✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
NPM Supply Chain Bypass: PackageGate and Shai-Hulud Exploits Expose Open-Source Risks in 2026
In January 2026, critical vulnerabilities dubbed "PackageGate" were revealed in NPM and several popular JavaScript package managers, exposing gaps in defenses against supply chain attacks like last year's Shai-Hulud incidents. Despite previous security improvements, attackers could still bypass NPM's safeguard against malicious package scripts by leveraging Git dependencies and malicious .npmrc configuration files, leading to unauthorized code execution—even when script blocking features were enabled. The flaws, discovered by Koi Security researchers, allowed full code compromise and had potential for massive developer credential and secret exfiltration, threatening tens of thousands of projects and their downstream users. These findings highlight the persistent risks in open-source supply chains and the accelerating pace of software supply chain attacks. As threat actors become more adept at exploiting package management tools, organizations face renewed urgency to bolster visibility, enforce granular access controls, and adopt defense-in-depth measures to protect development workflows and critical assets.
6 months ago
Kill Chain
Malicious AI-Powered VS Code Extensions Trigger Global Supply Chain Breach (2026)
In January 2026, cybersecurity researchers uncovered that two widely-distributed AI-powered Microsoft Visual Studio Code extensions, with over 1.5 million combined installs, were covertly exfiltrating developer source code and sensitive project data to servers based in China. The malicious extensions masqueraded as legitimate AI coding tools, enticing developers globally through the official VS Code marketplace. Once installed, these extensions surreptitiously uploaded confidential code and intellectual property, potentially endangering enterprise software assets and customer data. Investigators highlighted the supply chain risk, noting the threat’s scalability via trusted software distribution channels and the delays in detecting such activity. This incident underscores the escalating risks associated with third-party development tools, particularly those leveraging AI branding. The popularity and trust in official marketplaces can allow sophisticated advanced persistent threats (APTs) or criminal groups to exploit developers and organizations, necessitating enhanced scrutiny and continuous security monitoring of supply chain dependencies.
6 months ago
Kill Chain
Exposed Environment Files: The $(pwd) Webserver Reconnaissance Surge of Jan 2026
In January 2026, multiple sensors and the SANS Internet Storm Center reported a wave of targeted web application scans probing for exposed environment and configuration files on webservers using the /$(pwd)/ path pattern. Attackers, active since at least January 13th, systematically searched for sensitive files such as .env, docker-compose.yml, and terraform.tfstate, potentially exposing credentials and secrets. Two identified IP addresses (185.177.72.52, 185.177.72.23) led these scans, illustrating an automated approach likely leveraging misconfigured servers. While no confirmed breaches have been disclosed, such activity significantly raises the risk of follow-on exploitation or credential theft if vulnerable files are found. This incident highlights growing attacker sophistication in discovering misconfigurations and automating reconnaissance. The use of predictable directory traversal patterns and attempts to surface hidden files underscore the need for robust web application hardening and monitoring, especially as threat actors increasingly leverage similar tactics to bypass traditional defenses.
6 months ago
Kill Chain
ShinyHunters 2026: SSO Vishing Attacks Trigger Major SaaS Data Breaches
In January 2026, the cybercriminal group ShinyHunters orchestrated a series of sophisticated voice-phishing (vishing) attacks targeting corporate Single Sign-On (SSO) platforms, including Okta, Microsoft Entra, and Google. The attackers posed as IT support staff, manipulated employees into entering their credentials and multi-factor authentication tokens on fake login pages, and subsequently gained unauthorized access to SSO accounts. Leveraging these credentials, ShinyHunters accessed numerous connected SaaS applications such as Salesforce, Microsoft 365, and Slack, harvesting sensitive corporate data that was later used for extortion demands. High-profile organizations like SoundCloud, Betterment, and Crunchbase reported breaches and data losses as a result. This incident underscores a significant evolution in social engineering tactics, with attackers combining real-time phishing kits and vishing to bypass MFA and access a wide swath of corporate resources. As threat actors increasingly exploit identity-driven weaknesses and leverage SSO misconfigurations, organizations face greater risks of multi-system compromise and regulatory fallout.
6 months ago
Kill Chain
Russian Organizations Hit by Advanced Multi-Stage Phishing with Amnesia RAT and Ransomware
In January 2026, a sophisticated multi-stage phishing campaign targeted Russian organizations, leveraging social engineering emails that contained tampered business documents. These lures delivered a remote access trojan (Amnesia RAT) alongside ransomware, allowing attackers to establish stealthy persistence and ultimately encrypt sensitive data for extortion. The threat actors employed layered infection chains, executed lateral movement within infected environments, and exfiltrated critical information before deploying ransomware. The attack resulted in operational disruptions and financial risk for affected businesses. This incident reflects an escalating trend of multi-vector threats where initial phishing access rapidly pivots to advanced malware implants and ransomware. Security leaders must recognize the evolving sophistication and automation in phishing and malware delivery, and reinforce layered defenses, monitoring, and incident response to counter multi-stage cyber attacks.
6 months ago
Kill Chain
Konni Deploys AI-Built Malware Against Blockchain Engineers in 2026 Cyber Campaign
In January 2026, the North Korean-linked Konni APT (also known as Opal Sleet or TA406) launched a targeted cyber campaign against blockchain developers and engineers in the Asia-Pacific region, deploying bespoke PowerShell malware suspected of being generated using AI tools. Attackers lured victims with Discord-hosted ZIP files containing malicious shortcut links that, when launched, initiated a multi-stage infection chain. This included staged extraction of obfuscated PowerShell backdoors, privilege detection, scheduled task creation for persistence, and hourly beaconing to a remote command-and-control server. The malware focused on extracting sensitive development environment credentials, API keys, and potentially cryptocurrency wallet access, posing significant risks to both individuals and organizations handling blockchain assets. This incident exemplifies a sharp escalation in attacker sophistication, particularly the operational use of AI-powered malware, accelerating the pace at which advanced persistent threats can scale, adapt, and evade detection. As malicious actors increasingly leverage generative AI to develop modular, well-commented, and evasive code, organizations in crypto and other high-value sectors face a heightened need for adaptive security controls and rapid incident detection to keep defenses aligned with evolving attack techniques.
6 months ago
Kill Chain
CISA Urgently Flags Critical VMware vCenter Vulnerability (CVE-2024-37079) Amid Active Exploitation
In June 2024, a critical heap overflow vulnerability (CVE-2024-37079) affecting Broadcom VMware vCenter Server was identified and patched, but active exploitation was confirmed shortly thereafter. On January 10, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog after evidence surfaced of attackers leveraging the bug to execute unauthorized code remotely. Malicious actors could use this exploit to gain privileged access, conduct lateral movement, and potentially exfiltrate sensitive data or disrupt operations in environments utilizing unpatched vCenter servers. The incident underscores the continued targeting of core virtualization infrastructure by sophisticated threat actors and ransomware groups. With threat actors rapidly exploiting newly disclosed vulnerabilities, unpatched critical systems are at heightened risk, prompting urgency for patch management and layered security controls across enterprise environments.
6 months ago
Kill Chain
CISA Confirms Active Exploitation of Enterprise Supply Chain Vulnerabilities in 2026
In January 2026, the Cybersecurity and Infrastructure Security Agency (CISA) confirmed active exploitation of four critical vulnerabilities in enterprise software spanning supply chain, SD-WAN orchestration, front-end tooling, and webmail platforms. Attackers capitalized on flaws such as authentication bypasses in Versa Concerto, a supply-chain compromise in the eslint-config-prettier npm package, and local file inclusion in Zimbra's Webmail UI, bypassing access controls and risking the exposure of sensitive data and credentials. The vulnerabilities affected a range of organizations using these widely distributed platforms, underscoring the risks posed by third-party and open-source dependencies in software supply chains. This incident highlights a growing trend where attackers leverage chained vulnerabilities and software supply chain weaknesses to achieve lateral movement, privilege escalation, and large-scale data exfiltration. As regulatory scrutiny increases and adversaries target both enterprise and developer ecosystems, rapid patch management and improved visibility into third-party code become urgent mandates for security leaders.
6 months ago
Kill Chain
Malicious AI Extensions in VSCode Marketplace Steal Developer Data, Impacting 1.5 Million Users
In January 2026, researchers at Koi Security discovered that two AI-powered Visual Studio Code (VSCode) Marketplace extensions—ChatGPT – 中文版 and ChatMoss (CodeMoss)—were secretly exfiltrating developer files and sensitive data to China-based servers. Together, these malicious extensions had been installed 1.5 million times and collected data using real-time file monitoring, workspace file harvesting, and covert user profiling via embedded commercial analytics SDKs. The compromised extensions transmitted not only source code but potentially included API keys, configuration, and credential files without user consent, representing a major supply-chain compromise in the software development ecosystem. This incident highlights the persistent risks developers face from supply chain attacks through third-party plugins. As AI-driven code assistants surge in popularity, attackers are increasingly exploiting trusted extension marketplaces to deploy sophisticated data-stealing campaigns, raising urgent concerns for software security, compliance, and marketplace governance.
6 months ago
Kill Chain
Fortinet Zero-Day SSO Bypass Targets Fully Patched Firewalls in 2026
In January 2026, Fortinet confirmed that attackers actively exploited a new authentication bypass vulnerability affecting FortiCloud SSO on fully patched FortiGate firewalls. Despite organizations applying the latest security updates, adversaries used an undisclosed flaw to circumvent authentication protections, gaining unauthorized administrative access to network infrastructure. The incidents were detected within 24 hours of the latest firmware deployment, leading to compromised management interfaces and potentially broad security implications for affected enterprises utilizing FortiCloud SSO for remote management and single sign-on. This breach underscores a persistent challenge in cloud-managed network security: even well-maintained, up-to-date systems may be vulnerable to zero-day exploits. The event highlights increased attacker focus on SSO and management plane weaknesses, as well as the importance of layered defenses, rapid detection, and coordinated response in modern enterprise security architecture.
6 months ago
Kill Chain
How Stolen Credentials Enabled Stealthy LogMeIn RMM Attacks in 2026
In January 2026, researchers reported a campaign where attackers leveraged phishing emails to steal valid user credentials, allowing them to deploy legitimate LogMeIn Remote Monitoring and Management (RMM) software for covert, persistent access to corporate systems. By utilizing IT tools typically trusted by administrators rather than custom malware, the adversaries successfully bypassed traditional security measures and gained unrestricted access to sensitive business environments. The campaign underscores the increasing sophistication of credential-based attacks and the risks posed by the misuse of legitimate remote access tools. This incident is vital in the current cybersecurity landscape as it exemplifies the growing threat of identity-driven attacks and the exploitation of trusted IT software. Organizations face mounting regulatory and operational pressure to enforce zero trust principles and segment internal traffic, as traditional perimeter defenses and malware-centric detection are increasingly ineffective against modern attacker tactics.
6 months ago
Kill Chain
VMware vCenter Vulnerability (CVE-2024-37079) Actively Exploited—CISA Issues Immediate Directive
In January 2026, CISA added CVE-2024-37079, a critical out-of-bounds write vulnerability in Broadcom VMware vCenter Server, to its Known Exploited Vulnerabilities (KEV) Catalog due to verified evidence of active exploitation. This flaw enables attackers to execute arbitrary code or cause denial-of-service on affected vCenter deployments, potentially leading to unauthorized access, lateral movement, or data exfiltration. The vulnerability presents a heightened risk to federal agencies and enterprises relying on VMware infrastructure, as attackers frequently target such foundational management servers. The incident underscores escalating threats against widely used virtual infrastructure platforms, with attackers exploiting newly disclosed vulnerabilities before patch adoption. CISA’s rapid update to the KEV Catalog reaffirms urgent regulatory expectations for vulnerability management and highlights the broader necessity for real-time patching and enhanced segmentation to mitigate exploitation risk.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports