✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
CISA Orders Feds to Patch Active GeoServer XXE Vulnerability Exploitation
In June 2024, U.S. federal agencies were ordered by CISA to immediately patch a critical vulnerability in GeoServer, an open-source geospatial server widely deployed across government networks. Threat actors were observed actively exploiting an XML External Entity (XXE) injection flaw that allows attackers to access sensitive files, exfiltrate data, and potentially pivot within federal environments. The exploitation, which was discovered in the wild, underscores how quickly attackers can weaponize unpatched vulnerabilities to compromise mission-critical public sector infrastructure, putting sensitive government information at risk. This incident highlights a recent spike in the exploitation of internet-facing open-source software by both cybercriminal and nation-state groups. With regulatory pressure mounting around software supply chain risks and zero-day response times, such vulnerabilities remain a primary vehicle for initial access in sophisticated cyberattacks.
6 months ago
Kill Chain
Mesa County's 2021 Election System Data Breach: The Insider Threat Exposed
In 2021, Mesa County, Colorado experienced a significant breach of its election system data, orchestrated by then-county election clerk Tina Peters. Unauthorized copies of sensitive voting-system hard drives were made following the 2020 U.S. Presidential election and leaked to the public, purportedly to expose alleged voter fraud. The breach, which did not reveal any evidence of fraud, exposed highly confidential election infrastructure information, leading to criminal charges against Peters. The incident is widely recognized as one of the most impactful attacks on U.S. election security in recent years and undermined trust within the local community and beyond. This case highlights the ongoing risks to election system integrity posed by insider threats and emphasizes the importance of robust access controls, encryption, and segmentation. It is particularly relevant today as the U.S. prepares for upcoming elections amid heightened scrutiny of both technical and human vulnerabilities in election infrastructure.
6 months ago
Kill Chain
Fake Movie Torrent Delivers Agent Tesla Infostealer via Subtitles in 2024
In early June 2024, cybersecurity researchers discovered that a malicious torrent purporting to offer the Leonardo DiCaprio film 'One Battle After Another' was distributing infostealer malware through booby-trapped subtitle files. Unsuspecting users who downloaded the fake torrent were exposed to malicious PowerShell loaders, which delivered the Agent Tesla remote access trojan (RAT). This malware enabled attackers to steal sensitive credentials, exfiltrate data, and remotely monitor infected devices, highlighting how threat actors weaponize popular entertainment content to bypass user defenses and propagate infostealers. The incident underscores the evolving threat landscape in which cybercriminals exploit widely-used file formats and trusted brands to lure victims. Multimedia supply chains are increasingly being targeted through creative means—such as doctored subtitles—with infostealers and RATs surging in popularity. Organizations and individuals must heighten their vigilance, especially as compliance scrutiny and attack techniques grow more sophisticated.
6 months ago
Kill Chain
Critical Windows RasMan Zero-Day (2024) Disrupts Remote Access—What You Need To Know
In mid-2024, a new zero-day vulnerability was discovered in the Windows Remote Access Connection Manager (RasMan) service, allowing attackers to crash the service and potentially disrupt VPN and remote networking capabilities. Security researchers published unofficial patches after Microsoft had yet to release an official fix. The flaw enables a local attacker or malware to exploit the service, leading to denial-of-service (DoS) and potential impact on enterprise connectivity and productivity. Organizations relying on Windows-based remote access are particularly affected as attackers can target unpatched systems. This incident underscores the increasing trend of zero-day vulnerabilities targeting critical Windows services and highlights the need for rapid patch cycles and improved anomaly detection in IT environments. With unofficial fixes circulating before vendor patches, organizations face new risks in securing remote workforce infrastructure.
6 months ago
Kill Chain
CISA Flags Critical GeoServer XXE Vulnerability Exploited in the Wild
In December 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical XML External Entity (XXE) vulnerability, CVE-2025-58360, affecting OSGeo GeoServer to its Known Exploited Vulnerabilities catalog. This flaw impacts versions up to 2.25.5 and select subsequent releases, enabling unauthenticated attackers to exploit the /geoserver/wms GetMap endpoint. Successful exploitation may lead to unauthorized file access, Server-Side Request Forgery (SSRF), or denial-of-service attacks. The discovery, reported by vulnerability platform XBOW, has prompted warnings from both CISA and the Canadian Centre for Cyber Security, emphasizing risks to organizations using GeoServer in production environments. This incident underscores the persistent targeting of widely-used open-source tools by threat actors, particularly through unauthenticated exploit paths. Amid increased regulatory focus and real-world exploitation evidence, organizations face mounting pressure to patch vulnerable infrastructure and strengthen detective controls to mitigate post-exploitation impacts.
6 months ago
Kill Chain
React2Shell Exploitation: Global RCE Wave Sparks Emergency Security Response
In December 2025, the React2Shell vulnerability (CVE-2025-55182) emerged as a critical remote code execution flaw impacting React Server Components and several key frameworks such as Next.js, Vite, and RedwoodSDK. Threat actors rapidly exploited the unauthenticated deserialization bug, enabling arbitrary privileged JavaScript execution with a single HTTP request. Within days of public disclosure, multiple malicious campaigns leveraged the flaw to deploy malware, compromise sensitive systems—including government, critical infrastructure and technology entities—and conduct mass internet-wide scans. Over 137,200 exposed endpoints were tracked globally, prompting CISA to issue an accelerated mitigation deadline and security vendors to warn of global supply chain risks. React2Shell’s exploitation highlights the growing trend of mass-scale, opportunistic attacks leveraging zero-day vulnerabilities in widely-used cloud-native frameworks. With parallels drawn to systemic exploits like Log4Shell, organizations face rising regulatory and supply chain scrutiny to strengthen cloud security and incident response practices.
6 months ago
Kill Chain
Phishing in 2025: How Stolen Data Hits Telegram and the Dark Web Faster Than Ever
In early-to-mid 2025, a broad wave of phishing campaigns leveraged sophisticated data harvesting tools—including Telegram bots and automated admin panels—to exfiltrate user credentials and personal data from victims worldwide. Attackers collected credentials through fraudulent pages, relayed them instantly over secure messaging apps or specialized dashboards, and then swiftly funneled the stolen information into darknet marketplaces. Stolen data ranged from email logins and banking details to scans of personal documents, which were sorted, validated, and commoditized for direct fraud, resale, or subsequent targeted attacks on individuals and organizations. This incident highlights the acceleration of phishing-as-a-service ecosystems driven by real-time, evasive data exfiltration via commodity tools. The commodification of personal and corporate credentials intensifies regulatory and reputational risks, as stolen data is increasingly recycled for follow-on attacks—including identity theft and business email compromise—months or years after the initial breach.
6 months ago
Kill Chain
Critical React Server Components Flaws in 2025 Enable DoS and Code Leaks
In December 2025, several critical vulnerabilities were discovered in React Server Components (RSC), affecting core packages such as react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. Identified as CVE-2025-55184, CVE-2025-67779, and CVE-2025-55183, these flaws were exploited by attackers to perform pre-authentication denial-of-service (DoS) attacks and, in some cases, access sensitive server-side source code. Exploitation was enabled through unsafe deserialization of HTTP payloads, leading to server hangs, or via crafted requests that exposed function source code. The vulnerabilities impacted RSC versions 19.0.0 through 19.2.2 and were identified following active investigation by security researchers in the wake of CVE-2025-55182 exploitation in the wild. This incident underscores the growing trend of adversaries targeting server-side JavaScript frameworks through exploitation chains and rapid patch circumvention. Organizations relying on React for server-side rendering must remain vigilant, as repeated disclosures highlight both the software supply chain's fragility and the need for rigorous update cycles to fend off evolving threats.
6 months ago
Kill Chain
2025 Advanced Phishing Kits Exploit AI and MFA Bypass to Steal Credentials at Scale
In August 2025, cybersecurity firms identified four sophisticated phishing kits—BlackForce, GhostFrame, InboxPrime AI, and Spiderman—leveraging advanced AI and multi-factor authentication (MFA) bypass tactics to automate credential theft at massive scale. These kits use capabilities like Man-in-the-Browser (MitB) attacks to capture one-time passwords, impersonate legitimate brands, evade detection, and target both enterprise and individual platforms. Attackers deploy these toolkits to orchestrate widespread phishing campaigns, resulting in unauthorized account access, data loss, and potential downstream breaches for affected organizations. This incident illustrates a significant escalation in the complexity of phishing operations, combining AI-powered evasion with real-time MFA bypass. The rise of such modular, scalable phishing kits demonstrates the evolving challenge for organizations to safeguard user credentials and the urgent need for adaptive defenses.
6 months ago
Kill Chain
Fake OSINT and GPT GitHub Repos Used to Spread PyStoreRAT in Supply Chain Attack
In late 2025, cybersecurity researchers uncovered a supply chain attack involving malicious repositories on GitHub impersonating open-source Python utilities themed around OSINT and GPT automation. These repos covertly delivered a previously unseen JavaScript-based Remote Access Trojan dubbed PyStoreRAT, using minimal code to retrieve and execute a remote HTA file. Unsuspecting developers and security professionals, lured by the project's legitimate appearance, risked compromise when cloning or running the code, resulting in unauthorized remote access and potential data exfiltration. The campaign highlights the growing sophistication of attacks abusing trusted developer platforms and open-source supply chains. This incident underscores the urgent need for organizations to audit third-party code sources, bolster code supply chain security, and monitor for emerging malware targeting developer ecosystems. The tactic reflects broader trends in social engineering, weaponized open-source projects, and the exploitation of generative AI themes by threat actors.
6 months ago
Kill Chain
FBI Delivers 630 Million Compromised Passwords to HIBP: 2024 Credential Exposure
In June 2024, the FBI provided Have I Been Pwned (HIBP) with approximately 630 million compromised passwords uncovered during multiple cybercrime investigations. The credentials were amassed from seized devices linked to a criminal suspect and sourced from the open web, Tor-based marketplaces, Telegram channels, and infostealer malware logs. Notably, about 46 million of these passwords were new to HIBP's repository, enabling organizations and individuals to proactively block use of these widely circulated credentials and bolster account security. The addition further expands the scale and utility of accessible credential hygiene tools worldwide. This incident underscores the ongoing and massive prevalence of credential compromise in the cybercrime landscape, as password data continually proliferates across threat actors and dark markets. It highlights the urgent need for organizations to adopt robust password exposure monitoring and zero trust authentication policies.
6 months ago
Kill Chain
Critical Gogs Zero-Day Exploited in Ongoing Supply-Chain Attacks
In early 2024, security researchers revealed that attackers had actively exploited a zero-day vulnerability in Gogs, a popular self-hosted Git service, for several months. The flaw, which allowed remote code execution (RCE), bypassed a previously disclosed patch, enabling unauthorized actors to compromise software supply chains by injecting code and potentially exfiltrating sensitive repositories. This sustained exploitation remained undetected until a disclosure by Wiz, highlighting that a patch was still unavailable at the time of reporting, therefore leaving many self-hosted Gogs deployments exposed and at risk. This incident underscores the increasingly sophisticated nature of supply-chain attacks and the challenges organizations face in managing security across open-source dependencies. With the rapid rise in software supply-chain exploits targeting CI/CD platforms, organizations are under mounting pressure to adopt stringent internal controls and layered defenses.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports