Validated Containment Architectures are here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2707 threat reports
Page 205 of 226

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 24492460 / 2707 reports
Gladinet CentreStack & Triofox Zero-Day Leads to Chain Exploit and Remote Code Execution
Impact· medium

Gladinet CentreStack & Triofox Zero-Day Leads to Chain Exploit and Remote Code Execution

In October 2025, threat actors exploited a zero-day vulnerability (CVE-2025-11371) in Gladinet’s CentreStack and Triofox file sharing solutions, used by thousands of businesses worldwide. The flaw, a local file inclusion (LFI) bug present in all current product versions, was leveraged to extract sensitive configuration data and trigger a previously known deserialization vulnerability (CVE-2025-30406), resulting in remote code execution (RCE). At least three organizations have confirmed exploitation as attackers gained unauthorized access before Gladinet issued a patch, forcing emergency mitigations that affected platform functionality. This incident highlights how chained vulnerabilities and rapid exploitation of zero-days continue to threaten cloud-based file sharing services. With attackers escalating LFI into full RCE, organizations face heightened pressure to improve visibility, patch agility, and enforce Zero Trust controls, especially amid growing regulatory scrutiny.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Autonomous AI Hacking: The Tipping Point in Global Cybersecurity Risk (2025)
Impact· medium

Autonomous AI Hacking: The Tipping Point in Global Cybersecurity Risk (2025)

In mid-2025, a wave of autonomous AI-driven cyberattacks emerged globally, marking a pivotal evolution in threat activity. Across June through September, a combination of threat actors—including criminal groups and state-sponsored entities—leveraged advanced large language models (LLMs) and autonomous agent frameworks to conduct large-scale vulnerability discovery, network infiltration, and ransomware deployment. Attackers used tools like XBOW, HexStrike-AI, and AI-powered malware to execute rapid reconnaissance, credential harvesting, and automated extortion, targeting enterprises and critical infrastructure with unprecedented speed, scale, and sophistication. Businesses faced increased operational disruptions and data loss due to automated exploitation chains and persistent threats that outpaced traditional defense mechanisms. This wave of AI-enabled cyberattacks highlights a dangerous rise in the commoditization of sophisticated offensive tools and the diminishing window for detection and response. The incident underscores an urgent shift in the cyber threat landscape, with automation eroding the gap between disclosure and exploitation while spurring intense regulatory and industry focus on adaptive, AI-driven defense solutions.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AI Agents Under Fire: Memory Poisoning and the Rise of Persistent Prompt Injection
Impact· high

AI Agents Under Fire: Memory Poisoning and the Rise of Persistent Prompt Injection

In 2024, security researchers uncovered a novel AI/ML security incident where AI agents' long-term memory storage was compromised via persistent indirect prompt injection. Adversaries managed to embed malicious instructions within normal AI inputs; these poisoned prompts were subsequently retained by the AI's memory module. When later queries accessed this memory, the injected instructions could exfiltrate conversation history or impact future responses, creating a stealthy, long-term threat. The breach highlighted how modern agentic AI’s tendency to remember user input presents an unforeseen risk vector, with potential for data leakage and manipulation of AI-driven workflows. This incident signals a rising trend: as enterprises integrate AI agents and persistent memory, attackers are quickly adapting with prompt-based exploit techniques that subvert traditional security controls. The risk of covert data exfiltration and ongoing manipulation through AI memory will become a central compliance and governance issue in highly regulated industries.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
How a Breached BPO Account Led to Discord’s Massive 2025 Zendesk Data Breach
Impact· high

How a Breached BPO Account Led to Discord’s Massive 2025 Zendesk Data Breach

In late September 2025, attackers compromised a support agent account at an outsourced BPO provider and gained unauthorized access to Discord’s Zendesk support platform for 58 hours. Exploiting privileged access, they exfiltrated up to 1.6 TB of data, including approximately 8.4 million support tickets affecting 5.5 million users, with sensitive information such as emails, Discord IDs, phone numbers, partial payment data, and around 70,000 government-ID photos. The threat group leveraged integrations between Zendesk and Discord’s internal systems, extracted additional user details via APIs, and attempted a multimillion-dollar ransom before threatening public data release. This incident highlights the growing risk from third-party supply chain attacks targeting cloud-based customer support platforms and BPO providers. The attacker's tactics—abusing helpdesk integrations and privilege escalation—reflect broader cybercrime trends, including identity-driven attacks, data extortion, and rising regulatory scrutiny.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
From Infostealer to Full RAT: Inside the 2025 PureRAT Attack Chain
Impact· medium

From Infostealer to Full RAT: Inside the 2025 PureRAT Attack Chain

In October 2025, Huntress Labs analyzed a sophisticated attack campaign leveraging the PureRAT remote access trojan. The intrusion began with a targeted phishing email containing a ZIP archive that employed DLL sideloading to launch a cascade of in-memory loaders written in Python. Progressing through multi-layered obfuscation, hybrid encryption, and system persistence via Windows registry modifications, the attackers ultimately deployed PureRAT, granting full remote control over victim endpoints. Notably, the operation combined custom-developed loaders with commercial malware, demonstrating advanced evasion and command and control techniques, including encrypted communications and dynamic payload delivery. This incident highlights the growing complexity and modularity of post-phishing attack chains. Organizations must remain vigilant as threat actors increasingly blend bespoke scripts with off-the-shelf RATs, drastically lowering the barrier for stealthy, persistent intrusions targeting credential theft and long-term access.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
RondoDox Botnet Orchestrates Mass n-day IoT Attacks in 2025
Impact· medium

RondoDox Botnet Orchestrates Mass n-day IoT Attacks in 2025

In mid-2025, the RondoDox botnet emerged as a powerful threat targeting IoT and network devices by exploiting 56 known (n-day) vulnerabilities across over 30 device types, including routers, NVRs, DVRs, and CCTV systems. The operators, closely monitoring vulnerability disclosures—such as those revealed at Pwn2Own events—rapidly weaponized publicly disclosed exploits, including CVE-2023-1389 and CVE-2024-12856, using a high-volume "exploit shotgun" methodology to maximize infections. With operations observed since June 2025, the campaign affected both end-of-life and actively supported products, resulting in a widespread compromise of infrastructure, particularly among organizations and consumers with unpatched devices. This attack underscores a growing trend of mass exploitation of n-day vulnerabilities in IoT ecosystems, reflecting increasing automation and sophistication among botnet operators. The pace at which attackers operationalize new exploits demands faster patching, improved segmentation, and heightened baseline security practices across networked environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
China-Based Storm-2603 Weaponizes Velociraptor DFIR in 2025 Ransomware Attacks
Impact· high

China-Based Storm-2603 Weaponizes Velociraptor DFIR in 2025 Ransomware Attacks

In October 2025, security researchers uncovered that the China-based threat group Storm-2603 had abused the open-source Velociraptor DFIR tool in a wide-ranging ransomware campaign. The attacker exploited an outdated, vulnerable version of Velociraptor (CVE-2025-6264) to escalate privileges, create persistent admin accounts, and establish secure remote access on victim systems. This access enabled them to deploy ransomware variants including LockBit and Babuk across Windows and VMware ESXi environments, performing data encryption and exfiltration using PowerShell scripts. Endpoint protections were systematically disabled, and lateral movement leveraged tools like Impacket. This incident highlights an emergent trend: threat actors co-opting legitimate security tools for malicious purposes, increasing the difficulty of detection and response. The blending of nation-state TTPs with ransomware-as-a-service models signals evolving threats, regulatory scrutiny, and substantial operational risks for enterprises.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Universities Targeted: Storm-2657 Orchestrates 2025 Business Email Compromise via Payroll Phishing
Impact· high

Universities Targeted: Storm-2657 Orchestrates 2025 Business Email Compromise via Payroll Phishing

In March 2025, a financially motivated threat group tracked as Storm-2657 launched a series of "payroll pirate" attacks targeting U.S. university staff. The attackers leveraged advanced social engineering and adversary-in-the-middle (AITM) phishing techniques to compromise HR-related SaaS accounts, notably Workday. After stealing MFA credentials, they accessed Exchange Online accounts, manipulated payroll settings to hijack salary payments, set inbox rules for concealment, and enrolled attacker-controlled MFA devices for persistence. At least 11 accounts across three universities were breached, enabling phishing campaigns to almost 6,000 recipients spanning 25 institutions. The incident showcases a significant escalation in business email compromise (BEC) targeting the education sector, exploiting gaps in MFA and SSO implementations. With BEC attacks surging industry-wide—resulting in multimillion-dollar annual losses—this campaign emphasizes the urgent need for phishing-resistant MFA and robust email monitoring across academia and beyond.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
macOS Infostealer Ecosystem 2024: Atomic, Odyssey & Poseidon Unveiled
Impact· medium

macOS Infostealer Ecosystem 2024: Atomic, Odyssey & Poseidon Unveiled

In early 2024, cybersecurity researchers identified a surge in advanced macOS infostealer campaigns targeting enterprises and individuals, featuring prominent malware variants: Atomic, Odyssey, and Poseidon. These infostealers exploit social engineering and malicious downloads to achieve initial access, deploying payloads designed to extract sensitive data such as passwords, browser credentials, cryptocurrency wallets, and system information. Once installed, the malware communicates with command-and-control infrastructure using encrypted channels, effectively exfiltrating critical information while evading traditional antivirus tools. This campaign demonstrated sophisticated evasion techniques, cross-platform delivery, and broad targeting among macOS users. The growing sophistication and proliferation of macOS-targeting infostealers underscore a significant shift in attacker focus beyond Windows environments. With macOS adoption increasing in the enterprise and remote workforce, these campaigns illustrate heightened risk, regulatory urgency, and the pressing need for zero trust controls and vigilant endpoint protection against evolving cross-platform threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Inside the Qantas 2025 Ransomware Breach: Why Legal Measures Can’t Stop Data Leaks
Impact· high

Inside the Qantas 2025 Ransomware Breach: Why Legal Measures Can’t Stop Data Leaks

In October 2025, Qantas, the Australian airline, suffered a ransomware attack attributed to the 'Scattered LAPSUS$ Hunters' group. Attackers claimed to have breached Qantas’ systems via a supply chain vulnerability, exfiltrating personal and loyalty program data of potentially hundreds of thousands of customers, including high-profile individuals. After initial extortion attempts, the stolen data—including names, emails, and frequent flyer records—was publicly leaked when Qantas refused to pay ransom. Qantas took legal steps, securing a court injunction to limit data dissemination, but these measures proved ineffective at curbing the spread among criminal and international actors. This breach highlights the ongoing threat of ransomware and data extortion campaigns targeting major brands, frequently leveraging supply-chain infiltration and cloud-based service weaknesses. The incident also underscores the limited real-world efficacy of legal remedies like injunctions, as well as evolving attacker strategies involving public shaming and mass data exposure.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
The ShinyHunters Salesforce Extortion Spree: Lessons for Modern SaaS Security
Impact· high

The ShinyHunters Salesforce Extortion Spree: Lessons for Modern SaaS Security

In May 2025, the ShinyHunters/Scattered LAPSUS$ Hunters cybercrime coalition initiated a coordinated data extortion campaign against numerous Fortune 500 companies, exploiting voice phishing tactics to compromise Salesforce portals. Attackers tricked privileged users into connecting malicious applications, leading to the theft of over a billion customer records across companies such as Toyota, FedEx, Disney/Hulu, and UPS. Following the attacks, ShinyHunters launched a public shaming and extortion blog, threatening to publish the stolen data unless victims surrendered to ransom demands. Multiple related incidents included attacks on Red Hat's GitLab servers and Discord via a third-party support contractor, impacting sensitive business and PII data. Law enforcement action traced the threats to a blend of established groups, operating globally and leveraging emerging zero-day exploits. This breach underscores the increasing sophistication and scale of identity-driven and extortion-centered cyberattacks targeting cloud SaaS platforms. It coincides with a resurgence in social engineering, as threat actors exploit both technical vulnerabilities and human factors. The event highlights the urgency for robust controls around SaaS access, third-party risk, and east-west data movement visibility.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Polymorphic Python RAT: Next-Gen Malware Slips Past Defenses in 2024
Impact· high

Polymorphic Python RAT: Next-Gen Malware Slips Past Defenses in 2024

In October 2024, security researchers identified a new strain of Python-based remote access trojan (RAT) exhibiting advanced polymorphic capabilities. The malware, distributed as 'nirorat.py' and virtually undetectable by most antivirus engines on VirusTotal at the time of discovery, leverages self-modifying code, dynamic junk code injection, and obfuscation to evade detection. Its feature set includes network scanning, credential testing, data exfiltration, cryptomining, screen and audio recording, and file encryption. The Trojan is designed to mutate its code with each execution, making signature-based security tools largely ineffective and challenging forensic analysis post-compromise. This incident is emblematic of an ongoing trend: cybercriminals are increasingly using polymorphic programming techniques and open-source scripting languages to bypass detection and propagate malware. Organizations must adapt their defense strategies as attackers innovate to manipulate familiar toolchains, raising the stakes for endpoint and network security teams.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports