✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
React2Shell (CVE-2025-55182): New React Server Components Flaw Under Active Attack
In December 2025, attackers rapidly weaponized a critical deserialization vulnerability (CVE-2025-55182, "React2Shell") in React Server Components (RSC), enabling remote code execution on web servers running unpatched React libraries. Threat actors exploited the flaw—scoring a CVSS 10.0—by sending serialized payloads in POST requests, executing arbitrary commands, deploying malware, and exfiltrating credentials. Infections observed include crypto-miners, Mirai/Gafgyt bots, and the advanced RondoDox botnet targeting both Linux servers and IoT devices. Exploit activity began within hours of disclosure, with a sharp increase in attempts against internet-facing systems. This incident highlights the increasing speed at which proof-of-concept exploits are operationalized in the wild, emphasizing risks of deserialization vulnerabilities and dependency hygiene in modern web application stacks. Supply chain and cloud-centric attacks leveraging similar TTPs are expected to become more common, placing organizations with weak patch cycles at heightened risk.
6 months ago
Kill Chain
Spyware, Mirai, Docker Leaks & ValleyRAT: Anatomy of a 2025 Multi-Vector Breach
In December 2025, a sophisticated multivector cyberattack campaign exploited vulnerabilities across popular software, container platforms, and download channels. Hackers leveraged malicious browser extensions, tainted movie torrents, and compromised Docker images to disseminate a blend of Mirai botnet variants, ValleyRAT rootkits, and advanced spyware, evading traditional perimeter defenses. The attackers utilized encrypted communications and east-west movement to escalate privileges and exfiltrate sensitive organizational data. Impacts included operational outages, ransom demands, exposure of proprietary assets, and regulatory notification obligations for affected companies across multiple industries. This attack illustrates the intensifying convergence of commodity malware, supply chain threats, and network infiltration techniques. With ransomware, spyware, and rootkits increasingly delivered via trusted collaboration or cloud platforms, and as attackers exploit hybrid environments, organizations face urgent pressure to revisit segmentation, detection, and zero trust controls.
6 months ago
Kill Chain
Mythic: The Growing Threat of Post-Exploitation C2 Frameworks in Network Traffic
In early 2024, cybersecurity researchers revealed the widespread use of the Mythic post-exploitation framework by multiple threat actors to gain persistent control of compromised networks. Mythic, a versatile multi-platform C2 (command and control) toolkit, has enabled adversaries to evade endpoint detection tools while moving laterally, collecting data, and exfiltrating sensitive assets. By leveraging covert channels such as HTTP(S), SMB, WebSocket, Discord, and GitHub APIs, attackers have masked their traffic from traditional network security defenses. Incident response teams observed tailored communication modules, pivoting tactics, and sophisticated data encoding, resulting in delayed detection and prolonged dwell time within targeted organizations. This incident highlights the growing challenge for defenders as open-source offensive frameworks become more advanced and widely adopted. The surge of network-based C2 detection evasion tactics underscores the need for enhanced behavioral analysis, encrypted traffic inspection, and updated NDR/IDS capabilities, especially as regulatory and compliance scrutiny intensifies.
6 months ago
Kill Chain
CISA Adds OSGeo GeoServer CVE-2025-58360 to Known Exploited Vulnerabilities List
In December 2025, CISA added CVE-2025-58360, an Improper Restriction of XML External Entity Reference vulnerability in OSGeo GeoServer, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation in the wild. The vulnerability allows remote attackers to exploit XML parsing weaknesses to access sensitive data or execute arbitrary code by submitting malicious crafted XML to the GeoServer platform, which is widely used for geospatial data services. Malicious actors leveraging this flaw can bypass security controls, potentially leading to significant data breaches or operational disruption across organizations dependent on GeoServer. This incident highlights the increasing urgency of remediating software supply chain and core infrastructure vulnerabilities exploited in real-world attacks. The active exploitation of such high-impact flaws is driving regulatory entities and private organizations to re-examine patch management, incident response, and zero trust controls for critical applications.
6 months ago
Kill Chain
Varex Imaging 2025: Privilege Escalation Vulnerability in Dental Imaging Software
In December 2025, Varex Imaging disclosed a critical privilege escalation vulnerability (CVE-2024-22774, CVSS v4 8.5) affecting its Panoramic Dental Imaging Software (versions prior to 6.6.1.490). The flaw, caused by an uncontrolled search path element (CWE-427) in the SDK, could enable a standard user to gain NT Authority/SYSTEM privileges through DLL hijacking. While the vulnerability cannot be exploited remotely and no active exploitation has been reported, successful compromise could give attackers unrestricted system access in affected healthcare environments, with the potential to disrupt or manipulate sensitive imaging processes. This incident underscores the persistent risks of local privilege escalation vulnerabilities in healthcare software, especially where operational technology and patient systems converge. With increasing regulatory requirements and a rising focus on vertical-specific threats, incidents like this highlight the urgent need for robust patch management, secure software development practices, and vigilant network segmentation in healthcare environments.
6 months ago
Kill Chain
Critical GDCM Vulnerability Risks Healthcare Medical Imaging Workflows
In December 2025, a significant vulnerability was disclosed in the Grassroots DICOM (GDCM) library, a critical open-source imaging component widely used in healthcare systems worldwide. Identified as CVE-2025-11266, this out-of-bounds write vulnerability could be triggered by simply opening a specially-crafted DICOM file, potentially crashing affected applications such as SimpleITK and medInria. The flaw, present in versions GDCM 3.0.24 and earlier, allows for denial-of-service and partial data and integrity impacts, increasing operational risk for healthcare environments that rely on medical imaging interoperability. This incident highlights the persistent risk posed by vulnerable third-party libraries in regulated industries like healthcare. The rise in supply chain threats and software dependencies magnifies the urgency for organizations to maintain rigorous patching practices and robust segmentation, as attackers increasingly target widely-deployed open-source components to disrupt critical services.
6 months ago
Kill Chain
Shanya Packer-as-a-Service: Ransomware’s New Obfuscation Arsenal
In May 2024, security researchers uncovered an emerging Packer-as-a-Service (PaaS) called Shanya, designed to help ransomware operators evade modern enterprise defenses. Shanya provides advanced payload obfuscation capabilities to threat actors, enabling the delivery of ransomware that bypasses endpoint detection and response (EDR) solutions. Attackers using Shanya can rapidly pack malware before deployment, making it harder to analyze and detect. Early incidents showed Shanya-packed ransomware used to swiftly gain lateral movement across compromised environments, disrupt business operations, and facilitate significant data encryption and extortion campaigns. The rise of packers like Shanya signals a growing trend: ransomware groups are leveraging SaaS-style services to increase automation, evasion, and reach. With increased regulatory scrutiny on incident response and a surge in ransomware targeting sectors with critical operations, businesses must urgently strengthen detection and response strategies to address evolving malware delivery techniques.
6 months ago
Kill Chain
Storm-0249's Abuse of EDR Processes: A New Era of Stealth Attacks
In early 2024, threat actor Storm-0249 launched a series of stealthy attacks by weaponizing Endpoint Detection and Response (EDR) platforms alongside native Windows utilities. As an initial access broker, the group circumvented traditional EDR defenses to gain persistent entry into multiple enterprise environments. Leveraging legitimate EDR processes for their own activities, Storm-0249 was able to evade security monitoring, escalate privileges, and facilitate lateral movement. These tactics led to compromised data and footholds that were subsequently sold to other cybercriminal groups, increasing the overall risk for targeted organizations. The emergence of sophisticated actors repurposing security tools for malicious objectives highlights an urgent industry focus on advanced detection, segmentation, and the continual evolution of zero trust strategies. This incident reflects a growing trend: motivated threat groups exploiting trusted processes to blend in and extend dwell time inside modern network environments.
6 months ago
Kill Chain
AI Domain Impersonation Fuels 2024 ClickFix-Style Malware Surge
In early 2024, a cyberattack campaign known as the 'ClickFix Style Attack' emerged, exploiting cutting-edge social engineering and SEO poisoning techniques. Attackers leveraged widely searched AI-related domains such as Grok and ChatGPT, using search engine manipulation to lure unsuspecting users to weaponized websites. Once on these compromised pages, visitors were tricked into downloading malware under the guise of legitimate AI tools and browser extensions, enabling threat actors to gain persistent access to systems and exfiltrate sensitive data. The campaign highlights the growing sophistication and agility of attackers in blending trusted brands with social engineering ploys, ultimately threatening business operations and data integrity. This incident is particularly relevant as it showcases the convergence of AI hype, manipulated search results, and advanced social engineering, which increases the likelihood of successful malware delivery. Security teams must remain vigilant as attackers continue to target the widespread adoption of AI-driven tools and blur lines between legitimate and malicious sources.
6 months ago
Kill Chain
Microsoft December 2025 Patch Tuesday: Critical & Exploited Vulnerabilities Exposed
In December 2025, Microsoft addressed 57 vulnerabilities as part of its Patch Tuesday update, including three critical flaws and one (CVE-2025-62221) already being actively exploited. The vulnerabilities spanned across numerous Microsoft products such as Office, Outlook, Exchange, PowerShell, and the Windows Cloud Files Mini Filter driver. Notably, CVE-2025-64671 affected GitHub Copilot plugins for JetBrains, potentially enabling remote code execution via AI-driven code assistance. Attackers exploited privilege escalation and remote-code execution vectors, posing significant risks to system integrity and user data. The rapid disclosure and exploitation of some flaws before patches were available highlighted increasing attacker sophistication and speed. Incidents such as this emphasize the urgent need for timely patch management, especially as software supply chains and AI integrations become more prevalent. Security teams must remain vigilant against fast-emerging threats, as even mainstream platforms like Microsoft continue to face ongoing and complex exploitation attempts.
6 months ago
Kill Chain
Kubernetes NodeLogQuery (CVE-2024-9042): Command Injection Exploit Hits Windows Nodes
In late 2024, a command injection vulnerability in Kubernetes' NodeLogQuery feature (CVE-2024-9042) was actively exploited, primarily impacting clusters running Windows nodes with log read permissions enabled. Attackers leveraged the '/logs/' API endpoint, injecting operating system commands via GET parameters or path elements to gain unauthorized system access. Victims included enterprise environments utilizing the beta NodeLogQuery feature, which was not enabled by default. The exploit techniques involved turning Kubernetes' logging capabilities into a remote code execution avenue, exposing sensitive workloads to further compromise and potential lateral movement. This incident underscores a broader trend in targeting Kubernetes clusters at the API layer, as adversaries evolve their exploitation of cloud-native misconfigurations and insecure default settings. The attack highlights the need for enhanced east-west traffic controls, static analysis of cluster policies, and real-time anomaly detection to intercept emerging exploitation patterns in cloud and hybrid infrastructure.
6 months ago
Kill Chain
React2Shell: 2025’s Supply Chain Cyberattack Shocks 50+ Organizations
In June 2025, a surge of attacks leveraging the critical React2Shell vulnerability (CVE-2025-55182) swept across more than 50 organizations globally. The flaw, located in React Server Components and derivatives like Next.js, enabled diverse threat actors ranging from nation-states (notably North Korean and Chinese groups), cybercriminals, and botnets to achieve remote code execution. Attackers exploited unpatched instances, deploying a range of malware—including cryptominers, ransomware, and backdoors such as Mirai, XMRIG, and BPFDoor—affecting entities in finance, tech, education, government, and more. The incident’s rapid expansion was facilitated by the widespread availability of public proof-of-concept exploits and slow organizational patching. The React2Shell crisis highlights the fragility of the software supply chain and the speed at which novel exploits can be adapted by a wide array of adversaries. Security and regulatory scrutiny is intensifying, with urgent patching deadlines and increased concern due to the vulnerability’s ease of exploitation, high automation, and ability to evade traditional controls, reminiscent of the earlier Log4Shell incident.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports