✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Flood of Fake npm Packages Reveals Growing Supply Chain Attack Risk
In early 2024, a financially-motivated threat actor orchestrated a large-scale spam campaign that flooded the npm package registry with over 67,000 fake packages. By systematically publishing malicious and junk modules, the actor exploited npm’s open nature, allowing the fake packages to persist on the platform for nearly two years. These packages, often uploaded with auto-generated names and code, increased risks for developers by inflating dependency confusion attack surfaces and potentially delivering malware through the software supply chain. The incident underscored ongoing challenges in detecting and mitigating large-scale abuse within open-source ecosystems, disrupting trust and reliability for countless organizations relying on npm. This attack is emblematic of a wider trend in software supply-chain targeting, with threat actors increasingly exploiting public repositories to propagate malicious code or disrupt developer workflows. As software supply chains remain a critical risk focal point, organizations face mounting regulatory scrutiny and require robust governance and anomaly detection controls to safeguard development environments.
6 months ago
Kill Chain
Inside the Cisco 2025 Multi-Vector Breach: 0-Days, State Actors, and Encrypted Threats
In November 2025, Cisco experienced a sophisticated multi-vector cyberattack that leveraged previously unknown zero-day vulnerabilities across its networking equipment. Attackers combined techniques such as encrypted traffic evasion, lateral movement, and zero-trust segmentation bypasses, using advanced tools to avoid detection and compromise both east-west and north-south flows. The intrusion enabled threat actors—suspected of state affiliation—to exfiltrate internal data, disrupt encrypted hybrid connections, and potentially impact customer networks on a global scale before the breach was identified and contained. This incident highlights an emerging trend: attackers are orchestrating multiple, layered techniques to exploit evolving environments, such as hybrid and multi-cloud infrastructure. As organizations rely on AI-driven security and expand east-west traffic, defenders face increased complexity, raising the urgency for integrated, visibility-rich, and compliance-driven zero trust architectures.
6 months ago
Kill Chain
CISA Flags Critical WatchGuard Fireware Flaw: 54,000 Fireboxes at Risk from Unauthenticated Attacks
In November 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-9242, a critical out-of-bounds write vulnerability in WatchGuard Fireware OS, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. Attackers leveraged this flaw—rated CVSS 9.3—to gain unauthenticated remote access to over 54,000 exposed WatchGuard Firebox appliances worldwide, enabling potential system compromise and lateral network movement. The vulnerability affects Fireware OS versions 11.10.2 through recent releases, putting a significant number of network security devices at risk. This incident highlights the urgent need for aggressive patching and improved visibility into network infrastructure exposures. With attackers increasingly targeting edge devices and exploiting unpatched vulnerabilities, organizations must prioritize vulnerability management and zero trust network segmentation to contain emerging threats.
6 months ago
Kill Chain
Operation Endgame 2025: Law Enforcement Disrupts Rhadamanthys, Venom RAT, and Elysium Botnet
Between November 10 and 13, 2025, international law enforcement agencies led by Europol and Eurojust conducted Operation Endgame, a sweeping crackdown targeting malicious cyber infrastructures. The operation succeeded in dismantling key components of the Rhadamanthys Stealer, Venom RAT, and Elysium botnet, disrupting networks that facilitated global credential theft, remote access, and command-and-control activities. The coordinated seizures involved simultaneous server takedowns across multiple countries and the arrest of key individuals behind these malware operations, significantly diminishing the power and reach of these cybercriminal networks. This incident highlights an increasing trend of robust international cooperation in targeting advanced malware and botnet ecosystems. The disruption of these criminal infrastructures sends a strong message to threat actors, demonstrating both the technical capabilities and resolve of law enforcement to combat cybercrime at scale.
6 months ago
Kill Chain
2024 Salesloft-Drift Supply Chain Breach: AWS Credential Exposure and Cloud Security Lessons
In early 2024, a sophisticated supply chain attack targeted the Salesloft and Drift integration, leading to the compromise of AWS credentials and unauthorized access to cloud environments. Threat actors exploited weaknesses in the integration pipeline, leveraging exposed secrets to move laterally and access sensitive customer data before the breach became public. Red Canary detected anomalous cloud activity tied to this attack, providing early detection prior to broad public awareness and response, thereby helping to mitigate further impact. This incident is significant as it demonstrates the growing frequency and sophistication of supply chain attacks within SaaS and cloud services, especially those exploiting secret leaks and third-party application integrations. The breach highlights the need for heightened vigilance, identity and credential protection, and advanced threat detection capabilities in the cloud ecosystem.
6 months ago
Kill Chain
Akira Ransomware 2025: How Edge Device Vulnerabilities Fueled Infrastructure Attacks
In November 2025, the Akira ransomware group and affiliates such as Storm-1567 and Howling Scorpius intensified attacks on critical infrastructure sectors by exploiting edge device and backup server vulnerabilities. Threat actors leveraged techniques including authentication bypass, brute-force credential attacks, and the deployment of new Akira_v2 malware for rapid encryption. Their sophisticated methods involved lateral movement through RDP/SSH, defense evasion with remote tools (Anydesk, LogMeIn), disabling security controls, and stealthy data exfiltration via FTP/SFTP/cloud channels. Impacted sectors ranged from Manufacturing and Education to Healthcare and Finance, resulting in encrypted systems, data theft, and serious operational disruption. This incident underscores the persistent evolution of ransomware tactics and the growing threat to organizations of all sizes. The prevalence of supply chain risks, rapid malware adaptation, and exploitation of misconfigured or outdated security perimeters demand continuous vigilance and investment in advanced detection, rapid patching, and segmentation strategies.
6 months ago
Kill Chain
CitrixBleed 2: New Zero-Day Storm Hits Identity and Network Gateways
In early 2025, security teams discovered active exploitation of two newly identified zero-day vulnerabilities: CVE-2025-5777 in Citrix NetScaler and CVE-2025-20337 in Cisco Identity Service Engine (ISE). An advanced persistent threat (APT) group rapidly targeted both flaws, focusing on critical infrastructure where identity and access management systems form the backbone of secure connectivity. Attackers leveraged these zero-days to bypass authentication and elevate privileges, enabling lateral movement across east-west network segments and exfiltrating sensitive data. The incident underscores the risks posed by unpatched identity infrastructure in enterprise environments, leading to operational disruptions and an urgent patch response from affected vendors. This breach highlights a surge in sophisticated campaigns targeting the convergence of networking and identity technologies. The focus on identity-driven systems, rapid weaponization of zero-day exploits, and threat actors’ ability to pivot between vendors reinforce the growing challenge organizations face in defending mission-critical services amid a shifting risk landscape.
6 months ago
Kill Chain
Coyote & Maverick Banking Trojans: 2024 Banking Attacks Sweep Brazil
In 2024, cybersecurity researchers observed a surge in banking Trojan activity in Brazil, notably from two malware strains named Coyote and Maverick. These Trojans specifically target financial institutions and individual banking customers by using advanced phishing campaigns, malicious email attachments, and fake banking apps to infiltrate devices. Once installed, they deploy credential-stealing modules, monitor browser activity, and intercept authentication data, often leveraging encrypted and east-west network traffic to evade security controls. Maverick is engineered to self-terminate if it detects a target located outside Brazil, indicating a strong geo-targeting component. The campaign’s impact includes stolen banking credentials, financial fraud, and operational disruption for affected users and banks in the region. The continued advancement and targeted nature of these Brazilian banking Trojans demonstrate a significant evolution in threat actor sophistication, especially toward region-specific attacks. Organizations need to heighten their defenses and monitor emerging tactics as financially motivated cybercrime rises across Latin America.
6 months ago
Kill Chain
SmartApeSG Leverages ClickFix Fake CAPTCHA Pages to Spread NetSupport RAT (2024)
In November 2024, the SmartApeSG campaign shifted tactics by leveraging ClickFix-style fake CAPTCHA pages to deliver the NetSupport RAT, a powerful remote access trojan. Threat actors compromised websites by injecting malicious scripts that, under specific conditions, displayed convincing 'verify you are human' prompts. Unsuspecting users, influenced by the fraudulent CAPTCHA, executed clipboard-injected commands that downloaded and ran NetSupport RAT on their Windows systems, establishing persistent access via Start Menu shortcuts. The campaign was notable for its adaptation and the regular rotation of malicious infrastructure. This incident highlights a rising trend of social engineering combined with hands-on-keyboard malware delivery. The use of fake CAPTCHA solutions is proliferating, making traditional email-filter and endpoint controls less effective. Organizations should be aware of evolving attack chains and regularly review user education programs to counter these sophisticated lures.
6 months ago
Kill Chain
Breakdown: 2024 FormBook Infostealer Delivered via Multi-Stage Script Obfuscation
In November 2024, a sophisticated email campaign delivered the FormBook infostealer via a series of obfuscated scripts. Attackers distributed malicious ZIP email attachments containing an obfuscated VBS file, which initiated multiple layers of PowerShell-based deobfuscation and payload retrieval. The staged infection successfully bypassed standard detection tools by employing complex anti-analysis techniques, eventually injecting FormBook into a legitimate process and establishing command and control through a remote server. Impacts included potential credential theft, session hijacking, and risk of lateral movement within affected organizations. This incident highlights the increasing use of multi-stage script-based delivery vectors and advanced obfuscation in commodity malware campaigns. Detection challenges are heightened as attackers combine legacy script formats and cloud hosting services to evade conventional endpoint security controls and deliver persistent infostealing payloads.
6 months ago
Kill Chain
Operation Endgame 2024: Global Law Enforcement Strikes Down Major Malware Networks
In November 2024, a coalition of law enforcement agencies from 11 countries coordinated Operation Endgame, a major crackdown disrupting some of the most prolific malware networks globally. The operation targeted Rhadamanthys infostealer, VenomRAT remote access trojan, and the Elysium botnet—malware that collectively infected hundreds of thousands of computers and enabled the theft of millions of credentials. Authorities arrested the principal VenomRAT suspect in Greece, searched 11 sites across Europe, and dismantled more than 1,000 criminal servers and 20 illicit domains. With assistance from 30-plus cybersecurity companies, the operation also notified thousands of victims and exposed users of these illicit services, mitigating ongoing criminal campaigns. Operation Endgame underscores the rapidly evolving, cross-border nature of malware infrastructure and the growing need for coordinated responses by both public and private sectors. As attackers innovate and leverage distributed networks to evade law enforcement, regular collaborative enforcement actions and heightened detection capability are now critical to cybersecurity defenses worldwide.
6 months ago
Kill Chain
Rhadamanthys Infostealer Brought Down: Lessons from a Major Malware Disruption
In June 2024, law enforcement and security vendors successfully disrupted the Rhadamanthys infostealer operation, a prominent 'malware-as-a-service' offering used by cybercriminals to harvest sensitive data from infected devices. The takedown resulted in many malware operators reporting loss of access to their command-and-control servers, crippling active campaigns and rendering stolen data inaccessible. This disruption impacted both the malware's customers and the broader illicit ecosystem that depended on Rhadamanthys for credential theft, data exfiltration, and distribution of stolen information for financial gain. The incident highlights growing law enforcement coordination targeting infostealer infrastructure and criminal-as-a-service marketplaces. As infostealers proliferate with new evasion methods, their disruption remains a critical priority for organizations and defenders seeking to reduce exposure to credential theft and secondary breaches.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports