✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Automated Credential Attacks Storm Cisco & Palo Alto Networks VPNs
In December 2025, automated credential attacks targeted enterprise VPN gateways from Cisco and Palo Alto Networks. Threat monitoring platforms such as GreyNoise observed a surge of password spraying attempts, with 1.7 million login probes against Palo Alto GlobalProtect portals within 16 hours, and coordinated activity later targeting Cisco SSL VPNs. The attacks originated from over 10,000 unique IPs, predominantly routed through the 3xK GmbH cloud provider in Germany. Attackers employed scripted credential stuffing—leveraging common username and password combinations—to probe for weak authentication endpoints, with no evidence of software vulnerabilities being exploited. This campaign highlights the ongoing evolution and scale of credential-based attacks targeting critical remote access infrastructure. As password spraying and automated reconnaissance increase, robust authentication and monitoring remain pivotal to defending against perimeter breaches, especially as threat actors exploit enterprise weaknesses during periods of heightened cyber activity.
6 months ago
Kill Chain
Clop Ransomware Hits Gladinet CentreStack: 2025 Data Theft Alert
In December 2025, the Clop ransomware gang initiated a widespread extortion campaign by exploiting internet-facing Gladinet CentreStack file servers. Gladinet CentreStack, used by thousands of businesses worldwide, enables remote file sharing without VPNs. The attackers scanned for accessible servers, exploited a yet-undetermined (potentially zero-day or unpatched) vulnerability, and exfiltrated sensitive business data, leaving ransom notes for victims. The breaches escalated concerns after Clop’s history with major file transfer solutions, such as MOVEit and Oracle EBS, resulting in significant data leaks and operational disruption for affected organizations. This attack underscores the persistent risk posed by sophisticated ransomware groups exploiting file transfer and sharing platforms. With attackers rapidly leveraging unknown or unpatched security flaws, enterprises must prioritize robust vulnerability management for all internet-exposed assets and monitor threat actor trends targeting remote-access file servers.
6 months ago
Kill Chain
HPE OneView 2025: CVE-2025-37164 Remote Code Execution Threat
In June 2025, Hewlett Packard Enterprise (HPE) patched a critical vulnerability (CVE-2025-37164) in its OneView infrastructure management software, allowing unauthenticated remote code execution via network exposure. Rated CVSS 10.0, the flaw enabled threat actors to gain full control over affected systems by exploiting improper input validation in OneView’s remote management interfaces. This vulnerability posed immediate risk to critical infrastructure across industries relying on OneView for centralized management, potentially resulting in disruption, unauthorized access, or lateral movement within enterprise environments. The discovery highlights ongoing concerns around enterprise software supply chain security and the elevated threats facing privileged IT management tools. Increasingly, sophisticated threat actors target such infrastructure software to bypass traditional security controls, emphasizing the urgency for timely patching and advanced east-west traffic controls.
6 months ago
Kill Chain
2025 Multi-Vector Breach: WhatsApp Hijacks, MCP Leaks & AI Threats Signal New Era of Cyber Attacks
In December 2025, adversaries leveraged multiple cyberattack vectors—including WhatsApp account hijacking, major control plane (MCP) data leaks, generative AI reconnaissance, and the React2Shell exploit—to target organizations worldwide. Attackers combined social engineering, exploitation of unpatched vulnerabilities, and east-west traffic movement for lateral compromise. The orchestration of these tactics led to large-scale credential theft, successful ransomware deployment, and significant data exfiltration across cloud and on-premise environments. Notably, sophisticated evasion and automation tools hindered early detection and response, increasing operational disruption and risk exposure for affected enterprises. This incident exemplifies how weaponized AI, hybrid cloud vulnerabilities, and multi-vector attacks are converging. Organizations face growing urgency for zero trust segmentation, improved encrypted traffic controls, and comprehensive threat detection as attackers exploit interconnected infrastructure weaknesses and automation gaps.
6 months ago
Kill Chain
University of Sydney 2024 Data Breach Exposes Student and Staff Details
In June 2024, the University of Sydney disclosed a data breach following unauthorized access to an online coding repository. Attackers exfiltrated files containing personal information of students and staff by exploiting weak access controls on the system. The breach was identified after suspicious activity was detected, prompting immediate investigation and containment steps by the university. Impacted data reportedly includes names, contact details, and university credentials, potentially exposing the affected individuals to heightened phishing and identity theft risks. This breach underscores increasing attacks on educational institutions using supply chain and cloud repository vectors. With universities under pressure to rapidly digitize, protecting developer and collaboration tools has become critical amid surging credential-based attacks and regulatory scrutiny of personally identifiable information (PII) handling.
6 months ago
Kill Chain
Sha1-Hulud 2025: The Multi-Vector Threat Campaign that Redefined Cloud Security
In December 2025, security researchers observed a sophisticated multi-vector attack campaign, dubbed 'Sha1-Hulud,' targeting organizations across North America, Europe, and Asia. The campaign leveraged vulnerabilities in remote management tools such as ScreenConnect and MacSync to gain initial access, then proceeded laterally using encrypted traffic, zero trust segmentation evasion, and cloud-native pivoting. Attackers deployed covert remote access tools and exploited gaps in cloud firewall and egress controls to move data out, leaving organizations grappling with data theft, systems downtime, and regulatory exposure. This incident is notable for its integration of advanced encryption bypass, multicloud movement, and the blending of traditional and cloud-native evasion tactics. The convergence of infrastructure and cloud threats highlights the need for ubiquitous visibility, modern segmentation, and coordinated policy enforcement in response to increasingly diverse and distributed attacks.
6 months ago
Kill Chain
Inductive Automation Ignition Vulnerability Exposes Critical Infrastructure to Privilege Escalation in 2025
In December 2025, Inductive Automation disclosed a privilege escalation vulnerability (CVE-2025-13911) in its Ignition SCADA platform widely used across critical manufacturing, energy, and IT sectors. The flaw arises from inadequate controls in the Python scripting environment, enabling authenticated administrators to execute arbitrary code with SYSTEM-level privileges on affected Windows hosts. Attackers can upload malicious project files to the Ignition Gateway, potentially leading to complete host compromise if exploited. Although there are currently no reports of public exploitation, this issue underscores growing risks associated with misconfigured automation platforms and the importance of adhering to least-privilege principles. Recent trends in supply chain and ICS-targeted attacks have increased regulatory pressure on critical infrastructure operators to address privilege escalation vectors.
6 months ago
Kill Chain
React2Shell 2025: When AI-Generated Exploits Complicate Supply Chain Defense
In December 2025, the cybersecurity community was rocked by mass exploitation efforts targeting "React2Shell," a critical vulnerability in the popular React UI framework. Threat actors, including China-linked groups, quickly launched attacks just hours after the initial public advisory. Amid the chaos, researchers and automated AI tools published over a hundred proof-of-concept (PoC) exploits—many of which were either nonfunctional or misrepresented the true risk, leading to widespread confusion. This "AI slop" polluted vulnerability feeds and caused defenders to waste valuable time, potentially resulting in underestimating the urgency to patch real flaws. The incident exposed significant weaknesses in open-source supply chain security, the peer-review process for public PoCs, and how security teams triage emerging threats. The React2Shell event is emblematic of the growing challenges defenders face as AI-generated code and public exploit sharing accelerate the pace and volume of security noise. With enterprises relying on automated detection and research, this incident highlights systemic risks posed by false negatives, delayed remediation, and rushed patch management in the face of incomplete or misleading information.
6 months ago
Kill Chain
Critical Fortinet Flaws: Active Attacks Compromise Admin Accounts & Configs
In May 2024, threat actors began actively exploiting multiple critical vulnerabilities in Fortinet network devices, specifically targeting admin accounts to gain unauthorized access. Once authenticated, attackers exported sensitive device configurations containing hashed credentials and other proprietary information. The exploit allows lateral movement and increases the risk of sensitive enterprise data exposure, with widespread impacts noted across sectors relying on network infrastructure security. Fortinet urged immediate mitigation after observing attacks in the wild, with rapid patch releases and threat intelligence sharing. This incident highlights a concerning trend of attackers leveraging zero-day or freshly-disclosed vulnerabilities in widely deployed network appliances. As targeting of privileged accounts and network infrastructure rises, organizations must enhance monitoring, patch management, and segmentation strategies to prevent systemic compromise.
6 months ago
Kill Chain
Microsoft 2025 MSMQ and IIS Outage: A Cautionary Tale of Security Permissions Gone Wrong
In December 2025, Microsoft enterprise customers experienced widespread outages in applications and IIS web services following the deployment of Patch Tuesday updates (KB5071546, KB5071544, KB5071543). These updates introduced changes to the Message Queuing (MSMQ) security model, restricting NTFS permissions on the C:\Windows\System32\MSMQ\storage folder. As a result, non-administrator MSMQ users lost write access, causing MSMQ to fail and IIS sites to return misleading 'insufficient resources' errors. This affected core business processes dependent on MSMQ, with no immediate fix available; Microsoft urged affected organizations to reach out for mitigation guidance. This incident highlights ongoing risks from software supply chain updates and privileged permission management changes at the operating system level. As cloud workloads and zero-trust architectures become more prevalent, enterprises must strengthen configuration management and anomaly response to avoid business disruption from untested or misconfigured OS-level security changes.
6 months ago
Kill Chain
Critical React2Shell Flaw Triggers Ultra-Fast Weaxor Ransomware Attack (2025)
In December 2025, cybercriminals exploited the critical React2Shell vulnerability (CVE-2025-55182), an unauthenticated remote code execution flaw in React Server Components' Flight protocol, to immediately deploy Weaxor ransomware in targeted organizations. The attackers gained access to public-facing servers running React/Next.js applications, rapidly executed an obfuscated PowerShell script to establish a Cobalt Strike beacon for C2, disabled Windows Defender, and launched the ransomware encryptor within a minute. The incident resulted in data encryption, file extensions changed to '.WEAX', ransom demands, shadow copy deletion, and event log wiping. Impact was limited to the initially compromised server due to the absence of lateral movement or data exfiltration. This incident highlights the increasing speed of cybercriminal exploitation of disclosed critical vulnerabilities, even before widespread patching can occur. The use of automated tooling and rapid weaponization of exploits are fueling a surge in opportunistic ransomware attacks on public-facing infrastructure.
6 months ago
Kill Chain
SonicWall SMA1000 Zero-Day Breach: 2025’s Wake-Up Call for Secure Network Access
In December 2025, SonicWall disclosed active exploitation of two chained zero-day vulnerabilities (CVE-2025-40602 and CVE-2025-23006) in its SMA1000 Appliance Management Console (AMC). Attackers combined a local privilege escalation flaw with a critical pre-authentication deserialization vulnerability to achieve unauthenticated remote code execution with root privileges on exposed appliances. These devices, used by large organizations for secure VPN access, became an attractive target, with at least 950 systems publicly accessible at the time of disclosure. The threats originated from advanced actors leveraging these weaknesses to bypass security controls and gain deep network access. This incident highlights the persistent risk to network infrastructure from zero-day chaining and the ongoing focus of sophisticated attackers on secure remote access gateways. Heightened regulatory focus, increasing state-sponsored attack campaigns, and renewed emphasis on timely patch management are making such incidents highly relevant for CISOs and infrastructure owners today.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports