✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Pro-Russian APT Uses Linux VMs to Evade Windows Security in 2024
In early 2024, the pro-Russian threat group known as Curly Comrades leveraged Linux virtual machines within Windows environments to bypass security controls and evade detection. By deploying Linux VMs on compromised Windows hosts, the attackers concealed their activities, used native tools for lateral movement, and exfiltrated sensitive data without triggering traditional endpoint or network monitoring. This novel cross-OS technique allowed extended dwell time and left organizations vulnerable to espionage, data loss, and operational disruption. This incident is especially relevant given the continuing evolution of threat actor tactics, including living-off-the-land and virtualization abuse. Organizations must adapt defenses to anticipate adversaries' creative use of multi-platform infrastructures and strengthen their east-west visibility to prevent stealthy attacks.
6 months ago
Kill Chain
Proliance Surgeons Breach: Ransomware Exposes Hidden Supply Chain Risks
In January 2024, Proliance Surgeons, a major US healthcare provider, suffered a significant data breach after ransomware group Midas targeted its third-party vendor, PJ&A, which provides medical transcription services. The attackers exploited insufficient east-west traffic segmentation and leveraged VPN credentials to move laterally through Proliance’s environment, encrypting data and exfiltrating files containing patient names, addresses, dates of birth, medical record numbers, and clinical details. Business operations were disrupted for days, and regulatory investigations are underway, posing severe operational and reputational risks for both Proliance and its downstream partners. This breach underscores the ongoing vulnerability of healthcare organizations to supply chain ransomware attacks. With ransomware groups shifting tactics to exploit third-party vendors and focusing on lateral movement for maximum damage, healthcare organizations must modernize network segmentation, enhance detection capabilities, and achieve compliance with stricter data protection mandates.
6 months ago
Kill Chain
Major Supply-Chain Exposure Discovered in Popular Software Update Tool – 2024
In early 2024, a critical supply-chain vulnerability was identified in a widely used software update tool, threatening some of the world's largest technology enterprises. Attackers exploited insecure update mechanisms within this tool, enabling the potential injection of malware directly into production software across multiple organizations. The breach exposed businesses to risks including unauthorized access, lateral movement, and possible data theft. While no confirmed exploitation has been publicly reported to date, the threat mirrors the scale and impact of the infamous SolarWinds compromise, underscoring the profound risks inherent in trusted third-party code dependencies. This incident highlights the urgent and growing threat from software supply-chain attacks, which have rapidly increased in frequency and sophistication over the past two years. It spotlights the cybersecurity community’s intensified focus on software bill of materials (SBOM), continuous monitoring, and robust supply-chain controls as regulatory and industry expectations tighten.
6 months ago
Kill Chain
U.S. Treasury Sanctions North Korean Firms for Cryptocurrency Crime and IT Fraud (2024)
In June 2024, the U.S. Treasury Department sanctioned eight individuals and two companies linked to North Korea for laundering proceeds from cybercrime and IT worker schemes. These sanctioned parties allegedly funneled over $3 billion in stolen cryptocurrency and hundreds of millions in illicitly earned IT wages to the North Korean regime, supporting its weapons programs. Entities sanctioned include North Korean banking officials, an IT company operating in China, and financial institution representatives in both China and Russia, all accused of violating international sanctions, managing illicit funds, and enabling large-scale money laundering through sophisticated cyber and identity subterfuge. This incident underscores the advanced capabilities of North Korea’s cyber operations and their direct link to geopolitical threats, as well as the ongoing shift towards state-sponsored cryptocurrency theft and IT fraud as major funding sources for sanctioned regimes.
6 months ago
Kill Chain
Curly COMrades: Russian Hackers Hide Malware in Hyper-V Linux VMs to Evade Detection
In early 2024, threat intelligence analysts uncovered a sophisticated campaign by the Russian-backed group Curly COMrades, wherein attackers abused Microsoft's Hyper-V virtualization feature to bypass endpoint detection on target Windows systems. The attackers covertly deployed an Alpine Linux virtual machine, invisible to conventional security tools, and used it as a persistent foothold to run malware, facilitate lateral movement, and exfiltrate sensitive data. This technique allowed them to mask malicious processes and evade established EDR and antivirus solutions, posing serious risks to affected organizations. This incident highlights an alarming evolution in advanced persistent threat tactics, with adversaries exploiting virtualization infrastructure to evade modern security controls. As virtualized environments and cloud workloads proliferate, organizations must harden hypervisors, enhance east-west security, and advance detection capabilities to fend off similar stealthy threats.
6 months ago
Kill Chain
Top Browser Sandbox Threats: How Attackers Slip Past Security in 2024
In early 2024, a surge of browser-based attacks demonstrated the ability of sophisticated threat actors to bypass modern browser sandboxing, leveraging native browser features and vulnerable extensions to conduct credential theft, lateral movement, and data exfiltration. According to insights from Keep Aware and BleepingComputer, attackers exploit browser quirks and weaknesses such as unsanctioned extension access, credential harvesting via phishing overlays, and abuse of session tokens, often evading signature-based detection tools. Organizations affected by such campaigns have faced unauthorized data access, exposure of credentials, and in some cases, secondary compromise of internal systems. This incident highlights the evolving attack surface at the browser layer, where traditional endpoint and network protections may no longer suffice. As browser usage grows in enterprise settings and attackers refine tactics to evade sandboxing controls, security teams must re-examine their strategy for real-time browser-layer visibility and enforcement.
6 months ago
Kill Chain
Nikkei’s 2024 Slack Breach: How 17,000 Identities Were Compromised
In early June 2024, Japanese media giant Nikkei disclosed a significant data breach after its Slack messaging platform was compromised, exposing the personal information of more than 17,000 employees and business partners. Attackers gained unauthorized access to sensitive data such as names, email addresses, and potentially other details linked through Slack integration, by exploiting the company’s internal communications environment. The breach’s impact is broad, affecting both staff and partners, with Nikkei reporting the incident promptly to authorities and commencing investigation and notification processes. This incident highlights the growing risks posed by attacks on SaaS collaboration platforms like Slack, as organizations increasingly rely on these tools for internal and external communication. Threat actors are exploiting identity-based and third-party platform vulnerabilities, underlining the critical need for robust access controls and proactive monitoring of cloud communication systems.
6 months ago
Kill Chain
WordPress Post SMTP Plugin Exploited in Mass Admin Account Hijacks (2024)
In early June 2024, cybersecurity researchers identified that a critical vulnerability in the Post SMTP WordPress plugin was being actively exploited by threat actors. This vulnerability allowed attackers to hijack administrator accounts across more than 400,000 affected WordPress sites, enabling complete site control and potentially permitting installation of malicious payloads. Attackers gained initial access through the plugin's weak nonce verification, escalating privileges to compromise sites, deploy backdoors, and exfiltrate sensitive data. The incident demonstrates how widespread web application vulnerabilities can be rapidly weaponized, putting enterprises and small businesses alike at risk of data loss, defacement, or further compromise. The Post SMTP exploitation highlights a recent surge in attacks leveraging zero-day or unpatched CMS plugins on large scales, reflecting attackers’ growing focus on supply chain and SaaS-adjacent targets. As organizations increasingly depend on third-party tools and platforms, maintaining rapid patch cycles and comprehensive visibility into software components is more critical than ever.
6 months ago
Kill Chain
Akira Ransomware’s Disputed Data Breach: What Happened at Apache OpenOffice (2024)
In June 2024, the Akira ransomware group publicly claimed responsibility for a data breach affecting Apache OpenOffice, alleging the theft of 23 GB of sensitive corporate documents. Despite these assertions, the Apache Software Foundation conducted an internal investigation and officially disputed any evidence of compromise or unauthorized access, stating there were no indications of a breach in their infrastructure. This incident highlights the ongoing challenge organizations face with threat actor claims that may not always be substantiated but can cause reputational risk and user concern. Similar ransomware campaigns have surged in 2024, with groups leveraging public exposure even without confirming access to target data. The situation underscores the importance of proactive communication, transparent incident response, and technical validation as attackers increasingly use psychological pressure tactics in addition to technical intrusions.
6 months ago
Kill Chain
How Microsoft Uncovered the SesameOp OpenAI API Backdoor: 2025 Case Study
In November 2025, Microsoft’s security team identified a sophisticated backdoor campaign dubbed 'SesameOp,' wherein attackers leveraged the OpenAI Assistants API as a stealthy command-and-control (C2) channel. This unconventional tactic enabled the threat actors to instruct compromised systems via encrypted and authenticated OpenAI API communications, bypassing traditional security controls and network monitoring systems. The initial access vector is under investigation, but early signs point to phishing emails weaponized with malicious loader scripts. The use of a reputable third-party AI API provided attackers with enhanced persistence and made network traffic analysis difficult, delaying detection and remediation. This incident marks a significant escalation in attacker techniques exploiting trusted generative AI platforms for C2, illustrating the growing weaponization of legitimate SaaS services. Organizations must urgently reassess how they detect, monitor, and govern API traffic, particularly for large AI-driven platforms now woven deeply into business infrastructure.
6 months ago
Kill Chain
U.S. Cybersecurity Insiders Indicted for BlackCat Ransomware Attacks (2023)
Between May and November 2023, a trio of U.S.-based individuals—including two named suspects and an unnamed co-conspirator—compromised the networks of five American companies using BlackCat (ALPHV) ransomware. Prosecutors allege that the attackers, all cybersecurity insiders, leveraged privileged access and technical expertise to deploy ransomware on a range of targets, including a medical organization, resulting in considerable financial losses and data encryption. The conspirators used advanced methods to extort payments, disrupt operations, and evade detection. This incident highlights the growing risk posed by insider threats and the increasing sophistication of ransomware groups like BlackCat/ALPHV. Such attacks are driving regulatory calls for enhanced east-west network controls, granular segmentation, and robust anomaly detection as ransomware tactics continue to evolve.
6 months ago
Kill Chain
Google’s ‘Big Sleep’ AI Uncovers 5 Critical Safari WebKit Vulnerabilities
In October 2025, Apple publicly credited Google's AI-powered cybersecurity agent, 'Big Sleep', for identifying five critical vulnerabilities within the WebKit component of its Safari browser. These vulnerabilities, notably including CVE-2025-43429, could be exploited by attackers to trigger browser crashes or initiate memory corruption, potentially resulting in code execution or unauthorized system compromise. Google’s advanced AI techniques allowed rapid discovery and responsible disclosure, prompting Apple to issue urgent patches for all affected systems. This incident underscores a new trend where AI-driven security research exposes latent vulnerabilities faster than ever. It is increasingly relevant as cyber threats grow more sophisticated and organizations face regulatory pressure to promptly remediate critical flaws, especially in client-facing software like browsers.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports