Validated Containment Architectures are here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2707 threat reports
Page 203 of 226

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 24252436 / 2707 reports
F5 2025 Supply Chain Breach: BIG-IP Vulnerabilities Exposed by State Hackers
Impact· low

F5 2025 Supply Chain Breach: BIG-IP Vulnerabilities Exposed by State Hackers

In August 2025, cybersecurity company F5 detected a sophisticated supply chain attack resulting in the theft of source code and undisclosed vulnerabilities affecting its flagship BIG-IP products. The breach, attributed to state-sponsored hackers, did not lead to immediate exploitation but exposed potentially critical flaws. F5 responded by rapidly developing and releasing security patches for 44 vulnerabilities, proactively urging its global clientele—including many Fortune 500 companies and federal agencies—to update systems and implement enhanced monitoring. No evidence was found of modifications to the supply chain or active use of the stolen information as of disclosure. This incident highlights mounting concerns around supply chain security and zero-day vulnerability exposure, particularly within critical infrastructure and cloud environments. The breach also triggered regulatory intervention, with CISA issuing emergency directives for federal agencies, underscoring rising government attention to third-party risks and broader cybersecurity resilience in the face of advanced persistent threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Fake LastPass & Bitwarden Breach Alerts: Phishing Attack Delivers Malware (2024)
Impact· low

Fake LastPass & Bitwarden Breach Alerts: Phishing Attack Delivers Malware (2024)

In early June 2024, a sophisticated phishing campaign targeted users of password managers LastPass and Bitwarden. Attackers sent convincing emails, falsely claiming that the services had suffered security breaches and instructing recipients to download a new, supposedly more secure, desktop version. The malicious download actually installed malware, enabling attackers to hijack compromised PCs and potentially steal credentials or other sensitive data. Victims who downloaded the fake app were exposed to significant risks, including credential theft and remote control of their systems. This incident highlights escalating use of credible brand impersonation and urgent alert tactics by cybercriminals. The campaign underscores the vulnerabilities associated with password manager users and demonstrates the growing threat landscape for identity-driven and social engineering attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
PowerSchool 2024 Data Breach: College Student Sentenced for Massive Attack
Impact· high

PowerSchool 2024 Data Breach: College Student Sentenced for Massive Attack

In December 2024, PowerSchool, a major provider of cloud-based education technology, suffered a significant data breach orchestrated by 19-year-old college student Matthew D. Lane from Worcester, Massachusetts. Lane infiltrated PowerSchool’s systems by exploiting a combination of credential theft and vulnerabilities in internal access controls, enabling him to exfiltrate large volumes of sensitive student and faculty data over several weeks. Law enforcement investigation led to his arrest and subsequent sentencing to four years in prison, highlighting both the sophistication of modern attackers and the sensitivity of educational data targeted. The case is especially relevant as threat actors increasingly set their sights on critical SaaS platforms and education technology, exploiting gaps in zero trust implementation and east-west traffic visibility. The incident underscores a rising trend in data breaches against public sector organizations and the urgent need for robust controls in cloud and hybrid environments.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
How Adversaries Used AI CLI Tools for Command & Control in 2024
Impact· medium

How Adversaries Used AI CLI Tools for Command & Control in 2024

In early 2024, security researchers identified a new wave of cyber intrusions involving adversaries weaponizing AI-enabled command-line tools to facilitate command and control activities within targeted business environments. Attackers leveraged popular AI code-assistants such as Claude Code, integrating them into CLI workflows to generate and execute malicious payloads, exfiltrate credentials, and bypass conventional security controls. The attack chain typically relied on legitimate processes, enabling lateral movement and credential theft while avoiding detection by traditional endpoint defenses. Unauthorized east-west traffic and encrypted exfiltration allowed threat actors to maintain persistence and evade standard monitoring solutions, impacting both operational continuity and sensitive business data. The incident underscores a rapidly evolving threat landscape where generative AI and shell automation converge, accelerating the sophistication and speed of adversary tactics. As enterprises adopt AI-driven DevOps and operational tooling, the risk of shadow AI and undetected rogue automation increases, compelling a shift towards advanced visibility, zero trust segmentation, and policy enforcement across hybrid environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
2025 Mysterious Elephant Attack: Asia-Pacific Government Cyber-Espionage Exposed
Impact· medium

2025 Mysterious Elephant Attack: Asia-Pacific Government Cyber-Espionage Exposed

In early 2025, the Mysterious Elephant advanced persistent threat group launched a sophisticated campaign targeting government and foreign affairs entities across Pakistan, Bangladesh, Afghanistan, Nepal, and Sri Lanka. Utilizing spear phishing emails, exploit kits, and malicious documents as entry vectors, the group deployed custom and open-source malware—such as BabShell, MemLoader HidenDesk, and ChromeStealer—to gain persistent network access, move laterally, and exfiltrate sensitive data. Their tooling leveraged advanced evasion tactics and targeted WhatsApp data for exfiltration, compromising documents, images, and browser credentials. The operation demonstrates considerable code reuse and customized tooling, posing a significant disruption to national and diplomatic processes in the region. Mysterious Elephant’s shift to tailored malware, WhatsApp-specific exfiltration, and cloud-based infrastructure highlights a broader threat landscape trend: state-sponsored actors refining tactics for targeted governmental espionage. This underscores the importance of proactive monitoring and cross-border information sharing to address escalating nation-state risks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Microsoft Patch Tuesday Ring-fences 172 Flaws and Ends Windows 10 Support
Impact· medium

Microsoft Patch Tuesday Ring-fences 172 Flaws and Ends Windows 10 Support

In October 2025, Microsoft’s Patch Tuesday delivered critical security updates addressing 172 vulnerabilities in Windows operating systems, including two zero-days actively exploited in the wild. The first, CVE-2025-24990, is a flaw in the long-bundled Agere Modem driver exploited by attackers and removed entirely by Microsoft. The second, CVE-2025-59230, impacted Windows Remote Access Connection Manager (RasMan), risking privilege escalation through compromised VPN and remote access services. Remote code execution bugs in Office Preview Pane and a critical risk to Windows Server Update Services (WSUS) put both endpoints and patching infrastructure at significant risk. This large wave of vulnerabilities coincided with the end of official support for Windows 10, Exchange Server 2016, and other Microsoft products. The combination of zero-day exploitation and the end-of-life for popular products highlights the urgent need for proactive vulnerability management and secure migration paths as cybercriminals increasingly exploit outdated software.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Python Infostealer Exposes New Clipboard Image Attack Vector in 2024
Impact· medium

Python Infostealer Exposes New Clipboard Image Attack Vector in 2024

In October 2024, a new Python-based infostealer was discovered leveraging the clipboard’s picture functionality to stealthily exfiltrate screenshots and images from victim machines. The malware, observed in the wild using Telegram for command-and-control, exploits the common trust in clipboard features by targeting not only text but also graphical data such as screenshots often exchanged for reporting or documentation. Notably, the malware’s code contained Vietnamese-language comments, and a sample analyzed had a low detection score on VirusTotal, indicating low awareness and potential for widespread impact. This incident highlights the evolution of infostealer tactics as they expand data theft payloads beyond credentials and text, exploiting overlooked vectors like clipboard images. Such techniques present new challenges for organizations as attackers increasingly focus on fileless, cross-platform exfiltration and abuse of trusted collaboration workflows.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
PhantomVAI Loader in 2024: Advanced Malware Delivery and Infostealer Risks
Impact· medium

PhantomVAI Loader in 2024: Advanced Malware Delivery and Infostealer Risks

In early 2024, cybersecurity researchers at Palo Alto Networks Unit 42 identified PhantomVAI, a new loader malware designed to deliver a variety of infostealers such as Lumma Stealer and LokiBot. The campaign uses advanced steganography and heavily obfuscated scripts to evade detection, enabling attackers to distribute payloads through malicious downloads and compromised websites. PhantomVAI’s modular design allows cybercriminals to easily switch the delivered malware, raising the risk for rapid adaptation against defense mechanisms. Affected organizations may experience credential compromise, data exfiltration, and exposure of sensitive information. This incident exemplifies the increasing sophistication of malware loaders and highlights a growing trend toward customizable, evasive attack tools targeting businesses worldwide. As attackers continue to automate and obfuscate their delivery methods, organizations must enhance their monitoring and threat detection to keep pace with evolving threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Microsoft Patch Tuesday: October 2025 Brings Critical Zero-Day Exploits
Impact· medium

Microsoft Patch Tuesday: October 2025 Brings Critical Zero-Day Exploits

In October 2025, Microsoft disclosed and patched 175 vulnerabilities affecting its major products, marking the year's largest vulnerability release from the company. Notably, two zero-day vulnerabilities (CVE-2025-24990 in the Agere Windows Modem Driver and CVE-2025-59230 in Windows Remote Access Connection Manager) were discovered to be actively exploited in the wild. Attackers leveraging these flaws could elevate privileges, potentially gaining administrative or system-level access across all supported Windows versions. Microsoft acted promptly, removing the vulnerable modem driver and providing fixes for the Remote Access Connection Manager, with the U.S. Cybersecurity and Infrastructure Security Agency adding both zero-days to its known exploited catalog. This incident underscores the persistent threat posed by zero-day exploits and highlights the increasing rate at which attackers are targeting system-level services and third-party drivers. The surge of high-severity vulnerabilities, along with rapid exploitation, demonstrates the need for organizations to strengthen vulnerability and privilege management programs to respond to modern attack trends.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Chinese APT Exploits ArcGIS Tool for Stealthy Persistence and Credential Theft
Impact· medium

Chinese APT Exploits ArcGIS Tool for Stealthy Persistence and Credential Theft

In 2025, a Chinese state-sponsored Advanced Persistent Threat (APT) group, attributed to Flax Typhoon, maintained over a year of undetected access to an organization's network by exploiting a public-facing ArcGIS geo-mapping server. The attackers leveraged stolen administrator credentials to upload a malicious Java Server Object Extension (SOE) acting as a covert web shell, allowing them to execute commands via a REST API and escalate privileges internally. Persistence was further established by deploying SoftEther VPN Bridge, enabling encrypted outbound connectivity and facilitating lateral movement, data exfiltration, and credential harvesting within the victim's environment. This incident underscores the increasing sophistication of APTs exploiting legitimate third-party software and obscure admin features for stealthy, long-term persistence. The method's novelty, combined with highly targeted credential theft and the use of living-off-the-land techniques, highlights urgent gaps in detection, segmentation, and secure configuration, especially in public-facing or critical GIS applications.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Framework’s 2025 Secure Boot Bypass: How Signed UEFI Debug Tools Created a Supply-Chain Crisis
Impact· medium

Framework’s 2025 Secure Boot Bypass: How Signed UEFI Debug Tools Created a Supply-Chain Crisis

In October 2025, firmware security researchers revealed a supply-chain vulnerability affecting nearly 200,000 Framework Linux laptops, caused by the inclusion of signed UEFI shells with the powerful 'mm' (memory modify) command. This legitimate but dangerous command, intended for hardware debugging, could be used by attackers with local or physical access to bypass Secure Boot by overwriting memory critical to the boot process—disabling signature verification and enabling the loading of bootkits like BlackLotus or HybridPetya. The issue was not the result of an external compromise but a manufacturing oversight, impacting several Framework 13 and Framework 16 models, with firmware updates and mitigation guidance swiftly issued. This vulnerability highlights a growing risk in hardware supply-chain security, where trusted vendor-signed components can inadvertently enable sophisticated attacks that persist even after OS reinstalls. As attackers increasingly target firmware and boot processes, the incident underscores the urgency for robust device-level and manufacturing-time security controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Microsoft October 2025 Patch Tuesday: Six Zero-Days and 172 Vulnerabilities Addressed
Impact· medium

Microsoft October 2025 Patch Tuesday: Six Zero-Days and 172 Vulnerabilities Addressed

In October 2025, Microsoft released security patches addressing 172 vulnerabilities across its product suite, including six actively-exploited zero-day flaws. These vulnerabilities exposed users to potential remote code execution, privilege escalation, and data leakage risks. The zero-days were exploited prior to patch release, affecting Windows, Office, and other core services. Security researchers and threat intelligence teams observed active exploitation in the wild, prompting urgent patching and incident response from enterprises globally. Microsoft’s rapid disclosure and remediation response helped to mitigate further threat actor activity and contain the immediate risk. The significance of this Patch Tuesday lies not only in the sheer number of vulnerabilities and zero-days but also in the increasing prevalence of opportunistic and targeted attacks against widely-used software. Organizations are under heightened pressure to maintain timely patch cycles, given growing regulatory scrutiny and sophisticated attacker TTPs.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports