✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Pixnapping Attack: How Android 2FA Was Bypassed in 2024
In early 2024, researchers discovered a novel mobile vulnerability known as the 'Pixnapping' attack, which targeted Android applications to circumvent two-factor authentication (2FA) mechanisms. The attack leverages cleverly crafted overlays to capture sensitive information directly from protected apps such as Gmail, Google Accounts, Google Authenticator, Google Maps, Signal, and Venmo. While there is no evidence of widespread exploitation, the proof-of-concept demonstrates that malicious apps with appropriate permissions could bypass Android security boundaries, enabling attackers to steal both credentials and 2FA tokens, thereby jeopardizing highly sensitive user data on compromised devices. This incident underscores the urgent need for stronger in-app security controls and constant vigilance regarding permission granularity on mobile platforms. As more threat actors focus on mobile endpoints and multi-factor authentication, organizations and users must adapt their defenses to counter increasingly sophisticated and evasive attack methods.
6 months ago
Kill Chain
Microsoft's October 2025 Zero-Day Storm: What the Massive Patch Update Means for Your Business
In October 2025, Microsoft released a massive Patch Tuesday security update addressing over 100 vulnerabilities across its product suite, including multiple actively exploited zero-days and several high-severity privilege escalation flaws. Threat actors leveraged some of these unpatched vulnerabilities to gain elevated access to enterprise and government systems, exploiting both on-premises and cloud workloads. The update also marked the final round of Windows 10 security patches, raising urgency for legacy system owners to upgrade in order to remain protected. The overall business impact included increased risk of lateral movement, data exfiltration, service disruptions, and heightened remediation costs for organizations slow to patch. This incident underscores an ongoing trend of attackers rapidly weaponizing newly disclosed vulnerabilities, as well as the growing threat facing organizations who rely on end-of-life software. The scale and speed of exploit adoption highlight the critical importance of vulnerability management and proactive patching as top security priorities.
6 months ago
Kill Chain
Microsoft VS Code Marketplace Plugins Leak Sensitive Secrets: Supply Chain Alert
In early 2024, security researchers uncovered over 550 unique authentication secrets (such as API keys and credentials) leaking from extensions published on Microsoft's Visual Studio Code Marketplace. The exposed secrets, embedded within third-party extensions, created a major supply chain risk by potentially allowing attackers to compromise developer environments or escalate access to sensitive systems. Microsoft responded by enhancing its security review process, warning affected publishers, and initiating additional controls to prevent similar exposures in the future. This incident highlights the growing risks tied to open software ecosystems, where attackers increasingly target supply chain dependencies. With developer tools and plugin marketplaces at the core of modern workflows, secret leakage could enable widespread compromise, pushing organizations to urgently strengthen code supply chain security and compliance.
6 months ago
Kill Chain
Phishing Surge Exposes Password Manager Vulnerabilities: Lessons from the 2024 LastPass Incident
In early 2024, a series of highly targeted phishing campaigns were launched against users of LastPass and other leading password managers. Threat actors masqueraded as trusted service communications to exploit user trust, distributing convincing emails and fraudulent alerts to trick victims into providing master credentials or installing malicious software. Despite existing security controls, the attackers leveraged sophisticated social engineering and exploited the single point of failure inherent to password vaults, putting sensitive enterprise and personal accounts at risk. The attack underscores the vulnerability of credential management platforms to phishing-driven infiltration and the potential for widespread credential compromise. This incident highlights a surge in credential phishing tactics aimed at circumventing advanced security measures by exploiting human error. As password managers become more widespread, attackers are evolving methods to target the trust users place in these tools, emphasizing the need for continuous security awareness, robust MFA adoption, and proactive anomaly detection around high-value authentication solutions.
6 months ago
Kill Chain
Microsoft Halts Rhysida Ransomware Campaign Abusing Azure Certificates
In early 2024, Microsoft uncovered and disrupted a sophisticated ransomware campaign in which attackers abused more than 200 stolen or forged Azure Active Directory certificates to sign malicious Microsoft Teams binaries. This campaign, attributed to the Rhysida ransomware group, enabled threat actors to appear as legitimate Microsoft services, bypassing security controls and delivering the final ransomware payloads to targeted enterprise environments. Following detection, Microsoft swiftly revoked the malicious certificates and worked with affected customers to mitigate the threat, limiting further operational and financial damage. This incident underscores the increased attacker focus on abusing trusted cloud identities and supply chain trust mechanisms to facilitate stealthy lateral movement and ransomware deployment. Organizations are now under greater pressure to strengthen certificate governance, cloud identity monitoring, and east-west traffic security controls as threat actors escalate the abuse of cloud-native infrastructure.
6 months ago
Kill Chain
GlassWorm: A Self-Propagating Supply Chain Worm Targets VS Code Developers
In early 2024, a sophisticated supply chain attack targeting the Visual Studio Code (VS Code) developer ecosystem was uncovered, leveraging a self-propagating worm dubbed 'GlassWorm.' The attack exploited weaknesses in package distribution and dependency validation, spreading rapidly via malicious code hidden in open-source extensions and packages. Once executed on developer machines, GlassWorm covertly harvested credentials and turned compromised systems into nodes for broader criminal infrastructure, affecting nearly 36,000 endpoints globally. The incident illuminated the risks posed by highly automated, invisible code propagation through trusted development tools, impacting developer productivity and increasing the potential for downstream compromise across organizations that rely on shared code repositories. This breach is emblematic of the accelerating trend of supply chain attacks against development environments, with threat actors increasingly leveraging automation and legitimate software to undermine trust. The GlassWorm incident underscores the urgency for enhanced visibility, stringent code validation, and zero trust controls in modern software supply chains to counter evolving adversary tactics.
6 months ago
Kill Chain
How Flawed Vendor Guidance Led to Oracle WAF Attacks in 2024
In 2024, Oracle E-Business Suite customers became vulnerable after the company released flawed guidance on deploying its Web Application Firewall (WAF), failing to mitigate a critical zero-day vulnerability. The lack of effective instructions enabled threat actors to exploit the misconfiguration, leading to ransomware attacks and potential data breaches for numerous enterprises. Attackers leveraged the window before official patches or updated configurations, gaining lateral movement and access to sensitive business operations. This incident highlighted how vendor missteps in supply-chain security can cascade across customer environments, amplifying operational risk and compliance exposure. The breach underscores the increasing risk associated with supply-chain vulnerabilities and misaligned vendor guidance. As sophisticated threats target misconfigurations and third-party solutions, organizations must reassess their reliance on default vendor instructions and proactively harden their environments against emerging TTPs.
6 months ago
Kill Chain
Scattered LAPSUS$ Hunters Target Encrypted Traffic in 2024 Hybrid Cloud Breach
In early 2024, the cybercrime group Scattered LAPSUS$ Hunters was observed launching a series of attacks targeting high-performance encrypted traffic between enterprise environments. Leveraging advanced tactics such as packet sniffing and lateral movement across hybrid and multicloud networks, the group exploited weak internal segmentation and gaps in east-west traffic controls. The attackers circumvented some organizations’ use of line-rate encryption by targeting less-protected internal flows and using sophisticated threat detection evasion techniques. Operational impacts included service disruptions, potential data exfiltration, and compromised cloud environments. This incident underscores the evolution of cybercrime actors as they adopt more advanced methods to breach environments assumed to be protected by conventional encryption or traditional network segmentation. The trend highlights growing risks for enterprises relying on hybrid and multicloud infrastructure, and illustrates the urgent need for zero trust approaches and enhanced east-west traffic security.
6 months ago
Kill Chain
Jingle Thief: A 2024 Look at Cloud Gift Card Fraud in Retail
In early 2024, security researchers uncovered "Jingle Thief," a sophisticated cybercriminal campaign targeting major retail organizations through coordinated phishing and smishing attacks. The attackers leveraged credential harvesting to gain unauthorized, persistent access to enterprise cloud environments and exploited multicloud weaknesses to orchestrate large-scale, automated gift card fraud. This activity resulted in the theft of significant monetary value from targeted retailers and demonstrated the evolving tactics of financially motivated threat groups seeking to exploit cloud infrastructure and weak east-west security controls. Jingle Thief underscores an alarming trend: attackers increasingly exploit cloud misconfigurations and multifactor authentication gaps to maintain post-compromise access for extended periods. The campaign exemplifies the need for enterprises to adopt Zero Trust strategies and rigorous east-west segmentation as criminals shift focus toward cloud-native targets.
6 months ago
Kill Chain
Remote Code Execution Flaw in Abandoned Rust Library Exposes Global Supply Chain
In August 2024, Edera researchers discovered CVE-2025-62518, a high-severity remote code execution vulnerability in the abandoned async-tar library for the Rust programming language. This logic flaw, named "TARmageddon," was unwittingly propagated to millions of users through downstream forks like tokio-tar and widely used build tools such as uv and testcontainers. The systemic risk arises because the vulnerability was replicated across a deep lineage of forks, making it very difficult to detect and patch comprehensively. Exploitation allows attackers to achieve remote code execution by overwriting files via malicious tar archives—a threat amplified by the lack of direct visibility into indirect dependencies in modern supply chains. The incident is especially impactful as it highlights the persistent risks of open-source abandonware and insufficient maintenance of foundational software libraries. It underscores growing industry focus on supply-chain security, indirect dependency management, and the need for rapid, coordinated vulnerability disclosure and remediation.
6 months ago
Kill Chain
Stealit Malware Abuses Node.js SEA in 2025 Infostealer Supply Chain Campaign
In October 2025, cybersecurity experts uncovered an active malware campaign involving Stealit, an advanced infostealer that exploits Node.js' Single Executable Application (SEA) feature to deliver its malicious payloads. The campaign also utilized the Electron framework and disguised its distribution through popular but trojanized game and VPN installers. Once executed, Stealit exfiltrated sensitive data from victims—such as credentials, browser information, and cryptocurrency wallets—using stealthy techniques while evading detection. The attack led to significant risks of account compromise and potential financial loss, particularly for organizations relying on affected software supply chains. This incident highlights a broader trend of attackers weaponizing modern development frameworks (like Node.js and Electron) to bypass traditional endpoint defenses. The use of legitimate-looking installers and supply chain manipulation signal an evolution in infostealer delivery tactics, making vigilance and advanced network segmentation crucial for organizational resilience.
6 months ago
Kill Chain
ChaosBot Unleashed: Rust-Based Malware Breach Leverages Discord and Stolen Credentials
In October 2025, security researchers identified a targeted cyberattack involving a new Rust-based backdoor known as ChaosBot. The threat actors initially leveraged compromised credentials associated with both a Cisco VPN account and an over-privileged Active Directory service account, enabling them to gain stealthy remote access to victims’ environments. Once inside, ChaosBot connected to adversary-controlled Discord channels for command-and-control and allowed attackers to perform reconnaissance, execute arbitrary commands, and potentially move laterally through affected networks. The incident underscores attackers' increasing reliance on credential abuse, novel malware written in memory-safe languages, and abuse of popular cloud-based collaboration tools for C2, ultimately increasing the risk of data exfiltration and operational disruption for enterprises reliant on hybrid identity and VPN solutions. This incident exemplifies the growing threat of multi-vector identity compromise combined with cloud and modern malware tradecraft. Its emergence highlights the urgent need for organizations to adopt zero trust access controls, enforce strict privilege management, and monitor for suspicious activity across both cloud and on-premises assets.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports