✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Confucius APT Evolves: Python Backdoors Target Pakistan in 2025 Cyber-Espionage Escalation
In 2025, the Confucius advanced persistent threat (APT) group intensified its cyber-espionage operations targeting Pakistani government, military, and critical infrastructure organizations. Originally operating with infostealers like WooperStealer, Confucius shifted to deploying highly-obfuscated, Python-based surveillance backdoors such as AnonDoor. Attackers exploited spear phishing using spoofed authority emails and action-driven malicious attachments, which initiated complex infection chains via DLL sideloading, LNK files, and PowerShell loaders. This evolution improved persistence and evasiveness, resulting in increased risks to sensitive data and operational security for targeted institutions in Pakistan. The incident reflects a broader trend in state-sponsored cyberthreats: threat actors are adopting modular backdoors, diversifying attack vectors, and leveraging scripting languages to bypass security controls. Such agile TTPs (tactics, techniques, and procedures) heighten challenges for defenders, underscoring the urgent need for real-time threat detection and robust network segmentation.
6 months ago
Kill Chain
Red Hat's 2024 GitLab Breach: Supply Chain Risks and the Rise of Crimson Collective
In September 2024, Red Hat disclosed a breach of its self-managed GitLab instance used by its Consulting services, following claims by the Crimson Collective ransomware group of compromising over 28,000 private repositories. The attackers allegedly exfiltrated software source code and Customer Engagement Reports (CERs), which may contain network details, configuration data, and sensitive credentials. Red Hat initiated remediation steps and assured that its primary software supply chain and core products were not impacted. Belgian authorities warned of potential high-risk exposure for organizations with ties to Red Hat Consulting. This incident underscores a growing trend of supply chain attacks targeting private code repositories and related assets, especially in environments where critical infrastructure and third-party integrations are involved. As ransomware groups pivot to extortion and supply chain vectors, organizations must urgently review their repository and credential management, even on self-managed systems.
6 months ago
Kill Chain
Oracle 2025: Clop Ransomware Group Launches Extortion Campaign Against E-Business Suite Clients
In late September 2025, Oracle E-Business Suite customers were subjected to a wave of targeted extortion emails reportedly sent by threat actors aligned with the Clop ransomware group. The campaign leveraged hundreds of compromised legitimate third-party accounts to send messages claiming theft of customer data from Oracle environments. While Oracle confirmed the outreach and ongoing investigations, it did not specify which vulnerabilities were exploited nor confirm any customer data breach. Multiple Oracle E-Business Suite vulnerabilities, including remotely exploitable flaws, had been patched in July 2025, but ongoing research has yet to verify attack details or data loss. This incident is emblematic of the growing sophistication of financially motivated ransomware groups, who now often use large-scale phishing and extortion campaigns before confirming a breach. The campaign highlights increasing pressure on organizations to patch critical software rapidly and maintain heightened vigilance against social engineering, especially as adversaries leverage supply chain vectors and undermine trust with third-party compromise.
6 months ago
Kill Chain
How North Korean IT Workers Infiltrated Global Businesses: 2025 Insider Threat Surge
Between 2021 and mid-2025, North Korean nationals covertly infiltrated thousands of businesses worldwide by posing as legitimate remote IT and finance workers. According to Okta and other cyber threat intelligence sources, over 130 unique identities were linked to North Korean operatives who participated in more than 6,500 job interviews across roughly 5,000 companies, affecting industries from technology and finance to healthcare and manufacturing. The scheme enabled the North Korean regime to launder payments in violation of international sanctions, while threat actors refined methods to evade common screening controls and exploit global hiring pipelines. High volumes of applications, especially in remote roles, allowed these operatives to bypass national and enterprise-level defenses, embedding deeper into victim organizations’ critical workflows and data environments. The global expansion and sophistication of North Korea’s IT worker operation underscore a dangerous evolution in cyber-enabled insider threats and economic espionage. With a 220% increase in detected North Korean IT worker activity year-over-year, businesses worldwide now face heightened risk regardless of geography or sector, making identity vetting and remote work controls a top security priority.
6 months ago
Kill Chain
WestJet 2025 Data Breach: How Social Engineering and Remote Access Led to Massive Data Exposure
In June 2025, Canadian airline WestJet suffered a major data breach affecting approximately 1.2 million customers. Threat actors exploited social engineering to reset an employee’s password, gaining access through Citrix systems and compromising both Windows and Microsoft cloud networks. The attackers were able to exfiltrate sensitive personal data, including full names, dates of birth, physical addresses, passport or government IDs, travel information, rewards member data, and select customer service interactions. While no credit card numbers or passwords were disclosed, the incident required investigation by law enforcement and forced WestJet to notify affected users and authorities across North America, offering free identity monitoring. This breach highlights the growing effectiveness of identity-based attacks, particularly those leveraging social engineering to bypass traditional security controls via remote access platforms. With aviation and travel industries increasingly targeted, this incident underscores the urgent need for modern Zero Trust approaches and continuous monitoring of east-west traffic within enterprise networks.
6 months ago
Kill Chain
Allianz Life Data Breach 2025: Cloud CRM Attack Exposes 1.5 Million
In July 2025, Allianz Life, a major American insurance provider, suffered a significant data breach after threat actors—suspected to be part of the ShinyHunters extortion group—gained unauthorized access to a third-party cloud-based CRM system. The breach exposed sensitive personal information including names, addresses, dates of birth, and Social Security numbers for nearly 1.5 million individuals, encompassing customers, financial professionals, and employees. The incident was publicly disclosed shortly after it occurred, with Allianz confirming that Allianz SE, its global parent company, was not impacted. In response, Allianz initiated notifications to affected parties and regulatory authorities and is offering two years of free identity theft monitoring. This incident highlights the persistent risks posed by supply chain and third-party service vulnerabilities, especially as attackers increasingly target trusted cloud-based platforms such as Salesforce. The breach underscores the necessity for vigilant monitoring, rigorous access controls, and enhanced segmentation within cloud ecosystems for all organizations handling sensitive data.
6 months ago
Kill Chain
Ukraine 2025: CABINETRAT Backdoor Attack Leveraged Signal & XLL Add-ins
In September 2025, CERT-UA reported a targeted cyberattack campaign against Ukrainian organizations involving the CABINETRAT backdoor. The threat group tracked as UAC-0245 employed malicious Microsoft Excel XLL add-ins, disguised within ZIP archives distributed via Signal messenger, to covertly establish persistent backdoor access on victim systems. These XLL files, once executed, enabled attackers to conduct reconnaissance, data theft, and potential lateral movement inside compromised networks, raising concerns about operational disruption, espionage, and data confidentiality. This incident highlights the evolving threat landscape where adversaries leverage secure messaging platforms and file add-ins to bypass traditional email security and endpoint controls. The appearance of CABINETRAT underscores increasing sophistication in malware delivery and emphasizes the need for modern controls and East-West traffic visibility.
6 months ago
Kill Chain
2025 Red Hat OpenShift AI Vulnerability Exposes Hybrid Cloud to Full Takeover
In October 2025, a critical privilege escalation vulnerability was disclosed in Red Hat OpenShift AI, a popular platform for managing AI workloads across hybrid cloud infrastructures. The flaw allowed attackers to obtain elevated permissions and, under certain conditions, seize full control of affected environments. Security researchers identified that threat actors could exploit weak internal segmentation and misconfigurations within the AI lifecycle management layers, resulting in potential unauthorized lateral movement and broad operational impact across connected workloads. Red Hat promptly released advisories and patches, but organizations running unpatched versions remain at risk of infrastructure takeover and sensitive data exposure. This incident comes amid a surge in attacks targeting AI infrastructure and hybrid cloud environments, as adversaries increasingly exploit complex, interconnected platforms. The breach highlights the escalating risk posed by privilege escalation flaws in widely adopted enterprise AI solutions and underscores the urgent need for rigorous segmentation, threat detection, and rapid patch cycles.
6 months ago
Kill Chain
OneLogin 2025: OIDC/API Key Flaw Exposes Client Secrets to Attackers
In October 2025, a critical security vulnerability (CVE-2025-59363, CVSS 7.7) was disclosed in the One Identity OneLogin IAM platform. The flaw allowed threat actors to use compromised or exposed API keys to retrieve sensitive OpenID Connect (OIDC) application client secrets. Attackers exploiting this vulnerability could potentially impersonate trusted applications, resulting in unauthorized access to protected enterprise resources and disruption of identity-based authentication flows. OneLogin responded with a patch following public disclosure, but the exposure window placed numerous organizations at risk of credential theft and downstream compromise. This incident highlights persistent risks in identity and access management platforms, especially around API security and secret handling. Recent trends show attackers increasingly targeting IAM tools and exploiting weak OIDC/OAuth implementations, making robust zero trust segmentation, continuous threat monitoring, and compliance with established frameworks more critical than ever.
6 months ago
Kill Chain
Chinese APT Group Abuses VMware Privilege Escalation Flaw Throughout 2023
In 2023, sophisticated threat actors attributed to China exploited a previously unknown privilege-escalation vulnerability in VMware platforms for nearly a year before its discovery. Attackers leveraged this flaw, which appeared benign, to gain persistent and stealthy access to targeted virtual infrastructure. Their methods enabled lateral movement, data gathering, and privileged actions within highly segmented data center and cloud environments, affecting a broad range of organizations relying on virtualization for critical workloads. The long-term nature of the operation underscores challenges in detecting nation-state activity exploiting zero-day and privilege-related weaknesses. This incident highlights a broader escalation in advanced persistent threat (APT) campaigns targeting cloud and virtualization layers. As attackers increasingly exploit such integral software stacks with subtle techniques, organizations must reevaluate network segmentation, privilege management, and continuous monitoring to remain resilient.
6 months ago
Kill Chain
TOTOLINK X6000R Routers: 2025 Vulnerabilities Uncovered in Edge Devices
In June 2025, three new critical vulnerabilities (CVE-2025-52905, CVE-2025-52906, CVE-2025-52907) were discovered in TOTOLINK X6000R routers by Palo Alto Networks' Unit 42 researchers. These flaws exposed the devices to remote code execution and unauthorized access, potentially allowing attackers to gain persistent control over affected networks. The vulnerabilities stem from insecure input validation, weak authentication mechanics, and flaws in firmware that could be exploited over the internet. Immediate patching and network segmentation were recommended to prevent exploitation while vendor mitigation efforts commenced. This incident highlights ongoing risks to consumer and small business gateway devices, demonstrating how router vulnerabilities remain a rich attack surface for cyber actors. The event underscores the urgency for continuous vulnerability research, robust patch management, and defense-in-depth to counter the accelerating trend of targeting edge and IoT devices.
6 months ago
Kill Chain
Broadcom Patches VMware NSX Flaws Flagged by NSA: What It Means for Cloud Security in 2024
In June 2024, Broadcom addressed two high-severity vulnerabilities in VMware NSX, originally discovered and reported by the U.S. National Security Agency (NSA). The flaws—tracked as CVE-2024-22246 (Local Privilege Escalation) and CVE-2024-22247 (Authentication Bypass)—could allow attackers to escalate privileges or bypass security controls on affected VMware NSX deployments. No evidence of exploitation in the wild has been reported, but these vulnerabilities could have enabled threat actors to move laterally, evade segmentation, and compromise critical virtualized environments if left unpatched. This disclosure comes amid heightened scrutiny of virtualization platforms used in cloud and hybrid infrastructures. As state actors increasingly target foundational cloud technologies and security researchers identify complex flaws, enterprises are pressed to maintain rapid patch cycles and review dependency trust, especially for technologies underpinning multi-cloud architectures.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports