✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
CISA Orders Critical Patching After Gogs Zero-Day RCE Attacks Hit Hundreds of Servers
In January 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a directive to all federal agencies to urgently patch a critical remote code execution (RCE) vulnerability (CVE-2025-8110) in Gogs, a popular open-source git service, following multiple waves of active zero-day exploitation. The flaw leveraged a path traversal issue via the PutContents API, allowing authenticated attackers to overwrite files outside repositories—including SSH command configurations—to gain arbitrary code execution. At least 700 internet-facing Gogs servers showed signs of compromise, implicating risks across the federal enterprise. This incident underscores the accelerated threat posed by zero-day exploits targeting software supply chain and collaboration tools exposed to the internet. The increase in attacks against widely used developer platforms, combined with slow patch adoption and the rapid weaponization of vulnerabilities, demands renewed attention to secure configuration, real-time monitoring, and timely security updates.
6 months ago
Kill Chain
GoBruteforcer Botnet Exploits AI-Generated Weak Credentials to Breach Crypto Databases (2026)
In January 2026, the GoBruteforcer botnet orchestrated a campaign targeting cryptocurrency and blockchain project databases. Attackers exploited weak or default credentials on exposed Linux-based services, including FTP, MySQL, PostgreSQL, and phpMyAdmin, to gain unauthorized access and deploy IRC bots and web shells. Many of the compromised credentials were traced to AI-generated server setup examples and outdated web stack configurations. Once inside, the botnet employed brute-force modules to propagate, staged payloads, and established redundant command-and-control channels. One notable tactic involved scanning TRON blockchain addresses for accounts with non-zero balances, signaling a financially motivated focus on blockchain assets. This incident highlights the evolving intersection of automated attack tools, AI-influenced misconfigurations, and crypto-driven targeting. The persistent exploitation of misconfigured infrastructure underscores rising risks to technology firms, especially as low-effort credential attacks increasingly leverage AI-generated default settings.
6 months ago
Kill Chain
n8n npm Supply Chain Attack: OAuth Tokens Stolen via Malicious Community Nodes
In early January 2026, threat actors targeted the n8n workflow automation ecosystem by publishing eight malicious npm packages that mimicked legitimate integrations. These packages prompted unsuspecting users to connect OAuth-protected services like Google Ads, Stripe, and Salesforce. Once installed as community nodes, the malware exfiltrated encrypted OAuth tokens from the n8n credential store by decrypting them with n8n's own master key and sending them to attacker-controlled servers. The campaign exploited developer trust in community packages and highlighted a dangerous new avenue for credential theft at scale. This incident reflects the increasing sophistication and frequency of supply chain attacks, particularly against workflow automation tools that centralize sensitive credentials. With open-source ecosystems growing rapidly, businesses face heightened urgency to scrutinize third-party integrations and adopt least-privilege, zero trust security practices.
6 months ago
Kill Chain
Two Major Campaigns Expose AI/LLM Endpoint Security Flaws in 2024
In early 2024, security researchers observed two distinct attack campaigns targeting more than 91,000 public Large Language Model (LLM) endpoints. Threat actors systematically scanned for exposed LLM interfaces left accessible on the public internet, leveraging them to probe for sensitive data leaks and map organizational attack surfaces. Attackers exploited the unprotected AI endpoints primarily through direct web probes and API requests, taking advantage of lax access controls and lack of encryption. The business impact included the risk of sensitive internal data exposure, increased surface area for lateral movement, and potential regulatory non-compliance. The incident highlights the increasing threat to organizations deploying AI/GenAI technologies without robust security controls. As adoption of LLMs surges, attackers are pivoting to exploit these modern interfaces, driving urgency for enterprises to secure AI assets, enforce segmentation, and monitor for unauthorized use of LLM endpoints.
6 months ago
Kill Chain
Researchers Uncover How Subtle Tuning Can Corrupt LLMs via Inductive Backdoors
In January 2026, researchers published a pivotal study revealing new ways that adversaries can corrupt large language models (LLMs) through subtle data poisoning and finetuning techniques that exploit the models’ generalization abilities. The research demonstrated that minimal, targeted finetuning can induce LLMs to adopt outdated or harmful behaviors even outside the initial scope of manipulation. Notably, the study introduced the concept of "inductive backdoors," wherein LLMs generalize a malicious trigger and behavior relationship—resulting in broad, unpredictable misalignments and persona shifts not directly present in the source training data. No direct attacker, but the techniques expose exploitable weaknesses in LLM training pipelines and data supply chain security. This finding is urgent for organizations integrating AI/ML into business operations. It spotlights a new class of supply chain and insider risk: even small, unnoticed changes in model inputs or fine-tuning datasets can profoundly undermine trust, safety, and regulatory compliance in deployed AI systems.
6 months ago
Kill Chain
CISA Closes Era of Emergency Directives — Centralizes Federal Vulnerability Management in 2026
In January 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) retired ten Emergency Directives (EDs) that had been issued between 2019 and 2024 to mitigate high-risk vulnerabilities including DNS tampering, Microsoft Exchange flaws, Print Spooler vulnerabilities, SolarWinds compromise, and other widely exploited threats. CISA's review determined that remediation was complete and these urgent directives are now covered under Binding Operational Directive 22-01—which requires agencies to rapidly patch known exploited vulnerabilities (KEVs) in accordance with stricter deadlines. This mass retirement signals a shift from fragmented, incident-driven orders to centralized, ongoing vulnerability management via the KEV catalog. This move is especially relevant as threat actors continue to exploit unpatched vulnerabilities with increasing speed and sophistication. CISA’s new guidance streamlines federal agencies’ response, setting an industry precedent for proactive vulnerability management and rapid patch cycles aligned with emerging regulatory pressure and rising adversary activity.
6 months ago
Kill Chain
Hackers Exploit Misconfigured Proxies to Access Paid LLM Services in 2026
In late 2025 and early 2026, threat actors launched coordinated campaigns to identify and exploit misconfigured proxy servers providing unauthorized access to commercial large language model (LLM) services. Using enumeration techniques and server-side request forgery (SSRF) vulnerabilities, attackers probed over 73 LLM endpoints—like OpenAI, Anthropic, and Google Gemini—producing more than 80,000 sessions. Their tactics included low-noise queries to bypass security alerts, the injection of malicious registry URLs, and Twilio SMS webhooks. While the activity appeared research-oriented at times, the scale and automated reconnaissance efforts were indicative of broader malicious reconnaissance likely intended for future exploitation or abuse of these valuable AI assets. This incident underscores a broader rise in cloud misconfiguration attacks and highlights escalating threats targeting AI infrastructure. As reliance on LLM APIs grows, so too does the risk of credential abuse and exploitation, placing new urgency on proactive cloud security, real-time monitoring, and zero trust principles across managed AI services.
6 months ago
Kill Chain
Illinois DHS Exposes 700,000+ Residents in Years-long Data Misconfiguration
In September 2025, the Illinois Department of Human Services (IDHS) discovered a data exposure incident affecting nearly 700,000 residents, when maps containing sensitive information were found to be publicly accessible due to misconfigured privacy settings on a mapping website. The breach, which lasted for several years, involved the exposure of addresses, case numbers, demographic details, and medical assistance plan information for Medicaid and Medicare recipients (without names), as well as additional data including names for a smaller group of rehabilitation services clients. Upon discovery, IDHS promptly secured the exposed maps, reviewed affected materials, and implemented safeguards to prevent recurrence. This incident highlights the persistent risk of misconfiguration-based data exposures in public sector organizations, especially with increasing reliance on digital tools for data visualization and resource management. As regulatory scrutiny and public concern over privacy intensify, organizations must prioritize robust controls over platforms managing sensitive information.
6 months ago
Kill Chain
China-Linked Hackers Achieve VMware ESXi VM Escape with Zero-Days (2025)
In December 2025, security researchers discovered a sophisticated cyberattack attributed to Chinese-speaking threat actors who exploited three zero-day vulnerabilities in VMware ESXi (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226). The attackers gained initial access via a compromised SonicWall VPN appliance, followed by deploying a custom exploit toolkit designed to escape virtual machine isolation and compromise the hypervisor itself. Exploiting the flaws allowed attackers to run arbitrary code on the ESXi host, install persistent backdoors (via VSOCKpuppet), and potentially pave the way for ransomware or advanced persistent remote access, posing direct risks to organizations’ virtual infrastructure integrity. This incident highlights the increased sophistication of state-linked APT actors in targeting virtualization platforms using zero-day techniques and bypassing traditional detection methods. As organizations continue to rely on virtualization and hybrid cloud environments, vigilance around hypervisor and access point security is paramount in defending against similar high-impact threats.
6 months ago
Kill Chain
Fake AI Chrome Extensions Expose Sensitive Data of 900,000 Users
In January 2026, security researchers disclosed a major data breach in which two malicious Google Chrome extensions, posing as legitimate AI-powered tools for ChatGPT and DeepSeek, surreptitiously harvested sensitive information from over 900,000 users. These fake extensions, mimicking the functionality and branding of a trusted vendor, exfiltrated entire LLM chat conversations, browsing histories, confidential corporate URLs, internal credentials, and other proprietary data to an external command-and-control server. The scope of the incident included the exposure of intellectual property, business strategies, source code, and user credentials, highlighting significant risks for individuals and organizations whose employees utilized these tools in their workflows. With generative AI increasingly adopted for business and development tasks, this breach is a stark demonstration of the risks posed by third-party browser extensions—particularly those that intercept AI-driven sessions. It underscores the urgent need for stricter vetting controls, robust application security for browser add-ons, and user education in an environment where threat actors leverage AI both as target and tool.
6 months ago
Kill Chain
HPE OneView Critical Zero-Day Exploited for Remote Access in 2025
In June 2025, a critical vulnerability (CVE-2025-37164), was discovered and exploited in the wild against HPE OneView, the company’s IT infrastructure management platform. Attackers leveraged the flaw to achieve remote code execution without authentication, enabling full access to core infrastructure resources. Reported incidents indicate that threat actors used this vulnerability for initial access, privilege escalation, and potentially data exfiltration or ransomware deployment, threatening operational continuity for affected enterprises. HPE acted swiftly to release security advisories and patches, but exploitation occurred before widespread remediation could be implemented. This incident highlights the persistent targeting of critical infrastructure management tools and the increasing sophistication and speed with which attackers weaponize disclosed zero-day vulnerabilities. Organizations must prioritize patch management and vigilant monitoring to prevent compromise in an evolving landscape of high-consequence supply chain and platform attacks.
6 months ago
Kill Chain
Fancy Bear’s 2024 Credential Attacks: The Global Secrets Heist Reinvented
In early 2024, the Russian state-sponsored threat group APT28 (also known as Fancy Bear) intensified credential-harvesting campaigns targeting global governmental and enterprise networks. Leveraging basic techniques such as phishing and exploitation of unencrypted or weakly protected authentication channels, the attackers maintained persistent access and exfiltrated sensitive secrets across multiple sectors. The operations demonstrated a preference for cost-effective methods, including the abuse of stolen credentials, rather than relying on advanced custom malware—resulting in widespread data exposure and persistent breaches with significant geopolitical ramifications. This incident highlights the increasing sophistication of threat actors’ social engineering and credential-focused tactics, signaling a shift in espionage campaigns worldwide. As traditional perimeter defenses become less effective against targeted, credential-driven attacks, organizations face renewed urgency to adopt zero trust models, strong encryption, and robust monitoring to combat these persistent threats.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports