✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Microsoft's March 2026 Patch Tuesday: Addressing Critical Zero-Day Vulnerabilities
In March 2026, Microsoft released patches addressing 84 security vulnerabilities across its software portfolio, including two publicly disclosed zero-day flaws: CVE-2026-26127, a denial-of-service vulnerability in .NET, and CVE-2026-21262, an elevation of privilege vulnerability in SQL Server. Notably, over half of the patched vulnerabilities were related to privilege escalation, underscoring the critical need for organizations to apply these updates promptly to mitigate potential exploitation risks. ([anonhaven.com](https://anonhaven.com/en/news/microsoft-march-2026-patch-tuesday-83-cves/?utm_source=openai)) This incident highlights the ongoing challenges in securing complex software ecosystems and the importance of timely patch management. The disclosure of zero-day vulnerabilities before patches are available increases the window of opportunity for threat actors, emphasizing the need for organizations to maintain robust vulnerability management practices.
4 months ago
Kill Chain
Critical n8n Vulnerabilities Expose Systems to Remote Code Execution
In early 2026, multiple critical vulnerabilities were identified in n8n, an open-source workflow automation platform. Notably, CVE-2026-27577 and CVE-2026-27493 allowed for remote code execution (RCE) through expression sandbox escapes and unauthenticated expression evaluations via Form nodes, respectively. These flaws enabled attackers to execute arbitrary commands on the n8n host, potentially leading to full system compromise. ([thehackernews.com](https://thehackernews.com/2026/03/critical-n8n-flaws-allow-remote-code.html?utm_source=openai)) The discovery of these vulnerabilities underscores the importance of timely software updates and vigilant security practices. Organizations utilizing n8n are urged to upgrade to patched versions immediately to mitigate potential exploitation risks.
4 months ago
Kill Chain
Perplexity Comet AI Browser Phishing Attack 2026
In March 2026, security researchers demonstrated a critical vulnerability in Perplexity's Comet AI browser, where attackers could manipulate the browser's AI assistant into executing phishing scams autonomously. By intercepting the browser's communication with AI services and feeding it into a Generative Adversarial Network (GAN), the researchers trained the AI to bypass its security measures and enter user credentials into malicious websites within minutes. This exploit highlights a significant shift in attack vectors, targeting AI models directly rather than end-users. The incident underscores the evolving threat landscape where AI-driven systems can be manipulated to perform unauthorized actions, emphasizing the need for robust security measures in AI integrations. As AI technologies become more prevalent, ensuring their resilience against such sophisticated attacks is paramount to maintaining user trust and data security.
4 months ago
Kill Chain
Microsoft's March 2026 Patch Tuesday: Addressing 83 Vulnerabilities, Including Two Publicly Disclosed Zero-Days
In March 2026, Microsoft released security updates addressing 83 vulnerabilities across its product suite, including Windows, Office, SQL Server, Azure, and .NET. Among these, two zero-day vulnerabilities were publicly disclosed prior to patch release: CVE-2026-21262, an elevation of privilege flaw in SQL Server, and CVE-2026-26127, a denial-of-service vulnerability in .NET. Notably, none of these vulnerabilities were reported as actively exploited in the wild at the time of release. The update also included eight critical vulnerabilities, such as CVE-2026-21536, a remote code execution flaw in the Microsoft Devices Pricing Program, which Microsoft mitigated server-side without requiring user action. This Patch Tuesday marks the first in six months without any actively exploited zero-day vulnerabilities, indicating a positive trend in Microsoft's proactive security measures. However, the presence of publicly disclosed vulnerabilities underscores the importance of timely patch application to mitigate potential risks.
4 months ago
Kill Chain
Stryker's 2026 Cyberattack: A Wake-Up Call for Healthcare Cybersecurity
In March 2026, Stryker Corporation, a leading U.S. medical technology company, experienced a significant cyberattack attributed to the pro-Palestinian hacktivist group Handala. The attackers reportedly utilized wiper malware to erase data from over 200,000 systems, including servers and mobile devices, leading to widespread operational disruptions across Stryker's global network. Employees in multiple countries, notably Ireland, were sent home as the company worked to contain the incident. Handala claimed the attack was retaliation for a missile strike that resulted in civilian casualties in Iran. This incident underscores the escalating trend of state-sponsored hacktivism targeting critical infrastructure and healthcare sectors. Organizations must enhance their cybersecurity measures to defend against sophisticated threats that aim not only to steal data but also to cause operational paralysis. The use of wiper malware highlights the need for robust data backup and recovery strategies to mitigate the impact of such destructive attacks.
4 months ago
Kill Chain
APT28's 2026 Espionage Campaign: Exploiting Office Vulnerabilities with Advanced Malware
In early 2026, the Russian state-sponsored threat actor APT28, also known as Fancy Bear, launched a sophisticated cyber-espionage campaign targeting Ukrainian military personnel. The attackers utilized spear-phishing emails containing malicious Microsoft Office documents to exploit the CVE-2026-21509 vulnerability, allowing them to execute code via OLE objects without macros or warnings. This method facilitated the deployment of two advanced malware implants: BeardShell, a custom C++ backdoor leveraging the Icedrive cloud service for command-and-control communications, and Covenant, a heavily modified open-source .NET post-exploitation framework. These tools enabled APT28 to conduct long-term surveillance, data exfiltration, and maintain persistent access to compromised systems. ([cyberpress.org](https://cyberpress.org/apt28-exploits-office-vulnerability/?utm_source=openai)) This incident underscores a significant evolution in APT28's tactics, techniques, and procedures (TTPs), highlighting their ability to rapidly weaponize newly disclosed vulnerabilities and integrate legitimate cloud services into their command-and-control infrastructure. The campaign's success emphasizes the urgent need for organizations to promptly apply security patches, enhance phishing defenses, and monitor for abuse of legitimate services in cyber operations. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/03/10/sednit-espionage-toolkit-stealing-data/?utm_source=openai))
4 months ago
Kill Chain
Critical Vulnerabilities in Lantronix EDS3000PS and EDS5000 Devices Threaten Infrastructure Security
In March 2026, multiple critical vulnerabilities were identified in Lantronix EDS3000PS and EDS5000 devices, including OS command injection and authentication bypass issues. Exploitation of these vulnerabilities could allow attackers to execute code with root-level privileges, potentially compromising critical infrastructure sectors such as Communications, Information Technology, and Critical Manufacturing. ([cisa.gov](https://www.cisa.gov/news-events/bulletins/sb22-108?utm_source=openai)) This incident underscores the ongoing risks associated with unpatched vulnerabilities in network devices, highlighting the necessity for organizations to implement robust vulnerability management and regular system updates to mitigate potential threats.
4 months ago
Kill Chain
Unveiling Critical Reverse Proxy Header Vulnerabilities in 2025
In 2025, critical vulnerabilities were identified in reverse proxy applications, notably Fabio and OAuth2-Proxy, exposing significant security risks. CVE-2025-48865 in Fabio allowed attackers to manipulate or remove security-critical headers like X-Forwarded-Host and X-Real-IP by exploiting the HTTP Connection header, potentially leading to access control bypasses. Similarly, CVE-2025-64484 in OAuth2-Proxy enabled authenticated users to inject underscore variants of X-Forwarded-* headers, bypassing the proxy's filtering logic and potentially escalating privileges in upstream applications. These vulnerabilities underscore the importance of stringent header validation and normalization practices in reverse proxy configurations. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-48865?utm_source=openai)) The discovery of these vulnerabilities highlights a systemic issue in how reverse proxies handle HTTP headers, emphasizing the need for organizations to reassess and fortify their security measures to prevent similar exploits.
4 months ago
Kill Chain
SolarWinds Web Help Desk 2025 AjaxProxy RCE Vulnerability
In September 2025, a critical vulnerability (CVE-2025-26399) was identified in SolarWinds Web Help Desk, allowing unauthenticated remote attackers to execute arbitrary code on affected systems. This flaw, rooted in insecure deserialization within the AjaxProxy component, enables attackers to run commands on the host machine without authentication. Despite previous patches for related vulnerabilities (CVE-2024-28986 and CVE-2024-28988), this issue persisted, leading to active exploitation in the wild. Organizations using versions up to 12.8.7 are at significant risk and should apply the latest hotfix immediately. The recurrence of such vulnerabilities underscores the importance of comprehensive security reviews and prompt patch management. As attackers increasingly exploit deserialization flaws, organizations must prioritize securing their software supply chains and implementing robust monitoring to detect and respond to such threats promptly.
4 months ago
Kill Chain
Sednit's Resurgence: Advanced Cyber Espionage Targeting Ukrainian Military (2024-2026)
Between April 2024 and March 2026, the Russian state-sponsored group Sednit (also known as APT28 or Fancy Bear) reactivated its advanced development team, deploying sophisticated implants named BeardShell and Covenant to conduct prolonged surveillance on Ukrainian military personnel. These tools, leveraging legitimate cloud services for command and control, demonstrate a direct code lineage to Sednit's earlier malware from the 2010s, indicating a resurgence in their cyber espionage capabilities. This resurgence underscores the persistent threat posed by nation-state actors employing advanced techniques to infiltrate and monitor critical military infrastructures, highlighting the need for continuous vigilance and adaptive cybersecurity measures.
4 months ago
Kill Chain
APT28's Exploitation of Microsoft Office Vulnerability: A Deep Dive
In early 2026, the Russian state-sponsored hacking group APT28, also known as Fancy Bear, exploited a newly disclosed Microsoft Office vulnerability (CVE-2026-21509) to target Ukrainian government agencies. The attackers distributed malicious documents via phishing emails, leading to the deployment of the COVENANT malware framework and the BEARDSHELL backdoor, facilitating long-term surveillance and data exfiltration. This campaign underscores the rapid weaponization of zero-day vulnerabilities by nation-state actors and highlights the persistent cyber threats facing governmental institutions. Organizations are urged to promptly apply security patches and enhance their cybersecurity measures to mitigate such sophisticated attacks.
4 months ago
Kill Chain
Critical Ivanti EPM Vulnerability Exploited: Immediate Action Required
In February 2026, a critical authentication bypass vulnerability (CVE-2026-1603) was identified in Ivanti Endpoint Manager (EPM) versions prior to 2024 SU5. This flaw allows remote, unauthenticated attackers to access stored credential data by exploiting improper authentication mechanisms, specifically through malformed header concatenation in the WSAuth.dll component. Successful exploitation enables attackers to retrieve encrypted credential blobs for high-privilege accounts, potentially compromising the entire endpoint management trust model and facilitating lateral movement within networks. ([dbugs.ptsecurity.com](https://dbugs.ptsecurity.com/vulnerability/CVE-2026-1603?utm_source=openai)) The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-1603 to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation in the wild. Organizations are urged to upgrade to Ivanti EPM 2024 SU5 immediately to mitigate this risk. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-recently-patched-ivanti-epm-flaw-now-actively-exploited/?utm_source=openai))
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports