✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Vyro AI 2024 GenAI Data Leak: Why Cyber Hygiene Can't Wait
In early 2024, Vyro AI experienced a significant data leak involving the unintentional exposure of proprietary and sensitive user data via a GenAI platform. The incident occurred when internal users, unaware of best security practices, shared confidential information with generative AI tools that did not have adequate encryption or access controls. This exposed private data to unauthorized individuals and third parties, highlighting deficiencies in the company’s data protection policies and cloud application oversight. This breach is emblematic of the growing risks associated with GenAI usage in enterprise environments, where shadow IT and user-driven data sharing can sidestep traditional security controls. As organizations adopt AI at scale, ensuring robust data governance and compliance is more critical than ever to avoid regulatory and reputational fallout.
6 months ago
Kill Chain
VMScape: 2025’s Critical Hypervisor Isolation Attack Exposes Cloud Risks
In September 2025, security researchers from ETH Zurich disclosed 'VMScape,' a sophisticated side-channel attack that breaks guest-host isolation in virtualized environments by exploiting incomplete speculative execution mitigations in modern AMD and Intel CPUs. The exploit enables a malicious guest VM to leak sensitive data, such as cryptographic keys, from the unmodified QEMU hypervisor memory, bypassing existing Spectre defenses without requiring host compromise. The attack impacts AMD Zen 1–5 and Intel Coffee Lake CPUs, allowing memory leaks at rates that threaten cloud multi-tenancy and data privacy. While VMScape requires deep technical expertise and sustained attack duration, its discovery highlights ongoing challenges in securing virtualization infrastructure against novel hardware-level threats. The incident underscores the need for prompt hardware and software mitigation deployment and a renewed focus on isolation techniques amid rising CPU vulnerability disclosures.
6 months ago
Kill Chain
Ascension Health 2024: Kerberoasting Ransomware Attack Exposes Microsoft Security Risks
In May 2024, Ascension Health experienced a major ransomware breach, impacting over 5.6 million patient records. Attackers exploited a contractor’s click on a malicious Bing search result in Microsoft Edge, leveraging a 'Kerberoasting' attack against Microsoft Active Directory. By abusing weak and legacy RC4-encrypted Kerberos service account credentials, attackers escalated privileges and moved laterally across sensitive healthcare infrastructure, ultimately exfiltrating patient data and disrupting operations. The incident highlighted significant shortcomings in Microsoft's default security settings and communication of critical risks to enterprise customers, even after prior warnings from security experts and U.S. government officials. The breach is emblematic of a rising trend in identity-based and ransomware attacks exploiting outdated cryptographic standards across critical infrastructure sectors, especially healthcare. Regulatory and public scrutiny on vendor responsibility, ransomware defense, and secure default configurations have intensified following this high-profile compromise.
6 months ago
Kill Chain
Panama Ministry of Economy Breach: INC Ransomware’s 2025 Attack Explained
In September 2025, Panama's Ministry of Economy and Finance (MEF) announced a cyber incident after the INC Ransomware gang claimed liability for a breach. The ministry reported detecting malicious software on one workstation, activating security protocols, and asserting no core systems or sensitive data were affected. However, INC Ransom posted evidence and claimed to have exfiltrated over 1.5 TB of emails, financial, and budgeting documents from MEF. The threat actor listed MEF on its leak site and began releasing data samples, raising concerns about the extent of exposure. This incident underscores the continued evolution and impact of ransomware-as-a-service (RaaS) operations targeting government and finance sectors. With INC Ransom’s repeated high-profile attacks, the breach reflects the growing risk of sophisticated data theft and extortion campaigns confronting public sector organizations globally.
6 months ago
Kill Chain
2025 Cursor AI Code Editor Vulnerability: Supply-Chain Risk via Malicious Repositories
In September 2025, a security flaw was disclosed affecting Cursor, an AI-powered code editor, that allowed silent code execution when users opened repositories embedded with malicious payloads. The vulnerability stemmed from a default-disabled security setting, letting attackers execute arbitrary code on victim machines under their own user privileges. Security researchers highlighted the risk of potential supply-chain attacks, as any developer opening a tampered repository could unwittingly trigger the exploit, potentially leading to credential theft, system compromise, or further lateral movement within organizational networks. The impact was amplified by Cursor's AI-driven capabilities and its popularity in modern development environments. This incident spotlights the growing risks at the intersection of AI-driven tools and software supply chains. With more organizations relying on smart code editors and automated workflows, attackers are increasing their focus on weaknesses in tool defaults and developer behaviors, driving regulatory concern and heightening the urgency for robust code execution safeguards.
6 months ago
Kill Chain
Cryptojacking Surge: TOR-Based Attack Exploits Docker API Misconfigurations in 2025
In July 2025, cybersecurity researchers identified a new wave of cryptojacking attacks leveraging the TOR network to hide command-and-control infrastructure. Attackers targeted internet-exposed and misconfigured Docker APIs, deploying malicious containers that mined cryptocurrency on compromised infrastructures. This campaign, tracked by Akamai and initially reported by Trend Micro in June 2025, showed sophisticated behaviors including blocking rival threat actors and securing persistence, which increased the impact on affected organizations by silently draining cloud computing resources and escalating operational costs. This incident highlights the growing convergence of container security risks and anonymizing networks like TOR, reflecting a broader trend of attackers shifting toward stealthy, infrastructure-focused exploits. With cloud-native workloads and container orchestration becoming standard, organizations face urgent regulatory and operational pressure to harden APIs and improve cloud security hygiene.
6 months ago
Kill Chain
How Salt Typhoon & Volt Typhoon Forced a U.S. Critical Infrastructure Cybersecurity Rethink
Between 2021 and 2023, advanced Chinese threat actors known as Salt Typhoon and Volt Typhoon conducted highly covert cyber intrusions targeting U.S. telecommunications networks and critical infrastructure sectors. These groups utilized advanced tactics such as "living off the land," abusing legitimate administrative tools, and blending into east-west network traffic, making detection and remediation extremely challenging for defenders. Their primary objectives ranged from long-term espionage and persistent access to prepositioning for potential disruptive attacks in the event of geopolitical conflict. The hacks led federal agencies like the FBI and CISA to revise investigative methods, shifting to assume attackers may already be inside the network and forcing collaboration to uncover subtle anomalies rather than clear indicators. This incident is indicative of a broader industry trend: state-backed actors increasingly focus on stealth, cloud environments, and edge devices, targeting managed service providers and exploiting blind spots in monitoring. Their evolving tactics closely align with growing regulatory and CISO concern for stronger east-west visibility, zero trust controls, and continuous threat hunting across hybrid cloud infrastructure.
6 months ago
Kill Chain
npm Supply-Chain Attack Exposes Open-Source Dependencies: 2024 Incident Analysis
In June 2024, a supply-chain attack struck the widely used npm ecosystem when a threat actor compromised developer Josh Junon's account via a phishing-enabled two-factor reset. The attacker injected malicious code into 18 high-download open-source JavaScript packages, including 'ansi-styles', 'chalk', and 'debug', targeting cryptocurrency transactions. Although the incident caused significant alarm due to the downloads’ reach (>2 billion/week), rapid detection by the open-source community and immediate takedown by npm limited the impact. The injected packages were removed within hours, and the attacker ultimately stole just over $1,000 in cryptocurrency. This incident highlights the growing sophistication of supply-chain and social engineering attacks on open-source platforms. As attackers target developer credentials and critical project maintainers, organizations face renewed urgency to reassess their software supply chain controls and dependency management.
6 months ago
Kill Chain
KazMunayGas Penetration Test Mistaken for Russian Cyberattack: Lessons From a Simulated Incident
In early 2024, Kazakhstan's largest oil company, KazMunayGas, was mistakenly believed to have suffered a cyberattack attributed to a Russian Advanced Persistent Threat (APT) group using a compromised employee email account. Initial reports claimed that attackers breached internal systems, raising alarm over possible business disruption and data compromise. However, after internal review, the company clarified the activity was actually part of an authorized penetration testing exercise, not a malicious breach, and no operational impact or data loss occurred. This incident comes amid heightened concern about cyberthreats targeting energy companies, particularly in regions where geopolitical tensions and state-sponsored actors are active. It demonstrates the confusion that can arise when security drills mimic genuine adversary tactics, highlighting the necessity for robust communication around cybersecurity validation activities.
6 months ago
Kill Chain
Microsoft Patch Tuesday 2025: Patch Critical Privilege Escalation Flaws Now
In September 2025, Microsoft released patches addressing 81 vulnerabilities across enterprise products and core Windows systems. No vulnerabilities were detected as actively exploited, but experts cautioned that several critical and high-severity flaws could become prime targets. Notably, CVE-2025-55232 (CVSS 9.8) enables unauthenticated code execution on Microsoft High Performance Compute Pack installations. Critical elevation of privilege issues, such as CVE-2025-54918 (Windows NTLM) and CVE-2025-55234 (Windows SMB), expose organizations to potential lateral movement, ransomware, and large-scale data exfiltration risks if not remediated. This incident underscores the growing urgency of rapid patch cycles as attacker interest in privilege escalation and lateral movement techniques surges. With threat actors leveraging unpatched vulnerabilities for ransomware and data theft, organizations must bolster detection and enforcement around privilege-oriented exploits.
6 months ago
Kill Chain
How Outdated Encryption in Microsoft Defaults Enabled the 2024 Ascension Ransomware Attack
In February 2024, Ascension, one of the largest healthcare organizations in the United States, suffered a massive ransomware attack linked to longstanding encryption flaws in Microsoft’s default configurations. Attackers infiltrated Ascension’s network via a phishing email opened by a contractor on a company laptop using default Microsoft Edge and Bing settings. Exploiting weak encryption (RC4) and leveraging the Kerberoasting technique on Microsoft Active Directory, the ransomware group rapidly gained administrative privileges and deployed malware across the organization’s systems. This breach compromised sensitive data belonging to over 5.6 million patients, including personal, medical, payment, insurance, and government identification records, and severely disrupted business operations.
6 months ago
Kill Chain
Global NPM Phishing Breach Exposes Billions to Supply Chain Malware
In September 2023, threat actors compromised the NPM account of Qix, a well-known developer, through a phishing attack and used the access to publish malicious updates to 18 highly popular open-source packages. These tainted packages, which collectively garnered over 2 billion weekly downloads, included 'ansi-styles', 'debug', 'chalk', and 'supports-color'. The inserted malware aimed to steal cryptocurrency by tampering with API calls and redirecting wallet transactions. The attack window was brief—about two hours—before the breach was discovered, the malicious versions withdrawn, and further spread prevented. While technical fallout was limited and the attackers profited minimally, the incident exposed significant vulnerabilities in the open-source software ecosystem and generated substantial remediation efforts globally. This episode highlights urgent risks inherent in software supply chains and the dependency of modern development on a small number of package maintainers. Public attention to supply chain defense, rapid incident response, and robust dependency vetting is rising as organizations face the reality of widespread reliance on community-maintained resources.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports