✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Time-Bomb Malware Hidden in NuGet Packages Signals Alarming Supply Chain Threat
In 2023 and 2024, a set of nine malicious NuGet packages, attributed to the user 'shanhai666', were found to infect software supply chains by deploying time-delayed logic bombs. These packages, available through the official NuGet repository, hid code designed to execute malicious activities—such as sabotaging database operations and corrupting industrial control systems—on predefined future dates starting in August 2027. The sophisticated campaign leveraged delayed payload triggers, allowing attackers to infiltrate developer environments undetected for years before activation, thus maximizing potential operational and business disruption. This incident highlights the ongoing risks facing software supply chains, where attackers increasingly employ delayed and concealed attack mechanisms to evade early detection. Businesses across all sectors relying on third-party code repositories must reinforce supply chain security practices and continuously monitor for latent threats that could surface well after initial compromise.
6 months ago
Kill Chain
Chinese Nation-State Hackers Breach U.S. Non-Profit Using Legacy Bugs
In early 2025, a China-linked advanced persistent threat (APT) group carried out a sophisticated cyber espionage campaign targeting a prominent U.S. non-profit focused on policy issues. Leveraging legacy vulnerabilities such as Log4j and Microsoft IIS flaws, the attackers gained initial access, established persistent footholds, and conducted covert data exfiltration operations while remaining undetected for several months. According to detailed analyses by Symantec and Carbon Black, the group focused on harvesting sensitive documents related to U.S. government policy and influencing discussions through clandestine activity within compromised systems, amplifying strategic risk to both the organization and its stakeholders. This incident exemplifies a broader trend of nation-state actors weaponizing unpatched, well-known vulnerabilities for long-term espionage. Organizations with legacy infrastructure are increasingly attractive targets, underscoring the urgent need for proactive vulnerability management, encrypted traffic controls, and robust east-west security to counter evolving, identity-driven threats.
6 months ago
Kill Chain
Ollama and Nvidia AI Infrastructure Vulnerabilities: A Wake-Up Call for Enterprise Security in 2024
In June 2024, security researchers identified multiple critical vulnerabilities within key AI infrastructure products, most notably affecting Ollama and Nvidia platforms. The most severe flaws enabled authenticated remote code execution and unauthorized access to sensitive AI environments. Attackers could exploit insecure network interfaces and misconfigurations to laterally move across workloads or escalate privileges. These risks threaten the confidentiality, integrity, and availability of AI-powered operations, exposing organizations to theft of proprietary models, service disruption, and downstream compromise. The rapidly maturing adversary tactics around supply chain and platform vulnerabilities magnified these risks. This incident highlights an urgent trend: attackers are now aggressively targeting foundational AI infrastructure in enterprise and cloud settings, focusing on underlying software weaknesses rather than solely data or application layers. As AI adoption accelerates, so does the attack surface, making robust segmentation, encryption, and zero trust approaches vital for resilience.
6 months ago
Kill Chain
Nation-State Breach Hits Congressional Budget Office: 2024 Lessons
In early June 2024, the Congressional Budget Office (CBO), a key federal agency supplying budget and economic analysis to Congress, experienced a cybersecurity breach by a suspected nation-state actor. Attackers reportedly infiltrated CBO systems and may have accessed sensitive communications between lawmakers and agency researchers. Upon discovery, CBO moved quickly to contain the incident, implemented additional monitoring, and strengthened security controls. The breach echoed previous attacks on congressional entities by sophisticated threat actors aiming to compromise confidential governmental data and influence legislative processes. This incident highlights increasing targeting of government research bodies by foreign espionage groups seeking sensitive intelligence. With agencies routinely handling politically sensitive and high-value data, robust cybersecurity defenses and rapid incident response are now critical amid heightened global threat actor activity.
6 months ago
Kill Chain
ClickFix Evolves: Multi-OS Malware Delivered with Social Engineering and Video Tutorials
In early 2024, cybersecurity researchers observed a sharp evolution in the ClickFix malware campaign, which began targeting users with tailored multi-operating system payloads accompanied by step-by-step video tutorials to aid self-infection. The attackers employed social engineering by pressuring victims with countdown timers and offering clear, OS-specific instructions, effectively lowering the barrier for successful compromise. Leveraging these tactics, the malware operators could achieve widespread distribution, enabling credential theft and system control on both Windows and macOS platforms, and increasing risk of lateral movement across enterprise environments. This incident highlights a broader trend of combining technical innovation with advanced social engineering, making malware delivery easier and more efficient. The streamlined, multi-OS approach and use of multimedia content signal a significant shift in attacker tactics, accelerating the threat landscape and challenging traditional security awareness programs.
6 months ago
Kill Chain
SonicWall Cloud Backup Breach: How State-Sponsored Attackers Exploited API Weaknesses in 2025
In September 2025, SonicWall confirmed that state-sponsored threat actors orchestrated a security breach targeting its cloud backup environment. The attackers exploited an API vulnerability to gain unauthorized access to firewall configuration backup files stored in a specific cloud deployment. SonicWall's investigation determined the breach was limited to the exposure of these configuration files, with no evidence of lateral movement or impact to production systems. The breach prompted immediate containment actions, disclosure to affected customers, and a global review of cloud access controls and incident response procedures. This incident underscores the increasing risk posed by sophisticated, nation-state adversaries targeting cloud environments and API endpoints. It highlights how misconfigurations and insufficient segmentation in cloud infrastructure can facilitate data exposure, driving industry-wide reassessment of cloud-native security and compliance practices.
6 months ago
Kill Chain
Malicious AI Extension Sneaks onto VS Code Marketplace in Supply Chain Breach (2024)
In early June 2024, a malicious extension possessing rudimentary ransomware functionality, allegedly built with the aid of artificial intelligence, was discovered in Microsoft's Visual Studio Code (VS Code) Marketplace. The extension leveraged VS Code's trusted distribution to sneak past safeguards and, once installed, had the capability to encrypt targeted user files and demand a ransom. This supply chain attack was detected before it could be widely abused, but it highlights how adversaries are using AI to generate and deploy sophisticated threats within software ecosystems. This incident demonstrates a growing trend where supply chain platforms, such as code repositories and marketplaces, are exploited to gain privileged entry within developer environments. The blending of AI-enabled malware automation and trusted application channels raises urgent visibility, compliance, and policy enforcement concerns for organizations.
6 months ago
Kill Chain
How Ransomware Crippled Nevada State Agencies in 2025
In August 2025, the State of Nevada experienced a significant ransomware attack that disrupted the operations of over 60 state agencies, including those responsible for health and public safety. Attackers gained unauthorized access to internal systems, likely through a compromised credential or exposed remote access service. They rapidly deployed ransomware across the network, encrypting critical data and rendering multiple state services inaccessible while officials initiated emergency response protocols. The impact included delayed or suspended services for residents and a comprehensive recovery process lasting several weeks. This incident underscores a persistent trend: ransomware threat actors are increasingly targeting government entities, leveraging lateral movement and broad access to cripple essential public services. As attacks escalate and recovery costs rise, organizations face greater pressure to modernize segmentation, detection, and incident response strategies.
6 months ago
Kill Chain
Curly COMrades Weaponize Hyper-V: How Linux VMs Helped Evade Detection in 2025 Breach
In October 2025, the advanced persistent threat group Curly COMrades launched a sophisticated attack campaign exploiting Windows Hyper-V virtualization to evade endpoint detection and response (EDR) solutions. By covertly enabling Hyper-V on targeted systems, attackers deployed a minimal Alpine Linux-based virtual machine (VM) hidden within Windows hosts. This VM served as an isolated enclave to execute custom malware and facilitate command-and-control activities, significantly complicating detection and forensics for defenders. Victims experienced unauthorized data access and increased potential for lateral movement, while standard EDR tools failed to monitor the malicious payloads running inside the guest VM. This attack highlights a growing trend of leveraging virtualization and container technologies to bypass security controls. As organizations increasingly adopt hybrid and multi-cloud environments, adversaries are developing novel methods to mask malicious operations from traditional detection mechanisms, underscoring the need for advanced visibility and zero trust segmentation.
6 months ago
Kill Chain
Credential Stuffing at Scale: 2 Billion Email Addresses and 1.3 Billion Passwords Exposed in 2025
In late 2025, a massive credential stuffing incident came to light when nearly 2 billion email addresses and 1.3 billion unique passwords – sourced over years from various cybercriminal forums and compromised stealer logs – were aggregated and indexed by Synthient, then processed by Have I Been Pwned (HIBP) for user notification. The dataset included credentials from countless breaches, consolidated into one of the largest exposures of its kind to date. While the original leaks stemmed from malware infections, phishing, and prior breaches, the impact was compounded by password reuse and the easy redistribution of these records in the criminal underground. HIBP took technical and privacy-preserving steps to verify and notify affected users while preventing further risk of data linkage. This incident illustrates the ongoing risks posed by credential stuffing and highlights the long lifecycle of exposed data as threat actors continuously recycle and combine compromised information. The event underscores the importance of password hygiene, multi-factor authentication, and proactive notification as recycled data fuels ongoing cyberattacks across industries.
6 months ago
Kill Chain
Coinbase Hit by 2024 Phishing Attack Orchestrated by Scattered Spider
In February 2024, cryptocurrency exchange Coinbase experienced a sophisticated phishing attack executed by the 0ktapus (Scattered Spider) threat actor. Attackers sent targeted SMS and email messages to select Coinbase employees, impersonating IT support and leveraging social engineering to harvest login credentials and multi-factor authentication codes. They subsequently accessed internal dashboards, potentially viewing sensitive customer data. Prompt monitoring enabled Coinbase’s security team to detect the unusual access and contain the breach before widespread damage occurred, mitigating customer impact and avoiding direct financial loss. This incident highlights the increasing sophistication of phishing campaigns targeting high-value organizations, particularly those with significant user assets like Coinbase. Advanced phishing, often enabled by multi-stage social engineering and MFA bypass techniques, is intensifying across critical sector organizations in 2024.
6 months ago
Kill Chain
Cloudflare Top Domain Rankings Compromised by Aisuru Botnet in 2025
In October 2025, Cloudflare faced an unprecedented attack by the Aisuru botnet, a rapidly scaling network of compromised IoT devices. The botnet leveraged its vast fleet to overwhelm Cloudflare's public DNS resolver (1.1.1.1) with massive volumes of automated queries, propelling its malicious command-and-control domains to the top ranks of Cloudflare's most-queried website list. This manipulation triggered widespread concern over data integrity and brand confusion, as Aisuru domains temporarily displaced legitimate top domains like Google and Apple. In response, Cloudflare resorted to redacting and eventually removing suspicious domains from its ranking list, highlighting significant security gaps in popular trust datasets. This incident underscores the mounting risk posed by large IoT botnets to critical internet infrastructure, including DNS reliability and reputation-based services. It reveals how attackers exploit both technical and social trust mechanisms, with potential downstream effects on security decisions that leverage third-party domain rankings.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports