✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Ransomware Disrupts European Airports in 2025: HardBit & SonicWall VPN Exploit
In September 2025, a coordinated HardBit ransomware attack caused significant operational disruptions across several European airports. The attack exploited a vulnerability in SonicWall SSL VPN devices (CVE-2024-40766), allowing threat actors to bypass multi-factor authentication and gain unauthorized access to critical infrastructure. Prompt law enforcement action led to the arrest of an initial suspect by the UK’s National Crime Agency, though details remain limited as investigations continue. The attack, labeled by researchers as primitive yet effective, underscores how quickly threat actors are leveraging both publicly available exploits and compromised credentials to disrupt essential services with ransomware. This event made headlines due to its impact on vital transportation infrastructure and prompted an international response highlighting the growing urgency for robust network segmentation, encrypted traffic measures, and rapid threat detection. The incident also reflects a broader trend of ransomware actors increasingly targeting critical sectors using innovative entry vectors and expanding their global footprint.
6 months ago
Kill Chain
Mobile Malware Soars in Q3 2025: Key Insights from Kaspersky's Global Report
In Q3 2025, Kaspersky reported a significant surge in mobile malware activity, with 47 million attacks prevented globally targeting Android devices with Trojans, adware, banking malware, and ransomware. Threat actors exploited new variants—including BADBOX and sophisticated Trojans like Triada and Fakemoney—utilizing methods such as pre-installed backdoors and malicious app mods. Mobile banking Trojans (especially Mamont and Coper) and region-targeted malware attacks in Turkey, India, Iran, and Germany impacted financial data security and user privacy, highlighting expanding attacker sophistication and supply chain compromise. This incident is critical as it illustrates the rising prevalence and complexity of mobile threats, coinciding with increased ransomware attacks and evolving delivery channels. The continued targeting of financial apps and global user bases signals an urgent need for organizations to strengthen mobile security, visibility, and compliance with privacy mandates.
6 months ago
Kill Chain
ServiceNow AI Agents Breached in 2025 via Second-Order Prompt Injection
In November 2025, security researchers uncovered a novel method by which ServiceNow's Now Assist generative AI platform could be manipulated through second-order prompt injection attacks. By exploiting default configurations and inherent agent-to-agent communication, attackers could coerce agentic AI features into executing unauthorized operations. This exposure allowed malicious actors to access, copy, and exfiltrate sensitive enterprise data without proper user authorization. The attack leverages prompt injection to bypass intended policy boundaries, posing significant data risk to organizations relying on ServiceNow’s AI-driven automations. This incident highlights a growing threat landscape in which AI agent-to-agent interactions are harnessed for sophisticated attacks. With increased enterprise adoption of generative AI and autonomous agents, security around configuration and prompt validation has become mission-critical. Organizations should assess agent communication safeguards and be vigilant against emerging prompt injection and shadow AI risks.
6 months ago
Kill Chain
EdgeStepper: PlushDaemon’s DNS Hijack Shakes Supply Chain Trust
In late 2025, the threat actor PlushDaemon leveraged a custom Go-based implant named EdgeStepper to facilitate a sophisticated supply chain attack targeting organizations relying on automated software updates. By hijacking DNS queries via EdgeStepper, attackers rerouted legitimate update traffic to attacker-controlled infrastructure, covertly delivering malware payloads. This adversary-in-the-middle campaign exploited a weakness in outbound traffic validation and DNS trust, leading to silent compromise of enterprise endpoints through poisoned software update mechanisms. The incident resulted in widespread concerns over supply chain integrity and exposed gaps in security monitoring of encrypted or internal network flows. This incident highlights the growing trend of adversaries exploiting DNS and software supply chains as primary attack vectors. With regulatory and industry focus tightening on secure update mechanisms and zero trust, similar AitM tactics are escalating in both frequency and sophistication, requiring renewed urgency for organizations to enhance detection at the DNS and network boundary layers.
6 months ago
Kill Chain
NHS Flags PoC Exploit for 7-Zip Symlink RCE Vulnerability (CVE-2025-11001)
In November 2025, NHS England Digital issued an advisory regarding a significant vulnerability (CVE-2025-11001) in the popular 7-Zip compression software. While no active in-the-wild exploitation was detected, a publicly available proof-of-concept (PoC) exploit for a symbolic link–based remote code execution (RCE) flaw raised concerns of imminent risk. The flaw, if exploited, could allow attackers to execute arbitrary code on systems using 7-Zip, threatening the confidentiality, integrity, and availability of healthcare data critical to NHS operations. Security teams were urged to prioritize patching and closely monitor for suspicious activity. This incident highlights a broader industry trend: attackers are rapidly weaponizing PoC exploits for newly disclosed vulnerabilities, targeting widely used utilities to enable lateral movement and privilege escalation. The urgency of patching and proactive threat detection has never been greater, especially for organizations in regulated sectors like healthcare.
6 months ago
Kill Chain
WhatsApp Hijack: Eternidade Stealer Campaign Hits Brazilian Users via Python Worm
In November 2025, cybersecurity researchers identified a sophisticated campaign targeting Brazilian users via WhatsApp, where attackers leveraged a Python-based worm combined with social engineering tactics. Victims were tricked into installing a worm that hijacked WhatsApp sessions and propagated itself to contacts, while delivering a Delphi-based banking trojan known as Eternidade Stealer. The campaign exploited IMAP to dynamically resolve command-and-control infrastructure, enabling threat actors to orchestrate info-stealing and credential harvesting at scale and with resilience to takedown attempts. The incident had significant implications for financial fraud and impacted numerous personal and business WhatsApp accounts across Brazil. This campaign is emblematic of a wider surge in malware leveraging messaging platforms for lateral movement and rapid propagation. The popularity of WhatsApp, combined with increasingly modular infostealers and TTP reuse by criminal groups, highlights the urgent need for proactive controls and visibility across both east-west and outbound communication paths.
6 months ago
Kill Chain
Cloudflare's 2024 Outage: How a Simple Misconfiguration Led to Global Disruption
In June 2024, Cloudflare, a leading cloud services provider, experienced a major global outage initially suspected to be the result of a distributed denial-of-service (DDoS) attack. Further investigation revealed that the real cause was an internal configuration error: a routine permissions update inadvertently triggered a critical software failure within network infrastructure, disrupting access to innumerable customer websites and business services for several hours worldwide. The incident underscored the fragile interplay between automated change management and resiliency of cloud-based operations. This outage is especially timely as organizations accelerate cloud adoption and automation, increasing their susceptibility to operational lapses and accidental misconfigurations. Regulatory bodies and industry frameworks are now sharpening requirements for cloud governance, real-time visibility, and robust change controls to mitigate such risks.
6 months ago
Kill Chain
Anatomy of an Akira Ransomware Attack: 42 Days Hidden After a Fake CAPTCHA
In early 2024, a sophisticated cyberattack attributed to the Akira ransomware group exploited a fake CAPTCHA page to infiltrate an organization's environment. Attackers used this social engineering technique as an entry point, deploying malware that enabled persistent access and undetected movement across internal systems for 42 days. During this period, lateral movement and privilege escalation allowed the attackers to exfiltrate data and ultimately deploy ransomware, encrypting vital business assets and causing significant operational disruption. The incident illustrates how modern ransomware actors leverage stealth, deception, and extended dwell times to maximize their impact. This case underscores an escalating trend of increasingly complex and targeted ransomware attacks that blend technical exploitation with effective social engineering. Organizations are being challenged to enhance east-west traffic security, real-time threat detection, and zero trust segmentation to counter these evolving threats.
6 months ago
Kill Chain
Unicode: The Hidden Security Threat Fueling 2024's Obfuscated Code Attacks
In late 2024, security researchers highlighted a series of application security vulnerabilities caused by improper handling of the Unicode character set, impacting numerous platforms and development environments. Attackers exploited Unicode features such as confusable characters, variant selectors, and bidirectional text markers, enabling impersonation, injection, and severe obfuscation of code in public repositories. Notably, a self-propagating worm known as "Glass Worm" leveraged invisible Unicode code points to disguise malicious code in Visual Studio Code extensions, bypassing manual code review and automated security checks. These techniques led to increased risk of code injection, credential spoofing, and long-term compromise of software supply chains. Unicode-driven attack techniques continue to gain prominence due to their effectiveness at evading human and automated detection. The recent spike in attacks demonstrates a broader trend towards supply chain risk and advanced code obfuscation, demanding urgent attention to Unicode normalization, secure coding practices, and robust detection mechanisms in compliance-driven industries.
6 months ago
Kill Chain
Malicious NPM Packages Exploit Adspect in 2024 Supply Chain Breach
In June 2024, security researchers uncovered a supply chain attack involving seven malicious packages on the NPM registry that abused the Adspect cloud-based service. Attackers used these packages to redirect users through Adspect, circumventing many security sandboxes and researcher analysis tools. This sophisticated evasion allowed threat actors to selectively route potential victims to malicious payloads while deflecting scrutiny from security firms. The malicious packages were rapidly removed from NPM, but not before posing a significant risk to open-source software supply chains. This incident highlights the increasing exploitation of trusted third-party platforms and infrastructure in software supply chain attacks. With adversaries leveraging evasive redirects and advanced obfuscation tactics, organizations face a growing need for robust dependency management, automated threat detection, and enhanced monitoring of public code repositories.
6 months ago
Kill Chain
Hackers Exploit Ray AI to Launch Global Cryptojacking Botnet (2024)
In late 2024, malicious actors exploited an unauthenticated remote code execution vulnerability (CVE-2023-48022) in the open-source Ray AI framework, transforming exposed development environments into a globally distributed cryptojacking operation. Attackers leveraged Ray's scheduling and orchestration APIs to gain unauthorized access and deploy cryptomining payloads, particularly targeting environments with premium NVIDIA A100 GPUs. The campaign, identified by Oligo Security, unfolded in multiple phases: after initial malware delivery via GitLab infrastructure was disrupted, attackers quickly shifted to hosting on GitHub to sustain their operation. Over 200,000 exposed Ray clusters worldwide were at risk, significantly impacting cloud AI operations, startups, and research environments. This incident marks a major evolution in threat actor adaptation: rather than exploiting traditional network vulnerabilities, adversaries weaponized trusted automation features to evade detection and maximize illicit gain. The campaign illustrates mounting risks to cloud-hosted AI workloads, the dangers of insecure API exposure, and the urgent need for stringent internal network controls to defend against cryptojacking and abuse of compute resources.
6 months ago
Kill Chain
CISA 2025 Issues Guidance to Mitigate Bulletproof Hosting Provider Risks
In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA), together with the NSA, FBI, Department of Defense Cyber Crime Center, and international partners, released comprehensive guidance to combat risks posed by Bulletproof Hosting Providers (BPHs). BPHs are infrastructure providers that knowingly lease servers and networking resources to cybercriminals, enabling ransomware, phishing, malware distribution, and denial-of-service attacks at scale. The guidance urges Internet Service Providers and network operators to apply blocklists, traffic analysis, intelligence sharing, and stronger vetting to prevent malicious actors from exploiting BPH resources, aiming to bolster the digital resilience of critical infrastructure sectors globally. The ongoing proliferation of cyberattacks leveraging BPH infrastructure underscores the urgency of these recommendations. With threat actors increasingly turning to anonymized, resilient hosting to evade law enforcement and detection, proactive mitigation by ISPs is crucial to limiting damage and strengthening industry-wide cybersecurity defense.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports