✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
ShinySP1D3R Ransomware Hits Hybrid Clouds During Holiday 2024
In December 2024, organizations worldwide were targeted by the ransomware group known as ShinySP1D3R, identified as an offshoot of the Scattered LAPSUS$ Hunters collective. Attackers exploited vulnerabilities in unencrypted east-west and egress traffic to gain network access, rapidly deploying ransomware across hybrid cloud environments during the busy holiday season. The incident resulted in substantial service outages, data encryption, and led to operational delays for affected enterprises, reinforcing the dangers of sophisticated lateral movement paired with insufficient segmentation controls. This incident highlights a rising trend of threat actors striking during holidays when staffing is limited and detection/response windows are higher. The campaign’s use of advanced TTPs—such as distributed command and control and abuse of hybrid connectivity—emphasizes why zero trust architectures and continuous threat monitoring are now business-critical.
6 months ago
Kill Chain
Malicious Underground AI Models Like WormGPT 4 Are Supercharging Cybercrime in 2024
In early 2024, cybersecurity researchers uncovered an expanding underground marketplace for custom large language models (LLMs) such as WormGPT 4 and KawaiiGPT, designed to facilitate cybercrime. These jailbroken and open-source models, advertised and sold across dark web forums, lower the technical barrier for attackers by offering tools to scan for vulnerabilities, automate malware development, and accelerate tasks like phishing and lateral movement. Their accessibility—with minimal setup time, user-friendly interfaces, and affordable pricing—has enabled a broader range of cybercriminals to automate sophisticated attacks previously requiring advanced skills. The emergence of malicious LLMs highlights a growing trend where generative AI is weaponized in cybercrime. Unlike earlier incidents, these tools are now commercialized and widely supported, signaling a shift from simple model jailbreaking to specialized AI-enabled attack platforms. This evolution increases the urgency for organizations to strengthen AI risk management, augment detection strategies, and adapt compliance controls to address the new threat landscape.
6 months ago
Kill Chain
What the Gainsight–Salesforce Supply Chain Attack Teaches Us About SaaS Security in 2024
In late October 2024, Gainsight, a customer management SaaS provider, was implicated in a supply chain attack that impacted Salesforce environments. Attackers exploited the Gainsight connected app to obtain and abuse OAuth tokens, enabling unauthorized access to several Salesforce customer instances and raising concerns about lateral movement to other connected third-party applications. While initial reports from Salesforce identified compromised tokens and only a handful of affected customers, subsequent intelligence indicated the potential exposure of over 200 Salesforce instances. Mandiant and Salesforce collaborated to investigate the extent and mechanics of the attack, tracing earliest malicious activity to October 23, 2024. Despite ongoing forensics, Gainsight maintains that the breach impact was limited in scope, and no evidence has surfaced indicating a vulnerability within Salesforce’s platform itself. This incident reflects the growing trend of SaaS supply chain attacks that exploit authentication and integration mechanisms to reach downstream enterprise environments. The blend of fragmented disclosure, coordinated incident response, and rising third-party risks demonstrates the urgent need for improved visibility, segmented access, and standardized controls within interconnected SaaS ecosystems.
6 months ago
Kill Chain
Dartmouth College Data Breach: Clop Ransomware Targets Oracle EBS in 2024 Attack
In March 2024, Dartmouth College confirmed a data breach after the Clop ransomware gang published confidential information allegedly exfiltrated from the institution's Oracle E-Business Suite servers. The attackers exploited a zero-day vulnerability (associated with the MOVEit Transfer incidents) and infiltrated the college’s systems, ultimately stealing sensitive data, including personal and financial records of students, faculty, and staff. Dartmouth detected suspicious activity following Clop’s dark web disclosures, began forensics, and reported the incident to regulatory agencies. Disruptions to business operations and heightened security controls followed, with legal notifications sent to affected parties. The Dartmouth breach highlights the persistent targeting of higher education by ransomware groups exploiting supply chain and enterprise software vulnerabilities. With ransomware attacks involving exfiltration and public data leaks surging in 2024, institutions face mounting regulatory pressure and reputational risks, underscoring the urgent need for robust segmentation, encrypted traffic controls, and real-time threat detection.
6 months ago
Kill Chain
Banks and Governments Exposed: Code Beautifiers Leak Credentials in 2024
In early 2024, researchers discovered that thousands of sensitive credentials, API keys, and authentication tokens belonging to global banks, government agencies, and technology companies were inadvertently exposed through public submissions to online code formatting tools such as JSONFormatter and CodeBeautify. These web-based beautifier platforms, commonly used by developers to format or debug code, were found to be storing users’ uploads—including confidential configuration files—in publicly accessible repositories without adequate warning or access control. As a result, threat actors could easily discover and exploit these exposed secrets to compromise critical infrastructure or initiate supply chain attacks. This incident underscores the ongoing risks of third-party tool usage in secure development lifecycles. With data exposures driven by everyday tooling, organizations face mounting regulatory and operational scrutiny to audit developer practices, harden supply chain security, and implement broader controls for inadvertent credential leakage.
6 months ago
Kill Chain
How the OnSolve CodeRED Cyberattack Disrupted America’s Emergency Alert Infrastructure
In June 2024, Crisis24 confirmed that its OnSolve CodeRED platform—used by state and local governments, police, and firefighting agencies—suffered a cyberattack disrupting emergency notification systems nationwide. Attackers gained unauthorized access to critical infrastructure, resulting in outages that hindered the timely dissemination of emergency alerts and public safety updates. While the investigation is ongoing, the breach demonstrates significant operational risks associated with service provider platforms in the public safety sector, impacting communities’ emergency preparedness and response effectiveness. This incident underscores growing threats targeting third-party vendors in critical sectors, where cyberattacks exploit platform dependencies to cause widespread and immediate disruption. With increasing regulatory scrutiny and a surge in ransomware and extortion campaigns against essential services, organizations must reassess supply chain, segmentation, and incident response controls to maintain operational and compliance resilience.
6 months ago
Kill Chain
ToddyCat's 2025 Attack: How APTs Are Hijacking Microsoft 365 Email Tokens
In late 2025, the Advanced Persistent Threat (APT) group known as ToddyCat launched a sophisticated cyber espionage campaign targeting corporate environments across Europe and Asia. The attackers leveraged a new custom tool, TCSectorCopy, to steal Microsoft Outlook emails and Microsoft 365 OAuth 2.0 access tokens. By compromising user endpoints and abusing browser-based authentication flows, ToddyCat successfully exfiltrated sensitive email data and bypassed perimeter controls. The campaign, marked by its stealthy techniques, enabled attackers to maintain persistent access and move laterally within affected networks, significantly increasing the risk to sensitive enterprise communications and intellectual property. This incident highlights the growing reliance of threat actors on token theft and cloud-based attack vectors, posing new challenges for organizations with hybrid or cloud-first environments. It underscores the urgent need for advanced detection capabilities, Zero Trust network segmentation, and comprehensive identity protection strategies to counter emerging APT tactics.
6 months ago
Kill Chain
JackFix Campaign Exploits Fake Windows Updates to Spread Infostealers in 2025
In late 2025, cybersecurity researchers uncovered a campaign orchestrated by the JackFix group using cloned adult websites as a phishing lure, distributed primarily through malvertising channels. Victims visiting these sites were presented with fake Windows update pop-ups designed to imitate critical security notifications. Unsuspecting users were tricked into executing malicious payloads that installed multiple information stealers, enabling the attackers to exfiltrate credentials, session tokens, and sensitive browser data. This attack illustrates how adversaries exploit popular platforms and social engineering to bypass traditional security controls, posing significant risks to both individuals and enterprises. The incident is particularly significant given the continued adoption of sophisticated phishing techniques and the blending of legitimate web content with highly convincing fraudulent prompts. Enterprises must remain vigilant as such campaigns highlight persistent weaknesses in endpoint protections, user awareness, and lateral movement defenses against infostealers.
6 months ago
Kill Chain
The Shai-hulud Worm Returns: 2024 Supply Chain Malware Breach Analysis
In early 2024, cybersecurity researchers identified a resurgence of the Shai-hulud worm leveraging a novel infection vector in supply chain attacks. The new variant executes malicious code during software preinstall, exposing assets in both build and runtime environments before traditional defenses can activate. Attackers embedded the worm into widely-used application packages, facilitating undiscovered lateral movement and unauthorized access to sensitive data across multicloud and hybrid infrastructures. In several cases, the attack bypassed conventional endpoint protections and rapidly compromised internal east-west traffic, threatening operational availability and regulatory compliance for impacted organizations. This incident signals an evolution in malware tactics, underscoring the growing threat posed by supply chain attacks and sophisticated lateral movement in modern enterprise networks. The renewed Shai-hulud campaign highlights the urgent need for robust zero trust segmentation, encrypted data in transit, and real-time threat detection to counter risks targeting build pipelines and cloud-native workloads.
6 months ago
Kill Chain
ShadowRay 2.0: New Botnet Hijacks AI Clusters for Cryptocurrency Mining
In early 2024, cybersecurity researchers discovered that threat actors had exploited a vulnerability in the open-source Ray framework to infiltrate AI infrastructure in organizations worldwide. By abusing misconfigured or vulnerable Ray clusters, attackers deployed a self-propagating botnet named ShadowRay 2.0 that hijacked compute resources for unauthorized cryptomining and exfiltrated sensitive data. The campaign demonstrated advanced lateral movement across cloud workloads, showcasing AI services as lucrative targets and exposing gaps in east-west security and segmentation policies. Impact included disrupted operations, increased cloud costs, and exposure of confidential data, impacting both cloud-native and hybrid environments. This incident is a stark example of how attackers rapidly weaponize software flaws in emerging technologies like AI platforms. With the proliferation of open-source AI frameworks and increased integration into core business operations, misconfigurations and unpatched vulnerabilities become high-value entry points for financially motivated cybercriminals.
6 months ago
Kill Chain
Oracle 2025 Identity Manager Breach: CVE-2025-61757 Exploited in New Extortion Campaigns
In 2025, Oracle’s Identity Manager platform was found to have a critical vulnerability, designated CVE-2025-61757, which was actively exploited by threat actors. Attackers leveraged this flaw to gain unauthorized access, escalate privileges, and potentially move laterally across enterprise environments leveraging Oracle's identity suite. This campaign followed earlier Oracle Cloud security incidents and a notable extortion trend targeting Oracle E-Business Suite customers, raising concerns about the security posture of widely-deployed identity management systems. This breach underscores an urgent industry shift: as digital identity becomes the new security perimeter, attackers increasingly target identity infrastructure. The incident’s exploit path highlights the need for robust segmentation, real-time threat detection, and compliance-driven control across cloud and enterprise platforms.
6 months ago
Kill Chain
Chinese APTs Target Russian IT Firms via Cloud: Inside the 2024 Espionage Breach
In early 2024, Chinese state-sponsored threat actors leveraged commercial cloud services as command-and-control channels to conduct covert cyber espionage against leading Russian IT organizations. The sophisticated attackers evaded detection by hiding their communications within encrypted cloud traffic, enabling them to obtain sensitive data and intelligence from critical Russian technology infrastructure. The breach underscores the risks posed by advanced persistent threats (APTs) operating stealthily in hybrid, multicloud environments using legitimate cloud tools. The incident heightened tensions between China and Russia due to the exposure of confidential communications and potentially proprietary technologies. This breach demonstrates a growing trend of nation-state actors blending in with legitimate cloud activity, making detection far more challenging for defenders. It signals a shift in cyber espionage tactics, intensifying the urgency for organizations to strengthen east-west visibility, enforce zero trust principles, and monitor cloud infrastructure for anomalous behavior.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports