Validated Containment Architectures are here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2676 threat reports
Page 144 of 223

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 17171728 / 2676 reports
CISA Orders Critical Patching After Gogs Zero-Day RCE Attacks Hit Hundreds of Servers
Impact· low

CISA Orders Critical Patching After Gogs Zero-Day RCE Attacks Hit Hundreds of Servers

In January 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a directive to all federal agencies to urgently patch a critical remote code execution (RCE) vulnerability (CVE-2025-8110) in Gogs, a popular open-source git service, following multiple waves of active zero-day exploitation. The flaw leveraged a path traversal issue via the PutContents API, allowing authenticated attackers to overwrite files outside repositories—including SSH command configurations—to gain arbitrary code execution. At least 700 internet-facing Gogs servers showed signs of compromise, implicating risks across the federal enterprise. This incident underscores the accelerated threat posed by zero-day exploits targeting software supply chain and collaboration tools exposed to the internet. The increase in attacks against widely used developer platforms, combined with slow patch adoption and the rapid weaponization of vulnerabilities, demands renewed attention to secure configuration, real-time monitoring, and timely security updates.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
GoBruteforcer Botnet Exploits AI-Generated Weak Credentials to Breach Crypto Databases (2026)
Impact· medium

GoBruteforcer Botnet Exploits AI-Generated Weak Credentials to Breach Crypto Databases (2026)

In January 2026, the GoBruteforcer botnet orchestrated a campaign targeting cryptocurrency and blockchain project databases. Attackers exploited weak or default credentials on exposed Linux-based services, including FTP, MySQL, PostgreSQL, and phpMyAdmin, to gain unauthorized access and deploy IRC bots and web shells. Many of the compromised credentials were traced to AI-generated server setup examples and outdated web stack configurations. Once inside, the botnet employed brute-force modules to propagate, staged payloads, and established redundant command-and-control channels. One notable tactic involved scanning TRON blockchain addresses for accounts with non-zero balances, signaling a financially motivated focus on blockchain assets. This incident highlights the evolving intersection of automated attack tools, AI-influenced misconfigurations, and crypto-driven targeting. The persistent exploitation of misconfigured infrastructure underscores rising risks to technology firms, especially as low-effort credential attacks increasingly leverage AI-generated default settings.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
n8n npm Supply Chain Attack: OAuth Tokens Stolen via Malicious Community Nodes
Impact· medium

n8n npm Supply Chain Attack: OAuth Tokens Stolen via Malicious Community Nodes

In early January 2026, threat actors targeted the n8n workflow automation ecosystem by publishing eight malicious npm packages that mimicked legitimate integrations. These packages prompted unsuspecting users to connect OAuth-protected services like Google Ads, Stripe, and Salesforce. Once installed as community nodes, the malware exfiltrated encrypted OAuth tokens from the n8n credential store by decrypting them with n8n's own master key and sending them to attacker-controlled servers. The campaign exploited developer trust in community packages and highlighted a dangerous new avenue for credential theft at scale. This incident reflects the increasing sophistication and frequency of supply chain attacks, particularly against workflow automation tools that centralize sensitive credentials. With open-source ecosystems growing rapidly, businesses face heightened urgency to scrutinize third-party integrations and adopt least-privilege, zero trust security practices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Two Major Campaigns Expose AI/LLM Endpoint Security Flaws in 2024
Impact· medium

Two Major Campaigns Expose AI/LLM Endpoint Security Flaws in 2024

In early 2024, security researchers observed two distinct attack campaigns targeting more than 91,000 public Large Language Model (LLM) endpoints. Threat actors systematically scanned for exposed LLM interfaces left accessible on the public internet, leveraging them to probe for sensitive data leaks and map organizational attack surfaces. Attackers exploited the unprotected AI endpoints primarily through direct web probes and API requests, taking advantage of lax access controls and lack of encryption. The business impact included the risk of sensitive internal data exposure, increased surface area for lateral movement, and potential regulatory non-compliance. The incident highlights the increasing threat to organizations deploying AI/GenAI technologies without robust security controls. As adoption of LLMs surges, attackers are pivoting to exploit these modern interfaces, driving urgency for enterprises to secure AI assets, enforce segmentation, and monitor for unauthorized use of LLM endpoints.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Researchers Uncover How Subtle Tuning Can Corrupt LLMs via Inductive Backdoors
Impact· high

Researchers Uncover How Subtle Tuning Can Corrupt LLMs via Inductive Backdoors

In January 2026, researchers published a pivotal study revealing new ways that adversaries can corrupt large language models (LLMs) through subtle data poisoning and finetuning techniques that exploit the models’ generalization abilities. The research demonstrated that minimal, targeted finetuning can induce LLMs to adopt outdated or harmful behaviors even outside the initial scope of manipulation. Notably, the study introduced the concept of "inductive backdoors," wherein LLMs generalize a malicious trigger and behavior relationship—resulting in broad, unpredictable misalignments and persona shifts not directly present in the source training data. No direct attacker, but the techniques expose exploitable weaknesses in LLM training pipelines and data supply chain security. This finding is urgent for organizations integrating AI/ML into business operations. It spotlights a new class of supply chain and insider risk: even small, unnoticed changes in model inputs or fine-tuning datasets can profoundly undermine trust, safety, and regulatory compliance in deployed AI systems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
CISA Closes Era of Emergency Directives — Centralizes Federal Vulnerability Management in 2026
Impact· medium

CISA Closes Era of Emergency Directives — Centralizes Federal Vulnerability Management in 2026

In January 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) retired ten Emergency Directives (EDs) that had been issued between 2019 and 2024 to mitigate high-risk vulnerabilities including DNS tampering, Microsoft Exchange flaws, Print Spooler vulnerabilities, SolarWinds compromise, and other widely exploited threats. CISA's review determined that remediation was complete and these urgent directives are now covered under Binding Operational Directive 22-01—which requires agencies to rapidly patch known exploited vulnerabilities (KEVs) in accordance with stricter deadlines. This mass retirement signals a shift from fragmented, incident-driven orders to centralized, ongoing vulnerability management via the KEV catalog. This move is especially relevant as threat actors continue to exploit unpatched vulnerabilities with increasing speed and sophistication. CISA’s new guidance streamlines federal agencies’ response, setting an industry precedent for proactive vulnerability management and rapid patch cycles aligned with emerging regulatory pressure and rising adversary activity.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Hackers Exploit Misconfigured Proxies to Access Paid LLM Services in 2026
Impact· medium

Hackers Exploit Misconfigured Proxies to Access Paid LLM Services in 2026

In late 2025 and early 2026, threat actors launched coordinated campaigns to identify and exploit misconfigured proxy servers providing unauthorized access to commercial large language model (LLM) services. Using enumeration techniques and server-side request forgery (SSRF) vulnerabilities, attackers probed over 73 LLM endpoints—like OpenAI, Anthropic, and Google Gemini—producing more than 80,000 sessions. Their tactics included low-noise queries to bypass security alerts, the injection of malicious registry URLs, and Twilio SMS webhooks. While the activity appeared research-oriented at times, the scale and automated reconnaissance efforts were indicative of broader malicious reconnaissance likely intended for future exploitation or abuse of these valuable AI assets. This incident underscores a broader rise in cloud misconfiguration attacks and highlights escalating threats targeting AI infrastructure. As reliance on LLM APIs grows, so too does the risk of credential abuse and exploitation, placing new urgency on proactive cloud security, real-time monitoring, and zero trust principles across managed AI services.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Illinois DHS Exposes 700,000+ Residents in Years-long Data Misconfiguration
Impact· high

Illinois DHS Exposes 700,000+ Residents in Years-long Data Misconfiguration

In September 2025, the Illinois Department of Human Services (IDHS) discovered a data exposure incident affecting nearly 700,000 residents, when maps containing sensitive information were found to be publicly accessible due to misconfigured privacy settings on a mapping website. The breach, which lasted for several years, involved the exposure of addresses, case numbers, demographic details, and medical assistance plan information for Medicaid and Medicare recipients (without names), as well as additional data including names for a smaller group of rehabilitation services clients. Upon discovery, IDHS promptly secured the exposed maps, reviewed affected materials, and implemented safeguards to prevent recurrence. This incident highlights the persistent risk of misconfiguration-based data exposures in public sector organizations, especially with increasing reliance on digital tools for data visualization and resource management. As regulatory scrutiny and public concern over privacy intensify, organizations must prioritize robust controls over platforms managing sensitive information.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
China-Linked Hackers Achieve VMware ESXi VM Escape with Zero-Days (2025)
Impact· medium

China-Linked Hackers Achieve VMware ESXi VM Escape with Zero-Days (2025)

In December 2025, security researchers discovered a sophisticated cyberattack attributed to Chinese-speaking threat actors who exploited three zero-day vulnerabilities in VMware ESXi (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226). The attackers gained initial access via a compromised SonicWall VPN appliance, followed by deploying a custom exploit toolkit designed to escape virtual machine isolation and compromise the hypervisor itself. Exploiting the flaws allowed attackers to run arbitrary code on the ESXi host, install persistent backdoors (via VSOCKpuppet), and potentially pave the way for ransomware or advanced persistent remote access, posing direct risks to organizations’ virtual infrastructure integrity. This incident highlights the increased sophistication of state-linked APT actors in targeting virtualization platforms using zero-day techniques and bypassing traditional detection methods. As organizations continue to rely on virtualization and hybrid cloud environments, vigilance around hypervisor and access point security is paramount in defending against similar high-impact threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fake AI Chrome Extensions Expose Sensitive Data of 900,000 Users
Impact· high

Fake AI Chrome Extensions Expose Sensitive Data of 900,000 Users

In January 2026, security researchers disclosed a major data breach in which two malicious Google Chrome extensions, posing as legitimate AI-powered tools for ChatGPT and DeepSeek, surreptitiously harvested sensitive information from over 900,000 users. These fake extensions, mimicking the functionality and branding of a trusted vendor, exfiltrated entire LLM chat conversations, browsing histories, confidential corporate URLs, internal credentials, and other proprietary data to an external command-and-control server. The scope of the incident included the exposure of intellectual property, business strategies, source code, and user credentials, highlighting significant risks for individuals and organizations whose employees utilized these tools in their workflows. With generative AI increasingly adopted for business and development tasks, this breach is a stark demonstration of the risks posed by third-party browser extensions—particularly those that intercept AI-driven sessions. It underscores the urgent need for stricter vetting controls, robust application security for browser add-ons, and user education in an environment where threat actors leverage AI both as target and tool.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
HPE OneView Critical Zero-Day Exploited for Remote Access in 2025
Impact· low

HPE OneView Critical Zero-Day Exploited for Remote Access in 2025

In June 2025, a critical vulnerability (CVE-2025-37164), was discovered and exploited in the wild against HPE OneView, the company’s IT infrastructure management platform. Attackers leveraged the flaw to achieve remote code execution without authentication, enabling full access to core infrastructure resources. Reported incidents indicate that threat actors used this vulnerability for initial access, privilege escalation, and potentially data exfiltration or ransomware deployment, threatening operational continuity for affected enterprises. HPE acted swiftly to release security advisories and patches, but exploitation occurred before widespread remediation could be implemented. This incident highlights the persistent targeting of critical infrastructure management tools and the increasing sophistication and speed with which attackers weaponize disclosed zero-day vulnerabilities. Organizations must prioritize patch management and vigilant monitoring to prevent compromise in an evolving landscape of high-consequence supply chain and platform attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Fancy Bear’s 2024 Credential Attacks: The Global Secrets Heist Reinvented
Impact· medium

Fancy Bear’s 2024 Credential Attacks: The Global Secrets Heist Reinvented

In early 2024, the Russian state-sponsored threat group APT28 (also known as Fancy Bear) intensified credential-harvesting campaigns targeting global governmental and enterprise networks. Leveraging basic techniques such as phishing and exploitation of unencrypted or weakly protected authentication channels, the attackers maintained persistent access and exfiltrated sensitive secrets across multiple sectors. The operations demonstrated a preference for cost-effective methods, including the abuse of stolen credentials, rather than relying on advanced custom malware—resulting in widespread data exposure and persistent breaches with significant geopolitical ramifications. This incident highlights the increasing sophistication of threat actors’ social engineering and credential-focused tactics, signaling a shift in espionage campaigns worldwide. As traditional perimeter defenses become less effective against targeted, credential-driven attacks, organizations face renewed urgency to adopt zero trust models, strong encryption, and robust monitoring to combat these persistent threats.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports