✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
ShadowRay 2.0 Turns Ray AI Framework Flaw into GPU-Powered Cryptomining Botnet
In November 2025, the 'ShadowRay 2.0' campaign was uncovered actively exploiting an unpatched, two-year-old vulnerability in the Ray open-source AI framework. Threat actors leveraged this flaw to compromise cloud-hosted and on-premises Ray clusters equipped with NVIDIA GPUs, deploying a self-spreading botnet targeting large-scale cryptomining. The attackers automated lateral movement within cloud environments and data centers, rapidly enrolling new nodes into the botnet, and using high-performance GPUs for illicit cryptocurrency mining, resulting in significant resource abuse, potential data exposure, and increased operational costs for targets. ShadowRay 2.0 highlights the rising trend of adversaries abusing vulnerable AI/ML infrastructure for financially motivated campaigns. The incident underlines the security risks facing organizations using open-source workloads, as attackers increasingly automate botnet propagation, and reinforces the urgency of addressing software supply chain and east-west traffic security gaps.
6 months ago
Kill Chain
JustAskJacky 2025: AI/ML Exploitation Drives Major User Data Exposure
In November 2025, the AI-driven platform JustAskJacky was compromised, exposing sensitive user prompts and data after adversaries exploited weaknesses in encrypted traffic controls and inadequate egress security. Attackers orchestrated lateral movements across internal AI/ML workloads, leveraging insufficient segmentation and lack of effective visibility to siphon proprietary inputs and outputs through encrypted but poorly-monitored channels. The breach remained undetected for weeks, putting affected businesses and consumers at risk of prompt leakage, IP loss, and possible regulatory infractions in industries reliant on AI automation. This incident underscores a surge in sophisticated AI/ML exploitation techniques and highlights systemic gaps in east-west traffic security, zero trust segmentation, and anomaly detection across multicloud and hybrid environments. As organizations accelerate their adoption of AI-powered platforms, the need for robust compliance and zero trust frameworks has reached critical urgency.
6 months ago
Kill Chain
Tsundere Botnet: How Blockchain-Powered C2 Supercharged Windows-Based Attacks in 2025
In mid-2025, researchers identified a rapidly expanding botnet dubbed "Tsundere" specifically targeting Windows users. This malware, active since at least June 2025, leverages game-themed lures to infect systems, enabling attackers to execute arbitrary JavaScript code via a sophisticated command-and-control (C2) infrastructure built on the Ethereum blockchain for resilient communications. Tsundere’s propagation tactics remain opaque, but evidence indicates an advanced, multi-functional platform designed to maintain persistence, evade detection, and potentially facilitate lateral movement within victim networks. The business impact includes increased exposure to data theft, possible ransomware deployment, and widespread compromise of user endpoints. The Tsundere botnet exemplifies the rising trend of attackers exploiting blockchain technology for C2 communications, making conventional takedown efforts far more difficult. This incident underscores the urgency for organizations to enhance east-west threat visibility, strengthen endpoint defenses, and adopt zero-trust policies as botnets grow more evasive and robust.
6 months ago
Kill Chain
Fortinet Hit Again: WAF Zero-Day Exploitation Prompts Security Scrutiny
In June 2024, Fortinet disclosed that a second zero-day vulnerability affecting its FortiWeb Web Application Firewall (WAF) products was actively exploited in the wild. Attackers leveraged the undisclosed flaw to bypass security controls and potentially gain unauthorized remote access to customer environments, raising major concerns about the rapidity and transparency of Fortinet's incident response. The breach followed an earlier 2024 WAF zero-day, indicating a worrying escalation in threat actor targeting and sophistication against network-edge defense systems. This incident underscores the increasing prevalence of zero-day attacks against security appliances themselves, a trend accelerated by sophisticated threat actors who seek to exploit both technical weaknesses and delayed vendor responses. Rapid incident disclosure and robust patching are now critical to safeguarding key infrastructure.
6 months ago
Kill Chain
WhatsApp 'Eternidade' Trojan Self-Propagates Across Brazil
In early 2024, a sophisticated infostealer campaign dubbed 'Eternidade' began targeting Brazilian Portuguese–speaking WhatsApp users. The attackers distributed a trojan combining phishing, credential theft, and worm-like self-propagation via compromised WhatsApp messages. Victims were lured with messages containing malicious links; once infected, devices exposed sensitive banking credentials and personal data to attackers. The malware leveraged localized tactics and social engineering to increase infection rates and circumvent traditional perimeter defenses, leading to widespread compromise across individual users and organizations reliant on WhatsApp for communication. The rapid spread, data loss, and potential for further extortion amplified business and consumer risks. This breach signals the growing sophistication of infostealer operations, especially their ability to exploit trusted communication apps in regionally tailored attacks. The incident raises alarm over encrypted-messaging-based malware and highlights gaps in endpoint and messaging security as threat actors increasingly weaponize social communication platforms.
6 months ago
Kill Chain
Five Eyes Target Bulletproof Hosting: Sanctions Rock Media Land & Aeza Group in 2024
In June 2024, the Five Eyes intelligence alliance—comprising the US, UK, and Australia—executed coordinated sanctions against Russia-based bulletproof hosting provider Media Land, its executives, three subsidiaries, and entities supporting the previously sanctioned Aeza Group. These hosting providers were identified as key enablers for major ransomware groups (such as LockBit, BlackSuit, and Play), facilitating operations including malware delivery, phishing, and data extortion. Bulletproof hosting infrastructure aided threat actors by allowing them to mask malicious activity and evade law enforcement action, thereby supporting cybercrime at scale for nearly a decade. This incident highlights the increasing focus by global regulators and law enforcement on disrupting the infrastructure and services that underpin the cybercrime ecosystem, rather than targeting individual attackers. The coordinated international response signals a trend toward attacking the foundational services cybercriminals rely on, underscoring the evolving strategies required to address rising ransomware and data extortion threats.
6 months ago
Kill Chain
Cloudflare's 2024 Outage: What Happens When Cloud Control Goes Wrong?
On June 25, 2024, Cloudflare experienced its most significant outage since 2019, following a change to its database access controls that inadvertently propagated across its global network. This technical misconfiguration caused a cascade of failures, disabling the company's control plane and blocking access to thousands of websites and web services worldwide for nearly six hours. The incident was not attributable to cyberattack or malicious activity, but the widespread and prolonged downtime severely impacted Cloudflare's customers and highlighted the fragility of large-scale, cloud-driven infrastructure when faced with operational errors. This outage underscores a growing concern for enterprises reliant on cloud providers, as administrative mistakes and configuration errors have outsized impacts on digital availability. With rapid cloud adoption and increasingly complex infrastructures, businesses must prioritize robust change controls, real-time monitoring, and automated rollback capabilities to mitigate similar risks.
6 months ago
Kill Chain
Meet ShinySp1d3r: How Affiliate Ransomware Powered by ShinyHunters Ups the Stakes
In mid-2024, cybersecurity researchers discovered an in-development version of the ShinySp1d3r ransomware-as-a-service (RaaS) platform, believed to be created by the infamous ShinyHunters threat group. The platform equips criminal affiliates with a toolkit designed to automate ransomware deployment, data encryption, and multi-extortion capabilities. Early builds circulated within cybercrime forums preview advanced features, such as dashboard controls, automated leak sites, and an affiliate earnings model, underscoring the maturity and commercialization of the threat. The potential for widespread, coordinated attacks against enterprises and public sector organizations is significantly heightened by the accessibility and ease-of-use facilitated by this service. The emergence of ShinySp1d3r represents a growing trend of professionalized cybercrime, where sophisticated threat actors develop and market turnkey attack platforms to less-skilled operators. This further accelerates ransomware proliferation and amplifies the risks for organizations reliant on digital infrastructure.
6 months ago
Kill Chain
Operation WrtHug: How Legacy ASUS Routers Became a Global Botnet in 2024
In early 2024, thousands of end-of-life ASUS WRT routers worldwide were compromised in a large-scale campaign dubbed "Operation WrtHug". Attackers exploited at least six known vulnerabilities in outdated router firmware to hijack control of the devices. These compromised routers were assimilated into a new botnet infrastructure, enabling malicious actors to facilitate unauthorized traffic routing, launch further attacks, and potentially intercept sensitive data passing through these compromised endpoints. The incident points to neglected device lifecycle management and widespread exposure due to unpatched, unsupported consumer hardware. This breach is particularly notable as it reflects a growing trend: attackers shifting focus to vulnerable, unmaintained IoT and networking hardware. With legacy devices lacking security updates, organizations face heightened risk of compromise and regulatory scrutiny, while defenders must urgently address asset visibility and enforcement across distributed infrastructure.
6 months ago
Kill Chain
Sanctions Hit Russian Bulletproof Hosting Providers Backing Global Ransomware
In June 2024, the United States, together with the United Kingdom and Australia, imposed sanctions on Russian bulletproof hosting provider Media Land and associated entities. Investigations revealed these providers had knowingly facilitated ransomware operations and other cybercriminal activities by offering infrastructure shielding malicious actors from law enforcement, particularly ransomware gangs operating out of Russia. The sanctions block their financial assets and prohibit transactions, aiming to disrupt the ecosystem supporting high-profile global ransomware attacks and cybercrime. This incident is significant amid a surge in ransomware and supply-chain attacks worldwide, with threat actors increasingly relying on bulletproof hosting to evade detection. Governments are moving quickly to cut off these enablers as part of a broader strategy against organized cybercrime.
6 months ago
Kill Chain
Phishing-as-a-Service Evolves: Sneaky2FA Adds Browser-in-the-Browser Attacks in 2024
In early June 2024, cybersecurity researchers reported that the Sneaky2FA phishing-as-a-service (PhaaS) kit has adopted the Browser-in-the-Browser (BitB) attack tactic, previously used by red teamers, to improve the effectiveness of credential phishing campaigns. This new feature enables threat actors using the Sneaky2FA service to launch highly convincing fake login pop-ups, closely mimicking legitimate authentication flows, including prompts for multifactor authentication (MFA). The update broadens the risks for both organizations and individuals, as traditional indicators of phishing are increasingly hard to spot. The deployment of BitB tactics by a turnkey phishing kit marks a concerning development in the automation and commercial accessibility of advanced cybercrime techniques. This incident underscores the escalating sophistication of phishing attacks driven by the commoditization of offensive security techniques. Organizations face renewed urgency to revisit their authentication controls, user awareness training, and phishing-resistant MFA, as adversary innovation quickly outpaces conventional defense measures.
6 months ago
Kill Chain
Critical W3 Total Cache Plugin Vulnerability Enables PHP Command Injection on WordPress Sites
In June 2024, a critical security vulnerability was disclosed in the W3 Total Cache WordPress plugin, which is widely used to optimize website performance. Attackers could exploit this flaw by submitting a specially crafted comment to a vulnerable website, enabling them to execute arbitrary PHP commands on the underlying server. This vulnerability, involving insufficient sanitization and validation within comment processing, exposes affected websites to full compromise, including unauthorized data access, web defacement, and further lateral movement inside hosting environments. Immediate patching is required as active exploitation has been observed in the wild. This incident underscores the persistent risk of supply chain attacks and plugin vulnerabilities in content management systems like WordPress. As attackers increasingly target high-profile plugins to gain initial access, maintaining up-to-date software and implementing robust security controls has never been more critical.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports