✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Critical WordPress Modular DS Plugin Vulnerability Enables Site Takeover
In January 2026, a critical security vulnerability (CVE-2026-23550, CVSS 10.0) surfaced in all versions of the WordPress Modular DS plugin prior to 2.5.2. The flaw allowed unauthenticated attackers to escalate privileges and take over administrator accounts by exploiting a combination of weak route authentication and permissive auto-login features, impacting over 40,000 active websites. Active exploitation began on January 13, 2026, with attackers leveraging specifically crafted HTTP GET requests through the exposed "/api/modular-connector/login/" endpoint and originating from known malicious IPs. Compromised sites faced risks of full takeover, data exfiltration, or malware delivery. This incident underscores the growing trend of supply-chain and plugin-based attacks in widely used web platforms, highlighting attackers’ shift to exploiting software design weaknesses over traditional single code bugs. The case serves as a cautionary tale for organizations reliant on third-party integrations and CMS plugins, reinforcing the importance of timely patching and continuous risk assessments.
6 months ago
Kill Chain
AWS CodeBuild Misconfiguration Put GitHub Supply Chain at Risk in 2025
In September 2025, a critical misconfiguration in AWS CodeBuild was discovered by cloud security firm Wiz, potentially allowing attackers to gain full control over AWS's own public GitHub repositories, including the widely-used AWS JavaScript SDK. This vulnerability, dubbed 'CodeBreach,' arose when certain IAM roles in CodeBuild pipelines were over-privileged and could access connected GitHub repository OAuth tokens without sufficiently restrictive permissions. If exploited, an attacker could have injected malicious code into key software supply chains, jeopardizing thousands of AWS customer environments globally. AWS promptly remediated the flaw following responsible disclosure, averting a major breach. This incident highlights the persistent risks posed by cloud misconfigurations and the growing focus of attackers on software supply chains. With rapid cloud adoption, organizations must remain vigilant to configuration drift and privilege escalation risks inherent in third-party integration, especially as regulatory scrutiny and supply chain attacks continue to escalate.
6 months ago
Kill Chain
Microsoft Leads RedVDS Takedown: Shutting Down Cybercrime-as-a-Service in 2024
In June 2024, Microsoft, in collaboration with law enforcement agencies, successfully disrupted the notorious RedVDS cybercrime-as-a-service operation by seizing two of its primary domains. RedVDS had enabled a global network of cybercriminals to launch ransomware and data-theft attacks, facilitating millions of dollars in losses through their infrastructure. The takedown was part of an ongoing campaign targeting criminal online service providers that enable encrypted C2 traffic, lateral movement, and evasion of traditional network defenses. The operation demonstrated how threat actors are using such platforms to remain agile and scale attacks against diverse sectors worldwide. This takedown spotlights the increasing focus by law enforcement and cloud providers on dismantling illicit digital infrastructures. With cybercrime-as-a-service continuing to gain traction and lower the barrier for threat actors, addressing these platforms is pivotal to disrupting large-scale ransomware and data exfiltration campaigns.
6 months ago
Kill Chain
2024 Outlaw Botnet: Cryptojacking Breach Exposes SSH Weaknesses
In early 2024, a DShield honeypot operated as part of the SANS.edu BACS program detected a sophisticated cryptojacking and botnet campaign leveraging SSH password spraying as the initial access vector. Attackers, suspected to be affiliated with the Outlaw cybercrime group, gained access to exposed Linux hosts and executed automated enumeration scripts to assess system viability for botnet or cryptomining operations. Subsequently, evidence of persistent SSH backdoors and the transfer of malware—identified as both a Trojan and a miner—was observed, suggesting the compromised servers were targeted for both resource abuse and brokering to other cybercriminals for further exploitation. This incident highlights the ongoing trend of cybercrime groups specializing in initial access brokerage and automation of lateral compromise using credential attacks and script-based post-exploitation. Organizations should remain vigilant as password-based SSH, exposed management interfaces, and unmonitored east-west traffic continue to enable rapid propagation of botnets focused on monetizing vulnerable cloud and on-prem workloads.
6 months ago
Kill Chain
2026 n8n Remote Code Execution Exposes Supply-Chain Security Gaps
In January 2026, a critical supply-chain vulnerability (CVE-2026-21858, CVSS 10.0) was disclosed in n8n, a widely used open-source workflow automation tool. This unauthenticated remote code execution flaw enables attackers to fully compromise vulnerable self-hosted instances, potentially taking control of exposed servers across an estimated 100,000 global installations. The vulnerability is present in n8n versions between 1.65.0 and 1.120.4. No official mitigations or workarounds exist; remediation requires upgrading to version 1.121.0 or later. Attackers exploiting this bug could gain persistent access, manipulate workflows, or use impacted servers for further lateral movement and supply-chain attacks. This incident highlights a growing trend of attackers targeting automation and orchestration platforms as initial entry points. The rapid exploitation window, lack of mitigations, and broad exposure emphasize the urgent need for organizations to prioritize patching and review their supply-chain and workflow application security.
6 months ago
Kill Chain
Monroe University 2024 Breach: 320,000 Impacted by Massive Data Exposure
In December 2024, Monroe University suffered a significant data breach during which threat actors gained unauthorized access to the institution's network for two weeks, from December 9 to December 23. Attackers exfiltrated sensitive personal, financial, and health information belonging to over 320,000 individuals—including faculty, students, and affiliates—after penetrating university systems. The breach, discovered after a review of stolen files in September 2025, exposed details such as names, Social Security numbers, medical and health insurance information, government IDs, and financial credentials, prompting the university to notify affected individuals and offer credit monitoring services. This incident underscores the persistent challenges higher education institutions face in defending against data theft, especially as ransomware and targeted attacks exploit legacy systems and limited segmentation. With higher ed continuing to be a lucrative target and similar breaches on the rise, Monroe’s experience highlights the critical need for enhanced east-west security, proactive monitoring, and compliance controls to protect sensitive student and institutional data.
6 months ago
Kill Chain
Reprompt Attack: How Microsoft Copilot’s 2026 AI Vulnerability Enabled Silent Data Exfiltration
In January 2026, security researchers disclosed a critical vulnerability—termed the 'Reprompt' attack—in Microsoft Copilot Personal, enabling attackers to hijack user sessions and exfiltrate sensitive data through malicious prompt injection. By embedding harmful prompts in the 'q' URL parameter and leveraging Copilot's automatic execution, attackers could persistently access authenticated sessions and orchestrate stealthy data theft without user awareness. Microsoft Copilot, deeply integrated in Windows and Edge, was susceptible due to its handling of context and prompt flows; the attack chain was demonstrated by Varonis Security, who responsibly disclosed the flaw to Microsoft, leading to a patch release on January 2026's Patch Tuesday. Fortunately, there was no evidence of exploitation in the wild, and enterprise-targeted Copilot versions were unaffected due to stronger controls. This incident highlights the growing risk landscape as AI assistants and LLMs gain deeper access to personal and enterprise data. The Reprompt exploitation showcases the evolution of prompt injection from theoretical risk to practical attack, underlining the urgency for robust guardrails, user security awareness, and compliance-ready AI deployments as generative AI tools proliferate.
6 months ago
Kill Chain
Pax8’s 2026 MSP Partner Data Exposure: Lessons from a Cloud Email Mishap
In January 2026, cloud marketplace giant Pax8 disclosed that it inadvertently exposed sensitive business information related to approximately 1,800 managed service provider (MSP) partners. The incident occurred when a Pax8 EMEA account manager mistakenly emailed a spreadsheet—intended for internal use—to under 40 UK-based partners. The file contained details such as partner and customer organization IDs, Microsoft product SKUs, license counts, renewal dates, booking data, and internal pricing. While the leaked data reportedly did not include personally identifiable information, it revealed confidential customer portfolios and licensing metrics, with over 56,000 entries potentially providing valuable intelligence to competitors or cybercriminals. Pax8 moved quickly to recall the emails, directly requested deletion, and launched an internal review to address the flaw. This breach highlights the persistent risks linked to accidental data disclosures, especially within cloud ecosystems and partner networks. Data leaks through misdirected emails are increasingly exploited by threat actors for social engineering, competitive maneuvering, and phased cyberattacks, driving renewed urgency for zero trust controls and robust data-handling processes.
6 months ago
Kill Chain
Active Exploitation of Gogs CVE-2025-8110: Path Traversal Risks in DevOps Platforms
In January 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an alert regarding the active exploitation of a critical path traversal vulnerability (CVE-2025-8110, CVSS 8.7) in Gogs, a widely used self-hosted Git service. Attackers bypassed prior security controls using symbolic links within the repository editor and abused the PutContents API to overwrite sensitive files on a server, effectively achieving code execution. Over 700 Gogs instances were reported compromised, with thousands of internet-exposed installations at risk worldwide. The exploitation allowed adversaries to gain control over affected servers, posing serious risks to intellectual property, credentials, and sensitive data. This incident is particularly significant as it highlights the continued targeting of critical DevOps infrastructure through zero-day attacks, especially when rapid patching is not possible. The Gogs event reflects wider trends of supply-chain vulnerability exploitation and underlines the urgency for defense-in-depth and active monitoring.
6 months ago
Kill Chain
SHADOW#REACTOR: 2026’s Multi-Layered Remcos RAT Attack on Windows Systems
In January 2026, cybersecurity researchers uncovered an evasive malware campaign dubbed SHADOW#REACTOR that delivered Remcos RAT via a sophisticated, multi-stage Windows attack chain. Attackers used obfuscated VBS scripts initiated through user interaction to invoke PowerShell downloaders that fetched fragmented text-based payloads. These were assembled and decrypted in memory using .NET Reactor–protected loaders, eventually launching the Remcos RAT through MSBuild.exe to gain covert, persistent access. The campaign primarily targeted enterprises and SMBs, leveraging modular loaders and living-off-the-land binaries for stealth, resilience, and evasiveness, with a clear design to complicate detection and incident response. The campaign’s blending of text-only stagers, in-memory decoding, and LOLBin abuse demonstrates the ongoing evolution of malware delivery tactics. It highlights the rising sophistication of opportunistic attackers serving as initial access brokers, reflecting a broader trend toward modular, easily adaptable attack frameworks that challenge defensive controls in both enterprise and midmarket environments.
6 months ago
Kill Chain
Critical FortiSIEM Command Injection Exploit Puts Enterprises at Risk in 2024
In June 2024, a critical remote code execution (RCE) vulnerability was publicly disclosed for Fortinet's FortiSIEM solution (CVE-2024-23108/CVE-2024-23109). Public exploit code was released, enabling remote, unauthenticated attackers to execute arbitrary commands on affected systems. The flaw, rated CVSS 10.0, exposes organizations using FortiSIEM to the risk of full system compromise and data exfiltration, with security teams scrambling to identify exposure and deploy patches. Fortinet has released urgent security updates, while threat intelligence sources report active scanning and attempted exploitation in the wild within days of disclosure. This incident underscores an accelerating trend of attackers exploiting zero-day or n-day flaws rapidly after public disclosure, often leveraging weaponized PoCs released on open-source platforms. Enterprises with lagging patch cycles or poor internal segmentation remain at heightened risk amid regulatory scrutiny and increased lateral movement by threat actors.
6 months ago
Kill Chain
How the Free Mobile 2024 Data Breach Exposed Millions: Lessons in Telecom Security
In October 2024, Free Mobile—France's second-largest ISP—suffered a significant data breach when hackers compromised its management tool, exposing information of up to 23 million current and former subscribers. Attackers leveraged weak VPN authentication and exploited inadequate detection controls to exfiltrate sensitive customer data, including banking details (IBANs). The breach then led to data being offered for sale on a hacker forum, with later regulatory investigations confirming extensive security lapses, leading to a €42 million fine by CNIL for violations of GDPR related to security, breach notification, and data retention. This incident highlights the growing risk facing telecom providers from targeted attacks utilizing credential compromise and weak internal controls. It underscores regulatory attention and penalties for organizations that fail to meet cybersecurity and data protection obligations, particularly under GDPR.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports