Validated Containment Architectures are here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2676 threat reports
Page 151 of 223

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 18011812 / 2676 reports
Critical MongoDB Flaw Exposes Sensitive Server Memory to Unauthenticated Threats
Impact· high

Critical MongoDB Flaw Exposes Sensitive Server Memory to Unauthenticated Threats

In December 2025, a critical security flaw (CVE-2025-14847) was publicly disclosed in multiple versions of MongoDB, exposing organizations to the risk of uninitialized memory disclosure by unauthenticated attackers. The flaw stems from improper handling of length parameter inconsistencies within zlib compressed protocol headers, allowing remote, unauthenticated clients to read uninitialized heap memory. Impacted versions span major MongoDB releases 3.6 through 8.2, potentially exposing sensitive data in server memory. MongoDB responded by releasing patches and advised urgent upgrades or the disabling of zlib compression. This incident gains heightened significance as memory disclosure vulnerabilities enable threat actors to harvest sensitive information without authentication. The vulnerability underscores the increasing importance of rigorous software supply chain security and timely patch management amid a growing landscape of data exposure risks in widely used open-source technologies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Evasive Panda APT Uses DNS Poisoning for Prolonged Espionage: 2022–2024 Campaign
Impact· medium

Evasive Panda APT Uses DNS Poisoning for Prolonged Espionage: 2022–2024 Campaign

Between November 2022 and November 2024, the China-linked Evasive Panda APT group conducted a sophisticated cyber espionage campaign targeting entities in Türkiye, China, and India. The attackers leveraged DNS poisoning techniques to redirect requests for popular software updates (such as SohuVA and Tencent QQ) to attacker-controlled infrastructure. Through adversary-in-the-middle attacks, victims received trojanized loaders, which proceeded to fetch and decrypt highly targeted MgBot backdoors. The attack chain involved supply chain and AitM vectors, advanced encryption and obfuscation methods, and allowed persistent compromise and broad data theft, including keylogging and credential exfiltration. This campaign highlights the growing sophistication of APT operations exploiting core network infrastructure such as DNS to evade perimeter defenses. The increased prevalence of similar DNS-manipulation campaigns and targeted malware delivery emphasizes the urgent need for robust segmentation, encrypted traffic, and thorough network and endpoint visibility.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
2025's Stealth Loader and AI Exploit Wave: How Multi-Vector Attacks Redefined Cybersecurity
Impact· medium

2025's Stealth Loader and AI Exploit Wave: How Multi-Vector Attacks Redefined Cybersecurity

In late 2025, a coordinated wave of global cyber attacks leveraged stealthy multi-vector campaigns with commodity loaders, AI-powered exploits, and social engineering. Attackers weaponized legitimate tools like Nezha for post-exploitation, orchestrated large-scale phishing using fake updates and PoC exploits, and targeted both enterprise and consumer platforms. These campaigns saw loaders like Caminho deliver diverse malware such as XWorm, PureLogs, and RATs into manufacturing, government, and IT networks across several regions. Simultaneously, attackers abused vulnerabilities in AI assistants and exploited weaknesses in NFC-enabled Android malware, achieving persistent access, privilege escalation, data exfiltration, and lateral movement—all while skillfully blending malicious traffic with normal system behaviors. This incident highlights a sharp evolution in attack methods as threat actors increasingly favor low-noise, blended tradecraft over traditional smash-and-grab approaches. With the convergence of signature evasion, AI system manipulation, and commodity loader sharing, defenders must shift toward integrated, threat-aware security architectures. These incidents mark a critical inflection point, signaling a persistent rise in invisible, multi-layered threats fueled by automation and attacker collaboration.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Typosquatted MAS Domain Delivers PowerShell Malware in 2024 Attack
Impact· low

Typosquatted MAS Domain Delivers PowerShell Malware in 2024 Attack

In early 2024, cybersecurity researchers identified a campaign leveraging a typosquatted domain mimicking the legitimate Microsoft Activation Scripts (MAS) tool to distribute the 'Cosmali Loader' malware. Unsuspecting users seeking MAS utilities were tricked into downloading malicious PowerShell scripts, which silently loaded the Cosmali Loader onto Windows machines. The loader subsequently enabled additional payload delivery, providing attackers with persistent access and the ability to deploy further malware or conduct post-infection activities. The incident demonstrates the ongoing risks of social engineering via typosquatting and open-source tool impersonation, with users and organizations inadvertently compromising their systems. This campaign is particularly relevant as it highlights the resurgence of supply chain threats and the increasing sophistication of threat actors leveraging typosquatted domains to bypass conventional defenses. The incident signals a growing trend targeting both individual users and enterprise environments through deceptive domains and script-based malware.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Evasive Panda: APT Delivers MgBot via DNS Poisoning in Asia (2022–2024)
Impact· medium

Evasive Panda: APT Delivers MgBot via DNS Poisoning in Asia (2022–2024)

Between November 2022 and November 2024, the Evasive Panda APT group executed a sophisticated campaign targeting victims primarily in Türkiye, China, and India. Leveraging adversary-in-the-middle (AitM) techniques and DNS poisoning, the attackers delivered a unique MgBot malware implant through fake software updates and stealthy loaders. The operation employed hybrid encryption, memory injection in signed executables, and evaded traditional defenses to maintain long-term persistence. Multiple new and legacy C2 infrastructures enabled sustained access while attackers tailored payloads based on the victim’s OS. This incident showcases the ongoing evolution of nation-state threat actors, utilizing advanced evasion, supply chain impersonation, and DNS manipulation to bypass security controls. It reflects a broader surge in attacks exploiting trust in software supply chains and underlines the need for continuously adaptive security strategies as actor sophistication grows.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Nomani Scam Exposes AI Deepfake Threats to Social Media in 2025
Impact· high

Nomani Scam Exposes AI Deepfake Threats to Social Media in 2025

In 2025, the Nomani investment scam surged by 62%, leveraging sophisticated AI-based deepfake advertisements across major social media platforms including Facebook and YouTube. The scheme utilized convincing fake endorsements and manipulated video content to lure unsuspecting individuals into fraudulent investment schemes. Security firm ESET recorded over 64,000 unique URLs distributing the fraudulent campaign, indicating an expansion both in scale and reach. The attackers exploited trust in familiar faces, rapidly spreading the scam and leading to substantial financial losses and reputational risks for victims and targeted brands. This incident highlights the growing threat of AI-enabled social engineering, with deepfakes enabling unprecedented scale and believability. As identity manipulation technologies proliferate, organizations and regulators face increased pressure to combat fraud, educate users, and adapt security controls to counter the evolving landscape of digital deception.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
How Phantom Shuttle Chrome Extensions Undermined Enterprise Security with Man-in-the-Middle Attacks
Impact· medium

How Phantom Shuttle Chrome Extensions Undermined Enterprise Security with Man-in-the-Middle Attacks

In December 2025, cybersecurity researchers discovered two versions of a Google Chrome extension named 'Phantom Shuttle' that secretly intercepted network traffic and stole user credentials from over 170 targeted domains. Masquerading as a legitimate VPN and speed test tool, these browser add-ons leveraged proxy permissions and malicious JavaScript code to inject authentication credentials and enable man-in-the-middle attacks. Users paid for subscriptions believing they were purchasing a secure service, while in reality, their web traffic, including passwords, authentication cookies, credit card information, API keys, and browsing histories, was exfiltrated continuously to a threat actor-controlled command-and-control server. The operation leveraged a subscription model and payment integrations via Alipay and WeChat, while traffic was routed through threat actor proxies managed via PAC scripts. This incident highlights a growing trend of browser extension abuse, with attackers monetizing malicious add-ons under the guise of productivity or security tools. With enterprise users increasingly utilizing browser extensions for business workflows, unmanaged browser risk is rapidly becoming a critical threat to organizational data security and compliance.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Amazon Thwarts Massive North Korean IT Job Scam: Lessons in Zero Trust and Insider Defense
Impact· medium

Amazon Thwarts Massive North Korean IT Job Scam: Lessons in Zero Trust and Insider Defense

In 2024, Amazon confronted a surge of over 1,800 suspected North Korean state-sponsored IT job scammers who attempted to infiltrate the company’s workforce through fraudulent job applications. The attackers used sophisticated social engineering and impersonation tactics to pose as legitimate IT professionals, seeking remote work to gain internal access or sensitive data. Amazon’s security and HR teams collaborated to detect anomalies, verify identities, and block the hiring process for the fraudulent profiles, successfully preventing insider threats and potential exploitation of corporate assets. The operation underscores the increasing complexity and scale of employment-based attack vectors. This incident is particularly relevant as cybercriminals and nation-state actors are increasingly leveraging remote work trends and IT labor shortages to execute social engineering intrusions. It highlights the need for enhanced workforce vetting, robust anomaly detection, and proactive segmentation to protect organizations from evolving insider and supply chain threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Threat Actors Exploit Zero-Day Vulnerability in WatchGuard Firebox Devices
Impact· low

Threat Actors Exploit Zero-Day Vulnerability in WatchGuard Firebox Devices

In early 2024, cybercriminals exploited a previously unknown zero-day vulnerability in WatchGuard Firebox firewall devices, enabling unauthorized remote access and control over affected appliances. Attackers leveraged this flaw to bypass authentication, deploy malware, and establish persistent footholds within targeted organizational networks. The campaign resulted in potential data breaches, service disruptions, and exposure of sensitive internal traffic due to compromised network perimeters. WatchGuard has since released urgent patches and guidance, while security teams raced to detect and remediate compromised devices. This incident highlights the persistent targeting of edge security appliances by advanced threat actors and the speed at which zero-day exploits are weaponized. As remote work and hybrid cloud adoption surge, organizations must prioritize rapid patching and enhanced detection to mitigate risks posed by critical perimeter vulnerabilities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
How Russian State-Sponsored Cyberattacks Targeted Denmark’s Critical Infrastructure and Elections in 2024
Impact· high

How Russian State-Sponsored Cyberattacks Targeted Denmark’s Critical Infrastructure and Elections in 2024

In December 2025, Danish authorities attributed two major cyberattacks in 2024 to Russian-backed groups. The first attack targeted a Danish water utility, causing significant operational disruption, and was attributed to Z-Pentest, a pro-Russian threat actor. The second involved a series of distributed denial-of-service (DDoS) attacks against Danish municipal and regional council websites on the eve of critical elections, orchestrated by NoName057(16), another threat group with ties to Russia. These incidents highlighted the vulnerabilities of critical infrastructure and democratic processes to foreign state-sponsored actors. The fallout from these attacks underscores a broader pattern of rising state-sponsored cyber operations targeting essential services and democratic institutions across Europe. Heightened geopolitical tensions and the growing sophistication of threat actors are driving urgent calls for improved cyber defenses and regulatory responses.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Ascension 2024 Breach: How RC4’s Legacy Left Millions Exposed
Impact· medium

Ascension 2024 Breach: How RC4’s Legacy Left Millions Exposed

In May 2024, healthcare giant Ascension suffered a major data breach after threat actors exploited legacy support for the outdated RC4 encryption algorithm in Microsoft Windows environments. Attackers leveraged the well-known 'Kerberoasting' attack technique, enabled by RC4’s weak cryptography, to compromise credentials and move laterally between systems. This breach led to significant operational disruption across 140 hospitals, putting 5.6 million patient records at risk and critically impacting healthcare delivery. The incident highlighted the dangers of legacy cryptography persisting in critical infrastructure. The breach has brought renewed urgency to deprecate outdated cryptographic standards and accelerate upgrades within regulated industries. Regulatory scrutiny and increased attacker focus on cryptographic weaknesses make retiring end-of-life encryption technologies a top priority for all enterprises.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Global Enterprises Breached: Ukrainian Nefilim Ransomware Affiliate Exposed in 2024
Impact· high

Global Enterprises Breached: Ukrainian Nefilim Ransomware Affiliate Exposed in 2024

In December 2025, Ukrainian national Artem Aleksandrovych Stryzhak pleaded guilty to participating as an affiliate of the Nefilim ransomware gang, responsible for attacks on large enterprises across the U.S., Europe, and Australia between 2021 and 2022. Stryzhak and his accomplices, using custom-tailored ransomware, infiltrated businesses with revenues exceeding $100 million by exploiting online data gathering and targeting internal systems, leading to significant disruptions and ransom demands. Sensitive company data was threatened with public leaks to pressure victims into paying, amplifying both operational and reputational damage. U.S. authorities arrested Stryzhak in Spain in 2024, with sentencing scheduled for 2026. This incident exemplifies the continued operational sophistication and profitability of affiliate-based ransomware models. It also highlights evolving attacker methods that combine technical exploits with business intelligence gathering, and the increasing coordination among international law enforcement to counter cybercrime.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports