Validated Containment Architectures are here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2676 threat reports
Page 147 of 223

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 17531764 / 2676 reports
CISA Flags New Code Injection Threats in 2026: HPE OneView & Microsoft Office Under Attack
Impact· low

CISA Flags New Code Injection Threats in 2026: HPE OneView & Microsoft Office Under Attack

On January 7, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation of two critical code injection vulnerabilities: CVE-2009-0556 in Microsoft Office PowerPoint and CVE-2025-37164 affecting HPE OneView. Attackers leveraged these vulnerabilities to gain unauthorized code execution, potentially enabling lateral movement and data compromise within federal and enterprise environments. The exploitation highlighted weaknesses in outdated software and emphasized the urgency for immediate remediation to safeguard sensitive systems and data across government agencies and broader sectors. The rapid addition of these vulnerabilities to CISA's KEV Catalog reflects a broader industry trend of threat actors targeting lingering, unpatched software with advanced code injection techniques. Increasing regulatory pressure and new threat intelligence underscore the need for timely vulnerability management as attackers adapt to bypass existing defenses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Inside the Scattered Lapsus$ Honeypot: How Researchers Turned the Tables in 2024
Impact· medium

Inside the Scattered Lapsus$ Honeypot: How Researchers Turned the Tables in 2024

In early 2024, cybersecurity researchers staged a sophisticated deception operation targeting Scattered Lapsus$, also known as ShinyHunters, by deploying a realistic but fake dataset as a honeypot. The operation was designed to lure threat actors with what appeared to be sensitive credentials and data, allowing security experts to monitor the attackers' methods and behaviors in real time. Once engaged, Scattered Lapsus$ actors attempted lateral movement and data exfiltration using various covert tools and techniques, but their actions were closely tracked and documented. This resulted in a rare glimpse into the group's tactics, techniques, and procedures, as well as validation of multiple defensive controls. This incident is particularly noteworthy as it demonstrates the growing effectiveness of proactive threat intelligence gathering through deception and honeypots. With threat groups like Lapsus$ and ShinyHunters targeting high-value data across industries, similar methods are being adopted by defenders to preemptively understand and disrupt sophisticated adversaries.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Zestix Credential Heist: 2024 Cloud Infostealer Campaign Exposes MFA Weaknesses
Impact· low

Zestix Credential Heist: 2024 Cloud Infostealer Campaign Exposes MFA Weaknesses

In early 2024, a novel threat actor known as "Zestix" orchestrated a widespread credential theft campaign targeting enterprise file-sharing environments across multiple sectors. Using advanced infostealer malware, Zestix harvested cloud credentials at scale, exploiting organizations that had not enforced multi-factor authentication (MFA). The attackers subsequently gained unauthorized access to sensitive files and regulated business data from approximately 50 companies, causing both data exfiltration and operational disruptions. The breach underlines significant weaknesses in authentication and access controls within cloud ecosystems, with impacts ranging from compromised intellectual property to potential compliance violations. The incident underscores the urgent need for robust access controls and MFA as essential defenses in today’s cloud-first environments. With identity-driven breaches rising and attackers automating large-scale infostealer campaigns, organizations face increasing regulatory and reputational pressure to modernize and enforce cloud security policies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Generative AI Supercharges Active Directory Credential Attacks in 2026
Impact· low

Generative AI Supercharges Active Directory Credential Attacks in 2026

In early 2026, organizations relying on Microsoft Active Directory experienced a significant increase in successful identity attacks fueled by generative AI technology. Threat actors leveraged AI-powered password cracking tools, such as PassGAN, capable of predicting and cracking user passwords with unprecedented speed, particularly by exploiting patterns present in common password creation habits. These attackers combined automated reconnaissance—scraping public data with large language models—to generate highly targeted guesses, accelerating credential compromise, and enabling lateral movement within corporate networks. Weak password policies, reliance on basic MFA, and the wide availability of cost-effective GPU resources contributed to the scale and efficiency of these breaches. This incident highlights the urgent need for organizations to address evolving attack methodologies, as generative AI lowers the technical barrier for credential-focused attacks and shortens breach timetables. The cybersecurity landscape is rapidly shifting towards identity-driven threats facilitated by AI, demanding stronger, adaptive protections to prevent widespread compromise.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
D-Link Legacy Router Flaw Exploited: CVE-2026-0625 Zero-Day Endangers Networks
Impact· medium

D-Link Legacy Router Flaw Exploited: CVE-2026-0625 Zero-Day Endangers Networks

In early January 2026, a critical security incident involving D-Link legacy DSL routers came to light as attackers actively exploited a command injection vulnerability tracked as CVE-2026-0625. The flaw, caused by improper input sanitization in the dnscfg.cgi endpoint of several out-of-support D-Link DSL gateway models, allowed unauthenticated remote attackers to execute arbitrary shell commands and potentially gain full control over affected devices. Although the exploit was first detected by Shadowserver Foundation honeypots, the method was not previously public, raising the risk of widespread attacks on consumer and small business network infrastructure. Impacted routers—including the DSL-526B, DSL-2640B, DSL-2740R, and DSL-2780B—are end-of-life and will not receive security updates, leaving users exposed unless devices are decommissioned or isolated. This incident highlights the persistent risks associated with legacy, unsupported network hardware across both consumer and SMB environments, particularly as attackers increasingly exploit unpatched, remotely accessible routers. It underscores the urgent importance of retiring end-of-life devices or segmenting critical networks, as well as the need for improved asset management strategies in the face of rising supply-chain and infrastructure vulnerabilities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical n8n Vulnerability Enables Authenticated Command Execution (CVE-2025-68668)
Impact· medium

Critical n8n Vulnerability Enables Authenticated Command Execution (CVE-2025-68668)

In January 2026, a critical vulnerability (CVE-2025-68668) was disclosed in n8n, an open-source workflow automation platform, allowing authenticated users with workflow modification privileges to execute arbitrary system commands on the host server. The flaw, caused by a sandbox bypass in the Python Code Node (Pyodide), impacted all n8n versions from 1.0.0 up to 2.0.0. Prompted by Cyera Research Labs’ findings, the n8n team released version 2.0.0 as a fix and advised urgent security configuration changes or feature disablement as interim measures. The vulnerability poses high risks for supply-chain and SaaS environments using n8n in production, potentially enabling lateral movement or privilege escalation. This incident underscores the continued threat from vulnerabilities in low-code/no-code and automation platforms, especially as attackers increasingly leverage authenticated access and workflow manipulation to escalate privileges. Organizations should review security settings of workflow platforms due to a growing pattern of exploitation in automation pipelines.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
VS Code Forks Highlight Open VSX Supply Chain Vulnerability (2026)
Impact· medium

VS Code Forks Highlight Open VSX Supply Chain Vulnerability (2026)

In early 2026, a supply chain vulnerability involving popular AI-powered Visual Studio Code (VS Code) forks—such as Cursor, Windsurf, Google Antigravity, and Trae—was discovered. These IDEs recommended certain extensions that did not exist in the Open VSX registry, leaving the extension namespaces unclaimed and thus open to exploitation by malicious actors. Attackers could upload rogue extensions under these names, which unsuspecting developers would install due to these recommendations. Koi researchers demonstrated the risk by publishing a placeholder PostgreSQL extension on Open VSX, garnering over 500 installs, highlighting the real-world likelihood of sensitive data exposure and credential theft before the issue was mitigated by the IDE vendors and Open VSX registry maintainers. This incident underscores the persistent risk of supply chain attacks in open-source developer tooling, as adversaries increasingly exploit gaps in public code marketplaces. With threat actors targeting trusted workflows and dependency chains, organizations must elevate their scrutiny and controls around open-source software consumption.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Kimwolf Botnet’s 2024 Assault: How Residential Proxies Fueled Widespread Android Device Infections
Impact· medium

Kimwolf Botnet’s 2024 Assault: How Residential Proxies Fueled Widespread Android Device Infections

In 2024, the Kimwolf Android botnet rapidly expanded to over two million infected hosts by exploiting vulnerabilities in residential proxy networks to penetrate internal devices. This botnet, an evolution of Aisuru malware, leverages residential IP addresses to mask malicious activity and facilitate lateral movement inside targeted networks. By abusing these proxies, Kimwolf can bypass perimeter defenses, execute command-and-control operations, and enable wide-scale internal compromise of Android and IoT devices, causing extensive disruption and exposing organizations to data theft, downtime, and potential extortion. Kimwolf highlights a growing threat: attackers are increasingly leveraging residential proxies and internal lateral movement tactics to amplify reach and evade detection. Its success underscores the need for improved egress filtering, network segmentation, and east-west traffic monitoring as threat actors adopt more sophisticated methods to breach internal assets.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
DCRat Delivered Through Fake Booking Emails Hits European Hotels in 2026
Impact· low

DCRat Delivered Through Fake Booking Emails Hits European Hotels in 2026

In early 2026, a sophisticated cyberattack campaign, tracked as PHALT#BLYX, targeted the European hospitality sector using malicious fake booking emails. These emails redirected recipients to fraudulent Blue Screen of Death (BSoD) pages, pressuring hotel staff to install fake fixes. This social engineering technique resulted in the deployment of DCRat, a remote access trojan capable of stealing sensitive data, harvesting credentials, and providing attackers with persistent network access. The campaign, reported by Securonix, underscores the increasing professionalization of phishing lures and multi-stage malware delivery aimed at high-turnover verticals like hospitality. The attack highlights a recent trend of leveraging socially engineered booking-themed lures paired with malware disguised as system utilities. As similar TTPs proliferate and more malware-as-a-service tools become accessible, such incidents foreshadow growing risks for sectors with transient workforces and limited security training.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
TOTOLINK EX200 Unpatched Flaw Enables Remote Takeover in 2026
Impact· medium

TOTOLINK EX200 Unpatched Flaw Enables Remote Takeover in 2026

In January 2026, a critical unpatched firmware vulnerability (CVE-2025-65606) was disclosed by CERT/CC affecting TOTOLINK EX200 wireless range extenders. This flaw resides in the device’s firmware-upload error-handling logic, allowing a remote authenticated attacker to trigger processes leading to full device compromise. Successful exploitation provides total administrative control, enabling attackers to alter configurations, secretly listen to traffic, or pivot to other devices on the network. TOTOLINK has not released an update, leaving vulnerable devices exposed in both home and enterprise environments. This breach highlights the ongoing threat posed by IoT device vulnerabilities—especially as attackers increasingly exploit authentication-bypass flaws and manufacturer patch delays. The incident underscores the importance of swift vulnerability management and robust network segmentation in mitigating the risk from unpatched IoT endpoints.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Ransomware 2026: Inside the Surge of DDoS, Insiders, and Gig Worker Threats
Impact· high

Ransomware 2026: Inside the Surge of DDoS, Insiders, and Gig Worker Threats

In early 2026, ransomware groups rapidly adapted their extortion playbooks following a revenue decline, marked by a 47% year-over-year surge in attacks but falling ransom payments. Threat actors broadened tactics—reviving DDoS-for-hire within the Ransomware-as-a-Service (RaaS) model, ramping up recruitment of insiders (including targeting trusted employees and gig workers), and executing data theft via both technical and social attack vectors. Notably, attackers expanded beyond traditional Russian operators, evidencing global proliferation. These methods bypassed conventional defenses, with incidents tracked across multiple sectors and frequently resulting in significant data breaches, operational disruption, and reputational harm. The evolution of ransomware in 2026 highlights a rising urgency for enterprises to harden insider defenses, revisit DDoS mitigation, and validate physical security and third-party access. With attackers exploiting workforce instability, gig economy platforms, and hybrid extortion, a modernized, multi-layered security posture is now critical across all industries.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Inside the ClickFix Campaign: How Hospitality Firms Were Hit with DCRat Remote Access Attacks
Impact· medium

Inside the ClickFix Campaign: How Hospitality Firms Were Hit with DCRat Remote Access Attacks

In early 2024, a sophisticated phishing campaign known as 'ClickFix' targeted organizations in the hospitality sector with convincing fake 'Blue Screen of Death' error messages. Attackers leveraged social engineering techniques combined with a legitimate Microsoft utility to trick victims into executing malicious payloads. Once engaged, the attack delivered the DCRat remote access trojan, granting cybercriminals ongoing access and control over affected systems. The campaign demonstrated how legitimate tools and realistic lures can bypass conventional defenses, resulting in compromised credentials, lateral network movement, and potential data exfiltration. This incident reflects a wider trend of threat actors increasingly turning to legitimate software and advanced social engineering to evade detection. Remote access trojans like DCRat continue to be used in targeted attacks, particularly against sectors with complex digital footprints and limited security controls, making it vital for organizations to adapt their threat detection capabilities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports