Validated Containment Architectures are here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2675 threat reports
Page 126 of 223

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 15011512 / 2675 reports
SmartLoader's Exploitation of Oura MCP Server: A 2026 Supply Chain Attack
Impact· HIGH

SmartLoader's Exploitation of Oura MCP Server: A 2026 Supply Chain Attack

In February 2026, cybersecurity researchers uncovered a sophisticated supply chain attack involving the SmartLoader malware. Threat actors cloned the legitimate Oura Model Context Protocol (MCP) Server—a tool connecting AI assistants to Oura Ring health data—and distributed a trojanized version through deceptive GitHub repositories. This malicious server delivered the StealC infostealer, enabling attackers to exfiltrate credentials, browser passwords, and cryptocurrency wallet data from compromised systems. The attackers meticulously built credibility by creating fake GitHub accounts and repositories, submitting the trojanized server to legitimate MCP registries, and excluding the original author from contributor lists, thereby deceiving users into downloading the compromised software. This incident underscores a growing trend where threat actors exploit trusted platforms and tools to infiltrate systems. The methodical approach of building credibility over months highlights the evolving sophistication of supply chain attacks, emphasizing the need for organizations to rigorously verify the authenticity of software sources and implement robust security reviews before integrating third-party tools.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
AI Assistants Abused as Command-and-Control Proxies in Recent Cyberattacks
Impact· HIGH

AI Assistants Abused as Command-and-Control Proxies in Recent Cyberattacks

In February 2026, cybersecurity researchers disclosed a novel attack technique where AI assistants with web browsing capabilities, such as Microsoft Copilot and xAI Grok, were exploited as covert command-and-control (C2) proxies. This method, termed 'AI as a C2 proxy' by Check Point Research, allows attackers to blend malicious traffic with legitimate enterprise communications, thereby evading detection. The attack leverages anonymous web access combined with browsing and summarization prompts to create a bidirectional channel for data exfiltration and command execution. This development underscores the evolving threat landscape, where AI systems are not only tools for enhancing productivity but also potential vectors for sophisticated cyberattacks. The ability to abuse AI assistants as C2 proxies highlights the need for organizations to reassess their security postures, especially concerning the integration and use of AI technologies within their networks.

5 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Salesloft Drift Breach 2025: A Wake-Up Call for SaaS Security
Impact· HIGH

Salesloft Drift Breach 2025: A Wake-Up Call for SaaS Security

In August 2025, Salesloft's Drift application suffered a significant security breach when attackers exploited compromised OAuth tokens to access and exfiltrate data from over 700 organizations' Salesforce instances. The breach exposed sensitive information, including customer contact details, support case data, and, in some cases, credentials such as AWS access keys and passwords. Prominent companies like Cloudflare, Zscaler, and Palo Alto Networks were among those affected. The attackers, identified as the group "Scattered Lapsus$ Hunters," demanded nearly $1 billion in ransom to prevent the public release of the stolen data. This incident underscores the critical vulnerabilities associated with third-party integrations and the importance of robust security measures to protect against supply chain attacks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Understanding the 2026 ClickFix DNS PowerShell Attack
Impact· HIGH

Understanding the 2026 ClickFix DNS PowerShell Attack

In February 2026, a new variant of the ClickFix social engineering attack emerged, exploiting DNS queries to deliver malicious payloads. Attackers deceived users into executing an 'nslookup' command via the Windows Run dialog, which queried an attacker-controlled DNS server. The server responded with a DNS record containing a malicious PowerShell script, leading to the installation of malware, including the remote access trojan ModeloRAT. This method allowed attackers to blend malicious activities within normal DNS traffic, evading traditional detection mechanisms. This incident underscores the evolving sophistication of social engineering attacks, highlighting the need for heightened awareness and advanced security measures. The use of DNS as a delivery mechanism signifies a shift in attacker tactics, emphasizing the importance of monitoring DNS traffic and educating users about the risks of executing unsolicited commands.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(low)
Read Report
BeyondTrust 2026 Remote Code Execution Vulnerability: Immediate Action Required
Impact· CRITICAL

BeyondTrust 2026 Remote Code Execution Vulnerability: Immediate Action Required

In February 2026, BeyondTrust disclosed a critical remote code execution (RCE) vulnerability, identified as CVE-2026-1731, affecting its Remote Support (RS) and Privileged Remote Access (PRA) products. This flaw, with a CVSS score of 9.9, allows unauthenticated attackers to execute operating system commands remotely, potentially leading to full system compromise. The vulnerability impacts RS versions 25.3.1 and earlier, and PRA versions 24.3.4 and earlier. BeyondTrust issued patches on February 2, 2026, urging all customers, especially those with self-hosted instances not subscribed to automatic updates, to apply the patches promptly. ([beyondtrust.com](https://www.beyondtrust.com/trust-center/security-advisories/bt26-02?utm_source=openai)) The urgency of this situation is underscored by the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) directive for federal agencies to secure their BeyondTrust instances within three days, highlighting the active exploitation of this vulnerability in the wild. ([techradar.com](https://www.techradar.com/pro/security/cisa-tells-agencies-to-patch-beyondtrust-bug-now?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
OpenClaw 2026: A Cautionary Tale of AI Assistant Security
Impact· CRITICAL

OpenClaw 2026: A Cautionary Tale of AI Assistant Security

In early 2026, the OpenClaw AI assistant platform, formerly known as ClawdBot and MoltBot, experienced a significant security breach. Over 340 malicious 'skills' were uploaded to its ClawHub marketplace, many disguised as cryptocurrency tools. These skills, once installed, executed obfuscated commands leading to the deployment of the Atomic macOS Stealer (AMOS) malware. This malware targeted sensitive user data, including API keys, wallet private keys, SSH credentials, and browser passwords. The rapid adoption of OpenClaw, with over 30,000 online instances by late January 2026, coupled with minimal security oversight, facilitated this large-scale supply chain attack. ([aviatrix.ai](https://aviatrix.ai/threat-research-center/openclaw-2026-clawhub-malicious-skills/?utm_source=openai)) This incident underscores the growing trend of cybercriminals exploiting AI assistant platforms to distribute malware. The integration of AI agents into daily workflows, especially in sectors like cryptocurrency trading, presents new attack vectors. Organizations must prioritize the security of AI ecosystems, ensuring rigorous vetting of third-party extensions and continuous monitoring to mitigate such threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Washington Hotel Japan Ransomware Attack: A 2026 Case Study
Impact· MEDIUM

Washington Hotel Japan Ransomware Attack: A 2026 Case Study

In February 2026, Washington Hotel, a prominent hospitality chain in Japan, experienced a ransomware attack that compromised its servers and exposed various business data. The breach occurred on February 13, 2026, at 22:00 local time. Upon detection, the IT staff promptly disconnected the affected servers from the internet to prevent further spread. An internal task force, along with external cybersecurity experts, was established to assess the impact and coordinate recovery efforts. While customer data is believed to be secure, as it is stored on separate servers managed by a different company, some operational disruptions, including temporary unavailability of credit card terminals, were reported. The financial impact is under review, and the company is collaborating with law enforcement and cybersecurity professionals to investigate the incident. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/washington-hotel-in-japan-discloses-ransomware-infection-incident/?utm_source=openai)) This incident underscores the escalating threat of ransomware attacks targeting the hospitality industry, particularly in Japan. Recent data indicates a significant increase in such attacks, with small and medium-sized enterprises being primary targets. The Washington Hotel breach highlights the urgent need for robust cybersecurity measures and proactive strategies to mitigate the risks associated with ransomware and other cyber threats. ([linkedin.com](https://www.linkedin.com/pulse/ransomware-attacks-targeting-japanese-companies-increase-baek-glpcc?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Eurail 2026 Data Breach: What You Need to Know
Impact· HIGH

Eurail 2026 Data Breach: What You Need to Know

In January 2026, Eurail B.V., the operator of the Interrail ticketing platform, experienced a security breach resulting in unauthorized access to customer data. The compromised information includes names, contact details, passport information, and, for some DiscoverEU participants, bank account references and health data. Upon discovery, Eurail secured its systems, initiated an investigation with external cybersecurity specialists, and began notifying affected customers and regulatory authorities. As of mid-January 2026, there is no evidence of data misuse or public disclosure. This incident underscores the critical importance of robust cybersecurity measures in the travel industry, especially given the sensitive nature of the data involved. Organizations must remain vigilant against evolving cyber threats and ensure compliance with data protection regulations to safeguard customer information.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Lithuania's Digital Infrastructure Compromised by AI-Driven Social Engineering Attacks in 2026
Impact· HIGH

Lithuania's Digital Infrastructure Compromised by AI-Driven Social Engineering Attacks in 2026

In early 2026, Lithuania faced a surge in AI-driven social engineering attacks targeting its digital infrastructure. Cybercriminals utilized advanced AI tools to craft highly personalized phishing campaigns, deepfake videos, and voice-cloned calls, deceiving individuals into divulging sensitive information. These sophisticated attacks led to significant data breaches across various sectors, including finance and public services, compromising personal data and undermining trust in digital platforms. This incident underscores the escalating threat of AI-enhanced cyber fraud, highlighting the need for robust cybersecurity measures and public awareness. As AI technologies become more accessible, the potential for their misuse in cyberattacks grows, necessitating proactive defense strategies and continuous monitoring to safeguard digital ecosystems.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Outlook Add-In Hijack Exposes 4,000 Microsoft Accounts
Impact· HIGH

Outlook Add-In Hijack Exposes 4,000 Microsoft Accounts

In early February 2026, a threat actor exploited an abandoned Microsoft Outlook add-in named AgreeTo, originally a meeting scheduling tool, to conduct a phishing campaign. By claiming the add-in's orphaned URL, the attacker replaced its content with a phishing kit that mimicked Microsoft's sign-in page, leading to the compromise of over 4,000 Microsoft account credentials. This incident underscores the risks associated with unmaintained third-party applications and highlights the need for rigorous oversight of software supply chains. The attack also demonstrates how adversaries can leverage trusted platforms to distribute malicious content, emphasizing the importance of continuous monitoring and validation of third-party integrations.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
OpenClaw 2026 Infostealer Vidar Breach: A Wake-Up Call for AI Security
Impact· HIGH

OpenClaw 2026 Infostealer Vidar Breach: A Wake-Up Call for AI Security

In February 2026, cybersecurity researchers identified a significant security breach involving OpenClaw, an open-source AI agent platform. An infostealer malware, likely a variant of Vidar, infiltrated a user's system and exfiltrated sensitive OpenClaw configuration files. These files contained critical data, including API keys for AI services, OAuth tokens for platforms like Gmail and Slack, and detailed operational guidelines of the AI agent. The theft of these credentials enabled attackers to remotely access and control the victim's OpenClaw instance, potentially leading to unauthorized actions and data exfiltration. This incident underscores the evolving threat landscape where infostealer malware targets AI agent configurations, highlighting the urgent need for enhanced security measures in AI integrations. As AI agents become more embedded in professional workflows, they present attractive targets for cybercriminals aiming to exploit their access to sensitive data and systems.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Major Password Managers Exposed: Critical Vulnerabilities Affect Millions
Impact· MEDIUM

Major Password Managers Exposed: Critical Vulnerabilities Affect Millions

In February 2026, researchers from ETH Zurich and Università della Svizzera italiana identified critical vulnerabilities in three major cloud-based password managers: Bitwarden, LastPass, and Dashlane. The study revealed 25 distinct attacks that could compromise user vaults, ranging from integrity violations to complete access to all stored passwords. These vulnerabilities exploit flaws in key escrow mechanisms, item-level encryption, sharing features, and backward compatibility with legacy code. Collectively, these password managers serve over 60 million users and nearly 125,000 businesses. ([thehackernews.com](https://thehackernews.com/2026/02/study-uncovers-25-password-recovery.html?utm_source=openai)) This incident underscores the importance of scrutinizing the security claims of widely-used password management solutions. As cyber threats evolve, organizations must ensure that their security tools are resilient against sophisticated attacks, especially those targeting foundational security mechanisms like zero-knowledge encryption.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports