✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Amazon AWS 2025: Credential-Based Cryptomining Breach Hits the Cloud
In late 2025, Amazon's AWS GuardDuty team uncovered a significant cryptomining campaign that exploited compromised IAM credentials to gain access to AWS Elastic Compute Cloud (EC2) and Elastic Container Service (ECS) environments. The attackers used valid credentials, rather than technical vulnerabilities, to deploy a malicious Docker Hub image carrying an SBRMiner-MULTI cryptominer. By rapidly launching large-scale EC2 and ECS tasks with high compute and memory allocations, the threat actor inflicted resource exhaustion and financial losses upon AWS customers. Attackers also enabled termination protection on compromised instances, effectively delaying incident response and extending mining profits. This incident is emblematic of the growing sophistication and automation in cloud resource abuse, highlighting an uptick in attacks leveraging stolen credentials rather than software flaws. As cloud adoption surges and cryptomining threats evolve, organizations face urgent pressure to enhance IAM hygiene, monitoring, and automated remediation to reduce risk.
6 months ago
Kill Chain
China-Linked Ink Dragon Breaches Governments With ShadowPad and FINALDRAFT Malware
Between July and October 2025, a sophisticated cyber-espionage campaign orchestrated by the China-linked group 'Ink Dragon' (a.k.a. Jewelbug, CL-STA-0049, Earth Alux, REF7707) targeted multiple European, Southeast Asian, and South American governments. The attackers leveraged advanced tools such as ShadowPad and FINALDRAFT malware to infiltrate official networks, move laterally through compromised systems, and exfiltrate sensitive government data via encrypted channels. Their operations exhibited a high degree of stealth, blending custom malware with legitimate administrative tools and exploiting trust in east-west network flows, putting confidential geopolitical and citizen information at direct risk. This incident underscores the increasing frequency and sophistication of state-sponsored espionage operations against government entities worldwide. It marks a significant trend where threat actors are adopting modular malware and advanced lateral movement techniques, emphasizing the urgent need for stronger east-west security controls and real-time anomaly detection in critical infrastructure.
6 months ago
Kill Chain
Zeroday Cloud 2025: $320,000 Awarded for Critical Cloud Platform Zero-Days
In December 2025, the inaugural Zeroday Cloud hacking competition in London highlighted severe risks facing cloud infrastructure by awarding $320,000 for the demonstration of 11 zero-day vulnerabilities across components like Redis, PostgreSQL, Grafana, and the Linux kernel. Notably, researchers exploited a container escape flaw in the Linux kernel, threatening tenant isolation—a cornerstone of cloud security. The impacted databases are integral to storing sensitive information, including credentials and user data. Although the event was hosted in a controlled environment, it provided a real-world showcase of how adversaries can achieve lateral movement and severe impact using previously unknown vulnerabilities. As critical cloud services grow more ubiquitous and attackers continue to innovate, this incident underscores the urgency for organizations to address emerging threats through proactive vulnerability management, layered defense, and rapid response capabilities.
6 months ago
Kill Chain
France's Ministry of the Interior Breached in Nation-State Attack: 2024 Suspect Arrested
In June 2024, French authorities arrested a 22-year-old suspect in connection with a cyberattack targeting the Ministry of the Interior. The attack took place earlier in the month and was orchestrated using sophisticated nation-state level tactics, resulting in unauthorized access to sensitive government infrastructure. Although the Ministry quickly identified the incursion and initiated prompt containment measures, the breach underscored significant vulnerabilities in the security perimeter of key government agencies. Investigators believe the attacker leveraged advanced persistence techniques and attempted to exfiltrate confidential information before being apprehended. This incident underscores the growing sophistication of cyber operations targeting European governmental institutions. As nation-state and advanced persistent threats (APTs) escalate in frequency and impact, public sector organizations must reinforce zero trust segmentation, threat detection, and traffic encryption controls to stay ahead of evolving risks.
6 months ago
Kill Chain
SonicWall SMA 100 Breach 2025: CVE-2025-40602 Actively Exploited
In December 2025, SonicWall disclosed a security breach affecting its Secure Mobile Access (SMA) 100 series appliances, driven by exploitation of CVE-2025-40602—a local privilege escalation vulnerability. The issue arose due to insufficient authorization in the Appliance Management Console (AMC), enabling threat actors to elevate local privileges and gain greater control within affected systems. SonicWall confirmed active exploitation in the wild, prompting an urgent release of security patches while urging all customers to apply updates immediately. The incident underscores the risks facing network appliances and the rapid speed with which attackers can leverage new vulnerabilities to compromise enterprise infrastructure. This event occurs amidst a wider uptick in attacks targeting edge appliances from network security vendors, as adversaries increasingly exploit publicly disclosed software flaws soon after their publication. Organizations are under intensified regulatory and operational pressure to patch critical vulnerabilities rapidly and reinforce privilege management strategies.
6 months ago
Kill Chain
CISA Flags 3 New Actively Exploited Vulnerabilities: Cisco, SonicWall, ASUS
In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added three newly discovered vulnerabilities (CVE-2025-20393, CVE-2025-40602, and CVE-2025-59374) to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence. These flaws impact multiple Cisco products, SonicWall SMA1000, and ASUS Live Update, allowing attackers to gain unauthorized access, insert malicious code, or bypass input validations. Such exposures provide fertile ground for cybercriminals to enter networks, move laterally, and compromise data, posing significant operational and business continuity risks to affected organizations across sectors. Their rapid inclusion into the KEV Catalog reflects a surge in the exploitation of software supply chains and critical infrastructure technologies. With attackers leveraging faster exploit-to-impact timelines, government agencies and enterprises face mounting pressure to patch immediately and update their vulnerability and segmentation strategies to prevent cascading breaches.
6 months ago
Kill Chain
A $0 Transaction Triggers a Nation-State Cyberattack on Anthropic’s AI Platform
In early 2024, Anthropic, a leading artificial intelligence company, was targeted in a sophisticated nation-state cyber espionage campaign. Adversaries utilized compromised payment cards—previously validated through Chinese-operated card-testing services—to attempt unauthorized access to Anthropic's AI platform. The attackers leveraged an established cybercriminal kill chain: stealing card data, validating credentials through tester merchants, and ultimately using the compromised accounts to escalate their intrusion attempts. While no sensitive customer data was confirmed to be compromised, the incident underscored the vulnerability of downstream cloud-based AI assets to upstream financial fraud and highlighted the intersection of cybercrime with state-sponsored intelligence objectives. This attack serves as a high-profile example of how advanced fraud intelligence can act as an early detection mechanism for state-sponsored cyber operations. The incident exemplifies rapid convergence between financial fraud and targeted espionage, emphasizing the need for cross-domain threat visibility and proactive controls.
6 months ago
Kill Chain
AI Deepfake Geospatial Maps Incident Exposes New Security Frontier (2025)
In December 2025, a high-profile security research initiative revealed significant risks in the unchecked proliferation of AI-generated deepfake satellite maps. Sparked by the personal experience of a deepfake attack, a 17-year-old cybersecurity researcher demonstrated how adversaries could blend or fabricate satellite imagery using advanced GANs and diffusion models. These manipulations, undetectable to the naked eye, could mislead governments and emergency responders, mask critical infrastructure weaknesses, or facilitate large-scale misinformation campaigns with potentially catastrophic consequences on national security and public trust. The incident highlights a rising threat: geospatial deepfakes are evolving rapidly, outpacing current detection solutions and exposing new vulnerabilities in organizations' data and decision pipelines. Growing reliance on AI-generated imagery and the lack of robust verification frameworks make this an urgent issue for security leaders and risk managers in both public and private sectors.
6 months ago
Kill Chain
AWS IAM Credential Theft Drives Massive Cloud Cryptomining in 2024
In early 2024, threat actors exploited stolen Amazon Web Services (AWS) Identity and Access Management (IAM) credentials to launch an extensive cryptomining campaign. Attackers gained unauthorized access to multiple customer environments, leveraging compromised IAM keys to provision and operate Amazon EC2 instances at scale. This unauthorized infrastructure was then used to mine cryptocurrency, resulting in significant financial losses, increased resource utilization, and additional operational overhead for affected organizations. The incident exposed critical gaps in cloud credential management and highlighted the attackers’ agility in abusing cloud-native services for illicit profit. This attack underscores a growing trend where cybercriminals are rapidly pivoting to cloud environments, exploiting mismanaged or stolen credentials. As more businesses migrate workloads to multi-cloud platforms, identity-driven threats and cryptojacking incidents are rising, urging organizations to reexamine their cloud security postures and access controls.
6 months ago
Kill Chain
ESET H2 2025 Report: Multi-Vector Cyberattacks Disrupt Enterprise Defenses
In the second half of 2025, ESET’s telemetry detected a significant uptick in multi-vector cyberattacks targeting enterprises across cloud, hybrid, and on-premises environments. Adversaries leveraged sophisticated tactics such as encrypted traffic evasion, lateral movement through east-west traffic, and exploitation of cloud misconfigurations to bypass traditional security controls and exfiltrate sensitive data. These campaigns combined advanced persistent threat (APT) techniques, ransomware deployment, and the abuse of shadow AI tools, often resulting in business disruption, regulatory exposure, and reputational harm for affected organizations. This incident reflects an intensifying trend: cyber actors are increasingly combining multiple techniques to evade detection, overwhelm defenses, and exploit both legacy and cloud-native infrastructure. With regulatory scrutiny mounting and a surge in identity-driven and AI-enabled threats, proactive segmentation and real-time threat detection are now vital for enterprise resilience.
6 months ago
Kill Chain
VirtualBox Slirp Flaw Enables 2025 Virtualization Escape — What Enterprises Must Know
In late 2025, a critical vulnerability was disclosed in Oracle VirtualBox related to its use of a modified Slirp networking stack for NAT mode. Security researchers demonstrated a reliable virtualization escape technique by exploiting unsafe memory handling in the packet heap allocator. By manipulating packet headers from within a VM, attackers could achieve arbitrary code execution on the host, effectively breaching isolation and enabling full control over the underlying system. No authentication was required; only network access from the guest to the host's NAT interface. The incident prompted urgent patching and highlighted the continued risk of legacy code in hypervisor environments. This incident remains highly relevant as virtualization escape attacks are escalating, with attackers targeting cloud and data center hypervisor layers. Trends in lateral movement, advanced VM attacks, and increasing regulatory focus on workload security are intensifying the urgency for robust virtual infrastructure defenses.
6 months ago
Kill Chain
Hypervisors Under Fire: 2024 Ransomware Blitz Hits Virtualization Core
In early 2024, organizations across multiple sectors faced a wave of targeted ransomware attacks exploiting vulnerabilities in virtualization platforms' hypervisors. Threat actors used stolen administrative credentials and leveraged known and zero-day flaws in hypervisor management interfaces to bypass segmentation controls, moving laterally from corporate networks onto host environments. Once inside, attackers deployed ransomware payloads at the hypervisor level, simultaneously encrypting dozens of virtual machines and crippling key business operations for days or weeks. The impact included downtime cascading across critical workloads, increased ransom demands due to concentrated disruption, and challenges in restoring services due to the interlocked nature of virtualized systems. This incident spotlights the growing trend of ransomware groups shifting attacks from endpoint devices to virtualization infrastructure, exploiting weak visibility and east-west segmentation at the hypervisor layer. As businesses accelerate cloud and virtual adoption, the threat landscape is rapidly evolving, making hypervisor security an urgent priority for IT and security leaders.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports