Validated Containment Architectures are here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2707 threat reports
Page 215 of 226

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 25692580 / 2707 reports
RedNovember: 2025 Chinese State Cyber Espionage Campaign Hits Global Governments
Impact· low

RedNovember: 2025 Chinese State Cyber Espionage Campaign Hits Global Governments

In mid-2025, a Chinese state-sponsored threat group known as RedNovember (previously tracked as TAG-100) orchestrated a widespread cyber espionage campaign targeting government and private sector organizations across Africa, Asia, North America, South America, and Oceania. The attackers leveraged sophisticated tools including the Pantegana backdoor and Cobalt Strike to establish persistence, perform lateral movement, and exfiltrate sensitive data. Entry vectors included spear-phishing emails and exploitation of known network vulnerabilities, allowing RedNovember to stealthily compromise high-value systems and harvest intelligence for extended periods before discovery. The impact included unauthorized access to confidential government documents and disruption of critical data workloads. This incident underscores the persistent evolution of state-sponsored attack tactics, with RedNovember employing advanced, evasive techniques and custom malware. The growing use of encrypted command-and-control traffic and living-off-the-land strategies sets a concerning precedent, especially for government agencies and regulated enterprises facing a surge in sophisticated espionage operations.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Steganography Strikes: npm Supply Chain Breach Hides Malware in JavaScript Package (2024)
Impact· medium

Steganography Strikes: npm Supply Chain Breach Hides Malware in JavaScript Package (2024)

In June 2024, a malicious npm JavaScript package was discovered masquerading as a utility library while covertly deploying a credential-stealing malware. Attackers cleverly embedded the malicious payload using steganography by hiding harmful code within QR code images bundled in the package. Once installed by developers, the malware extracted sensitive credentials and communicated with attacker-controlled infrastructure, posing a significant risk to any organization that unknowingly integrated the tainted dependency in its software supply chain. This incident underscores the mounting threat posed by highly obfuscated, supply chain attacks leveraging trusted open-source platforms. The attack highlights the emergence of sophisticated malware delivery via unconventional vectors such as steganographic encoding within common file formats. With broad software ecosystem dependencies and rapid code adoption, organizations face increasing urgency to vet third-party packages and enforce robust supply chain security controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Cloud Misconfiguration: How Exposed Docker Daemons Fueled a 2024 DDoS Botnet
Impact· high

Cloud Misconfiguration: How Exposed Docker Daemons Fueled a 2024 DDoS Botnet

In early 2024, cybersecurity researchers uncovered a widespread campaign exploiting misconfigured Docker daemons in cloud environments. Attackers leveraged openly accessible Docker APIs to deploy malicious containers and enlist compromised servers into a large-scale DDoS (Distributed Denial of Service) botnet. Using legitimate, cloud-native tools made detection and remediation more challenging for security teams. The incident resulted in increased infrastructure costs, service disruptions, and heightened risk of lateral movement and data exfiltration within affected organizations. This attack is illustrative of a growing trend where adversaries abuse cloud-native technologies and misconfigurations to orchestrate large-scale, persistent threat activity. As organizations accelerate cloud adoption, gaps in cloud security posture and lack of network segmentation are creating new attack surfaces, stressing the need for enhanced visibility, zero trust controls, and real-time anomaly detection.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
GitHub’s NPM Supply Chain Attack Shows Urgent Need for Token Security in 2024
Impact· high

GitHub’s NPM Supply Chain Attack Shows Urgent Need for Token Security in 2024

In early 2024, GitHub took action to secure the NPM supply chain following a surge of sophisticated attacks exploiting weak authentication protocols and overly permissive access tokens. Adversaries—most notably those deploying the Shai-Hulud malware—compromised developer or maintainer accounts, then published malicious NPM packages, creating a vector for large-scale supply chain infection. The breaches risked both open-source and enterprise users, potentially allowing attackers access to downstream projects, credential leakage, and further lateral movement in corporate ecosystems. This incident is a critical reminder that software supply chains are increasingly targeted by cybercriminals using stolen credentials and token abuse. It highlights how even trusted platforms can expose organizations to risk when security controls such as MFA and token lifecycles are insufficiently enforced.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
How North Korean IT Workers Exposed the Next Insider Threat: Lessons from the 2025 Breach
Impact· high

How North Korean IT Workers Exposed the Next Insider Threat: Lessons from the 2025 Breach

In 2025, organizations across multiple industries discovered they had inadvertently hired North Korean IT workers—an emerging form of insider threat tied to sophisticated fraud and sanctions evasion tactics. These workers, embedded via remote roles and often identified through HR anomalies, funneled their earnings back to the North Korean regime, potentially exposing companies and their payment processors to strict sanctions liability. Initial detections stemmed from mismatched credentials or suspicious onboarding behaviors, with security and legal teams realizing the scope only after covert employment periods. Business impact included urgent compliance, forensic device recovery, and reputational risk, with legal exposure for both inadvertent payments and regulatory reporting lapses. This incident highlights an evolving threat landscape: state-sponsored employment fraud now overlaps with insider threat and compliance failures. Increased scrutiny from regulators, combined with ongoing geopolitical and cyber risk, is driving rapid change in how companies monitor, vet, and respond to workforce-related security incidents.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Russian Disinformation Group Rybar Orchestrates REST Media Election Campaign in Moldova
Impact· high

Russian Disinformation Group Rybar Orchestrates REST Media Election Campaign in Moldova

In June 2024, researchers revealed that REST Media, an online outlet targeting Moldova’s elections, is actually a front for the Russian disinformation group Rybar. Rybar, already sanctioned by the EU and wanted by the U.S., used REST Media to amplify anti-EU narratives and undermine the Party of Action and Solidarity, leveraging platforms like TikTok, Telegram, and X to achieve millions of views. Technical forensics linked REST Media’s online infrastructure and production workflows directly to Rybar, demonstrating operational overlap and deliberate efforts at obfuscation. The campaign exploited Moldova's fragmented media regulations, using cloaked registration accounts, privacy services, and anonymized hosting, making attribution complex while rapidly expanding its influence ahead of key elections. This incident exemplifies the growing sophistication of state-sponsored information operations, exploiting both technology and weak local controls. As hybrid threats, including coordinated disinformation and cyberattacks, continue to undermine democratic processes across Eastern Europe, organizations and governments face mounting regulatory, reputational, and operational risks from similar campaigns.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Brickstorm: The Next-Level Chinese APT Breach Impacting SaaS & Legal Sectors in 2025
Impact· medium

Brickstorm: The Next-Level Chinese APT Breach Impacting SaaS & Legal Sectors in 2025

In 2025, a highly sophisticated cyberespionage campaign attributed to a suspected Chinese advanced persistent threat (APT), utilizing malware later dubbed 'Brickstorm,' successfully infiltrated multiple US legal services and tech supply chain organizations. The attackers leveraged undisclosed zero-day vulnerabilities to gain initial access, maintain exceptional stealth with average dwell times of over 400 days, and move laterally into downstream customers. Their campaign targeted proprietary source code and sensitive trade/national security intelligence, making detection challenging through advanced cleanup techniques and non-overlapping infrastructure. This incident is particularly significant as it represents a new echelon of APT supply chain intrusions, echoing a rise in strategic, multi-year campaigns focusing on SaaS and cloud intermediaries. It highlights the growing need for robust east-west visibility, zero trust segmentation, and supply chain security amid evolving TTPs that routinely outpace traditional detection and response capabilities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
NPM Package 'Fezbox' Abused QR Codes in Sophisticated 2025 Supply Chain Attack
Impact· medium

NPM Package 'Fezbox' Abused QR Codes in Sophisticated 2025 Supply Chain Attack

In September 2025, a malicious npm package named 'fezbox' was discovered utilizing QR codes as a novel delivery mechanism for cookie-stealing malware. Masquerading as a legitimate utility library on npmjs.com, the package was downloaded at least 327 times before its removal. The attack involved the package embedding a reversed URL to evade detection, which, once decoded, retrieved a dense QR code image containing obfuscated, second-stage payload code. The malware specifically targeted credentials by harvesting cookies and sending harvested credentials to a command-and-control server via HTTPS POST, only proceeding if valid username and password data were detected. This incident highlights the increasing creativity of supply-chain attackers, leveraging steganography within QR codes to bypass traditional static security tools. As QR codes become more commonplace and attackers innovate their use beyond social engineering, organizations must strengthen package vetting, threat detection, and response for open-source dependencies within their development ecosystems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
GitHub npm 2025: Major Supply Chain Attacks Drive Aggressive Security Overhaul
Impact· high

GitHub npm 2025: Major Supply Chain Attacks Drive Aggressive Security Overhaul

In August and September 2025, GitHub's npm ecosystem suffered a series of coordinated supply chain attacks involving high-impact campaigns such as "s1ngularity," "GhostAction," and worm-style "Shai-Hulud." Threat actors infiltrated GitHub repositories and npm packages via credential compromise and weaknesses in access controls, ultimately compromising thousands of developer accounts and private repositories. These attacks resulted in theft of sensitive code and data, disruption across open-source ecosystems, and considerable remediation costs for affected organizations. In response, GitHub has announced the rapid rollout of mandatory two-factor authentication, granular access tokens, and removal of insecure authentication methods for npm publishing, aiming to prevent recurrence and empower developers to proactively enhance their security posture. This wave of supply chain attacks underscores the growing risk of software dependency manipulation at scale. The incident highlights the urgency of hardening access controls, enforcing stronger authentication, and shifting developer communities toward zero trust principles to counteract increasingly sophisticated threats facing software ecosystems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
SolarWinds Hit by Yet Another Web Help Desk RCE Patch Bypass in 2025
Impact· low

SolarWinds Hit by Yet Another Web Help Desk RCE Patch Bypass in 2025

In September 2025, SolarWinds disclosed a critical security vulnerability (CVE-2025-26399) in its Web Help Desk (WHD) software, affecting version 12.8.7 and prior. This flaw—stemming from unsafe deserialization in the AjaxProxy component—permits unauthenticated attackers to achieve remote code execution (RCE) on affected servers. The issue represents a patch bypass for earlier vulnerabilities (CVE-2024-28986, CVE-2024-28988), demonstrating persistent weaknesses in the remediation process. While there are no documented exploitations as of publication, previous flaws in this component were added to CISA’s Known Exploited Vulnerabilities catalog, underscoring risk to organizations reliant on WHD for ticketing and IT asset management. This incident underscores the enduring challenge of patch bypasses, where subsequent hotfixes fail to fully resolve underlying flaws, leading to repeated exposures. Weaknesses in serialization logic and high-value IT management software are a favored target for attackers seeking lateral movement, privilege escalation, or supply chain compromise.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
BadIIS Malware Spreads via SEO Poisoning in Operation Rewrite
Impact· medium

BadIIS Malware Spreads via SEO Poisoning in Operation Rewrite

In September 2025, cybersecurity analysts uncovered a targeted campaign in East and Southeast Asia, particularly Vietnam, orchestrated by a Chinese-speaking threat actor dubbed CL-UNK-1037. Using a custom malware named BadIIS, the group launched "Operation Rewrite" by employing SEO poisoning to direct unsuspecting users to compromised websites. These sites served as a launch point for deploying BadIIS, which stealthily redirected traffic, established persistent web shells, and enabled lateral movement within infected infrastructure. The attacks leveraged trusted search results to compromise both organizations and individuals, aiming to establish long-term footholds and facilitate future malicious operations. This incident highlights the increasing sophistication of adversaries leveraging advanced social engineering and technical tactics like SEO poisoning. The blending of supply chain and web application compromise with persistent malware demonstrates evolving TTPs that bypass conventional detection, emphasizing the urgent need for multilayered security and continuous vigilance for all organizations.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ShadowV2 Botnet Weaponizes AWS Docker Misconfigurations for DDoS-for-Hire Attacks
Impact· high

ShadowV2 Botnet Weaponizes AWS Docker Misconfigurations for DDoS-for-Hire Attacks

In September 2025, researchers uncovered that the ShadowV2 botnet exploited misconfigured Docker containers deployed on Amazon Web Services (AWS) instances. Attackers leveraged these open containers to install Go-based malware, transforming vulnerable cloud servers into nodes for distributed denial-of-service (DDoS) attacks available for hire. The botnet operators were able to saturate targets’ networks and disrupt organizational operations using cloud-scale resources, highlighting a sophisticated abuse of both infrastructure-as-a-service offerings and container orchestration weaknesses. The campaign predominantly impacted organizations with unmanaged or lax security practices around containerized workloads and cloud network borders. This attack underscores the growing trend of threat actors targeting cloud misconfigurations and using them as platforms for broader cybercriminal infrastructure. The incident reflects both the increasing commoditization of DDoS-as-a-service and the urgency of securing cloud-native deployments against well-known attack patterns.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports