✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
CISA & NSA Issue 2024 Guidance to Harden Microsoft Exchange Servers
In June 2024, the Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) issued joint guidance targeting administrators of Microsoft Exchange servers. This proactive measure follows a history of critical vulnerabilities in Exchange, which have enabled advanced threat actors and ransomware groups to access sensitive organizational email systems, often through unpatched servers and weak configurations. By outlining best practices for hardening Exchange, the agencies aim to help organizations mitigate risks from exploitation, data theft, and business disruption associated with increasingly sophisticated attack vectors seen throughout 2023 and 2024. This guidance reflects the heightened urgency around securing ubiquitous enterprise communications tools following high-profile breaches exploiting on-premise infrastructure. With persistent evolution in offensive capabilities and regulatory scrutiny increasing, consistently applying infrastructure hardening and Zero Trust controls is now critical for organizations of all sizes.
6 months ago
Kill Chain
CISA Orders Urgent Patch of VMware Tools Flaw Exploited by Chinese Hackers
In October 2024, Chinese state-sponsored hackers exploited a high-severity vulnerability in Broadcom’s VMware Aria Operations and VMware Tools software, targeting U.S. federal agencies through a software supply-chain attack. The attackers leveraged the unpatched flaw to gain unauthorized access, move laterally within networks, and potentially exfiltrate sensitive data. The Cybersecurity and Infrastructure Security Agency (CISA) responded by issuing an emergency directive, mandating all federal agencies to immediately patch the affected systems amid evidence of ongoing compromise. This incident underscores the persistent risks of vulnerable supply-chain components and the growing sophistication of state-sponsored adversaries. In light of increased regulatory scrutiny and rising exploitation of critical infrastructure platforms, organizations must prioritize rapid vulnerability management and layered defense strategies.
6 months ago
Kill Chain
PhantomRaven npm Attack: 2025’s Credential-Stealing Supply Chain Breach
In August 2025, cybersecurity researchers from Koi Security uncovered an extensive software supply chain attack involving over 120 malicious npm packages, collectively named "PhantomRaven." Disguised as legitimate dependencies, these packages were uploaded to the npm registry and, once installed on developers’ machines, exfiltrated sensitive assets such as GitHub authentication tokens, CI/CD secrets, and other credentials. The attacker’s use of common JavaScript project names and spellings facilitated widespread distribution before discovery. The breach triggered rapid mitigation responses across multiple organizations relying on npm in their software development lifecycles, raising concerns about dependency trust and software supply chain hygiene. The PhantomRaven campaign underscores a broader surge in supply chain attacks exploiting open-source ecosystems, with threat actors increasingly leveraging popular package managers as vectors. As the software industry’s reliance on third-party code grows, so does the urgency for proactive controls and real-time monitoring to counter sophisticated credential-stealing methods.
6 months ago
Kill Chain
Russian Ransomware Leverages AdaptixC2: 2025's Open-Source Attack Surge
In mid-2025, threat intelligence sources reported that Russian ransomware groups had begun leveraging the open-source AdaptixC2 framework to orchestrate highly targeted, advanced ransomware campaigns. AdaptixC2, originally designed for penetration testing, was weaponized to facilitate command-and-control communications, enable lateral movement, and automate deployment of ransomware binaries across hybrid cloud and enterprise environments. The attackers exploited weak internal segmentation and monitoring deficiencies, achieving extensive encryption of critical systems, data exfiltration, and ransom demands that disrupted multiple sectors, including finance and healthcare. This incident reflects a broader trend: threat actors are rapidly operationalizing legitimate open-source red team tools for malicious purposes. Organizations must respond to this evolution in attacker strategies, as post-exploitation frameworks become increasingly prevalent in real-world breaches, complicating detection and increasing regulatory and operational risk.
6 months ago
Kill Chain
CISA Alerts on Five New Actively Exploited Vulnerabilities in Critical Platforms (2025)
On October 20, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) Catalog, adding five actively exploited vulnerabilities across products from Apple, Kentico, Microsoft, and Oracle. These critical flaws—ranging from authentication bypasses in Kentico Xperience to a server-side request forgery in Oracle E-Business Suite and improper SMB access control in Microsoft Windows—are being leveraged by threat actors to gain unauthorized access, escalate privileges, or exfiltrate data. The directive mandates federal agencies to urgently remediate these risks to safeguard the federal enterprise and critical infrastructure from rapidly evolving threats. The continued expansion of the KEV Catalog highlights the persistent challenge organizations face in tracking and rapidly remediating high-impact vulnerabilities, especially as exploit techniques become more sophisticated and widely disseminated. The urgency is underscored by both regulatory pressure and the increase in observed exploitation campaigns targeting these vulnerabilities across public and private sectors.
6 months ago
Kill Chain
Critical 2025 Raisecomm Authentication Bypass: Root Access Risk to ICS Networks
In October 2025, a critical remote authentication bypass vulnerability (CVE-2025-11534) was publicly disclosed in Raisecomm RAX701-GC series network equipment, allowing unauthenticated attackers to establish SSH sessions and gain root shell access without providing valid credentials. Discovered and reported by security researchers from runZero, this exploit poses an elevated risk to infrastructure sectors relying on these devices globally, as affected firmware versions remain susceptible with exploits achievable at low complexity and no prior privileges. Business and operational impacts include full remote compromise, lateral movement potential, and the ability for attackers to implant persistent threats or disrupt essential communications and IT operations. The incident is especially pressing now, indicating a rising trend in targeting embedded and edge devices in critical environments via misconfigurations or software flaws. As attackers expand their focus to accessible infrastructure, organizations face increasing pressure to implement robust access controls, proactive segmentation, and defense-in-depth strategies to safeguard operational networks.
6 months ago
Kill Chain
CISA Warns of Active Exploitation: Motex LANSCOPE CVE-2025-61932 Added to KEV List
In October 2025, CISA added CVE-2025-61932 to its Known Exploited Vulnerabilities catalog after confirmation that attackers were actively exploiting an improper verification of source vulnerability in Motex LANSCOPE Endpoint Manager. This flaw enables malicious actors to bypass authentication controls or inject unauthorized communications by exploiting weak checks on communication channels. As a result, federal networks and enterprises using the affected endpoint management platform face increased risk of unauthorized access, lateral movement, and potential data compromise. The vulnerability was discovered as part of ongoing efforts to monitor critical endpoint management systems for exploitation in the wild and is considered a significant risk vector, especially for organizations reliant on enterprise management tools. The inclusion of this vulnerability in CISA’s KEV catalog underscores a broader surge in attacks targeting endpoint management platforms, reflecting the ongoing evolution of attacker techniques against core IT infrastructure. Timely patching and visibility into east-west traffic is increasingly essential, as threat actors exploit gaps before organizations can remediate newly disclosed weaknesses.
6 months ago
Kill Chain
Microsoft WSUS RCE Vulnerability (CVE-2025-59287) Exposes Critical Infrastructure
In October 2025, Microsoft disclosed and released an out-of-band security update for a critical remote code execution vulnerability (CVE-2025-59287) affecting Windows Server Update Services (WSUS) across multiple Windows Server versions (2012–2025). The flaw allowed unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges on unpatched WSUS servers, particularly when ports TCP 8530/8531 were exposed. Exploitation involved spawning child processes through wsusservice.exe or w3wp.exe, with threat actors leveraging PowerShell payloads and potentially broader lateral movement. Organizations failing to patch faced severe risk of compromise. This incident underscores the escalating trend of supply chain and infrastructure attacks, where core update and provisioning mechanisms are targeted to gain privileged access or disrupt operations. Active exploitation and KEV listing prompt heightened urgency for organizations to address legacy system exposures and reinforce privileged system monitoring.
6 months ago
Kill Chain
Vertikal Systems 2025: Healthcare Data at Risk via Hospital Manager Backend Vulnerabilities
In September 2025, Vertikal Systems disclosed two critical vulnerabilities affecting its Hospital Manager Backend Services. The first flaw (CVE-2025-54459) allowed unauthorized, remote access to the ASP.NET tracing endpoint, potentially exposing sensitive data such as authorization tokens and server metadata. The second (CVE-2025-61959) disclosed verbose error pages on invalid requests, inadvertently leaking application stack traces and configuration files. Both issues were exploitable without authentication, posing significant data privacy and operational risk across healthcare sites globally. This incident spotlights ongoing risks to healthcare organizations due to misconfigurations and unnecessary exposure of sensitive developer endpoints. With increasing regulatory pressure on patient data security and the healthcare sector's targeted threat profile, such vulnerabilities could lead to compliance violations or facilitate wider attacks.
6 months ago
Kill Chain
CISA Highlights Active Exploitation of XWiki & VMware Vulnerabilities in 2025 KEV Catalog Update
In October 2025, CISA added two actively exploited vulnerabilities—CVE-2025-24893 in XWiki Platform (Eval Injection) and CVE-2025-41244 in Broadcom VMware Aria Operations and VMware Tools (Privilege Defined with Unsafe Actions)—to its Known Exploited Vulnerabilities (KEV) Catalog. These flaws enable remote attackers to inject malicious code or escalate privileges, presenting substantial risks for the federal enterprise and beyond. The inclusion in the KEV Catalog signals confirmed in-the-wild exploitation and compels agencies to expedite remediation measures under Binding Operational Directive 22-01 to protect critical federal infrastructure networks. This incident underscores the persistent trend of attackers rapidly leveraging new or previously overlooked vulnerabilities with real-world consequences. As the speed of exploitation shortens and attack surfaces broaden, timely vulnerability management, zero trust practices, and proactive monitoring remain vital to reducing enterprise cyber risk.
6 months ago
Kill Chain
PhantomRaven’s Malicious npm Packages: 2024 Supply-Chain Risk with Invisible Dependencies
In early 2024, the "PhantomRaven" campaign targeted the open-source software ecosystem by distributing 126 malicious npm packages containing concealed, 'invisible' dependencies. These packages, published over several months, bypassed detection mechanisms and were downloaded over 86,000 times by unsuspecting developers. Threat actors leveraged these supply chain attacks to potentially exfiltrate sensitive data, propagate malware, or serve as initial entry points for deeper compromises in downstream applications and organizations dependent on these packages. The campaign highlighted significant vulnerabilities in supply-chain security and the risks associated with open-source package management. This incident is part of a rising trend of sophisticated supply-chain attacks leveraging trusted developer tools and repositories. With increasing regulatory scrutiny and mounting pressure to harden software dependencies, organizations must assess their exposure and implement robust controls to thwart similar attacks in the future.
6 months ago
Kill Chain
PhantomRaven Floods npm with Malicious Credential-Stealing Packages
In April 2024, the 'PhantomRaven' threat campaign targeted the JavaScript software ecosystem by flooding the npm package repository with dozens of malicious packages. These packages, aimed at developers and CI/CD environments, were crafted to harvest authentication tokens, CI/CD secrets, and GitHub credentials when installed. Attackers employed typosquatting and deceptive package naming techniques to trick developers into integrating the compromised code into their applications, thereby enabling broad access to source code and sensitive internal systems. The attack underscores the growing risk posed by software supply chain compromises, impacting thousands of potential downstream applications and organizations. This incident highlights an ongoing surge in supply chain attacks leveraging public code repositories, targeting both individual developers and enterprise development pipelines. Attackers are increasingly employing credential harvesting via trusted open-source channels, intensifying regulatory scrutiny and driving immediate needs for enhanced software integrity controls and threat detection across development workflows.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports