✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Microsoft Azure Faces Unprecedented 15 Tbps DDoS Attack Driven by Aisuru Botnet
In June 2024, Microsoft revealed that its Azure cloud network was targeted by the Aisuru botnet in a record-breaking Distributed Denial-of-Service (DDoS) attack that peaked at 15.72 terabits per second. The attack leveraged over 500,000 globally distributed IP addresses to inundate Azure’s infrastructure, demonstrating sophisticated command and control and massive botnet scale. Microsoft successfully mitigated the assault, which represented the largest DDoS attack it had ever recorded, but the event highlighted the evolving threat landscape and ongoing attacker focus on major cloud service providers. The incident is highly relevant today as DDoS tactics grow in scale and complexity, frequently outpacing conventional network defenses. The use of enormous botnets like Aisuru and automated attack infrastructure underscores the urgent need for advanced mitigation, segmentation, and resilient cloud architectures across all industries.
6 months ago
Kill Chain
Eurofiber France Data Breach 2024: Ticket System Compromise Exposes Customer Records
In June 2024, Eurofiber France disclosed a significant data breach after its ticket management system was compromised by threat actors who exploited a vulnerability. The attackers gained unauthorized access to the ticketing platform, proceeding to exfiltrate customer data before attempting to sell it on an underground forum. The breach exposed personal and business information, prompting notification to affected clients and regulatory authorities, and forced Eurofiber to review and enhance its internal security measures. This incident highlights the persistent targeting of essential infrastructure vendors via vulnerable business applications, such as ticketing systems. It reflects the growing risks of data exfiltration and underground marketplaces, prompting renewed scrutiny on third-party software security and compliance requirements.
6 months ago
Kill Chain
Princeton University Data Breach Exposes Alumni and Donor Information
On November 10, 2023, Princeton University experienced a significant data breach when unauthorized actors gained access to a university database containing sensitive information on alumni, donors, students, and faculty. The intrusion exposed personal details such as names, contact information, and donation records, with initial reports indicating the compromise originated from the university’s advancement and fundraising systems. Princeton moved quickly to secure impacted systems, notify affected individuals, and engage cybersecurity experts and law enforcement. The exposure raises concerns regarding the safeguarding of high-value personal and financial data held by educational institutions. This incident underscores the persistent threat higher education institutions face from cyberattacks targeting personal and philanthropic data. The Princeton breach highlights a surge in attacks exploiting third-party platforms and unencrypted internal data flows, aligning with broader trends toward increased ransomware and data extortion pressures observed throughout 2023.
6 months ago
Kill Chain
RondoDox Botnet Turns XWiki Flaw into Malware Launchpad in 2025
In June 2025, the RondoDox botnet began exploiting a critical remote code execution (RCE) vulnerability tracked as CVE-2025-24893 in the widely used XWiki platform. Threat actors leveraged this zero-day flaw to gain unauthorized control of vulnerable servers, rapidly conscripting them into a growing botnet for malicious purposes, including distributed denial-of-service (DDoS) attacks and potential data theft. Victims included enterprises and service providers relying on exposed or poorly-secured XWiki installations, with incident response teams rushing to contain infections and patch affected systems. This incident exemplifies the increasing sophistication of botnets that exploit newly-disclosed vulnerabilities, highlighting persistent risks to organizations running unpatched collaborative or CMS platforms. The trend underscores an urgent need for proactive vulnerability management, robust segmentation, and real-time traffic monitoring.
6 months ago
Kill Chain
Ransomware at a Breaking Point: 85 New Gangs and LockBit’s 2025 Re-Emergence
In Q3 2025, the ransomware threat landscape reached unprecedented fragmentation with 85 active ransomware and extortion groups, including the high-profile resurgence of LockBit following international law enforcement takedowns. Attackers targeted organizations across sectors, leveraging decentralized affiliate models to rapidly launch new ransomware 'brands' — 14 of which debuted this quarter. Tactics included sophisticated lateral movement, exploit of unencrypted east-west traffic, and multifaceted extortion through leak sites. Over 1,590 public victim disclosures underscored the sustained operational tempo, with significant financial and reputational losses reported by victims. This incident signals new urgency for defenders, as ransomware operations grow increasingly resilient and adaptive. The proliferation of new actor groups, coupled with a strong affiliate network and advanced techniques, means that traditional prevention strategies are being routinely bypassed, demanding adoption of modern security controls aligned to emerging frameworks and zero trust principles.
6 months ago
Kill Chain
APT42’s ‘SpearSpecter’: Iranian State Hackers Breach Defense & Government Targets in 2025
In September 2025, the Iranian state-sponsored threat group APT42 launched a targeted cyber-espionage campaign, codenamed 'SpearSpecter', against global defense and government organizations with ties or relevance to the Iranian Islamic Revolutionary Guard Corps (IRGC). Attackers employed spear-phishing and advanced malware to infiltrate internal systems, establish encrypted backdoors, and move laterally, aiming to gather intelligence and monitor sensitive communications. The operation has compromised multiple agencies, with impacts including loss of classified data and exposure of critical government operations. This incident underscores the intensifying sophistication of state-sponsored actors leveraging advanced persistence techniques and custom tooling to evade detection. These campaigns highlight the persistent threat posed by geopolitically motivated attacks and the urgent need for robust intrusion detection and segmenting sensitive assets.
6 months ago
Kill Chain
Dragon Breath Breaches Defenses: RONINGLOADER Deploys Gh0st RAT in Sophisticated 2025 Attack
In November 2025, the threat actor group known as Dragon Breath launched a targeted cyber campaign aimed at Chinese-speaking users, leveraging a sophisticated multi-stage loader called RONINGLOADER. By deploying trojanized NSIS installers disguised as popular applications like Google Chrome and Microsoft Teams, attackers successfully delivered a modified variant of Gh0st RAT. The malware chain allowed adversaries to bypass security tools, perform covert surveillance, and remotely exfiltrate sensitive data from compromised systems, achieving persistent access and extensive control over infected endpoints. This incident highlights the increasing use of advanced loader chains and tailored social engineering vectors to breach defenses. It reflects a broader trend in cyber threats shifting towards multi-stage, modular attacks capable of disabling endpoint protections and evading detection through highly customized payloads and targeted distribution tactics.
6 months ago
Kill Chain
How ClickFix-Driven EVALUSION Attacks Delivered Amatera Stealer and NetSupport RAT in 2025
In June 2025, a threat campaign tracked as 'EVALUSION' leveraged sophisticated ClickFix social engineering lures to distribute the Amatera Stealer and NetSupport RAT. Cybersecurity researchers observed the attackers primarily targeting organizations through crafted phishing emails and malicious web downloads, enticing victims to execute payloads. Once inside, Amatera Stealer—an evolution of previous AcridRain infostealer variants—exfiltrated credentials and system information, while NetSupport RAT enabled persistent remote control. This resulted in a significant compromise of sensitive data and elevated risks of follow-on attacks, including lateral movement and further intrusions across corporate networks. This incident highlights the rapid professionalization and diversification of infostealer toolkits. The growing adoption of ClickFix social engineering and commodity remote access tools by organized threat actors magnifies data exposure and regulatory risks, especially as hybrid and multi-cloud attack surfaces expand.
6 months ago
Kill Chain
Microsoft Patch Tuesday November 2025: Zero-Day & Critical Vulnerabilities Impact Enterprise Security
In November 2025, Microsoft released patches to address over 60 vulnerabilities affecting Windows operating systems and a broad suite of its applications, including Office, SQL Server, Visual Studio, and Azure Monitor Agent. Notably, this cycle contained at least one actively exploited zero-day flaw (CVE-2025-62215), a memory corruption vulnerability requiring local access, as well as a critical GDI+ bug (CVE-2025-60274) impacting broad swathes of enterprise and third-party applications. Additionally, a low-complexity Office vulnerability (CVE-2025-62199) enabling remote code execution was highlighted as a high priority for patching. Some users also faced complications enrolling in an extended Windows 10 security update program, partially addressed by out-of-band releases. This incident underscores the ongoing acceleration of zero-day and high-impact vulnerabilities targeting ubiquitous enterprise software, making timely patch deployment mission-critical. As the cadence and exploitation of software vulnerabilities increases, organizations must bolster patch management processes and align with evolving regulatory pressures to minimize risk exposure.
6 months ago
Kill Chain
Fortinet 2025: Multi-Vector AI Campaign Disrupts Global Networks
In early November 2025, a coordinated multi-vector campaign targeted Fortinet infrastructure worldwide, exploiting unpatched vulnerabilities in FortiGate VPN appliances. Attackers—some with ties to Chinese state-affiliated threat groups—combined AI-driven phishing-as-a-service (PhaaS) toolkits, malicious code deployment, and supply chain manipulation to bypass legacy perimeter defenses. The campaign leveraged trusted encrypted channels and cloud infrastructure to evade detection, enabling lateral movement and data exfiltration from government agencies, finance firms, and Fortune 500 companies. Cleanup and containment efforts required full infrastructure reviews and forensic triage, disrupting operations across multiple sectors. This incident exemplifies the accelerating convergence of advanced attacker automation, trusted-tool abuse (AI, VPNs), and commercial cybercrime platforms. Organizations must urgently address gaps in segmentation, encrypted traffic inspection, and detection controls to withstand increasingly stealthy, multi-stage attacks.
6 months ago
Kill Chain
Cursor Vulnerability: AI Code Assistant Supply-Chain Flaw Exposes Credentials
In early 2024, security researchers uncovered a significant supply-chain vulnerability affecting Cursor, an AI-powered coding assistant, enabling attackers to hijack Cursor's internal application browser via a malicious MCP (Model Control Protocol) server. Exploiting this weakness, threat actors could inject malicious code through the compromised server, control the tool’s browser processes, and steal sensitive user credentials, potentially jeopardizing developer environments and broader organizational security. The vulnerability allows attackers to manipulate trusted workspace sessions, escalating the risk of lateral movement within corporate infrastructure. This incident highlights the increasing risks associated with AI-driven developer tools and the broader supply chain, reflecting a growing attacker focus on abusing trust relationships within cloud-native and collaborative software platforms. Organizations must revisit supply-chain security and adopt robust detection and response strategies for AI-enabled environments.
6 months ago
Kill Chain
US Citizens Busted for Aiding North Korean IT Worker Supply-Chain Fraud in 2024
In 2024, four United States citizens pleaded guilty to helping North Korean nationals surreptitiously secure IT positions at American companies by misrepresenting the workers’ identities and providing remote access to corporate assets. This insider-assisted scheme enabled foreign IT professionals to bypass typical background checks and compliance controls, giving them potential access to sensitive information and intellectual property. The activities ran over a sustained period and leveraged supply-chain weaknesses in remote workforce onboarding and equipment provisioning, ultimately exposing numerous U.S. firms to regulatory and operational risk. This incident underscores a worrying trend in which threat actors exploit remote work arrangements, weak identity verification protocols, and gaps in third-party management—highlighting increased regulatory scrutiny on supply-chain and insider vulnerabilities, especially amid ongoing geopolitical tensions involving North Korea.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports