✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
GitHub Codespaces RCE Vulnerability: What Developers Need to Know
In early February 2026, security researchers identified multiple attack vectors within GitHub Codespaces that allow remote code execution (RCE) when users open malicious repositories or pull requests. The vulnerability exploits how Visual Studio Code-integrated configuration files are automatically processed, enabling attackers to execute arbitrary commands, exfiltrate GitHub tokens, and access sensitive resources without explicit user approval. Microsoft has currently deemed this behavior as 'by design,' and no CVE has been assigned. ([scworld.com](https://www.scworld.com/news/vs-code-config-files-abused-to-launch-rces-via-github-codespaces?utm_source=openai)) This incident underscores the growing trend of attackers leveraging trusted development environments to execute malicious code, highlighting the need for enhanced security measures and user awareness in cloud-based development platforms.
5 months ago
Kill Chain
Aisuru/Kimwolf Botnet's Unprecedented 31.4 Tbps DDoS Attack in 2025
In December 2025, the Aisuru/Kimwolf botnet launched a record-breaking distributed denial-of-service (DDoS) attack, peaking at 31.4 terabits per second (Tbps) and 200 million requests per second. This unprecedented assault targeted multiple companies, primarily in the telecommunications sector, and Cloudflare's own infrastructure. The attack, part of a campaign dubbed "The Night Before Christmas," was successfully mitigated by Cloudflare's automated systems, preventing significant disruptions. ([techradar.com](https://www.techradar.com/pro/security/the-biggest-ddos-attack-ever-has-been-detected-but-fortunately-you-probably-barely-noticed-it?utm_source=openai)) This incident underscores the escalating scale and sophistication of DDoS attacks, highlighting the urgent need for robust cybersecurity measures. The rapid growth of botnets like Aisuru/Kimwolf, which exploit vulnerabilities in IoT devices, poses a significant threat to global internet infrastructure. ([tomshardware.com](https://www.tomshardware.com/service-providers/network-providers/botnet-smashes-ddos-traffic-record-at-31-4-tb-s-equivalent-to-streaming-2-2-million-netflix-4k-movies-at-once-attack-was-large-enough-to-take-entire-countries-offline?utm_source=openai))
5 months ago
Kill Chain
Windows Screensaver Malware Attack 2026: A New Vector for Remote Access Exploitation
In early February 2026, cybersecurity researchers identified a spear-phishing campaign exploiting Windows screensaver files (.scr) to deploy remote access tools (RATs) on corporate networks. Attackers sent business-themed phishing emails containing links to download files disguised as routine documents, which were actually malicious screensaver files. When executed, these files installed legitimate remote monitoring and management (RMM) tools, such as SimpleHelp, providing attackers with persistent remote access to compromised systems. This method allowed adversaries to bypass traditional security controls, as screensaver files are often overlooked as potential threats. The campaign underscores the evolving tactics of threat actors who leverage unconventional file types and legitimate software to infiltrate networks, emphasizing the need for organizations to reassess and strengthen their security postures against such sophisticated social engineering attacks.
5 months ago
Kill Chain
DragonForce Ransomware Cartel: A New Era of Cyber Threats in 2025
In March 2025, the DragonForce ransomware group rebranded itself as a cartel, allowing affiliates to create their own brands while utilizing DragonForce's infrastructure and tools. This strategic shift led to increased collaboration among ransomware groups, notably with LockBit and Qilin, aiming to consolidate power and enhance operational effectiveness. The cartel model facilitated larger, more coordinated ransomware campaigns, employing advanced tactics such as double extortion, exploitation of known vulnerabilities, and the use of sophisticated tools like Cobalt Strike and Mimikatz. This evolution resulted in a significant uptick in ransomware incidents, impacting various sectors globally, including government entities, retail operations, manufacturing companies, and construction firms. The formation of such cartels underscores a concerning trend in the cyber threat landscape, where ransomware groups are increasingly collaborating to amplify their reach and impact. This development necessitates heightened vigilance and adaptive defense strategies from organizations to mitigate the evolving threats posed by these alliances.
5 months ago
Kill Chain
Iranian Cyber Espionage Intensifies: Middle East Expatriates Targeted in 2026
In early 2026, Iranian state-sponsored cyber actors intensified their espionage activities targeting Middle Eastern expatriates, Syrians, and Israelis. Utilizing sophisticated social engineering techniques, these actors created credible fake personas on multiple platforms, engaging targets over extended periods to build trust. Once rapport was established, they employed spear-phishing campaigns, often delivering malicious links or documents under the guise of legitimate communications. These operations aimed to steal sensitive information, monitor communications, and track the movements of individuals of interest. The impact of these campaigns has been significant, compromising personal and professional data, and posing threats to the safety and privacy of the targeted individuals. The use of advanced social engineering tactics underscores the evolving nature of cyber threats emanating from state-sponsored actors. This incident highlights the urgent need for heightened vigilance and robust cybersecurity measures, especially for individuals and organizations operating in or related to the Middle East. The increasing sophistication of these attacks, coupled with their targeted nature, reflects a broader trend of state actors leveraging cyber capabilities for intelligence gathering and influence operations.
5 months ago
Kill Chain
Phishing Campaign 2026: Malformed URLs Bypass Security Measures
In early February 2026, a sophisticated phishing campaign emerged, utilizing malformed URLs to bypass traditional email security measures. Attackers embedded URLs with irregular parameter structures in phishing emails, leading recipients to malicious websites. This technique effectively evaded detection systems that rely on standard URL parsing and validation, thereby increasing the likelihood of successful credential theft and malware distribution. The campaign underscores the evolving tactics of cybercriminals in circumventing established security protocols. The resurgence of such techniques highlights the need for organizations to continuously adapt their security strategies. As attackers refine their methods to exploit weaknesses in URL parsing and detection, it becomes imperative for security systems to incorporate advanced analysis capabilities to identify and mitigate these sophisticated threats.
5 months ago
Kill Chain
Microsoft's 2026 Breakthrough in AI Language Model Backdoor Detection
In February 2026, Microsoft unveiled a novel approach to detect backdoors in open-weight language models, addressing the growing concern of model poisoning where adversaries embed hidden behaviors during training. This research introduces a scalable scanner capable of identifying backdoored models by analyzing distinctive attention patterns and output behaviors, thereby enhancing trust in AI systems. The significance of this development is underscored by prior findings that even minimal malicious data can implant backdoors in large language models, emphasizing the urgency for robust detection mechanisms. Microsoft's initiative represents a proactive step towards securing AI deployments against such covert threats.
5 months ago
Kill Chain
Notepad++ Supply Chain Attack: A Wake-Up Call for Software Security
Between June and December 2025, Notepad++, a widely used text editor, was compromised through a sophisticated supply chain attack attributed to Chinese state-sponsored hackers. The attackers infiltrated the hosting provider's infrastructure, allowing them to intercept and redirect update traffic to malicious servers. This enabled the delivery of backdoored versions of Notepad++ to selected users, primarily targeting sectors such as government, telecommunications, and critical infrastructure. The breach was identified in early February 2026, prompting immediate security enhancements and advisories for users to update to version 8.9.1 or later. This incident underscores the escalating threat of supply chain attacks, where adversaries exploit trusted software distribution channels to infiltrate target systems. Organizations are urged to reassess and fortify their software update mechanisms, implement stringent verification processes, and remain vigilant against such sophisticated attack vectors.
5 months ago
Kill Chain
Coinbase Insider Breach 2025: A Cautionary Tale of Insider Threats in the Financial Sector
In May 2025, Coinbase, the largest U.S.-based cryptocurrency exchange, disclosed a significant data breach affecting approximately 69,461 customers. The breach, which occurred on December 26, 2024, was orchestrated by cybercriminals who bribed overseas customer support agents to gain unauthorized access to sensitive customer information. The compromised data included names, addresses, phone numbers, email addresses, masked Social Security numbers, masked bank account numbers, government-issued ID images, and account transaction histories. Notably, no passwords, private keys, or funds were exposed, and Coinbase Prime accounts remained unaffected. The attackers demanded a $20 million ransom, which Coinbase refused to pay, instead offering a $20 million bounty for information leading to the attackers' arrest. The company estimated remediation costs between $180 million and $400 million and pledged to reimburse affected customers. This incident underscores the critical importance of robust insider threat detection and prevention measures, especially in the financial sector. The breach highlights the vulnerabilities associated with third-party service providers and the need for stringent access controls and monitoring. As insider threats continue to pose significant risks, organizations must prioritize comprehensive security strategies to safeguard sensitive customer data and maintain trust.
5 months ago
Kill Chain
Home Depot's 2024 GitHub Token Leak: A Cautionary Tale in Credential Management
In early 2024, a Home Depot employee inadvertently published a private GitHub access token, exposing the company's internal systems for over a year. This token granted unauthorized access to hundreds of private source code repositories, cloud infrastructure, order fulfillment, and inventory management systems. Despite multiple attempts by security researcher Ben Zimmermann to alert Home Depot, the token remained active until December 2025, when media intervention prompted its revocation. This incident underscores the critical need for robust credential management and proactive security measures to prevent unauthorized access to sensitive systems. The prolonged exposure highlights systemic gaps in credential governance and the importance of timely response to security disclosures.
5 months ago
Kill Chain
Amaranth Dragon's 2025 Exploitation of WinRAR Vulnerability: A Cybersecurity Wake-Up Call
In August 2025, the cyberespionage group Amaranth Dragon, linked to China's APT41, exploited the CVE-2025-8088 vulnerability in WinRAR to target government and law enforcement agencies across Southeast Asia. By crafting malicious RAR archives, they leveraged the vulnerability to place encrypted payloads in the Windows Startup folder, ensuring persistence upon system reboot. These attacks were characterized by the use of legitimate tools combined with the custom Amaranth Loader, which retrieved payloads from command-and-control servers concealed behind Cloudflare infrastructure, enhancing stealth and targeting precision. The continued exploitation of CVE-2025-8088 by multiple threat actors underscores the critical need for organizations to promptly update software and implement robust security measures. Despite the release of WinRAR version 7.13, which addresses this flaw, many systems remain vulnerable due to delayed patching and user unawareness, highlighting a significant gap in cybersecurity defenses.
5 months ago
Kill Chain
Ransomware Groups Exploit VMware ESXi Vulnerability in 2026
In March 2025, Broadcom patched a high-severity VMware ESXi vulnerability (CVE-2025-22225) that allowed attackers with VMX process privileges to perform arbitrary kernel writes, leading to sandbox escapes. Despite the patch, by February 2026, ransomware groups began exploiting this flaw to gain unauthorized access to ESXi hypervisors, encrypting virtual machines and disrupting critical services. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed these exploitations and added the vulnerability to its Known Exploited Vulnerabilities catalog, urging organizations to apply mitigations or discontinue use if patches are unavailable. This incident underscores the persistent threat posed by unpatched vulnerabilities in widely used virtualization platforms, highlighting the need for timely updates and robust security practices to prevent exploitation by ransomware operators.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports