✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
North Korean Threat Actors Weaponize JSON Services for Stealthy Malware Campaigns
In late 2025, security researchers from NVISO identified a new supply chain attack campaign attributed to North Korean threat actors, leveraging popular JSON storage services—such as JSON Keeper, JSONsilo, and npoint.io—to covertly distribute trojanized malware payloads. The attackers embedded malicious code in legitimate-looking coding projects and lured developers, weaponizing widely used file formats and cloud APIs as their delivery mechanism. Consequently, targeted organizations experienced risks of credential theft, data exfiltration, and potential network breaches, with increased threat visibility due to attackers’ creative use of benign infrastructure as covert command and control channels. This incident highlights a broader trend: state-sponsored actors are rapidly innovating malware delivery by abusing cloud-based, trusted SaaS platforms. The use of developer-centric resources and supply chain lures expands attack surfaces and increases risk to technology-driven enterprises, intensifying the need for zero trust controls and supply chain vigilance.
6 months ago
Kill Chain
North Korean Insider Fraud Breach: How US Firms Were Infiltrated in 2024
In early 2024, the U.S. Department of Justice announced that five individuals pleaded guilty to helping North Korean operatives illicitly obtain remote IT work with American companies. The accused provided support and deception to facilitate North Korean nationals—working under assumed identities—to infiltrate U.S. organizations in a widespread insider threat campaign. These operatives gained access to proprietary data and corporate resources, generating significant revenue for North Korea through fraudulently obtained salaries, often paid in cryptocurrency. The scheme exploited remote work arrangements and weaknesses in identity verification, posing serious risks to sensitive sectors and exposing organizations to data theft and compliance violations. This case illustrates the increasing sophistication of insider threat attacks using stolen or falsified identities, especially targeting remote workforces. Organizations face growing urgency to enhance zero trust security, segment lateral movement, and strengthen controls for detecting and verifying remote personnel as geopolitical actors intensify efforts to bypass western sanctions and exploit globalized IT supply chains.
6 months ago
Kill Chain
Fortinet 2025: Chained FortiWeb Flaws Enable Remote Code Execution and Privilege Escalation
In November 2025, Fortinet disclosed two critical vulnerabilities (CVE-2025-64446 and CVE-2025-58034) affecting multiple versions of its FortiWeb web application firewall. Exploited as a chained attack, the first flaw—relative path traversal—enabled unauthenticated attackers to execute administrative commands via crafted HTTP/HTTPS requests, while the second—OS command injection—allowed privilege escalation and execution of unauthorized code by authenticated users. Security agencies confirmed observed exploitation in the wild, with potential impact including network compromise, lateral movement, and loss of control over critical web applications. Fortinet and CISA urged immediate upgrades and review of affected deployments. This incident underscores a broader trend of adversaries targeting internet-facing security appliances as entry points, chaining vulnerabilities for deeper network access. The rapid inclusion of these CVEs in CISA’s Known Exploited Vulnerabilities catalog reflects the elevated urgency and broader risk to organizations across sectors relying on web application firewalls as a key security control.
6 months ago
Kill Chain
Matryoshka Malware: How Attackers hide Exploits in Nested Office Files (2025)
In November 2025, security researchers identified a novel malware delivery technique leveraging Microsoft Office documents mimicking Russian Matryoshka dolls. Attackers embedded a weaponized RTF file exploiting CVE-2017-11882 inside an OOXML Word document, circumventing Microsoft's restrictions on automatic macro execution. Upon opening, the document triggers shellcode that writes a malicious DLL to the user's local Temp directory, which is then executed using an obfuscated command to evade detection. The attack demonstrates advanced evasion tactics, potentially linked to info-stealers such as FormBook, complicating detection and response efforts for organizations relying on traditional file-type controls. This incident highlights the ongoing relevance of document-based exploitation despite reduced macro attacks, as threat actors adopt creative nesting techniques. Security teams must adapt to evolving delivery mechanisms that circumvent recent platform protections, making layered defenses and behavioral detection increasingly essential.
6 months ago
Kill Chain
Clop Ransomware Hits Washington Post via Oracle Zero-Day in 2024
In July and August 2024, The Washington Post fell victim to a cyberattack orchestrated by the Clop ransomware group, which exploited a zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite. Attackers accessed the company’s Oracle environment for over six weeks, ultimately stealing sensitive HR data on nearly 10,000 current and former employees and contractors, including names, bank account details, and Social Security numbers. The breach went undetected until late September when Clop contacted executives with extortion demands. The company confirmed the scope of stolen data in late October, after initiating an internal investigation. This incident underscores the growing trend of threat actors leveraging zero-day vulnerabilities in widely used enterprise software to facilitate mass data theft and extortion. With ransomware groups like Clop escalating the use of targeted campaigns against technology supply chains, organizations face heightened exposure to financial, regulatory, and reputational risk.
6 months ago
Kill Chain
FBI Flags Akira Ransomware as Top Threat to US Critical Infrastructure in 2024
In September 2024, federal cyber authorities, including the FBI and CISA, issued a joint advisory detailing the significant threat posed by the Akira ransomware group. First identified in March 2023, Akira employs double-extortion tactics—stealing sensitive data before encrypting systems—to pressure victims for ransom. The group is associated with additional threat actors and has links to the former Conti operation. Akira has accumulated over $244 million in illicit proceeds by targeting small and medium-sized businesses, impacting sectors such as manufacturing, education, healthcare, IT, finance, and agriculture. The group leverages known vulnerabilities in critical infrastructure software, exploits stolen credentials, and uses remote access tools to compromise organizations, often exfiltrating data in just over two hours. The FBI considers Akira among its top five most consequential ransomware variants, reflecting a broader trend of increasingly sophisticated, fast-moving, and costly ransomware attacks. Recent activity highlights the group’s adaptability and operational security, reinforcing the urgent need for organizations to harden defenses as ransomware tactics evolve.
6 months ago
Kill Chain
CISA Flags WatchGuard Firebox Vulnerability: Network Security on High Alert in 2024
In April 2024, the Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive to all federal agencies to patch a critical vulnerability in WatchGuard Firebox firewalls. This flaw, actively exploited in the wild, allowed remote attackers to gain code execution privileges on unpatched devices, placing affected organizations at risk of network compromise. Exploitation was achieved through maliciously crafted requests, providing attackers with unauthorized access, persistence, and the potential to pivot laterally within victim environments. The incident prompted the federal government and private sector organizations to accelerate patch deployment to mitigate ongoing attacks. This breach underscores the persistent threat to network appliances and the importance of rapid vulnerability management as attackers increasingly target edge devices for initial access. The current trend reflects heightened regulatory scrutiny and an evolving attack surface driven by both state and financially motivated threat actors.
6 months ago
Kill Chain
Kerberoasting in 2025: Service Account Risks and Zero Trust Imperatives
In early 2025, a significant cyber incident occurred in which attackers leveraged Kerberoasting techniques to compromise Active Directory (AD) environments. Threat actors exploited weakly protected service accounts to request service tickets, subsequently brute-forcing their encrypted credentials offline. This attack method enabled them to escalate privileges and potentially gain domain administrator access, often without triggering security alerts. The intrusion highlighted shortcomings in credential hygiene, detection capabilities, and adherence to modern encryption standards within corporate IT infrastructures. Operational impacts included increased risk of lateral movement, data exfiltration, and potential business disruption had the attackers established persistent access. Kerberoasting attacks have become more prevalent due to their stealthy nature and the widespread reliance on legacy authentication protocols. As organizations accelerate digital transformation and adopt zero trust models, identity-based threats like these place added emphasis on proactive credential management, monitoring, and compliance with encryption regulations.
6 months ago
Kill Chain
The Washington Post Oracle Supply Chain Breach: Lessons on Third-Party Risk in 2024
In June 2024, The Washington Post began notifying nearly 10,000 employees and contractors that their personal and financial information had been exposed following a breach involving Oracle-managed systems. The incident stemmed from an attack on a third-party vendor, believed to be tied to the widespread theft of cloud-stored data, which granted unauthorized access to sensitive HR and payroll details. The compromise was discovered post-incident, and affected individuals include current and former staff spanning back several years. Although there is no evidence of active misuse, the breach has prompted heightened security reviews. This breach exemplifies escalating risks inherent in supply-chain and third-party systems, with attackers increasingly targeting service providers to access large pools of critical enterprise data. Organizations across all sectors are now under pressure to strengthen controls around third-party integrations to reduce exposure.
6 months ago
Kill Chain
Akira Ransomware Targets Nutanix AHV Linux VMs: 2024 Attack Analysis
In early 2024, threat actors associated with the Akira ransomware group expanded their operations to target Nutanix AHV virtual machines (VMs) running on Linux, according to alerts from CISA and other cybersecurity agencies. By leveraging compromised credentials or exploiting vulnerabilities, attackers gained access to enterprise infrastructure and deployed a Linux-based Akira encryptor capable of encrypting entire Nutanix VM environments. This strategy disrupted critical workloads and led to significant operational downtime, as well as potential data loss and extortion threats for affected organizations. This incident underscores a trend of ransomware groups shifting focus toward virtualization platforms and cloud infrastructure, extending risks beyond traditional endpoints. The Akira campaign highlights the growing sophistication of ransomware TTPs and the urgent need for robust segmentation and lateral movement controls within virtualized environments.
6 months ago
Kill Chain
ImunifyAV RCE Flaw Puts Millions of Linux Websites at Immediate Risk in 2024
In June 2024, a critical remote code execution (RCE) vulnerability was discovered in ImunifyAV, a malware scanner widely deployed on Linux web servers hosting millions of websites globally. Attackers could exploit this unauthenticated flaw to execute arbitrary code on vulnerable servers, potentially gaining full control over hosting environments and compromising customer websites at scale. The flaw threatened the security of hosting providers and their clients, enabling advanced threat actors to launch further attacks, steal data, or deploy additional malware. Immediate patching was required to prevent exploitation in the wild. This incident underscores the increasing risks posed by third-party security tool vulnerabilities, especially in shared and cloud-hosted web environments. Rapid exploitation of newly disclosed software flaws and supply chain attacks continues to rise, highlighting the critical importance of timely patch management and zero trust controls.
6 months ago
Kill Chain
IndonesianFoods npm Worm Floods Registry with 100,000 Packages in Major Supply Chain Incident
In June 2024, the npm package ecosystem was targeted by a self-propagating malware dubbed the 'IndonesianFoods' worm. The worm exploited npm’s open publishing model, rapidly flooding the registry with nearly 100,000 malicious, junk packages at a rate of one every seven seconds. Working autonomously, the malware replicated itself using pre-programmed scripts, creating an unprecedented scale of package spam, which overwhelmed the registry, threatened package discovery, and disrupted normal operations for developers worldwide. No evidence so far points to direct compromise of sensitive data or targeted attacks on organizations, but the overwhelming volume affected the trust and stability of the npm supply chain platform. This event spotlights the vulnerability of open-source ecosystems to automated spam and self-replicating threats, underscoring the growing risk in software supply chains from both criminal and experimental actors. The surge in npm-focused attacks amplifies calls for stronger package validation, improved security automation, and supply-chain controls industry-wide.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports