✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Critical SmarterMail Vulnerabilities Exploited in 2026
In January 2026, SmarterTools' SmarterMail software was found to have two critical vulnerabilities: CVE-2026-24423, an unauthenticated remote code execution flaw, and CVE-2026-23760, an authentication bypass issue. These vulnerabilities allowed attackers to execute arbitrary code and reset administrator passwords without authentication, leading to full system compromise. Exploitation began shortly after disclosure, with threat actors sharing exploit code and compromised credentials on underground forums. ([scworld.com](https://www.scworld.com/news/smartermail-vulnerabilities-exploited-in-ransomware-campaigns?utm_source=openai)) The rapid weaponization of these vulnerabilities underscores the increasing speed at which attackers exploit newly disclosed flaws. Organizations must prioritize timely patching and enhance monitoring of email infrastructure to prevent similar breaches. ([scworld.com](https://www.scworld.com/news/smartermail-vulnerabilities-exploited-in-ransomware-campaigns?utm_source=openai))
5 months ago
Kill Chain
AI Assistants: The New Frontier for Stealthy Malware Communication
In February 2026, cybersecurity researchers from Check Point Research identified a novel method by which AI assistants with web browsing capabilities, such as Microsoft Copilot and xAI's Grok, can be exploited to facilitate covert command-and-control (C2) communications for malware. By manipulating these AI platforms to fetch attacker-controlled URLs, threat actors can establish stealthy communication channels that blend seamlessly into legitimate enterprise traffic, thereby evading traditional detection mechanisms. This technique underscores the evolving landscape of cyber threats, where everyday AI tools are repurposed for malicious activities. The discovery highlights a significant shift in cyberattack methodologies, emphasizing the need for organizations to reassess their security postures in the context of AI integration. As AI assistants become more prevalent in enterprise environments, the potential for their misuse in cyberattacks increases, necessitating enhanced monitoring and adaptive defense strategies to mitigate such risks.
5 months ago
Kill Chain
Dell RecoverPoint Zero-Day Exploited by UNC6201
In mid-2024, a critical zero-day vulnerability (CVE-2026-22769) in Dell's RecoverPoint for Virtual Machines was exploited by the China-linked cyberespionage group UNC6201. This flaw, involving hardcoded credentials, allowed unauthenticated remote attackers to gain root-level access, facilitating lateral movement, persistent access, and deployment of malware such as BRICKSTORM and the newer GRIMBOLT backdoor. The attackers also employed 'ghost NICs' to stealthily pivot within virtualized environments, complicating detection and response efforts. The exploitation of this vulnerability underscores the persistent threat posed by state-sponsored actors targeting critical infrastructure. Organizations are urged to apply Dell's remediation measures promptly to mitigate potential risks associated with this exploit.
5 months ago
Kill Chain
Critical Flaws in Popular VS Code Extensions Put Millions at Risk
In February 2026, critical vulnerabilities were discovered in four widely used Visual Studio Code (VS Code) extensions—Live Server, Code Runner, Markdown Preview Enhanced, and Microsoft Live Preview—collectively installed over 125 million times. These flaws could allow attackers to steal local files and execute remote code by exploiting weaknesses in the extensions' handling of web content and local server configurations. Notably, CVE-2025-65717 in Live Server enables file exfiltration via malicious websites, while CVE-2025-65716 in Markdown Preview Enhanced permits arbitrary code execution through crafted markdown files. Despite disclosure in June 2025, three of these vulnerabilities remained unpatched as of February 2026, leaving developers exposed to significant security risks. ([thehackernews.com](https://thehackernews.com/2026/02/critical-flaws-found-in-four-vs-code.html?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting development environments. The exploitation of trusted tools like VS Code extensions highlights the need for developers to exercise caution when installing and updating extensions, and for maintainers to prioritize timely security patches to mitigate potential compromises.
5 months ago
Kill Chain
The Rise of RMM Tool Exploitation in Cyber Attacks
In early 2025, cybersecurity researchers observed a significant increase in cyberattacks leveraging legitimate Remote Monitoring and Management (RMM) tools such as AnyDesk, ScreenConnect, and SimpleHelp. Threat actors exploited these tools to gain unauthorized access to systems, maintain persistence, and execute malicious activities without deploying traditional malware. This method allowed attackers to blend seamlessly into normal IT operations, making detection challenging. The impact was widespread, affecting various sectors including healthcare, finance, and education, leading to data breaches, financial losses, and operational disruptions. This trend underscores a shift in cybercriminal tactics towards 'Living-off-the-Land' techniques, where adversaries misuse trusted tools to evade detection. The rise in RMM abuse highlights the need for organizations to enhance monitoring of legitimate software usage and implement stringent access controls to mitigate such threats.
5 months ago
Kill Chain
UNC3886's 2025 Cyber Attack on Singapore's Telecom Sector
In July 2025, Singapore's four major telecommunications providers—Singtel, StarHub, M1, and SIMBA Telecom—were targeted by the Chinese state-sponsored cyber espionage group UNC3886. The attackers employed sophisticated techniques, including rootkits and zero-day exploits in firewalls, to gain unauthorized access to parts of the telecom networks. Despite these efforts, the intrusion did not disrupt services or result in the exfiltration of sensitive customer data. The Singaporean government, in collaboration with the affected telcos, launched Operation Cyber Guardian, a coordinated response involving over 100 personnel from various agencies, to contain and mitigate the threat. ([channelnewsasia.com](https://www.channelnewsasia.com/singapore/unc3886-cyberattack-targets-singapore-telcos-threat-contained-5916906?utm_source=openai)) This incident underscores the persistent and evolving nature of cyber threats targeting critical infrastructure. The use of advanced tools and tactics by UNC3886 highlights the need for continuous vigilance and robust cybersecurity measures within the telecommunications sector to safeguard against potential future attacks.
5 months ago
Kill Chain
Microsoft Office Equation Editor Exploit: A 2026 Malware Campaign
In February 2026, a sophisticated malware campaign exploited the Microsoft Office Equation Editor vulnerability (CVE-2017-11882) to deliver malicious payloads. Attackers distributed emails with attachments that, when opened, triggered the exploit, leading to the download and execution of harmful scripts and DLLs. Notably, the campaign reused a JPEG image embedding the final payload, a technique observed in previous attacks, indicating a pattern of leveraging known vulnerabilities and methods. This incident underscores the persistent threat posed by unpatched vulnerabilities and the reuse of attack techniques. Organizations must prioritize timely patching and remain vigilant against evolving malware delivery methods to mitigate such risks.
5 months ago
Kill Chain
Anthropic's Git MCP Server Vulnerabilities: A Wake-Up Call for AI Security
In January 2026, Anthropic addressed critical vulnerabilities in its Git MCP server, a key component of the Model Context Protocol enabling AI tools to interact with code repositories. Security researchers identified three significant flaws: a path validation bypass (CVE-2025-68145), an unrestricted git_init issue (CVE-2025-68143), and an argument injection flaw in git_diff (CVE-2025-68144). These vulnerabilities, particularly when combined with the Filesystem MCP server, could allow remote code execution or file tampering via prompt injection. Reported in June 2025, these issues were patched by Anthropic in December 2025 with version 2025.12.18. While no active exploitation has been confirmed, this incident highlights the growing risks associated with integrating complex AI systems, where safe components may become vulnerable when used together. The event also references a prior incident from November 2025, where Anthropic's Claude AI was manipulated in a cyberespionage campaign targeting major global entities, underscoring the broader cybersecurity challenges linked to rapid AI adoption.
5 months ago
Kill Chain
Chinese APT UNC6201 Exploits Dell RecoverPoint Zero-Day Vulnerability
In mid-2024, the Chinese state-sponsored threat group UNC6201 exploited a critical zero-day vulnerability (CVE-2026-22769) in Dell's RecoverPoint for Virtual Machines. This flaw, stemming from hardcoded administrator credentials in Apache Tomcat, allowed unauthenticated remote attackers to gain full system access and establish root-level persistence. The attackers deployed malware such as Brickstorm and later Grimbolt, facilitating long-term espionage and data exfiltration. ([cyberscoop.com](https://cyberscoop.com/china-brickstorm-grimbolt-dell-zero-day/?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors targeting critical infrastructure. The prolonged undetected exploitation highlights the necessity for robust vulnerability management and continuous monitoring to detect and mitigate such sophisticated attacks. ([cyberscoop.com](https://cyberscoop.com/china-brickstorm-grimbolt-dell-zero-day/?utm_source=openai))
5 months ago
Kill Chain
Poland's Crackdown on Phobos Ransomware: A 2026 Update
In February 2026, Polish authorities arrested a 47-year-old man in the Małopolska region, suspected of affiliating with the Phobos ransomware group. The arrest was part of 'Operation Aether,' an international effort coordinated by Europol targeting Phobos ransomware infrastructure and affiliates. During the operation, law enforcement seized computers and mobile phones containing stolen credentials, credit card numbers, and server access data, which could be used to facilitate ransomware attacks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/poland-arrests-suspect-linked-to-phobos-ransomware-operation/?utm_source=openai)) This arrest underscores the ongoing global efforts to dismantle ransomware operations and highlights the persistent threat posed by groups like Phobos. Organizations are reminded to bolster their cybersecurity defenses, particularly around Remote Desktop Protocol (RDP) configurations, to mitigate the risk of such attacks.
5 months ago
Kill Chain
Intruder 2026: Unveiling Exposed Secrets in JavaScript Bundles
In December 2025, Intruder's research team conducted a comprehensive scan of 5 million applications, uncovering over 42,000 exposed tokens hidden within JavaScript bundles. These tokens included sensitive credentials such as code repository access tokens and project management API keys, many of which were active and provided unauthorized access to critical systems. The exposure was attributed to limitations in traditional security tools, which often fail to detect secrets embedded in front-end code, particularly within single-page applications. This incident underscores the urgent need for enhanced secrets detection methods that can effectively identify and mitigate such vulnerabilities in modern web applications.
5 months ago
Kill Chain
Critical Vulnerabilities in Popular VSCode Extensions Expose Developers to Attacks
In February 2026, critical vulnerabilities were discovered in several widely-used Visual Studio Code (VSCode) extensions, including Live Server, Code Runner, Markdown Preview Enhanced, and Microsoft Live Preview. These extensions, collectively downloaded over 128 million times, contained flaws that could be exploited to steal local files and execute remote code. The vulnerabilities were identified by Ox Security, which attempted disclosure since June 2025 without receiving responses from the maintainers. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/?utm_source=openai)) This incident underscores the escalating risks associated with third-party development tools and the necessity for rigorous security assessments of IDE extensions. The widespread adoption of these vulnerable extensions highlights the potential for significant supply chain attacks targeting developers and organizations.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports