✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Critical Vulnerabilities in SolarWinds Serv-U: Immediate Action Required
In February 2026, SolarWinds addressed four critical vulnerabilities in its Serv-U file transfer software, identified as CVE-2025-40538 through CVE-2025-40541. These flaws, each with a CVSS score of 9.1, could allow attackers with administrative privileges to execute arbitrary code as root. The vulnerabilities include broken access control, type confusion, and insecure direct object reference issues. While no active exploitation has been reported, similar past vulnerabilities have been targeted by threat actors, notably the China-based group Storm-0322. Organizations using Serv-U are urged to update to version 15.5.4 promptly to mitigate potential risks. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/25/solarwinds-serv-u-vulnerabilities-cve-2025-40538-to-cve-2025-40541/?utm_source=openai))
5 months ago
Kill Chain
Fake Next.js Job Interview Tests Backdoor Developers' Devices
In February 2026, a coordinated cyberattack targeted software developers through malicious repositories masquerading as legitimate Next.js projects. These repositories were shared during job interviews or technical assessments, leading developers to clone and execute the code. Upon execution, embedded JavaScript scripts initiated remote code execution (RCE), allowing attackers to deploy backdoors, exfiltrate sensitive data, and introduce additional payloads on compromised systems. The attack utilized multiple execution triggers, including VS Code tasks, development server commands, and backend startup scripts, to maximize infection rates. This incident underscores the evolving tactics of threat actors who exploit standard development workflows to infiltrate systems. The use of job-themed lures and the targeting of developers highlight a broader trend of sophisticated social engineering attacks aimed at the tech industry. Organizations must enhance their security protocols, particularly around code repositories and development tools, to mitigate such risks.
5 months ago
Kill Chain
SLH's Strategic Shift: Recruiting Women for Targeted Vishing Attacks in 2026
In February 2026, the cybercrime collective Scattered LAPSUS$ Hunters (SLH) initiated a campaign to recruit women for voice phishing (vishing) attacks targeting IT help desks. Offering financial incentives of $500 to $1,000 per call and providing pre-written scripts, SLH aims to enhance the effectiveness of their social engineering tactics by leveraging female voices to impersonate employees. This strategy is designed to manipulate help desk personnel into resetting passwords or installing remote monitoring tools, thereby granting unauthorized access to corporate networks. ([dataminr.com](https://www.dataminr.com/resources/intel-brief/slh-recruiting-women-for-vishing/?utm_source=openai)) This development underscores a significant evolution in cybercriminal methodologies, highlighting the increasing sophistication of social engineering attacks. Organizations must recognize the heightened risk posed by such targeted vishing campaigns and implement robust security measures to mitigate potential breaches.
5 months ago
Kill Chain
Malicious NuGet Packages Target ASP.NET Developers in 2026 Supply Chain Attack
In February 2026, cybersecurity researchers identified a supply chain attack involving four malicious NuGet packages—NCryptYo, DOMOAuth2_, IRAOAuth2.0, and SimpleWriter_—targeting ASP.NET developers. These packages, published between August 12 and 21, 2024, by a user named hamzazaheer, were downloaded over 4,500 times before removal. The attack exfiltrated ASP.NET Identity data, including user accounts and role assignments, and manipulated authorization rules to create persistent backdoors in victim applications. NCryptYo acted as a first-stage dropper, establishing a local proxy for command-and-control communication, while the other packages facilitated data theft and backdoor creation. This incident underscores the escalating threat of supply chain attacks targeting software developers. Similar campaigns have been observed in other ecosystems, such as the npm registry, where malicious packages like ambar-src have been used to deploy cross-platform malware. The increasing frequency and sophistication of these attacks highlight the critical need for developers to exercise caution when incorporating third-party packages and to implement robust security measures to protect their development environments and end-users.
5 months ago
Kill Chain
Google Disrupts UNC2814's Global Cyber Espionage Campaign
In February 2026, Google, in collaboration with industry partners, disrupted a sophisticated cyber espionage campaign orchestrated by the Chinese-linked group UNC2814. Active since at least 2017, UNC2814 infiltrated 53 organizations across 42 countries, primarily targeting telecommunications and government sectors. The group employed a novel backdoor, GRIDTIDE, which exploited the Google Sheets API to disguise command-and-control (C2) communications, enabling the execution of arbitrary shell commands and data exfiltration. The attackers gained initial access by compromising web servers and edge systems, subsequently moving laterally within networks using service accounts and living-off-the-land techniques. ([thehackernews.com](https://thehackernews.com/2026/02/google-disrupts-unc2814-gridtide.html?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors in leveraging legitimate cloud services to evade detection. The global scale and sophistication of UNC2814's operations highlight the critical need for organizations to enhance their cybersecurity measures, particularly in monitoring and securing cloud-based applications and APIs. ([thehackernews.com](https://thehackernews.com/2026/02/google-disrupts-unc2814-gridtide.html?utm_source=openai))
5 months ago
Kill Chain
Critical Security Flaws Uncovered in Anthropic's Claude Code
In early 2026, multiple critical vulnerabilities were discovered in Anthropic's Claude Code, an AI-powered coding assistant. These flaws allowed attackers to execute arbitrary code and exfiltrate API keys by exploiting configuration mechanisms such as Hooks, Model Context Protocol (MCP) servers, and environment variables. Notably, CVE-2026-21852 enabled malicious repositories to leak Anthropic API keys before users confirmed trust, potentially compromising sensitive data and infrastructure. ([thehackernews.com](https://thehackernews.com/2026/02/claude-code-flaws-allow-remote-code.html?utm_source=openai)) The incident underscores the evolving threat landscape in AI-driven development environments, highlighting the need for robust security measures in automated tools. As AI integration in software development grows, ensuring the integrity of configuration files and implementing strict trust mechanisms become imperative to prevent similar vulnerabilities.
5 months ago
Kill Chain
Malicious Next.js Repositories Exploit Developers via Fake Job Interviews
In February 2026, a sophisticated cyberattack campaign was identified targeting software developers through malicious Next.js repositories. Attackers, linked to North Korean state-sponsored groups, posed as recruiters offering fake job interviews. They lured developers into cloning and executing compromised repositories, leading to remote code execution and establishing persistent command-and-control channels on infected machines. This method allowed attackers to access sensitive assets such as source code, environment secrets, and cloud resources. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/malicious-nextjs-repos-developers-fake-job-interviews?utm_source=openai)) This incident underscores a growing trend of targeting developers through social engineering tactics, exploiting routine workflows to infiltrate development environments. The use of legitimate platforms like Next.js and GitHub in these attacks highlights the need for heightened vigilance and robust security measures within the software development community. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/02/24/c2-developer-targeting-campaign/?utm_source=openai))
5 months ago
Kill Chain
Lazarus Group's Medusa Ransomware Assaults on U.S. Critical Infrastructure in 2025
In early 2025, the North Korean state-sponsored Lazarus Group launched a series of sophisticated ransomware attacks targeting critical infrastructure sectors, notably healthcare and education, in the United States. Utilizing the Medusa ransomware, the group employed advanced tactics such as exploiting unpatched software vulnerabilities and deploying custom malware tools like Comebacker backdoor and Blindingcan RAT. These attacks led to significant data breaches, operational disruptions, and substantial financial losses for the affected organizations. ([secure.com](https://www.secure.com/news/north-koreas-lazarus-group-is-running-medusa-ransomware-attacks-on-u-s-healthcare?utm_source=openai)) The Lazarus Group's adoption of Medusa ransomware underscores a concerning trend of state-sponsored actors leveraging ransomware-as-a-service platforms to conduct financially motivated cyberattacks. This evolution highlights the urgent need for organizations to enhance their cybersecurity defenses, particularly in sectors handling sensitive data, to mitigate the risks posed by such advanced persistent threats.
5 months ago
Kill Chain
AI-Accelerated Cyberattacks in 2025: A 65% Increase in Speed
In 2025, cyber adversaries significantly enhanced their capabilities by integrating artificial intelligence (AI) into their attack strategies, leading to an 89% increase in AI-enabled operations. This integration resulted in a dramatic reduction in the average breakout time—the period between initial network intrusion and lateral movement—to just 29 minutes, a 65% acceleration from the previous year. Notably, the fastest observed breakout occurred in a mere 27 seconds. Attackers exploited AI systems by injecting malicious prompts into generative AI tools across more than 90 organizations, facilitating credential and cryptocurrency theft. Additionally, vulnerabilities in AI development platforms were leveraged to establish persistence and deploy ransomware, while some adversaries set up malicious AI servers impersonating trusted services to intercept sensitive data. ([crowdstrike.com](https://www.crowdstrike.com/en-us/press-releases/2026-crowdstrike-global-threat-report/?utm_source=openai)) This escalation underscores a critical shift in the cyber threat landscape, where AI serves both as an accelerant for adversarial operations and as a target for exploitation. The rapid adoption of AI by threat actors necessitates that organizations enhance their defensive measures to counteract these sophisticated, AI-driven attacks effectively. ([crowdstrike.com](https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-global-threat-report-findings/?utm_source=openai))
5 months ago
Kill Chain
Critical Security Flaws Discovered in Gardyn Home Kit: What You Need to Know
In February 2026, multiple critical vulnerabilities were identified in the Gardyn Home Kit, an AI-powered indoor gardening system. These flaws included insecure credential exchange (CVE-2025-29628), weak default SSH credentials (CVE-2025-29629), command injection vulnerabilities (CVE-2025-29631), and API credential leakage (CVE-2025-1242). Exploitation could have allowed unauthenticated users to remotely control devices, access user information, and pivot to other devices within the Gardyn cloud environment. Gardyn promptly addressed these issues by releasing firmware updates and advising users to ensure their devices were connected to the internet to receive automatic updates. ([mygardyn.com](https://mygardyn.com/blog/security-update/?utm_source=openai)) This incident underscores the growing security challenges in IoT devices, particularly those integrated into personal living spaces. The vulnerabilities highlight the importance of robust security practices in the development and maintenance of smart home technologies to prevent unauthorized access and potential data breaches.
5 months ago
Kill Chain
Critical Vulnerability in Soliton Systems' FileZen: Immediate Action Required
In February 2026, a critical OS command injection vulnerability (CVE-2026-25108) was identified in Soliton Systems' FileZen file transfer appliance. This flaw allows authenticated users to execute arbitrary operating system commands via specially crafted HTTP requests when the Antivirus Check Option is enabled. Affected versions include FileZen V5.0.0 to V5.0.10 and V4.2.1 to V4.2.8. Exploitation of this vulnerability could lead to full system compromise, data theft, and unauthorized access to sensitive information. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-25108?utm_source=openai)) The inclusion of CVE-2026-25108 in CISA's Known Exploited Vulnerabilities Catalog underscores the urgency for organizations to address this issue promptly. With active exploitation observed, entities using vulnerable versions of FileZen are at heightened risk. Immediate patching to version V5.0.11 or later is strongly recommended to mitigate potential threats. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/25/cve-2026-25108-filezen-vulnerability-exploited/?utm_source=openai))
5 months ago
Kill Chain
L3Harris Executive Sentenced for Selling Zero-Day Exploits to Russian Broker
In February 2026, Peter Williams, a former executive at L3Harris's cyber division Trenchant, was sentenced to 87 months in prison for selling eight zero-day exploits to a Russian broker, Operation Zero. Over a three-year period, Williams stole proprietary cyber tools intended for exclusive use by the U.S. government and its allies, causing an estimated $35 million in losses to L3Harris. He received approximately $1.3 million in cryptocurrency for the stolen exploits, which he used to purchase luxury items. This case underscores the severe risks posed by insider threats within defense contracting firms, especially concerning sensitive cybersecurity tools. The incident highlights the critical need for robust internal security measures and monitoring to prevent unauthorized access and exfiltration of proprietary information. Additionally, the U.S. Department of the Treasury sanctioned Operation Zero and its founder, Sergey Zelenyuk, for their role in acquiring and distributing cyber tools harmful to U.S. national security.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports