✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
SolarWinds Web Help Desk 2026 Untrusted Data Deserialization RCE
In January 2026, a critical vulnerability (CVE-2025-40551) was discovered in SolarWinds Web Help Desk (WHD), allowing unauthenticated remote code execution through untrusted data deserialization. Exploitation of this flaw enables attackers to execute arbitrary commands on the host system, potentially leading to full system compromise. SolarWinds released WHD version 2026.1 on January 28, 2026, addressing this and other vulnerabilities. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/cve-2025-40551?utm_source=openai)) The inclusion of CVE-2025-40551 in CISA's Known Exploited Vulnerabilities catalog underscores the urgency for organizations to apply the patch promptly. This incident highlights the persistent threat posed by deserialization vulnerabilities and the importance of timely software updates to mitigate such risks. ([securityweek.com](https://www.securityweek.com/fresh-solarwinds-vulnerability-exploited-in-attacks/?utm_source=openai))
5 months ago
Kill Chain
Eclipse Foundation's 2025 Response to Unauthorized Extension Uploads
In May 2025, the Eclipse Foundation identified a vulnerability in the Open VSX Registry's automated publishing system, potentially allowing unauthorized extension uploads. The flaw, reported by Koi Security researchers, involved inadequate isolation in build scripts, exposing a privileged token that could be exploited to publish extensions under any namespace. The issue was promptly addressed, with a fix deployed by June 24, 2025, and a comprehensive audit confirming no evidence of exploitation. As a precaution, 81 extensions were deactivated. This incident underscores the critical importance of securing automated processes in software supply chains to prevent unauthorized access and maintain trust in open-source ecosystems. The Eclipse Foundation has since implemented enhanced security measures, including sandboxing build processes and enforcing stricter credential management, to mitigate similar risks in the future.
5 months ago
Kill Chain
Understanding the n8n 2026 Authenticated RCE Vulnerability
In early 2026, multiple critical vulnerabilities were identified in n8n, an open-source workflow automation platform. These flaws, collectively tracked as CVE-2026-25049, allowed authenticated users with permissions to create or modify workflows to execute arbitrary system commands on the host server. Exploitation of these vulnerabilities could lead to full system compromise, including unauthorized access to sensitive data and potential lateral movement within connected systems. The issues were addressed in versions 1.123.17 and 2.5.2, released in January 2026. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/critical-n8n-flaws-disclosed-along-with-public-exploits/?utm_source=openai)) This incident underscores the importance of rigorous input validation and sandboxing mechanisms in software development. It also highlights the necessity for organizations to promptly apply security patches to mitigate risks associated with known vulnerabilities.
5 months ago
Kill Chain
NGINX Server Compromise 2026: Understanding the Traffic Redirection Attack
In early February 2026, a sophisticated cyberattack targeted NGINX servers, leading to unauthorized redirection of user traffic through attacker-controlled infrastructure. The threat actors exploited vulnerabilities in NGINX configurations, particularly by injecting malicious 'location' blocks into existing configuration files. This manipulation allowed them to intercept and reroute incoming requests without triggering standard security alerts, as the abuse leveraged legitimate directives like 'proxy_pass'. The campaign primarily affected websites with Asian top-level domains and government and educational institutions, compromising the integrity and confidentiality of user data. This incident underscores the critical need for organizations to regularly audit and secure their web server configurations. The attackers' method of embedding malicious instructions within NGINX configuration files highlights the evolving sophistication of cyber threats and the importance of proactive defense measures to prevent similar breaches.
5 months ago
Kill Chain
DEAD#VAX Malware Campaign: A New Era of Fileless Attacks
In early February 2026, cybersecurity researchers uncovered a sophisticated malware campaign named DEAD#VAX, which utilized phishing emails to distribute Virtual Hard Disk (VHD) files hosted on the InterPlanetary File System (IPFS). These VHD files, disguised as PDF documents, contained obfuscated scripts that, upon execution, deployed AsyncRAT—a remote access trojan—into trusted Windows processes entirely in memory, leaving minimal forensic traces on disk. This method allowed attackers to gain extensive control over compromised systems, facilitating surveillance and data exfiltration. The campaign's use of decentralized file hosting and fileless execution techniques highlights a significant evolution in malware delivery and evasion strategies. ([thehackernews.com](https://thehackernews.com/2026/02/deadvax-malware-campaign-deploys.html?utm_source=openai)) The DEAD#VAX campaign underscores a growing trend among cybercriminals to exploit legitimate system features and decentralized technologies to bypass traditional security measures. The reliance on IPFS for hosting malicious payloads and the employment of fileless malware execution present new challenges for detection and mitigation, emphasizing the need for advanced threat intelligence and adaptive defense mechanisms in the face of evolving cyber threats. ([thehackernews.com](https://thehackernews.com/2026/02/deadvax-malware-campaign-deploys.html?utm_source=openai))
5 months ago
Kill Chain
Microsoft's New Scanner Bolsters AI Security by Detecting LLM Backdoors
In February 2026, Microsoft unveiled a lightweight scanner designed to detect backdoors in open-weight large language models (LLMs). This tool identifies malicious alterations by analyzing three key behavioral signals: distinctive attention patterns triggered by specific inputs, unintended data memorization, and activation by multiple similar triggers. The scanner operates efficiently without requiring additional model training or prior knowledge of potential backdoors, making it applicable across various GPT-style models. However, it necessitates access to model files and is most effective against deterministic backdoors. This development underscores Microsoft's commitment to enhancing AI security and trustworthiness. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/02/04/detecting-backdoored-language-models-at-scale/?utm_source=openai)) The release of this scanner is particularly timely given the increasing integration of LLMs into critical applications. Recent research highlights the ease with which backdoors can be embedded into AI models, even with minimal malicious data. ([arstechnica.com](https://arstechnica.com/ai/2025/10/ai-models-can-acquire-backdoors-from-surprisingly-few-malicious-documents/?utm_source=openai)) Microsoft's proactive approach addresses these emerging threats, aiming to safeguard AI systems from covert manipulations that could compromise their integrity and reliability.
5 months ago
Kill Chain
Unveiling the Rublevka Team: A Deep Dive into the 2023 Crypto Wallet Draining Operation
In 2023, the cybercriminal group known as 'Rublevka Team' orchestrated large-scale cryptocurrency thefts, amassing over $10 million through affiliate-driven wallet draining campaigns. Operating as a 'traffer team,' they utilized a network of social engineering specialists to direct victims to malicious landing pages. These pages, impersonating legitimate crypto services, deployed custom JavaScript scripts that tricked users into connecting their wallets and authorizing fraudulent transactions. The group's fully automated infrastructure provided affiliates with tools such as Telegram bots, landing page generators, and support for over 90 wallet types, enabling high-volume scams with minimal oversight. This incident underscores the evolving threat landscape in the cryptocurrency sector, highlighting the shift towards scalable, service-based cybercrime models. The Rublevka Team's operations pose significant risks to cryptocurrency platforms, fintech providers, and brands, emphasizing the need for proactive monitoring and defense strategies to protect customers and maintain trust.
5 months ago
Kill Chain
GlassWorm Malware Compromises Open VSX Registry in 2026 Supply Chain Attack
In late January 2026, a sophisticated supply chain attack compromised the Open VSX Registry, an open-source marketplace for Visual Studio Code extensions. Threat actors gained unauthorized access to a trusted developer's account, 'oorzc,' and injected malicious code into four widely-used extensions: FTP/SFTP/SSH Sync Tool, I18n Tools, vscode mindmap, and scss to css. These extensions, collectively downloaded over 22,000 times, delivered the GlassWorm malware, which targeted macOS systems to exfiltrate sensitive data, including browser credentials, cryptocurrency wallets, and developer secrets. The malware employed advanced evasion techniques, such as locale checks to avoid Russian systems and utilizing the Solana blockchain for command-and-control communications. ([thehackernews.com](https://thehackernews.com/2026/02/open-vsx-supply-chain-attack-used.html?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks within the developer ecosystem. The exploitation of trusted extensions highlights the need for enhanced security measures in open-source platforms. Organizations must prioritize the integrity of their development tools and implement robust monitoring to detect unauthorized modifications promptly.
5 months ago
Kill Chain
Critical Security Flaws in Google Looker: A Wake-Up Call for Cloud Security
In late 2025, critical vulnerabilities were discovered in Google Looker, a widely used business intelligence platform. These flaws allowed attackers to execute remote code and exfiltrate sensitive data across different Google Cloud Platform (GCP) tenants. The most severe issue enabled unauthorized users to gain full control over Looker instances, potentially leading to data manipulation and deeper network infiltration. Google promptly patched these vulnerabilities in its cloud-hosted services; however, organizations using self-hosted Looker instances were required to manually apply the updates to mitigate the risks. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/04/google-looker-vulnerabilities-cve-2025-12743/?utm_source=openai)) This incident underscores the growing threat landscape targeting cloud-based business intelligence tools. As organizations increasingly rely on such platforms, ensuring robust security measures and timely patch management becomes imperative to prevent unauthorized access and data breaches.
5 months ago
Kill Chain
CISA Highlights Four Actively Exploited Vulnerabilities in February 2026
In February 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. These vulnerabilities include CVE-2019-19006 and CVE-2025-64328 in Sangoma FreePBX, CVE-2021-39935 in GitLab Community and Enterprise Editions, and CVE-2025-40551 in SolarWinds Web Help Desk. The vulnerabilities range from improper authentication and OS command injection to server-side request forgery and deserialization of untrusted data, posing significant risks to affected systems. The inclusion of these vulnerabilities in the KEV Catalog underscores the persistent threat posed by unpatched software. Organizations are urged to prioritize remediation efforts to mitigate potential exploitation, as these vulnerabilities are actively targeted by malicious actors.
5 months ago
Kill Chain
Unauthenticated API Leads to OAuth Token Exposure in 2025
In April 2025, a critical security vulnerability was discovered during a bug bounty program hosted by YesWeHack. An unauthenticated API endpoint exposed OAuth client credentials, allowing unauthorized access to sensitive personal and business data. This misconfiguration enabled attackers to impersonate trusted applications and retrieve confidential information without any authentication barriers. The flaw was promptly reported and addressed, mitigating potential exploitation. ([cyberpress.org](https://cyberpress.org/oauth-misconfiguration-enables-researchers-to-access-sensitive-data/?utm_source=openai)) This incident underscores the importance of securing API endpoints and properly managing OAuth credentials. As organizations increasingly rely on APIs for business operations, ensuring robust authentication and authorization mechanisms is crucial to prevent unauthorized data access and potential breaches.
5 months ago
Kill Chain
XWorm Malware Resurgence in 2025: Advanced Threats Unveiled
In mid-2025, cybersecurity researchers identified a resurgence of the XWorm Remote Access Trojan (RAT), notably with the release of version 6.0. This variant introduced advanced plugins, enhanced persistence mechanisms, and a ransomware module, significantly increasing its threat level. Attackers distributed XWorm V6 through sophisticated phishing campaigns, utilizing malicious JavaScript droppers that executed PowerShell scripts to deliver injector DLLs. The malware's modular design allowed for extensive data theft, system control, and file encryption, posing substantial risks to organizations across various sectors. The re-emergence of XWorm underscores the evolving nature of cyber threats, highlighting the necessity for organizations to adopt proactive and adaptive cybersecurity measures. The malware's advanced evasion techniques and modular capabilities reflect a broader trend of increasingly sophisticated attack vectors, emphasizing the importance of continuous monitoring, employee training, and robust security protocols to mitigate such threats.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports