✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Operation SkyCloak: Tor-Enabled OpenSSH Backdoor Infiltrates Defense Networks
In November 2025, a sophisticated cyber campaign dubbed 'Operation SkyCloak' was uncovered, targeting Russian and Belarusian defense sectors. Attackers distributed weaponized attachments via phishing emails, successfully implanting a persistent OpenSSH-based backdoor on compromised hosts. To conceal its activity, the malware leverages a customized Tor hidden service with obfs4 protocol, facilitating covert command-and-control and persistent unauthorized access. This campaign demonstrates advanced threat actor operational security, targeting high-value government and defense assets to enable espionage and data exfiltration. The use of Tor-enabled backdoors in defense-related attacks is surging, marking a shift towards more covert, untraceable threat tactics. This incident exemplifies the growing adoption of anonymized infrastructure by attackers to evade detection, highlighting urgent requirements for east-west traffic inspection, advanced threat detection, and zero trust segmentation for critical sectors.
6 months ago
Kill Chain
2025 Ransomware Tsunami: Why Real-Time Data Is Now Essential for Defense
In early 2025, organizations worldwide faced a dramatic surge in ransomware attacks, as threat actors embraced data-driven approaches and leveraged AI, new exploit techniques, and ransomware-as-a-service (RaaS) business models. Attackers rapidly escalated compromise using stolen credentials, lateral movement, and encrypted communications, bypassing traditional detection tools and reducing dwell time to under an hour. With nearly half of breaches attributed to ransomware and a sharp increase in identity-driven attacks, countless organizations experienced significant operational disruptions, financial losses, and reputational damage. This incident highlights a macro-shift in the threat environment: traditional signature-based or static ransomware detection methods are now largely ineffective against modern, fast-moving adversaries. The exponential rise of hands-on, machine-speed attacks and infostealer-driven access means organizations urgently need real-time, intelligence-led detection and response capabilities.
6 months ago
Kill Chain
Inside the 2025 Cybercrime Merger: Scattered Spider, LAPSUS$, and ShinyHunters Unite
In August 2025, a powerful new cybercrime collective emerged from the merger of Scattered Spider, LAPSUS$, and ShinyHunters—three of the most notorious threat groups involved in high-profile data theft, ransomware, and extortion. This unified entity quickly established 16 Telegram channels to coordinate attacks, evade platform moderation, and amplify operations. Leveraging advanced social engineering and data exfiltration techniques, the collective launched a string of multinational breaches targeting enterprises, exposing sensitive information and causing significant financial and reputational harm to victims. Security teams observed an uptick in lateral movement, exploitation of hybrid/cloud environments, and sophisticated policy evasion tied to these actors. This incident exemplifies a growing trend where cybercriminal syndicates combine resources and expertise, accelerating the pace and scale of attacks. The merger highlights the urgent need for organizations to adapt to evolving threat actor alliances and reinforces the importance of advanced segmentation, zero trust, and robust monitoring frameworks.
6 months ago
Kill Chain
Microsoft Teams Vulnerabilities: 2025’s Wake-Up Call for Application Security
In March 2025, security researchers uncovered four critical vulnerabilities in Microsoft Teams that allowed attackers to manipulate conversations and impersonate trusted colleagues without detection. By exploiting flaws in message handling and notifications, adversaries could initiate convincing phishing and social engineering attacks, posing as legitimate users and altering message content retroactively. These flaws were exploitable until Microsoft was notified through responsible disclosure, enabling potential internal threat activity or external compromise before patches were issued. This incident highlights the growing risks of business collaboration platforms as prime targets for socially engineered attacks. With enterprise reliance on unified communications, attackers are innovating new tactics to undermine trust, emphasizing the urgent need for proactive application security and real-time threat monitoring controls.
6 months ago
Kill Chain
Critical 2025 React Native CLI Flaw Exposes Millions to Supply-Chain Attacks
In November 2025, a critical vulnerability was disclosed in the widely used "@react-native-community/cli" npm package, exposing millions of developers and organizations that rely on React Native for application development. The flaw allowed remote, unauthenticated attackers to execute arbitrary operating system commands on systems running vulnerable versions of the CLI tool. The threat stemmed from insufficient input validation, enabling exploitation via malicious npm modules or manipulated code, creating a high-risk supply-chain attack vector. The vulnerability was swiftly patched, but it highlighted significant supply-chain security gaps across the software development ecosystem. This incident is notable for reinforcing the urgent need to secure development toolchains and underscores the increasing frequency of attacks targeting open-source software dependencies. As attackers continue to exploit weak links in the software supply chain, organizations must strengthen controls, monitoring, and vulnerability management to keep pace with evolving risks.
6 months ago
Kill Chain
CISA Flags Active Exploitation of 2025 Gladinet CentreStack, Triofox, and CWP Control Web Panel Flaws
In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA) identified and announced active exploitation of two critical vulnerabilities: CVE-2025-11371 in Gladinet CentreStack and Triofox (files or directories exposed to external parties), and CVE-2025-48703 in CWP Control Web Panel (an OS command injection flaw). Threat actors are leveraging these weaknesses to gain unauthorized file access or execute malicious code within affected environments, targeting organizations across sectors. The vulnerabilities enable lateral movement, data exfiltration, and potentially full compromise, with significant risk to sensitive data, business operations, and regulatory posture for organizations running vulnerable systems. This announcement underscores a broader trend of attackers exploiting unpatched software vulnerabilities in common enterprise tools. With automatic exploitation kits and a growing focus on file-sharing and web panel infrastructure, organizations face urgent pressure to accelerate vulnerability management and adopt Zero Trust practices to contain and monitor internal threats.
6 months ago
Kill Chain
SesameOp: AI API Abused as C2 in Advanced Malware Attack (2024)
In early 2024, cybersecurity researchers uncovered a sophisticated malware campaign involving the "SesameOp" backdoor, which leveraged OpenAI's API as a covert Command and Control (C2) channel. Threat actors behind this attack established persistence within targeted organizations using a custom Linux backdoor, routing communications through encrypted API calls to OpenAI infrastructure, thus evading traditional detection methods. The malware's use of legitimate AI service channels enabled threat actors to obfuscate malicious activity, complicating incident response and extending dwell time inside compromised environments. The incident underscored the rapid innovation of attacker tactics and the challenges enterprises face as generative AI ecosystems become embedded in critical workflows. This breach exemplifies a wider, emerging risk: attackers abusing popular cloud-based and AI-driven services for lateral movement, data exfiltration, and stealthy C2 operations. With AI adoption accelerating across industries, security teams must urgently reassess control frameworks, enhance anomaly detection, and enforce visibility on legitimate platforms often overlooked in legacy monitoring.
6 months ago
Kill Chain
Android BankBot-YNRK: 2024 Indonesian Mobile Wallets Targeted by Muting Malware
In 2024, a variant of the Android/BankBot malware known as YNRK targeted mobile users in Indonesia by disguising itself as legitimate applications, often distributed via third-party app stores or phishing campaigns. Once installed, the malware muted system alerts and abused accessibility services to perform unauthorized actions, including theft of credentials and the draining of cryptocurrency and mobile banking wallets. The attack leveraged overlays to capture user inputs and bypassed security mechanisms, resulting in significant financial losses for affected users, with widespread impacts across consumer mobile banking apps in the country. This incident highlights the ongoing evolution and sophistication of mobile banking malware, which increasingly targets emerging markets and exploits weak security controls on non-official app stores. The rapid adoption of mobile wallets and cryptocurrency platforms has made these attacks more lucrative and frequent, intensifying the need for proactive mobile security, user awareness, and regulatory oversight.
6 months ago
Kill Chain
Apple Patches 110 Vulnerabilities in Massive 2024 Security Update
In early November 2024, Apple released urgently needed security updates for its operating systems, patching 110 vulnerabilities across iOS, macOS, iPadOS, watchOS, tvOS, visionOS, Safari, and Xcode. Key vulnerabilities included memory corruption flaws in ImageIO and WebKit, with previous instances of such bugs leading to remote code execution. Several vulnerabilities could allow unauthorized access to sensitive user data or privilege escalation, and most major Apple product families were impacted. No active exploitation was reported, but these vulnerabilities posed significant risks, especially if exploited in the wild. This incident underscores the importance of timely patching for organizations leveraging Apple hardware, amid escalating regulatory expectations and sophisticated exploit development targeting zero-day vulnerabilities. With Apple devices often pivotal in hybrid and remote work environments, large-scale multi-platform vulnerabilities present an attack surface of interest to both cybercriminals and nation-state actors.
6 months ago
Kill Chain
SnakeStealer: 2024's Most Prolific Infostealer and Its Impact on Data Security
In early 2024, cybersecurity researchers identified a widespread surge in SnakeStealer malware infections targeting individuals and organizations across multiple sectors. This sophisticated infostealer penetrates devices through malicious attachments and compromised software, rapidly harvesting valuable personal and corporate information including browser credentials, cryptocurrency wallets, and sensitive documents. Once data is collected, it is exfiltrated to attacker-controlled servers, fueling cybercrime operations and secondary attacks. The rapid spread and effectiveness of SnakeStealer has led to significant business and operational risks, such as unauthorized access, data breaches, and identity theft. This incident highlights the escalating threat posed by modern infostealers, which continue to evolve their techniques to bypass security controls and evade detection. The sustained activity of SnakeStealer, coupled with copycat variants, underscores a trend of increasingly sophisticated, financially motivated cybercrime targeting both enterprise and individual data at scale.
6 months ago
Kill Chain
North Korean Operatives Pose as IT Job Seekers to Infiltrate Western Companies
In 2023, multiple Western technology firms fell victim to a sophisticated insider threat campaign involving North Korean operatives posing as freelance IT job seekers. These actors used false identities and forged CVs to secure remote employment and gain access to sensitive corporate environments. Once inside, they leveraged their positions to siphon proprietary information, commit financial fraud, and, in some cases, facilitate broader cyber-espionage activities by collecting credentials and mapping internal systems. The impact spanned financial loss, reputation damage, and increased exposure to supply chain attacks. This incident highlights the growing trend of well-resourced nation-state actors exploiting remote work arrangements and third-party talent networks. As companies aggressively scale digital transformation and outsourcing, vigilance against social engineering and identity fraud is critical to mitigate the risk of covert infiltration and regulatory non-compliance.
6 months ago
Kill Chain
Freight Brokers Targeted: Hackers Use RMM Tools in Supply Chain Heist (2024)
In 2024, cybercriminals executed a targeted supply chain attack against freight brokerages and trucking carriers by exploiting phishing emails and malicious links. Attackers used remote monitoring and management (RMM) tools to infiltrate corporate systems, taking control of freight scheduling and logistics platforms. This allowed the threat actors to manipulate cargo shipments, redirect valuable freight, and orchestrate the theft of physical goods. The attack revealed significant gaps in internal segmentation, endpoint security, and east-west visibility, resulting in financial loss, disrupted operations, and reputational impact across the logistics sector. This incident highlights an emerging trend in the weaponization of legitimate IT tools like RMMs for high-value supply chain attacks. As threat actors innovate with living-off-the-land techniques, organizations with critical logistics functions face heightened scrutiny from regulators and renewed urgency to close visibility and segmentation gaps.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports