Validated Containment Architectures are here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2699 threat reports
Page 199 of 225

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 23772388 / 2699 reports
Astaroth Banking Trojan Leverages GitHub to Evade Takedowns in 2025
Impact· medium

Astaroth Banking Trojan Leverages GitHub to Evade Takedowns in 2025

In October 2025, cybersecurity researchers uncovered a sophisticated campaign distributing the Astaroth banking trojan, which leveraged GitHub repositories as its primary command-and-control infrastructure. By shifting away from traditional, easily dismantled C2 servers, attackers used public code-hosting platforms to deploy configuration files and payloads. Targeted endpoints were infected through phishing campaigns, after which Astaroth would harvest credentials and financial data undetected. The integration with GitHub provided attackers increased operational resilience, making takedown efforts by defenders and law enforcement more challenging. Financial institutions and users experienced notable disruptions and heightened risk of unauthorized account activity due to these stealthy techniques. This incident highlights a growing trend of threat actors abusing legitimate platforms for illicit operations, undermining trust in cloud services. Organizations must reassess controls and detection strategies as adversaries increasingly exploit mainstream tools and shift to fileless, cloud-hosted malware models.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft Shuts Down IE Mode After Zero-Day Exploit Exposes Legacy Risks
Impact· low

Microsoft Shuts Down IE Mode After Zero-Day Exploit Exposes Legacy Risks

In August 2025, Microsoft responded to credible reports that unknown threat actors exploited Internet Explorer (IE) mode in the Edge browser. Attackers used a combination of unpatched (zero-day) JavaScript vulnerabilities and basic social engineering to compromise legacy IE mode, which allowed unauthorized access to Windows devices. The exploitation leveraged backward compatibility for legacy web apps, serving as an entry point for attackers to install persistent backdoors and potentially exfiltrate sensitive data. Microsoft swiftly revamped and locked down IE mode to prevent further abuse, minimizing ongoing risk and alerting organizations reliant on legacy web technologies. This incident underscores the persistent risks of maintaining backward compatibility for legacy browser features. As attackers increasingly target older components embedded within modern platforms, organizations face new urgency to accelerate deprecation plans and strengthen zero trust security controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
TA585’s MonsterV2: Unveiling 2025’s Next-Gen Phishing Infostealer Threat
Impact· medium

TA585’s MonsterV2: Unveiling 2025’s Next-Gen Phishing Infostealer Threat

In October 2025, cybersecurity researchers uncovered new activities by the previously undocumented threat actor TA585, which was observed conducting sophisticated phishing attacks to deliver the MonsterV2 infostealer malware. The group leveraged advanced tactics, including web injections and traffic filtering, to evade detection and ensure payload delivery. Once deployed, MonsterV2 enabled TA585 to harvest sensitive information and credentials, posing significant risks to organizational data integrity and confidentiality. The attack chains exploited weaknesses in email security and endpoint controls, demonstrating a concerning evolution in social engineering and malware delivery. This incident highlights the growing prevalence of stealthy infostealer campaigns targeting enterprises across multiple sectors. It underscores the urgent need for organizations to reevaluate network segmentation, multi-cloud visibility, and anomaly detection strategies to counter increasingly capable threat actors and align with evolving compliance standards.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
How Malicious Open Source Packages Used Discord to Breach Developer Supply Chains in 2025
Impact· medium

How Malicious Open Source Packages Used Discord to Breach Developer Supply Chains in 2025

In October 2025, security researchers uncovered a widespread supply chain attack targeting popular open source repositories—including npm, PyPI, and RubyGems. Malicious packages were uploaded to these ecosystems and leveraged Discord webhooks as a covert command-and-control (C2) channel to exfiltrate sensitive developer data upon installation. The attackers took advantage of the ease of publishing code to open source registries, embedding scripts that silently siphoned credentials, environment variables, and other project secrets. Dozens of projects and potentially thousands of developers or organizations were impacted, risking further compromise via credential leakage and downstream dependency poisoning. This incident underscores the urgency of enforcing robust dependency hygiene and highlights a rising trend: attackers increasingly abusing trusted supply chains and common collaboration tools for exfiltration. As open source usage soars and supply chain security intensifies, organizations must be vigilant against covert exfiltration methods and adopt multilayered security controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Microsoft’s 2025 Windows Zero-Day Exploitation: What Every Enterprise Needs to Know
Impact· medium

Microsoft’s 2025 Windows Zero-Day Exploitation: What Every Enterprise Needs to Know

In October 2025, Microsoft revealed that two previously unknown zero-day vulnerabilities had been discovered and actively exploited in every supported and unsupported version of Windows, following its Patch Tuesday release. Attackers leveraged these unpatched flaws to compromise systems, facilitating unauthorized access and the potential for privilege escalation and lateral movement. The vulnerabilities affected both enterprise and consumer endpoints, raising concerns about widespread risk at a time when older Windows 10 systems reached end-of-support unless enrolled in paid extended coverage. This incident forced rapid emergency patch deployment and incident response in enterprises worldwide. This event underscores a rising trend in the exploitation of zero-day flaws in core operating systems, putting organizations under pressure to minimize their exposure and improve vulnerability and patch management. Regulatory scrutiny and increased attacker sophistication have elevated expectations for response times and organizational cyber resilience.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How Attackers Bypass Synced Passkeys: Lessons from the 2025 Incident
Impact· medium

How Attackers Bypass Synced Passkeys: Lessons from the 2025 Incident

In October 2025, a significant security incident highlighted how attackers are bypassing synced passkey protections via adversary-in-the-middle (AiTM) techniques. Attackers exploited weaknesses in the synchronization of passkeys—where user credentials are stored in the cloud and synchronized across devices—to circumvent strong authentication requirements. By leveraging AiTM phishing kits and triggering fallback authentication flows, adversaries gained unauthorized access to enterprise accounts, exposing sensitive data and business operations. This vector sidesteps traditional multi-factor authentication and identity-first defenses, putting organizations reliant on passkey sync at risk. This incident demonstrates an urgent shift in attacker tactics toward abusing authentication recovery and synchronization flows that are increasingly common with passwordless deployments. As more businesses move to passkeys for convenience, the associated risks with synced secrets and recoveries have become a major security concern that demands new approaches and controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
VS Code Extension Access Token Leak: A 2025 Supply Chain Wake-Up Call
Impact· medium

VS Code Extension Access Token Leak: A 2025 Supply Chain Wake-Up Call

In October 2025, a major supply chain risk was exposed when over 100 Visual Studio Code (VS Code) extensions were found to have leaked access tokens, allowing threat actors to publish malicious updates to widely used extensions. Attackers who obtained these tokens could have distributed compromised software versions to millions of developers globally, undermining trust in open-source ecosystems and introducing the risk of code tampering, credential theft, or insertion of backdoors into organizational environments. The vulnerability lay in the mishandling and inadvertent leakage of personal access tokens (PATs) for both the VSCode Marketplace and Open VSX, giving adversaries an insidious update path into developer workstations and CI/CD pipelines. This incident highlights the increasing frequency and sophistication of supply chain attacks targeting developer tools and open-source dependencies. As the software landscape grows more interconnected, private access tokens and code-signing credentials now represent high-value targets, requiring robust security controls and zero trust validation across the development lifecycle.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Chinese APT 'Jewelbug' Compromises Russian IT Provider in Stealthy 2025 Attack
Impact· medium

Chinese APT 'Jewelbug' Compromises Russian IT Provider in Stealthy 2025 Attack

In early 2025, the Chinese state-linked threat group known as 'Jewelbug' stealthily infiltrated a prominent Russian IT service provider over a five-month period, according to findings from Symantec. The attackers gained initial access in January, likely leveraging supply chain or credential compromise vectors, and subsequently maintained persistent, undetected presence until May. Jewelbug is known for sophisticated tactics, including advanced lateral movement, encrypted traffic, and covert exfiltration. As a result, sensitive data and core IT systems within the provider’s infrastructure were at risk, potentially impacting downstream Russian clients who relied on its managed services. This incident highlights the expanding global reach of advanced persistent threats (APTs), with Jewelbug moving beyond historical targets in Southeast Asia and South America to now conduct espionage in Russia. The breach demonstrates increasing sophistication in supply chain and east-west attack techniques, underscoring urgent need for robust lateral movement prevention, segmentation, and cloud visibility controls.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Russian Hackers Evolve Malware via 'I am not a robot' Captchas in 2024
Impact· low

Russian Hackers Evolve Malware via 'I am not a robot' Captchas in 2024

In early 2024, the Russian state-sponsored group Star Blizzard intensified its cyber-espionage operations, leveraging advanced malware strains (NoRobot, MaybeRobot) delivered via deceptive "I am not a robot" CAPTCHA prompts in targeted ClickFix phishing campaigns. Attackers executed multi-stage infection chains, enticing victims to enable malicious browser extensions or download trojanized payloads under the guise of legitimate productivity fixes. These campaigns enabled persistent access to sensitive organizational data, posed risks of lateral movement within networks, and facilitated exfiltration of proprietary intelligence. This incident underscores a concerning trend: the use of dynamic, highly-adaptive social engineering and malware delivery methods by state-backed actors. As similar tactics are increasingly observed across sectors, organizations must harden entry-point protections and improve internal visibility to counter evolving nation-state threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Inside the LinkPro Linux Rootkit: eBPF Backdoors AWS Cloud in 2025
Impact· medium

Inside the LinkPro Linux Rootkit: eBPF Backdoors AWS Cloud in 2025

In October 2025, security researchers from Synacktiv revealed the discovery of LinkPro, a sophisticated GNU/Linux rootkit targeting AWS-hosted infrastructure. The attackers leveraged advanced eBPF techniques to install two modules: one for stealth, allowing the malware to evade detection, and another granting remote access via specially crafted TCP packets (magic packets). This backdoor enabled threat actors to persist undetected, hide their presence, and maintain control of compromised systems in cloud environments, posing severe risks to the underlying business operations and data confidentiality of affected organizations. This incident highlights the escalating use of kernel-level and cloud-specific attack techniques, exploiting eBPF to bypass traditional defenses. The campaign underscores a growing trend of attackers utilizing cloud-native technologies to achieve stealth and persistence, raising urgent concerns for CISOs overseeing both public cloud and Linux workloads.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Cursor & Windsurf IDEs Hit by 94+ Chromium Vulnerabilities – Supply-Chain Exposure in 2024
Impact· low

Cursor & Windsurf IDEs Hit by 94+ Chromium Vulnerabilities – Supply-Chain Exposure in 2024

In early 2024, security researchers identified that the latest releases of the Cursor and Windsurf integrated development environments (IDEs) were vulnerable to over 94 known and patched security vulnerabilities within the embedded Chromium browser and V8 JavaScript engine. These n-day vulnerabilities exist because the IDEs relied on outdated Chromium builds, exposing users to a range of critical issues, including remote code execution, privilege escalation, and data leakage. The supply-chain nature of the incident means development teams using these IDEs could inadvertently introduce risk across their entire workflow and environments. This incident underscores the persistent risk posed by vulnerable software dependencies and highlights an urgent need for improved supply-chain security. With attackers increasingly targeting development tools for initial access or lateral movement, organizations must re-evaluate their patch management, vendor risk assessments, and layered network protections.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical Command Injection Flaw Found in TP-Link Omada Gateways (2024)
Impact· medium

Critical Command Injection Flaw Found in TP-Link Omada Gateways (2024)

In June 2024, TP-Link disclosed a critical security vulnerability (CVE-2024-5035) affecting several Omada gateway models. The flaw is a pre-authentication operating system command injection that could allow remote, unauthenticated attackers to execute arbitrary commands on vulnerable devices, compromising the integrity and availability of network infrastructure. TP-Link quickly released firmware patches, urging customers to update immediately. This exposure heightened the risk of unauthorized access to internal networks, potentially leading to data breaches, lateral movement, or infrastructure disruption for organizations reliant on impacted Omada devices. The incident underscores an ongoing trend of targeting network infrastructure via supply chain or firmware vulnerabilities, which have become increasingly prevalent as attackers seek to exploit core networking hardware. This highlights the need for vigilant patch management and segmentation in defense strategies, as well as resilience against emerging firmware and gateway attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports