Validated Containment Architectures are here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2676 threat reports
Page 156 of 223

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 18611872 / 2676 reports
Fortinet 2024 Auth Bypass Exploited: Urgent Actions for Network Security
Impact· low

Fortinet 2024 Auth Bypass Exploited: Urgent Actions for Network Security

In early June 2024, threat actors actively exploited newly disclosed authentication bypass vulnerabilities in multiple Fortinet products, including FortiOS and FortiProxy. Attackers leveraged these flaws (notably CVE-2024-21762 and CVE-2024-23113) shortly after Fortinet's patch release, gaining unauthorized admin-level access to vulnerable devices. The intruders then extracted system configuration files, risking exposure of sensitive network data and credentials. Several organizations reported compromises and system disruptions, prompting urgent advisories from Fortinet and government agencies to patch immediately and review system integrity. This incident underscores a dangerous trend: rapid mass exploitation of zero-day vulnerabilities in network security devices. The high-profile breach highlights mounting risks to organizations that delay critical patching and demonstrates the persistent targeting of edge appliances by sophisticated attackers.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Amazon Stops Russian GRU Hackers Targeting Cloud Edge Devices in 2025
Impact· medium

Amazon Stops Russian GRU Hackers Targeting Cloud Edge Devices in 2025

In December 2025, Amazon's Threat Intelligence team thwarted a sophisticated cyber-espionage campaign attributed to the Russian GRU, which actively targeted Western critical infrastructure via AWS cloud environments. Beginning in 2021 and intensifying through 2025, the threat actors transitioned from exploiting known and zero-day vulnerabilities to targeting misconfigured customer-managed edge devices such as VPN gateways and network appliances hosted on EC2. This allowed them to gain persistent access, harvest credentials, and move laterally within networks, yet there was no compromise of AWS's own infrastructure. Amazon responded rapidly by securing affected instances, notifying customers, and sharing threat intelligence with partners. This incident highlights the growing trend of state-sponsored groups shifting from vulnerability exploitation to leveraging customer misconfigurations. The persistent focus on edge devices underscores the importance of robust configuration and monitoring practices, especially as critical infrastructure organizations move sensitive operations into the cloud.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
GhostPoster: Malicious Firefox Addon Logos Expose Supply Chain Security Risks
Impact· medium

GhostPoster: Malicious Firefox Addon Logos Expose Supply Chain Security Risks

In early 2024, a supply chain attack campaign known as 'GhostPoster' was uncovered targeting users of malicious Firefox browser extensions. Threat actors embedded obfuscated JavaScript payloads within the image logos of these add-ons, leveraging steganography to evade detection and distribute malware. Once installed, the trojanized extensions—with more than 50,000 downloads—granted actors persistent access to victims' browsers, allowing for activity monitoring and enabling backdoor capabilities. The campaign exploited the trust in official browser markets while circumventing traditional security measures. This breach illustrates the rising sophistication of supply chain attacks, particularly those leveraging legitimate software distribution channels. It highlights the necessity for stronger internal and external vetting of browser add-ons, as the technique is being replicated across other software ecosystems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
APT Groups Leverage React2Shell to Plant Linux Backdoors in 2025
Impact· medium

APT Groups Leverage React2Shell to Plant Linux Backdoors in 2025

In December 2025, security researchers from Palo Alto Networks Unit 42 and NTT Security discovered active exploitation of the React2Shell vulnerability targeting Linux environments worldwide. The attackers leveraged this flaw in unpatched systems to deploy advanced remote access tools such as KSwapDoor and ZnDoor. These malware families provided persistent backdoor access, enabling lateral movement and data exfiltration. The campaign was characterized by sophisticated evasion techniques, stealthy command-and-control channels, and targeted critical infrastructure, raising the risk of operational disruption and regulatory exposure for affected organizations. The exploitation of React2Shell reflects a broader surge in advanced persistent threat (APT) activity focused on Linux workloads, with threat actors increasingly targeting vulnerabilities in remote access and open-source software. This trend underscores the urgent need for enhanced east-west traffic security, rapid patching, and anomaly detection to prevent organizational compromise.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Active Attack: Fortinet FortiGate SAML SSO Authentication Bypass Exposes Networks
Impact· medium

Active Attack: Fortinet FortiGate SAML SSO Authentication Bypass Exposes Networks

In December 2025, threat actors began exploiting two critical authentication bypass vulnerabilities (CVE-2025-59718 and CVE-2025-59719, both CVSS 9.8) in Fortinet FortiGate appliances. By targeting the FortiCloud SSO feature—enabled during FortiCare registration—they leveraged crafted SAML messages to gain unauthorized access to admin accounts. Once inside, attackers exported device configuration files, risking credential compromise and broader network infiltration. The U.S. CISA quickly classified the flaws as Known Exploited Vulnerabilities, urging immediate patching. This incident demonstrates the evolving risk of identity-driven network attacks and rapid exploitation following vulnerability disclosure. With opportunistic threat actors targeting edge infrastructure, similar authentication-based attacks are likely to increase, further incentivized by regulatory and industry pressure for swift vulnerability management.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Cellik Android Malware: The New Frontier for Trojanized Google Play Apps
Impact· medium

Cellik Android Malware: The New Frontier for Trojanized Google Play Apps

In December 2025, cybersecurity researchers identified a new Android malware-as-a-service (MaaS) dubbed Cellik that enables cybercriminals to create malicious variants of popular Google Play Store apps. Distributed via underground forums, Cellik’s service allows threat actors to select legitimate apps, inject sophisticated malware, and maintain original app functionality, thereby bypassing typical user suspicion and potentially evading Google Play Protect. Cellik's features include real-time screen streaming, notification interception, filesystem browsing, data exfiltration, device wiping, and encrypted command-and-control communications. Attackers can also overlay fake login screens, inject malicious payloads into trusted apps, and exploit a hidden browser to steal credentials using stored cookies from infected devices. The emergence of Cellik signals an evolution in Android threat tooling, where MaaS kits empower less skilled actors to launch advanced attacks. This development heightens risks for organizations subject to mobile threats as attackers embrace more modular and evasive tactics, underlining the urgent need for advanced mobile security controls and proactive user education.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Amazon Reveals Years-Long GRU Cyber Espionage on Critical Cloud & Energy Infrastructure
Impact· low

Amazon Reveals Years-Long GRU Cyber Espionage on Critical Cloud & Energy Infrastructure

Between 2021 and 2025, Amazon's threat intelligence team uncovered a multi-year cyber campaign attributed to Russia's Main Intelligence Directorate (GRU), specifically associated with APT44/Sandworm. The attackers targeted Western energy sector organizations, critical infrastructure providers, and cloud-hosted network environments by exploiting vulnerabilities and, increasingly, leveraging misconfigured network edge devices. This facilitated credential interception and lateral movement through persistent network access, with efforts focused on credential harvesting and replay against victim organizations. Amazon responded by notifying affected customers and disrupting active operations, limiting further impact. This incident underscores the sophistication and persistence of nation-state actors in targeting vital infrastructure by adapting TTPs to minimize exposure. The campaign signals an urgent shift towards exploiting cloud and network misconfigurations rather than relying solely on zero-day vulnerabilities—a trend that broadens risk for organizations across sectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Inside the 2025 KPop Malware Hunter Takedowns: Exposing Cloud Attack Trends
Impact· medium

Inside the 2025 KPop Malware Hunter Takedowns: Exposing Cloud Attack Trends

In 2025, a coordinated intelligence operation led by an international alliance of cybersecurity researchers, dubbed the KPop Malware Hunters, dismantled several prolific malware campaigns targeting global cloud and data center environments. Threat actors, including the group Salt Typhoon, exploited east-west traffic routes and unencrypted data in transit to achieve lateral movement post-compromise. Using advanced encrypted traffic analytics and inline IPS, defenders identified high-volume command-and-control exchanges masked within routine inter-region traffic. The operation led to significant disruption of adversary infrastructure, restoration of business operations, and improved threat visibility for impacted organizations worldwide. This takedown is highly relevant amid heightened attacks on hybrid and multicloud architectures, where sophisticated adversaries increasingly exploit internal cloud pathways and vulnerable segmentation. 2025’s events spotlight the urgent need for zero trust, inline threat detection, and rigorous compliance alignment as attackers leverage AI-driven evasion and cloud-native persistence.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Compromised IAM Credentials Fuel AWS Cryptomining Attack in 2025
Impact· high

Compromised IAM Credentials Fuel AWS Cryptomining Attack in 2025

In November 2025, Amazon Web Services (AWS) became the target of a widespread cryptomining campaign exploiting compromised Identity and Access Management (IAM) credentials. The attackers used stolen keys to access AWS accounts, deploy cryptomining operations, and leverage persistence mechanisms to avoid detection and maintain access. Amazon’s GuardDuty threat detection tools were instrumental in uncovering the activity, which leveraged novel Tactics, Techniques, and Procedures (TTPs) including lateral movement and privilege escalation, putting customer cloud resources and budgets at risk through accelerated resource consumption and possible data exposure. This incident is emblematic of an escalating trend where threat actors exploit cloud identity weaknesses for financial gain. It underscores the urgent necessity for robust multi-factor authentication, real-time anomaly detection, and comprehensive cloud security strategies as identity-driven attacks proliferate in the cloud era.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Rogue NuGet Impersonates Tracer.Fody, Orchestrates Multi-Year Crypto Wallet Theft
Impact· medium

Rogue NuGet Impersonates Tracer.Fody, Orchestrates Multi-Year Crypto Wallet Theft

Between February 2020 and December 2025, a malicious NuGet package named "Tracer.Fody.NLog" posed as the legitimate .NET tracing library, Tracer.Fody, and was covertly distributed via typosquatting and mimicking developer identities. The package, uploaded by a threat actor under the handle "csnemess," evaded detection for almost six years, collecting over 2,000 downloads. Instead of offering legitimate functionality, this package deployed a wallet stealer: scanning the default Stratis wallet directory on Windows systems, exfiltrating wallet data and passwords to threat actor infrastructure hosted in Russia, with attackers leveraging crafted code and hidden routines to bypass superficial code reviews. The prolonged success of this attack underscores the persistent risk supply chain threats pose to open-source ecosystems, especially for developer tools and libraries. It highlights attackers’ sophistication in mimicking trusted maintainers, the difficulty of detecting such manipulation, and ongoing regulatory and security pressures to improve package repository hygiene and detection.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Opexus 2024 Insider Breach: Lax Vetting Enables Sensitive Federal Data Theft
Impact· high

Opexus 2024 Insider Breach: Lax Vetting Enables Sensitive Federal Data Theft

In February 2024, Opexus, a federal IT services provider, suffered a significant internal data breach at the hands of recently terminated employees, Muneeb and Sohaib Akhter. Despite passing standard background checks, the Akhter twins—who had prior convictions for cybercrimes—were able to exploit their insider access minutes after being fired, deleting and exfiltrating sensitive data from U.S. government agencies, including DHS, IRS, and EEOC. Key company missteps included inadequate offboarding controls, missed red flags in hiring, and delayed user account revocation, compounding the impact on critical federal data and operations. This breach underscores rising risks linked to insider threats, especially among trusted staff with privileged access. Failures in vetting, change management, and technical safeguards contributed to the severity and highlight the urgent need for robust zero trust, continuous monitoring, and improved personnel screening, particularly for organizations entrusted with sensitive public sector data.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Apple Patches 2025 WebKit Zero-Day Exploits Used in Sophisticated Spyware Attacks
Impact· low

Apple Patches 2025 WebKit Zero-Day Exploits Used in Sophisticated Spyware Attacks

In December 2025, Apple urgently released patches for two zero-day vulnerabilities in its WebKit browser engine—CVE-2025-43529 and CVE-2025-14174—after reports of their exploitation in highly sophisticated attacks targeting specific individuals. Discovered in collaboration with Google's Threat Analysis Group, these vulnerabilities enabled potential arbitrary code execution via malicious web content due to use-after-free and memory corruption flaws. The vulnerabilities overlapped with a mysterious zero-day Google patched in Chrome, underlining the risk of cross-platform exposure via shared components. Affected devices included iOS, iPadOS, and macOS, with rapid patch distribution through emergency security advisories. This incident spotlights a growing trend of highly targeted, advanced exploitation chains, frequently leveraging zero-day flaws used in commercial spyware and state-level operations. It underscores the increasing urgency for organizations and individuals to maintain aggressive patch hygiene and layered endpoint defenses as anonymous, sophisticated exploitations proliferate.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports