✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Fortinet FortiWeb Zero-Day Abuse: 2024 Attack Highlights Security Device Risks
In June 2024, Fortinet disclosed a critical zero-day vulnerability in its FortiWeb web application firewall that was being actively exploited in the wild. Threat actors leveraged the unknown flaw to gain unauthorized access to targeted organizations, bypassing authentication and potentially altering application configurations or exfiltrating sensitive data. Fortinet responded promptly by releasing security patches and urging customers to update affected devices, while security researchers warned this campaign was already impacting several organizations before public disclosure. This incident is part of a growing trend of sophisticated attacks targeting network and security appliances through undisclosed vulnerabilities. Organizations face heightened risk as attackers weaponize zero-days more quickly, making swift patch management and layered controls essential to defending digital infrastructure.
6 months ago
Kill Chain
Google Chrome 2024 Zero-Day Exploited in the Wild: What You Need to Know
In June 2024, Google disclosed and patched a critical zero-day vulnerability in the Chrome web browser (CVE-2024-5274) that had actively been exploited in the wild. Attackers leveraged a type confusion flaw in Chrome’s V8 JavaScript engine to execute arbitrary code on victim devices, enabling full compromise of targeted systems. Google's rapid response—releasing an emergency security update—helped mitigate exploitation risks. The vulnerability represented the seventh zero-day affecting Chrome this year, underscoring persistent targeting of popular browsers for initial access into corporate and consumer environments. This incident illustrates the sustained threat posed by browser zero-days and the increasing velocity with which attackers are weaponizing new flaws. As web browsers remain a ubiquitous endpoint attack vector, organizations must ensure rapid patch cycles and layered security controls to limit exposure.
6 months ago
Kill Chain
Microsoft Thwarts Record-Breaking 15.72 Tbps DDoS Attack Orchestrated by AISURU Botnet
In November 2025, Microsoft successfully detected and mitigated an unprecedented Distributed Denial-of-Service (DDoS) attack that peaked at 15.72 Tbps, targeting a cloud endpoint in Australia. The attack, orchestrated by the AISURU botnet leveraging TurboMirai-class malware, generated nearly 3.64 billion packets per second. Advanced protections within Microsoft's Azure platform automatically neutralized the threat before it could affect customer availability or data. Microsoft attributed the attack to highly automated botnets leveraging compromised IoT devices and observed a rapid, multi-vector assault designed to test cloud resilience and incident response. This record-breaking event highlights the escalating scale and sophistication of DDoS activity targeting foundational cloud infrastructure. As attackers exploit larger IoT botnets and novel malware strains, defenders face mounting pressure to evolve detection and mitigation at cloud-scale. Organizations must increasingly invest in robust DDoS protection and continuously monitor for emerging threats.
6 months ago
Kill Chain
ShadowRay 2.0: How Ray Cluster Flaws Fueled a Cryptomining Botnet
In June 2024, cybersecurity researchers identified a coordinated global attack campaign dubbed ShadowRay 2.0 targeting exposed Ray clusters—open-source distributed computing environments widely used in AI and machine learning workloads. Attackers exploited an unpatched remote code execution vulnerability in Ray's dashboard service, gaining unauthorized access to cloud and on-premises clusters. Once inside, adversaries deployed self-spreading cryptomining malware, turning infected clusters into part of a large-scale botnet that harnessed high-performance compute resources for illicit cryptocurrency mining, causing potential performance degradation, elevated cloud bills, and risk of further lateral movement. This campaign demonstrates the growing threat surface posed by AI and data infrastructure, as adversaries increasingly automate the exploitation of software supply chain and configuration weaknesses. The incident highlights the urgency of securing east-west traffic, enforcing least privilege, and maintaining continuous vulnerability management in distributed and cloud-native environments.
6 months ago
Kill Chain
npm Supply-Chain Threat: Seven Malicious Packages Cloak Crypto Scams in 2025
In late 2025, cybersecurity researchers uncovered a supply-chain attack involving seven malicious npm packages uploaded by the threat actor 'dino_reborn.' These packages leveraged Adspect cloaking technology to detect if visitors were victims or security researchers. Unsuspecting users were redirected to fraudulent cryptocurrency-themed websites, exposing them to potential scams or malware. The packages were published between September and November 2025 and remained available until detection, highlighting the challenges in securing open-source ecosystems. This incident is part of a growing trend involving supply-chain attacks targeting widely used software repositories. As more attackers adopt advanced evasion measures like traffic cloaking and nuanced social engineering, the risk and complexity of defending modern development pipelines are rapidly increasing.
6 months ago
Kill Chain
Researchers Reveal Tuoni C2’s Role in 2025 Real-Estate Cyber Attack
In early November 2025, a prominent U.S.-based real-estate company was targeted in a sophisticated cyber attack utilizing the Tuoni command-and-control (C2) framework, a new red-teaming tool known for implementing stealthy, in-memory payload delivery. The attackers exploited Tuoni C2’s advanced capabilities to infiltrate the network while evading traditional security controls, demonstrating lateral movement and attempting data collection within internal segments. Although swift detection halted major exfiltration, the intrusion highlighted gaps in east-west traffic visibility and segmentation, causing temporary disruption to key business systems and prompting an urgent review of internal controls. This attack underscores the growing trend of adversaries adopting novel, freely available C2 tools to bypass existing enterprise defenses. It reflects broader industry concern as C2 frameworks like Tuoni fuel increased attack sophistication, especially in sectors handling large volumes of sensitive data such as real estate and finance.
6 months ago
Kill Chain
Sneaky 2FA Kit Innovates with BitB Pop-up Phishing: MFA Bypass at Scale
In November 2025, security researchers reported on the evolving Sneaky 2FA Phishing-as-a-Service (PhaaS) kit, which now features sophisticated Browser-in-the-Browser (BitB) pop-ups that convincingly mimic legitimate browser address bars. These enhancements enable threat actors, including low-skilled attackers, to deploy highly realistic phishing attacks at scale and bypass multi-factor authentication (MFA) protections. Victims, typically employees of enterprises and large organizations, are tricked into entering credentials and 2FA codes into deceptive portals, facilitating account compromise and potential unauthorized access to sensitive business assets. This incident highlights a troubling trend of phishing toolkits increasing in sophistication, making advanced attacks accessible to broader criminal audiences. Organizations are now facing growing regulatory and operational pressure to update authentication, identity protection, and detection controls amid a wave of phishing leveraging MFA bypass and deceptive visual TTPs.
6 months ago
Kill Chain
CISA Flags Critical Fortinet FortiWeb Vulnerability: CVE-2025-58034 Joins KEV Catalog
In November 2025, CISA added CVE-2025-58034, a Fortinet FortiWeb OS Command Code Injection vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of in-the-wild exploitation against internet-exposed FortiWeb appliances. Threat actors leveraged this critical flaw to execute arbitrary system commands remotely, enabling them to gain unauthorized access, pivot laterally, or deploy additional malware. The urgency was amplified by ongoing exploitation and a recently published Fortinet security advisory, prompting CISA to recommend an accelerated one-week remediation deadline for federal and enterprise environments. This incident exemplifies the continued targeting of web application infrastructure by attackers exploiting unpatched devices. The rapid exploitation timeline, coupled with directives like BOD 23-02, highlights the increasing regulatory focus and operational risk posed by known—but unremediated—vulnerabilities in public-facing systems.
6 months ago
Kill Chain
Malicious npm Packages Leverage Adspect Cloaking to Fuel Crypto Supply Chain Scam (2024)
In early 2024, a sophisticated supply chain attack was uncovered involving a wave of malicious npm packages that abused Adspect cloaking techniques to avoid detection. Attackers published seemingly benign JavaScript libraries to the official npm registry. Once installed, these packages deployed malware via fake cryptocurrency-related sites, using cloaking to distinguish between legitimate victims and security researchers. The campaign allowed threat actors to evade automated scans, maximize the longevity of their malicious payloads, and target developers and end users with credential theft and crypto scams. This incident highlights the evolving threat landscape around open-source software supply chains. The use of advanced traffic cloaking and victim filtering marks a new escalation in attacker TTPs, forcing organizations to revisit how they vet third-party dependencies and monitor developer ecosystems for hidden threats.
6 months ago
Kill Chain
KongTuke 2025: Real-World Insights from a Fake CAPTCHA Malware Campaign
In November 2025, the KongTuke threat actor (also referenced as LandUpdate808 or TAG-124) orchestrated a malware campaign leveraging sophisticated Traffic Distribution System (TDS) techniques. The attackers compromised legitimate websites by injecting malicious scripts that displayed fake CAPTCHA pages designed to lure victims into executing clipboard-injected PowerShell commands. Once executed, these commands downloaded a ZIP archive containing a Windows-compatible Python environment and a malicious Python script, which established persistence via scheduled tasks and generated encrypted HTTPS traffic to external infrastructure. The infection sequence was confirmed within Active Directory environments, highlighting the attacker's ability to evade detection and automate persistence. This incident underscores an increasing trend in malware distribution leveraging trusted websites as initial access vectors, blending social engineering with technical innovation. Organizations should take note of the evolving sophistication in initial lure tactics and persistence mechanisms, as such approaches complicate traditional detection methods and pose substantial risk to enterprise endpoints.
6 months ago
Kill Chain
Fortinet’s Silent Patch Leaves FortiWeb Customers Exposed to Critical Exploit in 2024
In October 2024, Fortinet faced significant criticism after a critical vulnerability (CVE-2025-64446) in its FortiWeb application firewall was exploited by attackers before the flaw was publicly disclosed or a CVE was assigned. Although a patch was silently released on October 28, public notification and technical details were delayed for over two weeks, leaving customers unaware of the immediate risk posed by the vulnerability. During this window, attackers leveraged a path-traversal bug to gain administrative command execution and persistent access, potentially compromising affected infrastructures and evading detection until after widespread exploitation was underway. This incident highlights the increasing risk that delayed vulnerability disclosures pose to organizations, as attackers can weaponize defects before defenders are informed. The event has intensified calls for timely vendor transparency and reinforced scrutiny from regulators as the cyber threat landscape evolves toward faster exploitation cycles and greater demands for coordinated defensive action.
6 months ago
Kill Chain
Pennsylvania Attorney General Hit by Ransomware: 2025 Data Breach Exposes Medical Information
In August 2025, the office of Pennsylvania's Attorney General fell victim to a ransomware attack orchestrated by the INC Ransom group. Attackers infiltrated internal networks and subsequently encrypted critical systems, ultimately exfiltrating files containing sensitive information, including personal and medical data belonging to individuals engaged with the office. The breach disrupted business operations and prompted an immediate investigation and regulatory disclosure. Investigators found that the attackers leveraged privilege escalation, moved laterally within the network, and evaded basic security controls, showcasing the advanced tactics employed by today’s ransomware operators. This incident highlights the growing threat of sophisticated ransomware gangs targeting public sector entities, expanding their focus to sensitive government-held data. The frequency and impact of ransomware incidents on critical services underscore an urgent need for robust segmentation, modern encryption, and relentless threat monitoring.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports