✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Ransomware Attack Disrupts Multiple London Councils’ IT Systems in 2024
In June 2024, the Royal Borough of Kensington and Chelsea (RBKC) and Westminster City Council experienced operational disruption following a ransomware cyberattack on their shared IT provider, Westminster City Council Integrated IT (WCCIT). Attackers infiltrated municipal digital infrastructure, encrypted data, and impacted critical online services such as resident portals and payment processing. Public-facing platforms were taken offline as a precaution, and council operations shifted to manual workarounds, affecting both internal processes and citizen-facing services. The incident underscores the vulnerabilities within local government supply chains and highlights the ramifications of targeting shared service models in the public sector. This attack is a sobering reminder of the increasing incidence of ransomware campaigns targeting public entities in the UK and globally. With local authorities managing sensitive citizen data and critical services, the urgency for robust cybersecurity controls and incident response processes has never been more acute.
6 months ago
Kill Chain
Signature Verification Bypass in node-forge Threatens Software Supply Chains (2024)
In early 2024, a critical security vulnerability (CVE-2024-33298) was discovered in the widely used JavaScript cryptography library 'node-forge'. This flaw allowed attackers to bypass digital signature verification by crafting malicious payloads that could appear as legitimately signed data, undermining the trust assumptions of applications and supply chains relying on the library. Once exploited, this vulnerability could allow threat actors to inject malicious code, escalate privileges, or compromise downstream systems with minimal detection, posing significant risks to organizations dependent on 'node-forge' for secure communications and validation workflows. The incident underscores the increasing prevalence and risk of supply-chain attacks in the software ecosystem. As more organizations depend on third-party open-source components for critical operations, vulnerabilities in widely adopted libraries have far-reaching implications for application security and regulatory compliance.
6 months ago
Kill Chain
FBI: $262M Lost to ATO Fraud as AI Phishing and Holiday Scams Surge in 2025
In late 2025, the FBI reported an alarming uptick in Account Takeover (ATO) fraud totaling over $262 million in losses. Cybercriminals, leveraging advanced AI-driven phishing tactics and holiday-themed scams, targeted individuals, businesses, and financial institutions with convincing impersonations to steal credentials and gain access to banking and sensitive accounts. Upon entry, attackers executed lateral movement, funds transfers, and data exfiltration, impacting organizations of all sizes and sectors by causing substantial financial loss, reputational harm, and regulatory scrutiny. This incident underscores an acceleration in AI-powered social engineering and the increasing sophistication of phishing campaigns, especially during high-activity periods like the holidays. Security teams now face heightened urgency to adapt with advanced detection, identity controls, and zero trust segmentation to address evolving threats using AI and automation.
6 months ago
Kill Chain
RomCom Exploits SocGholish Loader in U.S. Civil Engineering Breach
In June 2025, a U.S.-based civil engineering firm was targeted by the RomCom cybercriminal group leveraging the SocGholish JavaScript loader to deliver the advanced Mythic Agent malware. This marked the first known instance of RomCom using SocGholish for payload distribution. Attackers gained initial access through fake browser update lures hosted on compromised websites, allowing them to deploy the remote access trojan (RAT) and establish persistent control within the victim’s network. The attack resulted in exposure of sensitive engineering data and raised concerns regarding lateral movement and potential data exfiltration. This incident illustrates the ongoing trend of converging threat actor tactics, with attackers combining phishing, living-off-the-land tools, and stealthy malware loaders to increase their reach. As cybercriminal organizations diversify their infection vectors, organizations must swiftly adapt their detection and response strategies.
6 months ago
Kill Chain
Shai-Hulud v2 Strikes: Massive npm and Maven Supply Chain Breach Exposes Secrets
In November 2025, a major multi-ecosystem software supply chain attack was uncovered when the Shai-Hulud v2 campaign spread beyond the npm registry into Maven Central. Threat actors compromised over 830 npm packages and at least one Maven package (org.mvnpm:posthog-node:4.18.1), embedding malicious loaders and payloads that silently exfiltrated thousands of developer and organizational secrets. This attack leveraged highly automated techniques to inject stealthy code across registries, making mitigation and detection notably difficult. The campaign’s broad reach threatened applications, organizational infrastructure, and customers reliant on compromised components. This incident highlights a rising trend where sophisticated threat actors exploit trusted open-source software ecosystems, dramatically increasing supply chain risk. Recent surges in attacks targeting developer supply chains have prompted urgent calls for enhanced controls, continuous monitoring, stronger segmentation, and stricter compliance with software integrity standards.
6 months ago
Kill Chain
Qilin Ransomware Orchestrates Major Supply Chain Attack on South Korean MSPs in 2025
In October 2025, a sophisticated supply chain attack targeted multiple South Korean financial sector organizations via a compromised Managed Service Provider (MSP). The threat was executed by the Qilin Ransomware-as-a-Service (RaaS) group, with indications of potential collaboration from North Korea-affiliated Moonstone Sleet actors. Attackers infiltrated the MSP’s infrastructure, leveraged lateral movement to access at least 28 client environments, and deployed the Qilin ransomware payload, resulting in mass data exfiltration and operational disruption. The group publicized stolen information on their so-called 'Korean Leaks' site to pressure victims for ransom, significantly impacting banking, insurance, and fintech operations region-wide. This attack underscores the growing risk of supply chain compromise, particularly where highly interconnected MSP platforms are leveraged to target multiple downstream entities simultaneously. The tactic reflects emerging ransomware trends seen globally, where threat actors exploit trusted service providers to maximize victim impact and amplify regulatory, reputational, and economic damage.
6 months ago
Kill Chain
Executive Breach Brief: Scattered LAPSUS$ Hunters’ 2025 Salesforce Ransomware Campaign
In May 2025, the Scattered LAPSUS$ Hunters (SLSH) cybercriminal group orchestrated a wide-scale ransomware and data extortion campaign targeting the Salesforce environments of over thirty major corporations, including brands like Toyota, FedEx, Disney/Hulu, and UPS. Leveraging sophisticated voice phishing for initial access, SLSH tricked employees into connecting malicious apps to internal Salesforce portals, facilitating rapid exfiltration of sensitive corporate data. Public threats of mass data leaks via their extortion site, insider recruitment, and the deployment of the new ShinySp1d3r ransomware further amplified organizational and reputational risk, prompting companies and regulators to respond swiftly. This incident exemplifies the convergence of advanced social engineering and ransomware-as-a-service models, alongside a growing ecosystem of cybercrime collaboration. Attackers’ use of collaboration platforms, custom malware, and drive to monetize breaches through both data theft and extortion spotlights the need for zero trust and enhanced compliance controls in identity, SaaS, and egress security.
6 months ago
Kill Chain
DPRK’s FlexibleFerret Infiltrates macOS: Credential Theft at Scale
In early 2024, North Korea-linked threat group tracked as FlexibleFerret intensified targeted credential-theft campaigns focusing on macOS users, evolving their "Contagious Interview" social engineering lures. By masquerading as recruiters and leveraging tailored malware, the group tricked victims into opening malicious attachments, deploying a specialized macOS information stealer. The attackers' refinements enabled broader credential compromise, facilitating unauthorized access to sensitive accounts across professional and personal domains. This incident underscores a growing operational sophistication in DPRK-attributed campaigns and heightened risk to macOS environments previously perceived as less targeted. This case highlights a surge in credential-theft, social engineering, and platform-diverse malware, especially against enterprise macOS users. Security teams must adapt defenses to evolving threat actor tactics and close compliance and detection gaps regarding endpoint security and user education.
6 months ago
Kill Chain
ShinySP1D3R Ransomware Hits Hybrid Clouds During Holiday 2024
In December 2024, organizations worldwide were targeted by the ransomware group known as ShinySP1D3R, identified as an offshoot of the Scattered LAPSUS$ Hunters collective. Attackers exploited vulnerabilities in unencrypted east-west and egress traffic to gain network access, rapidly deploying ransomware across hybrid cloud environments during the busy holiday season. The incident resulted in substantial service outages, data encryption, and led to operational delays for affected enterprises, reinforcing the dangers of sophisticated lateral movement paired with insufficient segmentation controls. This incident highlights a rising trend of threat actors striking during holidays when staffing is limited and detection/response windows are higher. The campaign’s use of advanced TTPs—such as distributed command and control and abuse of hybrid connectivity—emphasizes why zero trust architectures and continuous threat monitoring are now business-critical.
6 months ago
Kill Chain
Malicious Underground AI Models Like WormGPT 4 Are Supercharging Cybercrime in 2024
In early 2024, cybersecurity researchers uncovered an expanding underground marketplace for custom large language models (LLMs) such as WormGPT 4 and KawaiiGPT, designed to facilitate cybercrime. These jailbroken and open-source models, advertised and sold across dark web forums, lower the technical barrier for attackers by offering tools to scan for vulnerabilities, automate malware development, and accelerate tasks like phishing and lateral movement. Their accessibility—with minimal setup time, user-friendly interfaces, and affordable pricing—has enabled a broader range of cybercriminals to automate sophisticated attacks previously requiring advanced skills. The emergence of malicious LLMs highlights a growing trend where generative AI is weaponized in cybercrime. Unlike earlier incidents, these tools are now commercialized and widely supported, signaling a shift from simple model jailbreaking to specialized AI-enabled attack platforms. This evolution increases the urgency for organizations to strengthen AI risk management, augment detection strategies, and adapt compliance controls to address the new threat landscape.
6 months ago
Kill Chain
What the Gainsight–Salesforce Supply Chain Attack Teaches Us About SaaS Security in 2024
In late October 2024, Gainsight, a customer management SaaS provider, was implicated in a supply chain attack that impacted Salesforce environments. Attackers exploited the Gainsight connected app to obtain and abuse OAuth tokens, enabling unauthorized access to several Salesforce customer instances and raising concerns about lateral movement to other connected third-party applications. While initial reports from Salesforce identified compromised tokens and only a handful of affected customers, subsequent intelligence indicated the potential exposure of over 200 Salesforce instances. Mandiant and Salesforce collaborated to investigate the extent and mechanics of the attack, tracing earliest malicious activity to October 23, 2024. Despite ongoing forensics, Gainsight maintains that the breach impact was limited in scope, and no evidence has surfaced indicating a vulnerability within Salesforce’s platform itself. This incident reflects the growing trend of SaaS supply chain attacks that exploit authentication and integration mechanisms to reach downstream enterprise environments. The blend of fragmented disclosure, coordinated incident response, and rising third-party risks demonstrates the urgent need for improved visibility, segmented access, and standardized controls within interconnected SaaS ecosystems.
6 months ago
Kill Chain
Dartmouth College Data Breach: Clop Ransomware Targets Oracle EBS in 2024 Attack
In March 2024, Dartmouth College confirmed a data breach after the Clop ransomware gang published confidential information allegedly exfiltrated from the institution's Oracle E-Business Suite servers. The attackers exploited a zero-day vulnerability (associated with the MOVEit Transfer incidents) and infiltrated the college’s systems, ultimately stealing sensitive data, including personal and financial records of students, faculty, and staff. Dartmouth detected suspicious activity following Clop’s dark web disclosures, began forensics, and reported the incident to regulatory agencies. Disruptions to business operations and heightened security controls followed, with legal notifications sent to affected parties. The Dartmouth breach highlights the persistent targeting of higher education by ransomware groups exploiting supply chain and enterprise software vulnerabilities. With ransomware attacks involving exfiltration and public data leaks surging in 2024, institutions face mounting regulatory pressure and reputational risks, underscoring the urgent need for robust segmentation, encrypted traffic controls, and real-time threat detection.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports