✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Phishing Campaign Evades AI Detection with HTML Comment Padding
In July 2026, a sophisticated phishing campaign was identified, utilizing oversized HTML attachments filled with extensive comment padding to evade AI-based email security filters. The phishing emails masqueraded as Microsoft Teams notifications, featuring attachments named to resemble legitimate documents. These attachments, significantly larger than typical phishing payloads, contained minimal functional content surrounded by large blocks of HTML comments, effectively diluting the malicious code and bypassing detection mechanisms. This technique underscores the evolving tactics of cybercriminals in circumventing advanced security measures. The incident highlights a growing trend where attackers exploit AI and machine learning systems' limitations by manipulating content to evade detection. As AI becomes more integral to cybersecurity defenses, adversaries are developing methods to exploit its weaknesses, necessitating continuous adaptation and enhancement of security protocols to address these sophisticated evasion techniques.
2 weeks ago
Kill Chain
Helix Vishing Group Exploits SharePoint in Data Theft Attacks
In July 2026, a new data-extortion group named Helix emerged, employing sophisticated identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to infiltrate SharePoint environments. The attackers initiated contact by impersonating managers over the phone, convincing employees to provide device codes, thereby gaining unauthorized access to their accounts. Once inside, Helix operators registered new MFA applications to maintain persistence, systematically enumerated SharePoint content, and exfiltrated sensitive files. The stolen data was then used to extort victim organizations by threatening public disclosure or selling it to other cybercriminals. This incident underscores a significant shift towards identity-based attacks targeting cloud services, highlighting the vulnerabilities in current authentication processes. The Helix group's methods bear similarities to previous tactics employed by groups like ShinyHunters and BlackFile, indicating a possible evolution or rebranding of these threat actors. Organizations must reassess and strengthen their security protocols, particularly around identity verification and access controls, to mitigate the risks posed by such sophisticated social engineering attacks.
2 weeks ago
Kill Chain
Understanding the Bucket Hijacking Threat in Cloud Storage
In July 2026, a critical cloud storage attack technique known as 'bucket hijacking' was disclosed, enabling threat actors to silently redirect an organization's active cloud data streams, including audit logs and telemetry, into attacker-controlled external storage buckets across major cloud platforms. This vulnerability exploits the global uniqueness of cloud storage bucket names, allowing attackers to register a previously deleted bucket name and reroute data streams intended for the original bucket. The attack affects major cloud providers, including Google Cloud, Amazon Web Services (AWS), and Microsoft Azure, and detection is extremely challenging once deployed. ([serisec.com](https://serisec.com/index.php/2026/06/27/new-bucket-hijacking-attack-allows-hackers-to-reroute-cloud-data-streams-to-external-storage/?utm_source=openai)) This incident underscores the escalating risks associated with cloud misconfigurations and the critical need for organizations to implement robust monitoring and configuration management practices. As cloud environments become increasingly complex, the potential for such vulnerabilities to be exploited grows, emphasizing the importance of proactive security measures to safeguard sensitive data.
2 weeks ago
Kill Chain
Dormant GitHub Accounts: A New Vector in Supply Chain Attacks
In July 2026, Datadog Security Labs identified multiple coordinated campaigns systematically enumerating corporate GitHub organizations, repositories, and user accounts via the GitHub API. Attackers utilized automated scraping tools with custom or legitimate-sounding user agents, leveraging dormant 'ghost' accounts—created two to five years prior and left inactive—as well as compromised OAuth tokens and personal access tokens (PATs) from legitimate users. While much of the activity targeted public data, some instances involved cloning private repositories, indicating a significant escalation in threat actor capabilities. This incident underscores the evolving tactics of threat actors who exploit dormant accounts and compromised credentials to conduct reconnaissance and access sensitive information. Organizations must enhance their monitoring of API activities and implement robust access controls to mitigate such risks.
2 weeks ago
Kill Chain
npm 12 Enhances Security by Disabling Automatic Install Scripts
In July 2026, GitHub released npm version 12, implementing significant security enhancements by disabling install scripts by default. This change prevents automatic execution of preinstall, install, and postinstall scripts during package installation, addressing a major attack vector exploited in previous supply chain attacks. Additionally, npm v12 requires explicit approval for Git and remote URL dependencies, further strengthening the ecosystem's security posture. This update is particularly relevant as supply chain attacks have become increasingly prevalent, with attackers leveraging automatic script execution to compromise systems. By requiring explicit consent for script execution and external dependencies, npm v12 aims to mitigate these risks, promoting a more secure development environment.
2 weeks ago
Kill Chain
GigaWiper: Unveiling a Multifaceted Cyber Threat
In July 2026, Microsoft uncovered a sophisticated Windows backdoor named GigaWiper, which integrates three destructive functionalities: a raw disk wiper that overwrites physical drives and partition tables, a fake ransomware module that encrypts files without saving the decryption key, and a Windows drive wiper that overwrites system drives multiple times. Additionally, GigaWiper possesses espionage capabilities, including screen recording, hidden VNC sessions, and system manipulation, all while masquerading as legitimate services like OneDrive. The malware utilizes legitimate business services such as RabbitMQ, Redis, and MinIO for command and control, making detection challenging. The emergence of GigaWiper underscores a concerning trend in cyber threats, where attackers combine destructive and espionage functionalities within a single malware package. This evolution highlights the necessity for organizations to implement robust detection mechanisms, maintain offline backups, and stay vigilant against sophisticated attack vectors that blend legitimate services with malicious intent.
2 weeks ago
Kill Chain
AI-Powered Attack Compromises AWS Environment in Record Time
In July 2026, a lone threat actor utilized agentic AI workflows to orchestrate a sophisticated attack on a large Amazon Web Services (AWS) environment, achieving full compromise within 72 hours. The attacker exploited weaknesses across application services, AWS resources, source code repositories, CI/CD pipelines, runtime components, and data stores, leading to financial extortion of the victim. This incident underscores the evolving threat landscape where AI accelerates the speed and scale of cyberattacks, enabling even individual actors to execute complex operations rapidly. Organizations must adapt by enhancing their detection and response capabilities to counteract AI-assisted threats effectively.
2 weeks ago
Kill Chain
AI Gateway Compromise Exposes Critical Security Vulnerabilities
In July 2026, a threat actor compromised an Amazon EC2 server hosting an AI gateway connected to Amazon Bedrock services. The attacker utilized this access to deploy cryptomining software, exploiting the gateway's privileged position to potentially access AI models, manipulate workflows, and infiltrate the organization's cloud infrastructure. This incident underscores the critical vulnerabilities associated with AI gateways, which often serve as central points of access to sensitive data and services. The increasing deployment of AI gateways in enterprise environments highlights the urgent need for robust security measures. As these gateways aggregate access to multiple AI models and datasets, they become attractive targets for attackers seeking to exploit centralized points of control. Organizations must implement stringent access controls, continuous monitoring, and regular security assessments to mitigate the risks posed by such vulnerabilities.
2 weeks ago
Kill Chain
GodDamn Ransomware: Exploiting PoisonX Driver in Advanced Attacks
In May 2026, a new ransomware variant named GodDamn emerged, utilizing the PoisonX kernel driver to disable endpoint security defenses. This tactic, known as a Bring Your Own Vulnerable Driver (BYOVD) attack, allows the ransomware to neutralize security software by exploiting a signed but vulnerable driver. GodDamn is assessed to be a rebranded version of the Beast ransomware, which itself evolved from the Monster ransomware first detected in March 2022. The attackers employed tools like AnyDesk for remote access and a NirSoft-based credential harvester to extract sensitive information before deploying the ransomware payload. The use of signed drivers to disable security measures represents a significant evolution in ransomware tactics, highlighting the increasing sophistication of threat actors. Organizations must be vigilant against such advanced techniques, as they can render traditional security solutions ineffective, leading to severe operational disruptions and data loss.
2 weeks ago
Kill Chain
ESET Threat Report H1 2026: Unveiling PromptSpy, the First AI-Driven Android Malware
In February 2026, ESET researchers discovered PromptSpy, the first known Android malware to utilize generative AI during its execution. This malware leverages Google's Gemini AI to interpret on-screen elements dynamically, enabling it to adapt its behavior across various Android devices and maintain persistence by preventing uninstallation. PromptSpy is distributed through a malicious dropper disguised as a system update, primarily targeting Spanish-speaking users in South America, especially Argentina. Once installed, it abuses Accessibility Services to monitor and control the user interface, deploys a Virtual Network Computing (VNC) module for remote access, and captures sensitive data such as lockscreen credentials and screen activity. ([eset.com](https://www.eset.com/us/about/newsroom/research/eset-research-discovers-promptspy-first-android-threat-using-genai/%3Fsrsltid%3DAfmBOoqZ_0fHGAaMnVaEZ5B0AuPdwhhXlaecY3Klyk-8QVRG-fAAlTy6?utm_source=openai)) The emergence of PromptSpy signifies a pivotal shift in mobile cybersecurity, illustrating how threat actors are integrating generative AI to enhance malware adaptability and persistence. This development underscores the urgent need for advanced detection mechanisms and proactive security measures to counteract AI-driven threats in the evolving cyber landscape.
2 weeks ago
Kill Chain
CISA Urges Immediate Patching of Langflow Vulnerability CVE-2026-55255
In July 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) mandated federal agencies to patch a critical vulnerability in Langflow, a popular AI development tool. Identified as CVE-2026-55255, this Insecure Direct Object Reference (IDOR) flaw allows authenticated attackers to execute flows belonging to other users by manipulating the /api/v1/responses endpoint. Exploitation of this vulnerability can lead to unauthorized access to sensitive data and resource consumption. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-prioritize-patching-langflow-auth-bypass-flaw/?utm_source=openai)) The urgency of this directive underscores the increasing targeting of AI development platforms by cyber actors. As AI tools become integral to various sectors, ensuring their security is paramount to prevent potential data breaches and operational disruptions.
2 weeks ago
Kill Chain
KDDI Data Breach 2026: Zero-Day Vulnerability Exploited
In June 2026, Japanese telecommunications giant KDDI detected unauthorized access to its email platform, affecting multiple internet service providers (ISPs) including STNet, JCOM, Chubu Telecommunications, NIFTY Corporation, and BIGLOBE. The breach, initiated on May 16, exploited a zero-day vulnerability in third-party software, leading to the exposure of approximately 12.23 million email addresses and 7.61 million passwords. KDDI promptly blocked the attackers upon discovery on June 17 and implemented defensive measures to secure the compromised systems. This incident underscores the critical importance of securing third-party software components, as vulnerabilities in such software can serve as entry points for attackers. Organizations are urged to conduct thorough security assessments of third-party tools and implement robust monitoring systems to detect and respond to unauthorized access promptly.
2 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports