2026 Cybersecurity Wake-Up Call
Impact· HIGH

ClickFix Malware Campaign: A 2026 Cybersecurity Wake-Up Call

In early 2026, a significant malware campaign known as 'ClickFix' exploited a critical vulnerability in the Ghost Content Management System (CVE-2026-26980) to compromise over 700 websites, including those of prominent educational institutions and tech companies. Attackers injected malicious JavaScript into these sites, presenting users with fake Cloudflare verification prompts that instructed them to execute commands leading to malware installation. This social engineering tactic effectively bypassed traditional security defenses, resulting in widespread data breaches and operational disruptions. The ClickFix campaign underscores a growing trend in cyber threats where attackers leverage trusted platforms and social engineering to deploy malware. The rapid evolution of such tactics highlights the need for organizations to adopt advanced detection methods, such as YARA-based structural analysis, and to enhance user awareness training to mitigate the risks associated with these sophisticated attacks.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports