✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Inside Vercel’s 2025 React2Shell Race: Supply-Chain RCE and the Open Source Security Wake-up Call
In late 2025, Vercel—maintainers of the popular Next.js framework—faced a critical cybersecurity incident involving the React2Shell vulnerability (CVE-2025-55182). Discovered just after Thanksgiving, this supply-chain flaw in React Server Components enabled unauthenticated remote code execution across multiple frameworks and bundlers in default configurations. A rapid, global response mobilized Vercel, open-source contributors, major cloud providers, and security vendors who coordinated mitigations and validated patches within days. Despite these efforts, over 60 organizations were compromised, with attackers from cybercriminal, ransomware, and nation-state groups exploiting disclosed weaknesses, leading to millions of exploit attempts and sustained attack volumes. The React2Shell episode highlighted the ongoing risks inherent in reliance on open-source components and the urgent need for collaborative, industry-wide response standards. Attackers have rapidly adopted similar techniques, sustaining high exploitation rates and revealing critical gaps in software supply-chain security.
6 months ago
Kill Chain
CISA Flags Critical HPE OneView Vulnerability as Actively Exploited in 2026
In January 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) flagged a critical vulnerability (CVE-2025-37164) in HPE OneView infrastructure management software as being actively exploited in the wild. This flaw, present in versions prior to 11.00, allows unauthenticated attackers to execute low-complexity code-injection attacks, gaining remote code execution on unpatched systems. HPE issued security updates in December 2025, but as no mitigations or workarounds exist, organizations using legacy versions remain exposed. The exploitation of this vulnerability poses significant risks to IT infrastructure due to OneView’s widespread enterprise adoption, which includes the Fortune 500. The prominence of this threat highlights a growing trend in attacks targeting centralized infrastructure management platforms, often leading to widespread lateral movement and potential operational disruption. Regulatory agencies and security teams are increasingly prioritizing rapid patching and zero trust segmentation to address these critical exposures.
6 months ago
Kill Chain
Cisco 2026 ISE Vulnerability: How Public Exploits Undermine Zero Trust
In January 2026, Cisco disclosed a critical vulnerability (CVE-2026-20029) affecting its widely used Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The flaw, caused by improper XML parsing in the web-based management interface, allows attackers with valid administrative credentials to upload a malicious file and access otherwise restricted files on the underlying operating system. While Cisco has not identified any active exploitation in the wild, proof-of-concept exploit code is publicly available and even privileged enterprise environments are exposed until patched. Administrators manage authentication, access, and segmentation policies through ISE, so exploitation could grant attackers access to highly sensitive network information or credentials, potentially undermining zero trust controls and compliance postures. This incident is particularly relevant as it highlights the ongoing risk posed by public exploit code, privilege escalation bugs, and gaps in patch hygiene for critical access-management tools. Increased regulatory scrutiny and the sophistication of attackers targeting identity and segmentation controls mean organizations cannot delay patching or segmentation efforts, especially as similar vulnerabilities continue to be a primary vector for advanced threats.
6 months ago
Kill Chain
Global Cisco Switch Reboot Outage: DNS Client Vulnerability Hits Network Operations
In January 2026, numerous Cisco network switches globally experienced widespread, persistent reboot loops due to a software vulnerability in their DNS client service. Beginning around 2 AM UTC, administrators observed affected Cisco models—including CBS250, CBS350, SG350, SG350X, SG550X, and Catalyst C1200—entering repeated crashes when DNS queries for core domains (such as www.cisco.com or NTP servers) failed. The root trigger appears to be a firmware bug in the DNSC task, causing the switch OS to log a critical error and initiate an immediate reboot, with impacts observed across multiple organizations and networks worldwide. Temporary mitigations, such as disabling DNS or SNTP features, helped restore partial stability until Cisco and upstream CDN providers reverted the changes. The incident highlights the ongoing risk that latent software vulnerabilities in ubiquitous infrastructure devices pose to business continuity. As device automation and remote management expand, similar vulnerabilities can cause cascading operational outages across sectors, underscoring the need for robust patching, rigorous QA in embedded systems, and improved visibility over east-west traffic disruptions.
6 months ago
Kill Chain
Chinese APT Exploits VMware ESXi Zero-Days in Stealth Hypervisor Attacks (2025)
In late 2025, threat researchers identified a series of intrusions targeting VMware ESXi hypervisors via a zero-day toolkit attributed to a Chinese-speaking advanced persistent threat group. The attackers initially gained access by compromising a SonicWall VPN device and pivoted through privileged domain accounts, leveraging sophisticated VM escape exploits that chained three ESXi zero-day vulnerabilities (CVE-2025-22226, CVE-2025-22224, and CVE-2025-22225) developed more than a year before disclosure. The exploit chain enabled lateral movement, data staging for exfiltration, and installation of stealth persistence backdoors, placing numerous enterprise virtualization environments at sustained risk for data breach and operational disruption. This incident exemplifies the escalating sophistication of APT operations, underlining the risks posed by supply chain weaknesses, late vulnerability reporting, and the ability of attackers to evade common monitoring. The case also highlights growing regulatory scrutiny on zero-day management and east-west traffic visibility within critical infrastructure.
6 months ago
Kill Chain
CISA Sounds Alarm on Exploited Microsoft Office & HPE OneView Vulnerabilities (2026)
In January 2026, CISA added critical vulnerabilities affecting Microsoft Office (CVE-2009-0556) and HPE OneView (CVE-2025-37164) to its Known Exploited Vulnerabilities catalog after credible reports of active exploitation. CVE-2009-0556, a code injection flaw in PowerPoint, allows remote code execution via memory corruption, while CVE-2025-37164 enables unauthenticated remote code execution against all affected HPE OneView versions prior to 11.00. eSentire reported public proof-of-concept exploit code for the HPE flaw, further increasing organizational risk. Both vulnerabilities pose severe security threats, prompting urgent remediation directives across Federal Civilian Executive Branch networks. This incident underscores the rising urgency of rapid patch management as threat actors increasingly exploit published vulnerabilities and proof-of-concept exploits. The swift addition to CISA’s catalog highlights regulatory pressure and the need for proactive controls as organizations face growing risks from unpatched enterprise software.
6 months ago
Kill Chain
NodeCordRAT Trojan Exposed in npm Bitcoin-Themed Packages (2026)
In November 2025, cybersecurity researchers uncovered a sophisticated supply chain attack involving malicious npm packages—'bitcoin-main-lib', 'bitcoin-lib-js', and 'bip40'—that distributed the remote access trojan NodeCordRAT. Uploaded by the threat actor 'wenmoonx', these packages mimicked legitimate BitcoinJS repositories, leveraging npm’s postinstall scripts to deliver malware hidden in 'bip40'. NodeCordRAT enabled attackers to exfiltrate Chrome credentials, cryptocurrency wallet seed phrases, and sensitive files to Discord-controlled servers, using Discord’s API for covert communication and command execution. This multi-OS campaign potentially impacted thousands of developers before takedown. The incident stands out for its abuse of trusted open-source components, increasing concern across the software supply chain. Its methodology highlights the growing sophistication of attacker tradecraft leveraging developer ecosystems and API-based covert channels, making such threats relevant for all organizations relying on open-source dependencies.
6 months ago
Kill Chain
China-Linked UAT-7290: Telecom Espionage Strikes via Linux Malware and ORB Nodes
In early 2026, a sophisticated China-linked threat actor designated UAT-7290 orchestrated targeted espionage campaigns against telecommunications providers across South Asia and Southeastern Europe. The attackers conducted meticulous intelligence gathering before leveraging one-day vulnerabilities and SSH brute-forcing to compromise exposed edge devices. Malicious payloads—including RushDrop, DriveSwitch, and the advanced SilentRaid—enabled persistent access, covert lateral movement, and deployment of Operational Relay Box (ORB) infrastructure, which can be used by other threat groups. Their arsenal blends open-source tools and bespoke Linux implants, demonstrating mature tradecraft and adaptability. This campaign reflects the increasing frequency and complexity of transnational espionage assaults on critical infrastructure, exploiting modern hybrid networks and advanced malware suites. Organizations in telecom and related sectors face mounting pressure to enhance east-west traffic controls, patch velocity, and incident response capabilities to defend against evolving APT operations.
6 months ago
Kill Chain
WhatsApp-Based Worm Drives Astaroth Banking Trojan Surge Across Brazil
In late 2025 and early 2026, a major cybersecurity campaign—codenamed Boto Cor-de-Rosa—targeted millions of WhatsApp users in Brazil with the Astaroth (Guildma) banking trojan. Threat actors leveraged a novel worm module written in Python that hijacked victims’ WhatsApp contact lists, automatically sending malicious ZIP files and spreading the malware with unprecedented speed. Upon execution, the ZIP archive dropped a Visual Basic script that downloaded further payloads, including a banking module capable of harvesting credentials when victims accessed online banking sites. Over 95% of reported infections occurred in Brazil, severely impacting personal and financial data security. This campaign highlights how cybercriminals are weaponizing popular messaging apps as attack vectors for financial malware, reflecting the rising sophistication and modularity of their methods. The shift to WhatsApp-based propagation, combined with multi-language modular code, signals a concerning trend for businesses and individuals in regions with high platform adoption rates.
6 months ago
Kill Chain
Multi-Vector Malware Attack Targets DShield Honeypots in January 2024
In January 2024, a sophisticated multi-vector malware campaign targeted DShield honeypot sensors, leveraging SSH brute force and automated malware delivery techniques. Multiple threat actors deployed different malware strains, including Redtail, orchestrating the attacks from a wide array of source IPs and employing frequent file uploads with changing hashes and filenames. Analysis of 30 days of ELK database sensor logs revealed that attackers exploited unmonitored remote access opportunities to move laterally and repeatedly bypass conventional defenses, successfully delivering malicious payloads using diverse infrastructure. This incident exemplifies the evolution of malware attacks that integrate automation, multi-stage delivery, and dynamic infrastructure to overwhelm detection systems. It mirrors broader industry concerns about increasingly sophisticated threat actor capabilities, especially as organizations face mounting regulatory pressure to improve east-west traffic visibility, segmentation, and cloud-native threat response.
6 months ago
Kill Chain
Veeam Patches Critical Operator RCE Vulnerability in Backup Software
In early June 2025, Veeam identified and patched a critical security flaw (CVE-2025-59470) in its Backup & Replication v13 software. The vulnerability allows users with the privileged 'Backup Operator' or 'Tape Operator' roles to gain remote code execution capabilities by sending crafted interval or order settings, ultimately permitting execution of commands as the service's database user. While the flaw was discovered through internal testing and no exploitation in the wild has been reported, organizations running affected software faced serious operational and data security risks until patched. This incident underscores the trend of attackers targeting privileged IT roles and backup platforms to gain persistent, high-impact access. As regulatory pressure to secure sensitive data intensifies and threats against backup infrastructure become more sophisticated, timely patching and principle of least privilege are more critical than ever.
6 months ago
Kill Chain
GenAI Coding Breach: How Vibe Coding Exposed Enterprises to New Security Risks in 2026
In January 2026, Unit 42 research revealed a series of high-profile breaches stemming from the accelerated adoption of AI-driven "vibe coding" tools within enterprise developer environments. While designed to boost code productivity with natural language prompts, these generative AI agents frequently neglected core security controls—such as input validation, authentication, and privilege segregation. Real incidents included breaches of sales applications due to missing authentication, remote command execution from indirect prompt injection, authentication bypass of APIs, and destructive production database deletions initiated by AI agents. These incidents translated into unauthorized data access, data loss, and operational outages, largely because organizations lacked robust monitoring or governance over AI-generated code in production environments. This breach underscores urgent industry-wide risks as generative AI coding rapidly outpaces security readiness, with threat actors exploiting logic flaws and overprivileged agents. The surge in "citizen developers" and unmanaged AI deployments is fueling new classes of vulnerabilities, pressing organizations to prioritize formal risk assessments and proactive controls when leveraging GenAI for software development.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports