✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Synnovis 2024 Ransomware Breach: UK Healthcare Services and Patient Data Exposed
In June 2024, Synnovis, a leading UK pathology services provider, suffered a significant ransomware attack that led to operational disruption and the exposure of sensitive patient data. The attack, attributed to Russian-speaking threat actor group Qilin, resulted in widespread IT outages across London hospitals, delaying critical healthcare procedures and temporarily halting diagnostic services. Investigations revealed that attackers were able to steal files containing patient information before encrypting core systems, underscoring the vulnerability of healthcare organizations to ransomware campaigns targeting their critical infrastructure. This incident is emblematic of a surge in highly targeted ransomware attacks against the healthcare sector globally. With a marked increase in double-extortion tactics and operationally disruptive attacks, this event highlights escalating cyber risk, increasing regulatory oversight, and the urgent need for robust cyber-resilience in healthcare.
6 months ago
Kill Chain
Citrix & Cisco Face 2025 Zero-Day Onslaught: Custom Malware Targets Network Cores
In early 2025, a sophisticated threat actor leveraged zero-day vulnerabilities—CVE-2025-5777 ('Citrix Bleed 2') in NetScaler ADC/Gateway and CVE-2025-20337 in Cisco Identity Services Engine (ISE)—to gain initial access into targeted enterprise environments. Exploiting these flaws before vendor patches were available, attackers deployed custom malware to establish persistent command-and-control and facilitate lateral movement, affecting sensitive east-west and outbound network traffic. The advanced nature of this attack enabled the evasion of traditional security controls, resulting in unauthorized access to confidential data and business operations disruptions. This breach highlights a critical evolution in adversary tradecraft: coordinated and simultaneous exploitation of zero-day flaws in widely deployed network infrastructure. With threat actors increasingly chaining vulnerabilities to maximize impact, proactive threat detection and effective segmentation are more essential than ever for organizations seeking resilience against such rapid exploitation campaigns.
6 months ago
Kill Chain
DanaBot Returns: Windows Banking Trojan Resurges After Global Takedown
In early 2024, the notorious DanaBot banking Trojan resurfaced after a six-month hiatus following major international law enforcement crackdowns under Operation Endgame in May 2023. This new version targets Windows systems through phishing campaigns, using malicious email attachments to gain initial access. Once deployed, DanaBot leverages modular capabilities for credential theft, lateral movement, and potential data exfiltration, threatening organizations and individuals with financial losses and malware proliferation. The resurgence highlights the continuously evolving tactics of threat actors in the financial malware ecosystem despite decisive takedown efforts. DanaBot's return signals the persistent threat posed by adaptive malware campaigns, with attackers quickly retooling to evade detection and capitalize on lapses in endpoint security. This incident stresses the importance of modern inbound threat detection measures and rapid response to evolving banking malware tactics.
6 months ago
Kill Chain
2025 Microsoft Kernel Zero-Day: Privilege Escalation Risks & Response
In November 2025, Microsoft disclosed and patched 63 security flaws across its platforms, including a Windows Kernel zero-day vulnerability (CVE-2025-XXXX) that was exploited in the wild prior to the update. Attackers leveraged this privilege escalation flaw to gain elevated access on targeted devices, enabling them to bypass security controls, move laterally, and potentially deploy additional malicious payloads. While the majority of these vulnerabilities were rated as important, four—including the actively exploited zero-day—were rated critical, underlining the heightened risk for organizations that were slow to apply updates. The prompt response in releasing patches aimed to minimize further exploitation and potential operational disruptions for Microsoft enterprise customers globally. This incident highlights increasing attacker focus on privilege escalation flaws within widely-used platforms, particularly those with a large installed base like Windows. The ongoing exploitation of zero-days demonstrates the urgency of timely patch management, robust endpoint defenses, and threat detection as adversaries accelerate the weaponization of newly discovered vulnerabilities.
6 months ago
Kill Chain
Amazon Discovers Zero-Day Exploits Targeting Cisco and Citrix Appliances
In October 2025, Amazon's threat intelligence division uncovered an advanced cyberattack that targeted undisclosed zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix NetScaler ADC appliances. The attackers leveraged these flaws to gain privileged access within victim environments, deploying tailor-made malware to compromise critical identity and network infrastructure. By exploiting trusted network appliances, the threat actor bypassed conventional perimeter security, enabled persistent lateral movement, and threatened both operational continuity and data confidentiality for affected organizations. This incident underscores a growing shift in attacker tactics, with a strategic focus on exploiting zero-days in widely deployed network infrastructure. It highlights rising concerns about supply chain risks, the increasing sophistication of threat actors, and an urgent need for proactive detection and patch management across enterprise environments.
6 months ago
Kill Chain
Quantum Route Redirection: How Automated Phishing Bypassed Microsoft 365 Email Security in 2024
In early 2024, a sophisticated phishing campaign targeting Microsoft 365 users was discovered operating across more than 90 countries. Attackers leveraged Quantum Route Redirection, a tool that automates smart redirect chains to bypass traditional email security tools and Secure Email Gateways. Victims received carefully crafted phishing emails containing weaponized links that appeared benign during initial scanning but redirected users to credential harvesting sites upon access. The streamlined attack flow remarkably reduced technical hurdles for cybercriminals while heightening detection evasion, resulting in widespread compromised accounts and elevated business risks for global organizations reliant on Microsoft 365 ecosystems. This campaign demonstrates the sharply increasing threat posed by advanced phishing techniques, especially as attackers weaponize automation and adaptive redirection to undermine standard security stacks. The ease of executing such attacks democratizes sophisticated phishing, making it a prominent, urgent concern for organizations facing surging identity-based threats and tightening compliance requirements.
6 months ago
Kill Chain
Microsoft Exchange Faces Ongoing 2024 Attacks: Critical Infrastructure at Risk
In early 2024, Microsoft Exchange servers emerged as a primary target for multiple threat actors exploiting unpatched vulnerabilities and weak configurations. Attackers leveraged known flaws—such as ProxyNotShell and other remote code execution bugs—to gain unauthorized access, move laterally within victim organizations, and exfiltrate sensitive data. Microsoft and independent security researchers observed a surge in infrastructure compromise attempts, with a mix of advanced persistent threats (APTs) and financially-motivated ransomware groups executing tailored campaigns. The fallout included operational disruption, data leakage, and increases in business email compromise (BEC). This incident highlights the ongoing risk to enterprise email platforms as attackers shift from widespread spray-and-pray tactics to more persistent, targeted exploitation. The escalation in attack volume underscores the urgency for organizations to patch, segment, and continuously monitor Exchange environments to prevent cascading breaches.
6 months ago
Kill Chain
CISA Flags Actively Exploited Multi-Vendor Vulnerabilities in 2025
In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added three newly discovered, actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2025-9242 (WatchGuard Firebox), CVE-2025-12480 (Gladinet Triofox), and CVE-2025-62215 (Microsoft Windows). Threat actors leveraged these vulnerabilities to gain unauthorized access, execute code, and move laterally within affected environments. Federal agencies were instructed, under Binding Operational Directive 22-01, to remediate these vulnerabilities by mandated deadlines due to their significant risk, while all organizations were strongly advised to prioritize swift patching and mitigation efforts to reduce potential impact. The rising frequency and severity of multi-vendor vulnerabilities exploited in the wild underscores a persistent trend of opportunistic attacks targeting unpatched systems. Regulatory momentum and new compliance directives are pushing both public and private entities to accelerate vulnerability management and incident response, as attackers increasingly leverage these CVEs for ransomware, data exfiltration, and access brokering operations.
6 months ago
Kill Chain
Patch Now: Microsoft Confronts Zero-Day and Zero-Click Vulnerabilities in 2023
In November 2023, Microsoft promptly addressed a set of high-severity vulnerabilities—including an actively exploited zero-day and critical zero-click bugs—potentially enabling remote attackers to gain system access without user interaction. These flaws, impacting various Microsoft products, were highlighted in the company’s latest Patch Tuesday. Attackers could leverage the zero-click bugs to execute code and escalate privileges by exploiting services exposed to the internet or internal networks, heightening risks of system compromise, data exposure, and lateral movement throughout the organization if left unpatched. The rapid emergence and exploitation of zero-day and zero-click vulnerabilities underscores an escalating threat landscape, where sophisticated threat actors seek to bypass user involvement or traditional security layers. Proactive patch management, network segmentation, and real-time threat detection are now mission-critical to mitigating such attack vectors.
6 months ago
Kill Chain
Microsoft November 2025 Patch Tuesday: Kernel Vulnerability Under Active Exploitation
On November 11, 2025, Microsoft released security patches addressing 80 vulnerabilities as part of its monthly Patch Tuesday cycle. Among these, CVE-2025-62215, an actively exploited privilege escalation vulnerability in the Windows Kernel, stood out. The flaw enables threat actors to elevate their permissions on compromised systems with relatively minimal effort, leveraging methods similar to previous kernel exploits. Additional critical vulnerabilities affected GDI+, DirectX, and Microsoft Office, broadening the potential attack surface across Windows environments and productivity tools. Although no "Patch Now" advisories were flagged, the vulnerabilities collectively present significant risk, especially if left unpatched in large enterprise infrastructures. The urgency around privilege escalation and remote code execution vulnerabilities reflects an industry-wide increase in attacks leveraging unpatched endpoints, lateral movement, and broad attack surfaces. Organizations are under growing regulatory and operational pressure to accelerate vulnerability management and implement advanced detection and segmentation, as threat actors increasingly automate exploit chains for initial foothold and privilege escalation.
6 months ago
Kill Chain
GlobalLogic's 2024 Ransomware Breach: Clop Hits Oracle E-Business Suite Customers
GlobalLogic, a subsidiary of Hitachi, suffered a significant data breach after the Clop ransomware group exploited a zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite. The breach, which began on July 10, 2024, went undetected for months and resulted in the theft of sensitive human resources data for nearly 10,500 current and former employees. Attackers accessed items such as names, SSNs, salary and bank details, passport information, and more, ultimately issuing extortion demands and threatening to leak the stolen data. GlobalLogic promptly initiated incident response actions, notified regulators, and applied Oracle's critical software patches to mitigate the threat after discovering the breach on October 9, 2024. This incident is part of a broader campaign targeting multiple Oracle customers, with ransom demands reaching as high as $50 million and almost 30 organizations named as victims on Clop’s data leak site. This attack underscores the ongoing threat of ransomware groups exploiting enterprise application vulnerabilities and highlights the growing risks posed by sophisticated supply chain and zero-day attacks. Organizations relying on popular ERP software must increase vigilance and prioritize patch management, while regulators and security leaders raise concern over attackers' speed, stealth, and extortion tactics.
6 months ago
Kill Chain
Microsoft Patches Active Windows Kernel Zero-Day in 2025 Security Update
In November 2025, Microsoft addressed 63 vulnerabilities impacting core Windows systems, including an actively exploited zero-day flaw (CVE-2025-62215) in the Windows Kernel. This vulnerability, rated CVSS 7.0, is triggered via a race condition by local attackers using crafted applications to gain elevated privileges. Independent security researchers confirmed the existence of functional exploits in the wild, though no public proof-of-concept had surfaced at the time. Additional risks included several flaws in the Windows Ancillary Function Driver for WinSock and a high-severity remote code execution bug affecting the Graphics Component. Microsoft responded with patches on its monthly Patch Tuesday update. This incident underscores the persistent threat of privileged escalation bugs in foundational operating system components. As attackers increasingly target complex race conditions, organizations must prioritize timely patching and layered controls to limit exploitation windows, particularly on endpoints with local user access.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports