✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Legacy Python Bootstrap Scripts Expose PyPI Supply Chain to Domain Takeover Risk
In June 2025, cybersecurity researchers at ReversingLabs uncovered a significant vulnerability in legacy Python packages distributed via PyPI. The weakness stems from outdated bootstrap scripts within the widely used zc.buildout automation tool, which reference external domains that have since become unregistered. This creates a supply chain attack risk: if an attacker registers one of these lapsed domains, they could host malicious code, which would be executed during package installation, compromising developer, CI/CD, or production environments. While there are no confirmed mass exploits yet, the affected ecosystem is large due to the extended usage of these packages. This incident is highly relevant as supply chain risks in open-source ecosystems continue to grow, and domain takeover remains a low-cost, high-impact attack vector. Increased attention to legacy codebases and dependency hygiene is essential as regulations tighten and attackers show rising interest in poisoning software development infrastructure.
6 months ago
Kill Chain
Gainsight-Salesforce 2025 Breach: A Wake-Up Call for SaaS Supply-Chain Security
In November 2025, Gainsight reported a security incident involving its SaaS applications integrated with Salesforce, after Salesforce observed suspicious API calls from non-allowlisted IP addresses linked to Gainsight services. This prompted Salesforce to revoke affected access tokens, limit integration capabilities, and initiate investigations, temporarily disrupting data flows for several customers and connected platforms such as Zendesk and HubSpot. Forensic analysis revealed threat activity tied to proxy/VPN infrastructure and IPs previously associated with the UNC6040 threat cluster, which had targeted Salesforce CRMs in past extortion campaigns, though no confirmed data exfiltration occurred. This incident exemplifies the persistent risk of supply-chain compromise through interconnected SaaS platforms, emphasizing how attackers can leverage trusted applications to pivot laterally and exploit enterprise data pipelines. With the steady rise in OAuth-based integrations and API dependency, businesses face mounting urgency to reevaluate third-party access, enforce zero-trust principles, and proactively monitor for anomalous behaviors within their SaaS ecosystems.
6 months ago
Kill Chain
North Korean Hackers Target Developers with Massive npm Supply-Chain Attack
In November 2025, North Korean threat actors associated with the "Contagious Interview" campaign launched an extensive supply-chain attack by publishing 197 malicious npm packages. According to threat intelligence from Socket, these packages—downloaded over 31,000 times—were engineered to distribute a new OtterCookie malware variant, combining features from BeaverTail and earlier OtterCookie strains. The attackers leveraged the npm ecosystem to infiltrate development pipelines, enabling remote code execution and persistent access across compromised environments, potentially exposing confidential data and intellectual property. This incident underscores the escalating risks of supply chain attacks targeting software registries. With developers increasingly relying on open-source dependencies, threat actors are focusing on abusing trusted platforms like npm to propagate sophisticated malware at scale. Organizations must strengthen software supply chain security and closely monitor package repositories to mitigate these emerging threats.
6 months ago
Kill Chain
OpenAI Mixpanel Breach: 2024 Supply-Chain Exposure of API Customer Data
In June 2024, OpenAI disclosed that a breach at its third-party analytics provider Mixpanel exposed limited identifying information of certain ChatGPT API customers. According to the company's notification, attackers compromised Mixpanel's systems and accessed data such as organization names and email addresses transmitted through Mixpanel's embedded analytics scripts. OpenAI clarified that payment or sensitive API data was not affected, and the incident did not impact all users. Prompt investigation and mitigation steps were initiated, including collaboration with Mixpanel and additional security controls around third-party integrations. This incident underscores the persistent risks associated with the digital supply chain. As organizations increasingly rely on external vendors for analytics and infrastructure, threat actors continue to exploit third-party weaknesses to obtain customer data—driving heightened attention from regulators and boards.
6 months ago
Kill Chain
2025 Multi-Vector Attack: AI Malware, Voice Bots, Crypto Laundering & IoT Breach
In November 2025, threat analysts observed a coordinated, multi-vector cyberattack campaign targeting enterprises across finance, healthcare, and IoT-heavy sectors. Attackers leveraged AI-powered malware, compromised voice bots, and elaborate cryptocurrency laundering techniques to infiltrate organizations, bypass security controls, and exfiltrate sensitive data. Initial access was achieved via sophisticated phishing augmented by AI voice impersonation, while lateral movement and data theft exploited weaknesses in internal segmentation and unencrypted east-west traffic. The campaign’s complexity resulted in service downtime, financial losses, and data exposure for several multinational organizations. This incident is notable for blending diverse threat techniques—AI-driven social engineering, voice-based exploits, and infrastructure abuses—reflecting the current trend towards multifaceted attacks capable of outmaneuvering traditional defenses. The scale and automation highlight increased attacker innovation and challenge existing compliance and zero trust frameworks.
6 months ago
Kill Chain
Bloody Wolf's NetSupport RAT Campaign Breaches Kyrgyzstan and Uzbekistan: 2025 Analysis
In mid-2025, the threat actor known as Bloody Wolf launched a targeted cyber campaign against government and enterprise entities in Kyrgyzstan, later expanding its operations to Uzbekistan by October 2025. Utilizing sophisticated phishing lures, attackers delivered Java-based loaders that deployed the NetSupport Remote Access Trojan (RAT), allowing persistent access and potential data exfiltration. The campaign featured advanced evasion tactics, encrypted command-and-control traffic, and was attributed by Group-IB and local cybersecurity agencies. Affected organizations faced risks of unauthorized network access and potential compromise of sensitive information. This incident highlights ongoing regional cybercrime escalation, especially the trend of weaponizing legitimate tools like NetSupport RAT through creative malware loaders. With cross-border expansion and zero-day techniques, the event exemplifies how remote access trojans are reshaping threat landscapes and driving demand for advanced network and east-west traffic controls.
6 months ago
Kill Chain
Anthropic AI Breach: Chinese State-Sponsored Espionage Campaign Shakes Cybersecurity Landscape
In late 2024, Anthropic disclosed a sophisticated espionage campaign linked to Chinese state-sponsored actors who leveraged the Claude AI platform to automate and scale cyber-operations targeting at least 30 global organizations. Attackers reportedly used Claude to streamline reconnaissance and intrusion tasks, combining AI capabilities with human expertise to enhance operational stealth and impact. The U.S. House Homeland Security Committee responded by summoning Anthropic’s CEO and other tech leaders to testify about the security implications of AI-augmented tradecraft and the risks posed by pairing AI with emerging technologies like quantum computing. This incident underscores how state-sponsored groups are rapidly evolving, using commercially available AI to bypass defenses and accelerate cyber operations. The attack has triggered urgent calls for stronger safeguards, regulatory clarity on AI security, and cross-sector strategies to counter AI-enabled cyber threats.
6 months ago
Kill Chain
Crisis24 Shuts Down CodeRED Emergency System Following Ransomware Breach
In early June 2024, Crisis24 permanently shut down its OnSolve CodeRED emergency notification system after a ransomware attack severely damaged the platform's environment. The incident, attributed to the INC ransomware group, involved unauthorized access to and exfiltration of user data, including names, addresses, email addresses, phone numbers, and passwords. Forensic analysis indicated the attack was contained within the legacy CodeRED environment. The shutdown left dozens of municipalities and law enforcement agencies temporarily without emergency notification services, though the U.S. government's Emergency Alert System was unaffected. Crisis24 accelerated rollout of its new platform, conducted a security audit, and notified law enforcement. This breach underscores the increasing risk posed by ransomware groups targeting public safety infrastructure. With attackers leaking sensitive personal data and causing operational disruptions, organizations face mounting pressure to modernize legacy systems and enhance both incident response and segmentation controls in light of sophisticated, persistent threats.
6 months ago
Kill Chain
ASUS Issues Urgent Patch for Critical AiCloud Authentication Bypass Flaw in Routers
In June 2024, ASUS disclosed a critical authentication bypass vulnerability (CVE-2024-3080) affecting several router models running AiCloud. Attackers could exploit this flaw remotely, without authentication, to gain administrative access and potentially control router functions—enabling unauthorized changes, interception of network traffic, and further lateral movement within home or small business networks. The flaw was one of nine vulnerabilities addressed by an urgent firmware patch released by ASUS, after receiving responsible disclosure and industry warnings. Although there are no major reports of exploitation in the wild yet, affected users were strongly urged to update immediately to prevent potential compromise. This incident highlights the increasing targeting of network infrastructure and IoT devices by attackers seeking easy entry points into corporate and personal environments. With a surge in authentication bypasses and router-based exploits, organizations and individuals must prioritize timely patching and implement additional network segmentation and anomaly detection controls.
6 months ago
Kill Chain
Microsoft Hardens Entra ID Against Script Injection Attacks in 2026
In October 2026, Microsoft announced significant upgrades to the Entra ID authentication platform to address vulnerabilities exposed by script injection attacks targeting the sign-in process. Attackers had exploited weaknesses in the handling of external scripts within the authentication flow, enabling potential bypass of security controls and unauthorized access to user accounts. While no large-scale breaches were publicly disclosed, Microsoft proactively moved to deploy enhanced protections and harden the Entra ID authentication framework, limiting the exploitation window and strengthening controls. The business impact focused on the increased risk to user identity and the need for rapid security enhancements within core authentication infrastructure. This incident underscores the evolving threat landscape facing identity providers, with attackers increasingly leveraging advanced script injection and authentication bypass techniques. It highlights the urgent need for continuous improvement of identity and access management security controls, as threat actors seek novel vectors to compromise critical authentication flows across cloud and enterprise environments.
6 months ago
Kill Chain
Ransomware Attack Disrupts Multiple London Councils’ IT Systems in 2024
In June 2024, the Royal Borough of Kensington and Chelsea (RBKC) and Westminster City Council experienced operational disruption following a ransomware cyberattack on their shared IT provider, Westminster City Council Integrated IT (WCCIT). Attackers infiltrated municipal digital infrastructure, encrypted data, and impacted critical online services such as resident portals and payment processing. Public-facing platforms were taken offline as a precaution, and council operations shifted to manual workarounds, affecting both internal processes and citizen-facing services. The incident underscores the vulnerabilities within local government supply chains and highlights the ramifications of targeting shared service models in the public sector. This attack is a sobering reminder of the increasing incidence of ransomware campaigns targeting public entities in the UK and globally. With local authorities managing sensitive citizen data and critical services, the urgency for robust cybersecurity controls and incident response processes has never been more acute.
6 months ago
Kill Chain
Signature Verification Bypass in node-forge Threatens Software Supply Chains (2024)
In early 2024, a critical security vulnerability (CVE-2024-33298) was discovered in the widely used JavaScript cryptography library 'node-forge'. This flaw allowed attackers to bypass digital signature verification by crafting malicious payloads that could appear as legitimately signed data, undermining the trust assumptions of applications and supply chains relying on the library. Once exploited, this vulnerability could allow threat actors to inject malicious code, escalate privileges, or compromise downstream systems with minimal detection, posing significant risks to organizations dependent on 'node-forge' for secure communications and validation workflows. The incident underscores the increasing prevalence and risk of supply-chain attacks in the software ecosystem. As more organizations depend on third-party open-source components for critical operations, vulnerabilities in widely adopted libraries have far-reaching implications for application security and regulatory compliance.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports