✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Fortinet 2024 Auth Bypass Exploited: Urgent Actions for Network Security
In early June 2024, threat actors actively exploited newly disclosed authentication bypass vulnerabilities in multiple Fortinet products, including FortiOS and FortiProxy. Attackers leveraged these flaws (notably CVE-2024-21762 and CVE-2024-23113) shortly after Fortinet's patch release, gaining unauthorized admin-level access to vulnerable devices. The intruders then extracted system configuration files, risking exposure of sensitive network data and credentials. Several organizations reported compromises and system disruptions, prompting urgent advisories from Fortinet and government agencies to patch immediately and review system integrity. This incident underscores a dangerous trend: rapid mass exploitation of zero-day vulnerabilities in network security devices. The high-profile breach highlights mounting risks to organizations that delay critical patching and demonstrates the persistent targeting of edge appliances by sophisticated attackers.
6 months ago
Kill Chain
Amazon Stops Russian GRU Hackers Targeting Cloud Edge Devices in 2025
In December 2025, Amazon's Threat Intelligence team thwarted a sophisticated cyber-espionage campaign attributed to the Russian GRU, which actively targeted Western critical infrastructure via AWS cloud environments. Beginning in 2021 and intensifying through 2025, the threat actors transitioned from exploiting known and zero-day vulnerabilities to targeting misconfigured customer-managed edge devices such as VPN gateways and network appliances hosted on EC2. This allowed them to gain persistent access, harvest credentials, and move laterally within networks, yet there was no compromise of AWS's own infrastructure. Amazon responded rapidly by securing affected instances, notifying customers, and sharing threat intelligence with partners. This incident highlights the growing trend of state-sponsored groups shifting from vulnerability exploitation to leveraging customer misconfigurations. The persistent focus on edge devices underscores the importance of robust configuration and monitoring practices, especially as critical infrastructure organizations move sensitive operations into the cloud.
6 months ago
Kill Chain
GhostPoster: Malicious Firefox Addon Logos Expose Supply Chain Security Risks
In early 2024, a supply chain attack campaign known as 'GhostPoster' was uncovered targeting users of malicious Firefox browser extensions. Threat actors embedded obfuscated JavaScript payloads within the image logos of these add-ons, leveraging steganography to evade detection and distribute malware. Once installed, the trojanized extensions—with more than 50,000 downloads—granted actors persistent access to victims' browsers, allowing for activity monitoring and enabling backdoor capabilities. The campaign exploited the trust in official browser markets while circumventing traditional security measures. This breach illustrates the rising sophistication of supply chain attacks, particularly those leveraging legitimate software distribution channels. It highlights the necessity for stronger internal and external vetting of browser add-ons, as the technique is being replicated across other software ecosystems.
6 months ago
Kill Chain
APT Groups Leverage React2Shell to Plant Linux Backdoors in 2025
In December 2025, security researchers from Palo Alto Networks Unit 42 and NTT Security discovered active exploitation of the React2Shell vulnerability targeting Linux environments worldwide. The attackers leveraged this flaw in unpatched systems to deploy advanced remote access tools such as KSwapDoor and ZnDoor. These malware families provided persistent backdoor access, enabling lateral movement and data exfiltration. The campaign was characterized by sophisticated evasion techniques, stealthy command-and-control channels, and targeted critical infrastructure, raising the risk of operational disruption and regulatory exposure for affected organizations. The exploitation of React2Shell reflects a broader surge in advanced persistent threat (APT) activity focused on Linux workloads, with threat actors increasingly targeting vulnerabilities in remote access and open-source software. This trend underscores the urgent need for enhanced east-west traffic security, rapid patching, and anomaly detection to prevent organizational compromise.
6 months ago
Kill Chain
Active Attack: Fortinet FortiGate SAML SSO Authentication Bypass Exposes Networks
In December 2025, threat actors began exploiting two critical authentication bypass vulnerabilities (CVE-2025-59718 and CVE-2025-59719, both CVSS 9.8) in Fortinet FortiGate appliances. By targeting the FortiCloud SSO feature—enabled during FortiCare registration—they leveraged crafted SAML messages to gain unauthorized access to admin accounts. Once inside, attackers exported device configuration files, risking credential compromise and broader network infiltration. The U.S. CISA quickly classified the flaws as Known Exploited Vulnerabilities, urging immediate patching. This incident demonstrates the evolving risk of identity-driven network attacks and rapid exploitation following vulnerability disclosure. With opportunistic threat actors targeting edge infrastructure, similar authentication-based attacks are likely to increase, further incentivized by regulatory and industry pressure for swift vulnerability management.
6 months ago
Kill Chain
Cellik Android Malware: The New Frontier for Trojanized Google Play Apps
In December 2025, cybersecurity researchers identified a new Android malware-as-a-service (MaaS) dubbed Cellik that enables cybercriminals to create malicious variants of popular Google Play Store apps. Distributed via underground forums, Cellik’s service allows threat actors to select legitimate apps, inject sophisticated malware, and maintain original app functionality, thereby bypassing typical user suspicion and potentially evading Google Play Protect. Cellik's features include real-time screen streaming, notification interception, filesystem browsing, data exfiltration, device wiping, and encrypted command-and-control communications. Attackers can also overlay fake login screens, inject malicious payloads into trusted apps, and exploit a hidden browser to steal credentials using stored cookies from infected devices. The emergence of Cellik signals an evolution in Android threat tooling, where MaaS kits empower less skilled actors to launch advanced attacks. This development heightens risks for organizations subject to mobile threats as attackers embrace more modular and evasive tactics, underlining the urgent need for advanced mobile security controls and proactive user education.
6 months ago
Kill Chain
Amazon Reveals Years-Long GRU Cyber Espionage on Critical Cloud & Energy Infrastructure
Between 2021 and 2025, Amazon's threat intelligence team uncovered a multi-year cyber campaign attributed to Russia's Main Intelligence Directorate (GRU), specifically associated with APT44/Sandworm. The attackers targeted Western energy sector organizations, critical infrastructure providers, and cloud-hosted network environments by exploiting vulnerabilities and, increasingly, leveraging misconfigured network edge devices. This facilitated credential interception and lateral movement through persistent network access, with efforts focused on credential harvesting and replay against victim organizations. Amazon responded by notifying affected customers and disrupting active operations, limiting further impact. This incident underscores the sophistication and persistence of nation-state actors in targeting vital infrastructure by adapting TTPs to minimize exposure. The campaign signals an urgent shift towards exploiting cloud and network misconfigurations rather than relying solely on zero-day vulnerabilities—a trend that broadens risk for organizations across sectors.
6 months ago
Kill Chain
Inside the 2025 KPop Malware Hunter Takedowns: Exposing Cloud Attack Trends
In 2025, a coordinated intelligence operation led by an international alliance of cybersecurity researchers, dubbed the KPop Malware Hunters, dismantled several prolific malware campaigns targeting global cloud and data center environments. Threat actors, including the group Salt Typhoon, exploited east-west traffic routes and unencrypted data in transit to achieve lateral movement post-compromise. Using advanced encrypted traffic analytics and inline IPS, defenders identified high-volume command-and-control exchanges masked within routine inter-region traffic. The operation led to significant disruption of adversary infrastructure, restoration of business operations, and improved threat visibility for impacted organizations worldwide. This takedown is highly relevant amid heightened attacks on hybrid and multicloud architectures, where sophisticated adversaries increasingly exploit internal cloud pathways and vulnerable segmentation. 2025’s events spotlight the urgent need for zero trust, inline threat detection, and rigorous compliance alignment as attackers leverage AI-driven evasion and cloud-native persistence.
6 months ago
Kill Chain
Compromised IAM Credentials Fuel AWS Cryptomining Attack in 2025
In November 2025, Amazon Web Services (AWS) became the target of a widespread cryptomining campaign exploiting compromised Identity and Access Management (IAM) credentials. The attackers used stolen keys to access AWS accounts, deploy cryptomining operations, and leverage persistence mechanisms to avoid detection and maintain access. Amazon’s GuardDuty threat detection tools were instrumental in uncovering the activity, which leveraged novel Tactics, Techniques, and Procedures (TTPs) including lateral movement and privilege escalation, putting customer cloud resources and budgets at risk through accelerated resource consumption and possible data exposure. This incident is emblematic of an escalating trend where threat actors exploit cloud identity weaknesses for financial gain. It underscores the urgent necessity for robust multi-factor authentication, real-time anomaly detection, and comprehensive cloud security strategies as identity-driven attacks proliferate in the cloud era.
6 months ago
Kill Chain
Rogue NuGet Impersonates Tracer.Fody, Orchestrates Multi-Year Crypto Wallet Theft
Between February 2020 and December 2025, a malicious NuGet package named "Tracer.Fody.NLog" posed as the legitimate .NET tracing library, Tracer.Fody, and was covertly distributed via typosquatting and mimicking developer identities. The package, uploaded by a threat actor under the handle "csnemess," evaded detection for almost six years, collecting over 2,000 downloads. Instead of offering legitimate functionality, this package deployed a wallet stealer: scanning the default Stratis wallet directory on Windows systems, exfiltrating wallet data and passwords to threat actor infrastructure hosted in Russia, with attackers leveraging crafted code and hidden routines to bypass superficial code reviews. The prolonged success of this attack underscores the persistent risk supply chain threats pose to open-source ecosystems, especially for developer tools and libraries. It highlights attackers’ sophistication in mimicking trusted maintainers, the difficulty of detecting such manipulation, and ongoing regulatory and security pressures to improve package repository hygiene and detection.
6 months ago
Kill Chain
Opexus 2024 Insider Breach: Lax Vetting Enables Sensitive Federal Data Theft
In February 2024, Opexus, a federal IT services provider, suffered a significant internal data breach at the hands of recently terminated employees, Muneeb and Sohaib Akhter. Despite passing standard background checks, the Akhter twins—who had prior convictions for cybercrimes—were able to exploit their insider access minutes after being fired, deleting and exfiltrating sensitive data from U.S. government agencies, including DHS, IRS, and EEOC. Key company missteps included inadequate offboarding controls, missed red flags in hiring, and delayed user account revocation, compounding the impact on critical federal data and operations. This breach underscores rising risks linked to insider threats, especially among trusted staff with privileged access. Failures in vetting, change management, and technical safeguards contributed to the severity and highlight the urgent need for robust zero trust, continuous monitoring, and improved personnel screening, particularly for organizations entrusted with sensitive public sector data.
6 months ago
Kill Chain
Apple Patches 2025 WebKit Zero-Day Exploits Used in Sophisticated Spyware Attacks
In December 2025, Apple urgently released patches for two zero-day vulnerabilities in its WebKit browser engine—CVE-2025-43529 and CVE-2025-14174—after reports of their exploitation in highly sophisticated attacks targeting specific individuals. Discovered in collaboration with Google's Threat Analysis Group, these vulnerabilities enabled potential arbitrary code execution via malicious web content due to use-after-free and memory corruption flaws. The vulnerabilities overlapped with a mysterious zero-day Google patched in Chrome, underlining the risk of cross-platform exposure via shared components. Affected devices included iOS, iPadOS, and macOS, with rapid patch distribution through emergency security advisories. This incident spotlights a growing trend of highly targeted, advanced exploitation chains, frequently leveraging zero-day flaws used in commercial spyware and state-level operations. It underscores the increasing urgency for organizations and individuals to maintain aggressive patch hygiene and layered endpoint defenses as anonymous, sophisticated exploitations proliferate.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports