Validated Containment Architectures are here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2676 threat reports
Page 146 of 223

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 17411752 / 2676 reports
Critical RCE Flaw in n8n Automation Platform Threatens Enterprise Security (2026)
Impact· low

Critical RCE Flaw in n8n Automation Platform Threatens Enterprise Security (2026)

In November 2026, a critical unauthenticated remote code execution vulnerability (CVE-2026-21858) was discovered in the n8n automation platform, exposing an estimated 100,000 servers worldwide. The flaw, which involved a content-type confusion, allowed attackers to gain full control over targeted networks and access sensitive customer data, secrets, and CI/CD pipelines. While the issue was immediately reported and patched by November 18, public disclosure lagged until almost two months later, heightening risk as proof-of-concept code surfaced and attackers ramped up reconnaissance against exposed n8n instances. Organizations using n8n are strongly urged to upgrade to version 1.121.1 or later as there are no workarounds, and delayed patching increases exposure to opportunistic threat actors. This incident is particularly significant because n8n is commonly integrated into business-critical workflows containing high-value credentials and assets. As attackers increasingly focus on exploiting vulnerabilities in automation and orchestration tools, the "ni8mare" flaw exemplifies the need for rapid patching and mature exposure management practices across the enterprise software supply chain.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Veeam 2026 RCE Vulnerability: Ransomware’s Direct Path into Enterprise Backups
Impact· high

Veeam 2026 RCE Vulnerability: Ransomware’s Direct Path into Enterprise Backups

In January 2026, Veeam disclosed several critical vulnerabilities affecting its popular Backup & Replication software platform, including CVE-2025-59470—a remote code execution (RCE) flaw that allowed highly privileged Backup or Tape Operators to execute arbitrary code as the postgres user by manipulating input parameters. While the vulnerability required high privileges, threat actors have a history of targeting Veeam's backup systems to gain lateral access, destroy backups, and enable ransomware attacks, especially given the software's widespread deployment across large enterprises. Notably, historic ransomware operations such as Cuba, FIN7, Akira, and Frag have exploited Veeam flaws to undermine business continuity, infect victim networks, and erase recovery options. This incident underscores the ongoing threat of ransomware actors prioritizing backup infrastructure as a major attack vector, leveraging RCE flaws to cripple organizations’ resilience. The rapid evolution and regular targeting of backup systems show a critical need for enforced least privilege, defense-in-depth for privileged roles, and prompt patch deployments, particularly as backup environments remain frequent targets for sophisticated attackers seeking maximal impact.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
ownCloud Issues Urgent MFA Advisory After Credential Compromise
Impact· high

ownCloud Issues Urgent MFA Advisory After Credential Compromise

In June 2024, ownCloud, a widely-used open-source file-sharing platform, warned its global user base after reports of attackers exploiting stolen credentials to compromise accounts and access sensitive data. The advisory followed observed instances of credential stuffing attacks, whereby threat actors leveraged previously breached usernames and passwords to gain unauthorized access to user files and information. As a precaution, ownCloud urged all users to immediately enable multi-factor authentication (MFA) to block further attempts and reduce the risk of additional breaches across its service. While no specific number of impacted users was disclosed, the potential for unauthorized data access remains considerable, particularly in organizational environments where MFA is not enforced. This incident highlights the ongoing surge in credential-based attacks, escalated by widespread data leaks and the persistent reuse of passwords across services. OwnCloud's advisory aligns with broader industry trends as organizations face mounting regulatory and reputational risks stemming from inadequate authentication controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
AI-Enhanced Cybercrime in 2026: Vibe Hacking & HackGPT Threats Explained
Impact· low

AI-Enhanced Cybercrime in 2026: Vibe Hacking & HackGPT Threats Explained

In early 2026, the cybersecurity landscape saw a significant shift with the rise of AI-enhanced cybercrime through a phenomenon known as 'vibe hacking'. Threat actors began leveraging accessible AI tools—often marketed as FraudGPT, PhishGPT, WormGPT, and similar—to automate cyberattacks such as phishing, credential theft, and fraud, regardless of the attacker’s technical skill. These AI-assisted services, readily advertised across dark web forums and encrypted messaging platforms, enabled novice cybercriminals to bypass traditional knowledge barriers and orchestrate sophisticated campaigns at scale. The operational impact includes an unprecedented increase in AI-driven threats, reduced discernibility of malicious communications, and a lower barrier to cybercrime participation, leading to broader, more frequent attacks on organizations worldwide. The current relevance of this trend is underscored by the growing commercialization of AI-jailbreaking and attack automation techniques, which are rapidly propagating through cybercrime channels. As these tools proliferate, defenders face a surge in threat volume and complexity, compelling organizations to rethink detection, response, and training in the face of AI-enabled adversaries.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Ni8mare: Critical 2026 n8n RCE Vulnerability Risks Full Server Takeover
Impact· medium

Ni8mare: Critical 2026 n8n RCE Vulnerability Risks Full Server Takeover

In January 2026, over 100,000 self-hosted instances of the n8n open-source workflow automation platform were exposed to complete remote takeover due to a maximum-severity flaw named "Ni8mare" (CVE-2026-21858). The vulnerability arose from a content-type confusion in n8n's webhook parsing logic, allowing unauthenticated attackers to access arbitrary files, exfiltrate sensitive credentials, escalate privileges, and potentially execute arbitrary code. Attackers could exploit this flaw with simple HTTP requests, targeting the platform’s broad deployment in AI orchestration and process automation. This incident highlights the continued risk posed by unauthenticated remote code execution flaws in widely-used DevOps and automation tools, especially as critical secrets and API keys are increasingly concentrated in such orchestration platforms. The rapid rise of AI and automation in enterprise environments elevates both the impact and urgency of addressing similar vulnerabilities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical jsPDF Node.js Flaw Exposes Sensitive Data via Generated PDFs
Impact· high

Critical jsPDF Node.js Flaw Exposes Sensitive Data via Generated PDFs

In January 2026, a critical vulnerability (CVE-2025-68428) was uncovered in the popular JavaScript PDF generation library jsPDF, impacting its Node.js builds prior to version 4.0. Attackers could exploit improper input validation in the 'loadFile' function, enabling local file inclusion and path traversal. If user-controlled data was passed as a file path to certain methods, sensitive local files could be incorporated into generated PDFs, risking data exposure or exfiltration. The flaw's severity score of 9.2 reflects the widespread use of jsPDF—over 3.5 million weekly downloads—as well as the supply-chain risk to downstream applications that integrated vulnerable versions. This incident highlights the persistent risk associated with supply-chain dependencies and their indirect impact on downstream systems. With development teams increasingly relying on open-source libraries, vulnerabilities like CVE-2025-68428 demonstrate the urgent need for vendor diligence, dependency hygiene, and layered input validation in modern application stacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
GoBruteforcer Botnet Hits Crypto Projects via AI-Configured Default Credentials
Impact· medium

GoBruteforcer Botnet Hits Crypto Projects via AI-Configured Default Credentials

In January 2026, a significant wave of GoBruteforcer botnet attacks targeted cryptocurrency and blockchain projects by exploiting misconfigured, internet-facing servers. Attackers leveraged weak default credentials in commonly used XAMPP, MySQL, PostgreSQL, FTP, and phpMyAdmin deployments—many set up using AI-generated configuration examples. After brute-forcing access, threat actors deployed web shells and specialized utilities to scan for vulnerable cryptocurrency wallets, aiming to exfiltrate crypto assets from compromised infrastructure. Over 50,000 servers were estimated at risk, with threat actors automating large-scale scans and credential spraying campaigns over public IP space. This campaign highlights a critical trend: the proliferation of weak security settings driven by widespread adoption of AI-generated setup scripts, as well as persistent use of outdated, insecure server stacks. The convergence of automation, botnet-scale brute-forcing, and blockchain-targeted payloads marks an evolution in how cybercriminals exploit configuration drift and endpoint exposure in modern DevOps environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Misconfigured Email Routing Enables Sophisticated Internal Domain Phishing Attacks
Impact· low

Misconfigured Email Routing Enables Sophisticated Internal Domain Phishing Attacks

In early 2026, Microsoft disclosed that threat actors exploited misconfigured email routing and insufficient spoof protections to impersonate internal organizational domains. Attackers leveraged these configuration flaws to bypass domain authentication controls, distributing phishing emails that appeared to originate from trusted internal addresses. Tactics included the use of phishing-as-a-service (PhaaS) platforms like Tycoon 2FA, resulting in credential theft and increased risk of lateral movement within affected organizations. The incident underscored systemic weaknesses in email routing setups and the importance of enforcing secure communication protocols. This attack highlights a growing trend of adversaries abusing overlooked, internal cloud and email infrastructure weaknesses to evade legacy defenses. The prevalence of PhaaS platforms has lowered the barrier for conducting sophisticated phishing campaigns, emphasizing the urgency for organizations to audit and remediate their email and domain configurations against evolving social engineering tactics.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Veeam Backup & Replication 2026: Critical RCE Flaws and Enterprise Risk
Impact· high

Veeam Backup & Replication 2026: Critical RCE Flaws and Enterprise Risk

In January 2026, Veeam disclosed and patched four critical vulnerabilities in its Backup & Replication software, with the most severe (CVE-2025-59470, CVSS 9.0) enabling remote code execution as the postgres user by authorized Backup or Tape Operators. Additional flaws allowed for RCE as root and arbitrary file writes, impacting Veeam Backup & Replication 13.0.1.180 and prior. While exploitation requires highly privileged roles, prior incidents have shown that threat actors rapidly exploit vulnerable backup platforms, risking backup integrity, ransomware proliferation, and data exfiltration. Immediate patching is essential to prevent lateral movement and data loss, per Veeam's and industry guidance. The incident underscores the ongoing risk of privilege abuse and the critical importance of timely vulnerability management in backup infrastructures, especially as threat actors increasingly target backup systems to disable recovery and amplify ransomware impacts.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical 2026 n8n Vulnerability Lets Attackers Remotely Execute Code Without Credentials
Impact· medium

Critical 2026 n8n Vulnerability Lets Attackers Remotely Execute Code Without Credentials

In early January 2026, security researchers disclosed CVE-2026-21858 ("Ni8mare"), a critical (CVSS 10.0) vulnerability in the n8n workflow automation platform. Affecting versions up to 1.65.0, the flaw allows unauthenticated remote attackers to exploit the application's "Content-Type" processing logic, enabling arbitrary file reads and ultimately granting full system takeover by escalating to remote code execution (RCE). Attackers can leverage exposed n8n instances, retrieve sensitive admin credentials, forge session tokens, and create malicious workflows to execute system commands. Globally, over 26,000 systems were identified as potentially exposed at disclosure time, many internet-accessible, posing grave risk to organizations running n8n. This incident underscores a growing trend in supply chain and automation-tool attacks, where threat actors exploit complex integrations and insufficient access controls. The prevalence of automation platforms as central hubs for organizational secrets intensifies the impact radius. The urgent need to patch, limit internet exposure, and apply zero trust controls remains critical to prevent similar high-impact breaches.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical RCE in n8n Workflow Platform Exposes Cloud & Self-Hosted Users (2026)
Impact· medium

Critical RCE in n8n Workflow Platform Exposes Cloud & Self-Hosted Users (2026)

In January 2026, open-source workflow automation platform n8n disclosed a critical vulnerability (CVE-2026-21877) affecting both its self-hosted and cloud environments. The flaw, rated CVSS 10.0, allows authenticated users to execute arbitrary code remotely under specific conditions, potentially leading to the full compromise of affected instances. The vulnerability impacts versions >=0.123.0 and <1.121.3, and was responsibly disclosed by security researcher Théo Lelasseux. Immediate mitigation includes upgrading to version 1.121.3 or higher, and temporarily disabling certain nodes for additional protection. This incident underscores the persistent risks associated with supply chain and automation software, which are increasingly targeted due to their ubiquity and privileged access. The n8n case also reflects a trend of continuous discovery of critical flaws in widely used DevOps tooling, making timely patching and access control more important than ever.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Black Cat SEO Poisoning Campaign Unleashes Mass Infostealer Outbreak Across China
Impact· medium

Black Cat SEO Poisoning Campaign Unleashes Mass Infostealer Outbreak Across China

Between December 7 and 20, 2025, the cybercrime gang Black Cat orchestrated a large-scale SEO poisoning campaign targeting Chinese users searching for popular software via Microsoft Bing and similar engines. By pushing fraudulent lookalike websites (e.g., mimicking Notepad++, Google Chrome, QQ International, iTools) to the top of search results, Black Cat tricked users into downloading compromised installers. When executed, these installers side-loaded backdoor trojans that exfiltrated sensitive information, such as browser data, keystrokes, and clipboard contents, back to attacker-controlled infrastructure. At least 277,800 hosts were infected in less than two weeks, with daily compromise rates peaking above 62,000 machines. This campaign marks a significant escalation in the use of SEO poisoning for initial malware access, reflecting a trend in highly targeted, financially motivated infostealer operations. As search engines become the go-to for software discovery, this incident strongly highlights the risks of relying on unverified download sources and demonstrates attackers' growing sophistication in exploiting user trust.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports