✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
2025 Salesforce Data Breach: Supply Chain Extortion Hits Retail Sector
In mid-2025, a coordinated cybercriminal campaign led by UNC6395 and affiliates of Muddled Libra targeted Salesforce tenants via a multi-stage supply chain attack stemming from infiltrated third-party integrations such as Salesloft and Drift. Attackers used advanced social engineering and process exploitation rather than technological vulnerabilities to gain access to Salesforce customer data—including sensitive records like accounts, contacts, and opportunities. The operation highlighted the growing focus on data theft extortion tactics and the use of encrypted communications, with threat actors actively marketing stolen data through Telegram channels under monikers like "Scattered LAPSUS$ Hunters." The impact has been significant for retailers and digital platform users, driving urgent defensive and policy changes at Salesforce and affected enterprises. This incident underscores an accelerating threat shift in 2025: attackers are increasingly leveraging social engineering and the SaaS supply chain to circumvent traditional defenses, monetizing access through extortion rather than ransomware. The event has intensified industry efforts to tighten access controls and enforce encryption, amid persistent regulatory and law enforcement actions.
6 months ago
Kill Chain
Apple’s 2025 Zero-Day Puts iOS & macOS Security in Spotlight: What You Need to Know
In September 2025, Apple issued urgent patches for iOS, iPadOS, and macOS in response to several critical vulnerabilities, with CVE-2025-43300 standing out due to active exploitation in sophisticated targeted attacks. The vulnerability, affecting the ImageIO component, enabled attackers to compromise devices by processing malicious image files, potentially resulting in memory corruption and enabling unauthorized access or control. Previous patches were limited to the latest OS versions, leaving older systems exposed until this coordinated rollout addressed those gaps. Apple further backported fixes to supported older releases to mitigate the heightened risk of exploitation. This incident underscores an accelerating wave of zero-day vulnerabilities leveraged in real-world attacks, highlighting the persistent threats facing major software ecosystems like Apple’s. The discovery and rapid backporting response reflects mounting regulatory and industry pressure to quickly secure even legacy platforms and close compliance gaps.
6 months ago
Kill Chain
npm’s Largest Supply Chain Compromise: Phishing and the Fragility of Open Source Security
In June 2024, a major npm supply chain compromise saw attackers inject malicious code into 18 highly popular JavaScript packages, including chalk and debug, which together accounted for over 2.6 billion weekly downloads. The breach began with a successful phishing attack targeting a package maintainer, resulting in the theft of two-factor authentication credentials. Threat actors quickly published backdoored versions of affected packages, which were downloaded millions of times in minutes before rapid detection and disclosure limited the fallout. The immediate financial losses were low, with only minimal amounts of cryptocurrency stolen, but the operational impact included widespread remediation efforts across thousands of organizations dependent on these open-source assets. This incident exemplifies the growing risk and frequency of supply chain attacks leveraging compromised maintainers and rapid malware propagation in software registries. It highlights the urgent need for enhanced account security, ecosystem-level safeguards, and improved transparency, as such compromises are increasingly targeted by sophisticated actors and threaten the core trust mechanisms of modern digital infrastructure.
6 months ago
Kill Chain
Malicious MCP Servers: How AI Supply Chain Integrations Were Weaponized in 2024
In early 2024, security researchers uncovered a novel supply chain attack exploiting the Model Context Protocol (MCP), an emerging integration layer for AI assistants. Attackers published seemingly legitimate MCP servers on public repositories such as PyPI, which, once installed by developers, silently harvested sensitive credentials, SSH keys, cloud configs, and API secrets. Data exfiltration was cleverly disguised as benign HTTP requests to plausible endpoints, while the malicious packages mimicked real productivity tools, evading both user scrutiny and common detection mechanisms. This attack leveraged implicit trust in third-party AI extensions, exposing a major blind spot for organizations integrating AI into development workflows. This breach reflects a growing trend where adversaries weaponize trusted AI integration points, mirroring techniques seen in Open Source and DevOps supply chain compromises. As enterprise AI adoption accelerates, similar threats targeting protocol-level integration, plugin ecosystems, and shadow AI deployments are expected to rise, intensifying regulatory and governance pressures around software supply chain security.
6 months ago
Kill Chain
Salesloft GitHub Compromise: How a 2025 Supply-Chain Attack Rippled Across 22 Companies
In mid-2025, Salesloft disclosed a significant data breach stemming from a compromise of its GitHub account linked to its Drift application. The incident was investigated by Mandiant, which attributed the activity to the threat actor group UNC6395. Attackers maintained unauthorized access from March through June 2025, enabling them to pivot laterally and potentially compromise sensitive code, data, and operational assets. The breach's supply-chain nature led to downstream impacts, reportedly affecting at least 22 distinct organizations that relied on the compromised software or APIs. This breach highlights the persistent risk posed by supply-chain compromises and stolen developer credentials within cloud ecosystems. With threat actors increasingly targeting development tools and identity-driven pipelines, organizations face mounting regulatory and operational urgency to remediate authentication weaknesses and enforce segmenting policies across their CI/CD toolchains.
6 months ago
Kill Chain
How Stark Industries Evaded EU Sanctions: The Persistence of Bulletproof Hosts in 2025
In May 2025, Stark Industries Solutions Ltd.—a notorious bulletproof hosting provider closely linked to Russian cyberattacks and disinformation—was placed under EU financial sanctions, alongside its Moldova-based conduits and owners. Despite these efforts, Stark rapidly rebranded as the[.]hosting, shifted its assets to new legal entities (including Dutch-based WorkTitans BV and Moldova's PQ Hosting Plus S.R.L.), and maintained operational infrastructure with covert support from providers like MIRhosting. Investigations revealed continued operations and asset management by the original threat actors, rendering the sanctions ineffective and allowing persistent delivery of DDoS campaigns, Russian-language proxy services, and malware with minimal disruption. This incident highlights the sophisticated resilience and adaptability of bulletproof hosting operations, as well as the challenges for regulators attempting to curtail nation-state-aligned cyber infrastructure. Similar evasion techniques—including cross-border asset transfers and complex corporate rebranding—are on the rise, escalating pressure on global cybersecurity, law enforcement, and compliance efforts.
6 months ago
Kill Chain
Inside the 2025 Salesloft Drift SaaS Supply Chain Breach: Lessons in Token Management
In early 2025, a significant supply chain breach occurred when threat actor UNC6395 exploited a dormant OAuth token from a third-party Salesloft Drift integration within a Salesforce environment. Leveraging the compromised token—which bypassed MFA—the attacker launched automated connections from multiple unknown VPNs, enumerating CRM accounts and exfiltrating customer data, including embedded credentials. This enabled lateral movement, granting persistent, unauthorized access to hundreds of downstream client Salesforce instances and facilitating privilege escalation into additional systems via harvested secrets. The incident underscores an urgent trend of attackers exploiting inadequately governed third-party integrations, token sprawl, and absent monitoring. With growing SaaS adoption and rising API-driven architectures, identity-driven supply chain attacks have become top risks, accelerating regulatory scrutiny and industry demand for automated token hygiene, lifecycle management, and more rigorous third-party security postures.
6 months ago
Kill Chain
2025 Salesforce Supply Chain Breach Unveiled: UNC6040 and UNC6395’s Advanced OAuth Attacks
In mid-2025, cybercriminal threat clusters UNC6040 and UNC6395 launched coordinated attacks targeting the Salesforce environments of major global enterprises, leveraging supply chain compromises, OAuth token abuse, and social engineering tactics. Attackers tricked employees into authorizing malicious OAuth apps or exploited stolen access tokens, enabling mass data exfiltration from Salesforce—including sensitive 'Accounts', 'Contacts', and support case records containing credentials and cloud secrets. Stolen information was subsequently used by the ShinyHunters extortion group for ransom threats and further infiltrations, impacting organizations such as Google, Cisco, Adidas, and major cybersecurity firms. This incident exemplifies a growing wave of attacks exploiting trusted third-party platforms and identity federation weaknesses to compromise cloud SaaS data at scale. The sophisticated multi-stage approach highlights urgent risks related to SaaS supply chains, the need for robust OAuth governance, and increased vigilance toward privilege escalation via indirect access vectors.
6 months ago
Kill Chain
Gentlemen Ransomware Exploits Vulnerable Driver to Disable Enterprise Security (2024)
In early 2024, the Gentlemen ransomware group executed a sophisticated attack leveraging a vulnerable version of the ThrottleStop.sys driver to disable antivirus and endpoint detection and response (EDR) systems. By exploiting this signed but flawed driver, the attackers were able to gain kernel-level privileges, terminate security defenses, and deploy ransomware effectively across targeted organizations. The impact resulted in rapid file encryption, significant operational disruption, and increased ransom demands as incident response capabilities were bypassed. This incident highlights the growing trend of ransomware operators abusing trusted, vulnerable drivers to evade security controls. The ease with which attackers weaponize driver vulnerabilities underscores the urgent need for organizations to enhance driver and device control, patch management, and implement Zero Trust security strategies.
6 months ago
Kill Chain
SonicWall Firewalls Under Siege: Akira Ransomware Exploits CVE-2024-40766
Between July and August 2024, Akira ransomware affiliates targeted SonicWall firewall devices by exploiting CVE-2024-40766, a vulnerability in the SSL VPN protocol, combined with widespread configuration errors. Despite the availability of patches, attackers successfully accessed devices where remediation steps such as local password resets after firmware upgrades and proper multi-factor authentication (MFA) implementation were neglected. These campaigns leveraged misconfigured LDAP group permissions and compromised credentials to gain initial access, enabling Akira to steal sensitive data and encrypt systems across numerous organizations. The resulting attacks led to data theft, system downtime, and expensive ransom demands, with impacts observed globally, including within Australia. Akira’s ongoing surge illustrates the growing sophistication and persistence of ransomware groups in targeting both unpatched and improperly configured perimeter devices. This attack wave highlights the critical need for organizations to not only apply security patches promptly but to rigorously follow up with secure configuration and identity management measures to prevent operational and financial losses.
6 months ago
Kill Chain
AsyncRAT Attackers Exploit ConnectWise ScreenConnect—Credential & Crypto Theft on the Rise
In September 2025, cybersecurity researchers identified a sophisticated attack leveraging the ConnectWise ScreenConnect remote monitoring tool to deliver AsyncRAT, a potent remote access trojan. Threat actors exploited legitimate RMM infrastructure to establish unauthorized access, bypass defenses, and deploy a VBScript-based loader on victim systems. Once installed, AsyncRAT facilitated unauthorized credential harvesting and cryptocurrency theft from compromised hosts, exposing sensitive business and personal data. The campaign’s use of trusted IT management software as an initial entry vector complicated detection and posed significant risks to organizations relying on remote administration tools. This incident underscores an increasing security challenge: the abuse of legitimate remote management solutions by attackers to evade detection and propagate malware. As identity-driven and tool-based attacks surge, businesses must re-examine their controls, segmentation, and monitoring to counter exploitation of sanctioned IT utilities.
6 months ago
Kill Chain
Microsoft September 2025 Patch Tuesday: Critical Vulnerabilities in Cloud, URL Security Zones, and More
On September 9, 2025, Microsoft released its September Patch Tuesday updates, addressing 177 vulnerabilities across its ecosystem, including 86 that impacted Microsoft products directly. Among these, 13 were rated as critical, and two had already been publicly disclosed. Notable vulnerabilities included improper URL security zone classification (CVE-2025-54107, CVE-2025-54917), which could allow attackers to bypass security features, and several remote code execution flaws affecting critical workloads. While none of these vulnerabilities were exploited before disclosure, their wide range—including issues in Azure, Office, and the Windows kernel—signals continued risk across cloud and on-premises environments. These vulnerabilities highlight evolving attacker techniques, such as zone misclassification and privilege escalation in cloud services, while underscoring the complexity of patch management in hybrid infrastructures. The scale of affected Microsoft and open-source components (like Azure Linux/Mariner) points to the growing regulatory and operational urgency for comprehensive and timely vulnerability management.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports