✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Q2 2025 Vulnerability Exploitation: Multi-Platform Attacks and C2 Automation
In Q2 2025, there was a surge in the exploitation of both newly reported and longstanding software vulnerabilities across enterprise environments. Threat actors leveraged critical CVEs—targeting platforms like Microsoft Windows, Linux, document-editing suites, UEFI firmware, AI frameworks, and remote access tools—to gain initial access and escalate privileges on victim systems. Notably, advanced persistent threat (APT) groups demonstrated increased use of C2 frameworks such as Sliver, Metasploit, Havoc, and Brute Ratel to automate exploitation and maintain persistence, highlighting attackers’ growing sophistication and automation. The operational impact ranged from data theft and malware deployment to strategic risks, as attackers pivoted laterally and disabled security mechanisms. The Q2 2025 wave underscores a broader industry trend: attackers are rapidly exploiting both legacy and emerging weaknesses, especially as vulnerability disclosure volumes continue to rise. Automation within C2 frameworks and exploitation targeting multi-cloud and hybrid environments reinforce the urgency to modernize detection and patch-management programs to keep pace with evolving threats.
6 months ago
Kill Chain
Argo CD 2025 API Flaw Exposes Repository Credentials: What Enterprises Must Know
In September 2025, a critical vulnerability (CVE-2025-55190) in Argo CD—a widely used Kubernetes-native continuous deployment platform—was discovered that allowed API tokens, including those with minimal project-level permissions, to access API endpoints and retrieve all repository credentials for a given project. While the flaw required possession of a valid Argo CD API token, even low-privileged users could exploit this issue to bypass established isolation mechanisms and exfiltrate sensitive repository usernames and passwords. This exposure could enable attackers to clone proprietary codebases, inject malicious configurations, and potentially initiate supply chain compromises or further lateral movement, particularly impactful given Argo CD's widespread enterprise adoption by organizations like Adobe, Google, IBM, and Capital One. The incident underscores the ongoing risks posed by misconfigured API permissions in CI/CD pipelines, particularly as attackers increasingly target software supply chains. With credential-based attacks on the rise and major regulatory and industry scrutiny on API security, organizations must act quickly to patch, enhance access controls, and apply zero-trust principles in DevOps contexts.
6 months ago
Kill Chain
Q2 2025 Global Ransomware Surge: Qilin, Nefilim, Black Kingdom, and the Modern Threat Landscape
In Q2 2025, the global ransomware threat landscape saw a significant surge with the discovery of 1,702 new ransomware variants and nearly 86,000 users targeted. High-profile law enforcement actions included indictments and extraditions involving Black Kingdom, Nefilim, Ryuk, DoppelPaymer, and RobbinHood operators. Major campaigns leveraged vulnerabilities in SAP NetWeaver, Fortinet devices, and Microsoft Windows (CLFS driver), with actors like Qilin and DragonForce demonstrating adeptness in exploiting zero-days and supply chain weaknesses. Double extortion and rapid lateral movement were widely observed, affecting critical sectors worldwide, including healthcare, government, and managed service providers. This incident underscores the advancement of ransomware attack tactics, the spread of sophisticated variants, and the persistence of threat actors despite law enforcement measures. The continued exploitation of newly discovered vulnerabilities and focus on high-revenue targets highlight the urgent need for enhanced prevention, detection, and incident response across organizations of all sizes.
6 months ago
Kill Chain
How Attackers Are Sidestepping macOS Built-in Security in 2024
In 2024, researchers and incident responders observed a sophisticated wave of cyberattacks targeting macOS systems, where adversaries adapted to built-in security protections such as Keychain, Gatekeeper, TCC, and System Integrity Protection. Threat actors leveraged utilities like Chainbreaker to extract password data, employed social engineering to bypass File Quarantine and Gatekeeper, and manipulated permission prompts through clickjacking techniques. By exploiting command-line utilities, attackers disabled or evaded standard protections, leading to potential exposure of sensitive credentials and increased risk of full system compromise. The macOS attack landscape continues to evolve, with adversaries innovating to evade resilient, native defenses. Rising adoption of macOS in enterprise environments and the seamless integration with personal devices make these evasion TTPs especially critical for security teams and compliance requirements focused on regulated and sensitive data.
6 months ago
Kill Chain
2025 Spotlight: ESET Uncovers First AI-Powered PromptLock Ransomware
In September 2025, ESET Research identified PromptLock, the first documented case of AI-powered ransomware. While not deployed in active attacks, PromptLock is a sophisticated proof-of-concept that leverages OpenAI’s gpt-oss-20b model via the Ollama API to create malicious Lua scripts in real-time. Written in Golang for both Windows and Linux, PromptLock automates enumeration, exfiltration, and encryption of target system files, with variants found on VirusTotal. Its design demonstrates the feasibility of AI-augmented malware, where dynamic scripting enables rapid adaptation to environments and highly automated attack flows. PromptLock’s discovery highlights the emergence of AI-driven tactics that could accelerate ransomware development and proliferation. As AI tools become more accessible, the risk of advanced, autonomous threats challenging enterprise security controls grows sharply, signaling a pivotal shift in the threat landscape.
6 months ago
Kill Chain
Inside the 2025 Salesloft Supply Chain Breach: Token Theft at Scale
In August 2025, Salesloft, a leading AI chatbot provider, suffered a significant supply chain compromise when attackers exfiltrated authentication tokens via its Drift integration. The breach allowed unauthorized access to hundreds of customer-connected services, including Salesforce, Slack, Google Workspace, Amazon S3, Azure, and OpenAI, impacting more than 5,000 customers. The attackers, tracked as UNC6395 and possibly linked to ShinyHunters or Scattered Spider, began siphoning sensitive corporate data from at least August 8 to August 18, 2025. The incident led to mass data theft, urgent token invalidation efforts, and subsequent blocking of Drift integrations by Salesforce. This breach highlights the surging threats posed by identity-driven attacks and the risks of over-permissive third-party integrations in the enterprise cloud ecosystem. As attackers increasingly exploit centralized authentication and SSO environments, organizations face urgent pressure to revisit access controls and strengthen detection of abuse within legitimate user sessions.
6 months ago
Kill Chain
Azure AD Credential Exposure: Public Config File Leak Spotlights Cloud Risks
In early 2024, a significant security incident was discovered involving the inadvertent exposure of Azure Active Directory credentials via a misconfigured JSON configuration file. The public accessibility of this file enabled malicious actors to directly authenticate against Microsoft’s OAuth 2.0 endpoints, bypassing traditional security controls and potentially infiltrating cloud environments. Attackers leveraged this cloud misconfiguration to escalate cloud access, risking business-critical Azure resources, data loss, and lateral movement inside affected organizations. Detection came after researchers observed unusual authentication patterns linked to public file sharing, prompting rapid investigation and remediation efforts. The incident underscores how easily overlooked misconfigurations can undermine enterprise cloud security and compliance obligations. The breach highlights ongoing challenges as organizations migrate sensitive workflows to the cloud. Public file exposure, credential leakage, and abuse of identity platforms like Azure Active Directory remain top attack vectors. This incident amplifies recent regulatory scrutiny, reinforces the need for cloud visibility and zero trust practices, and signals rising attacker sophistication in exploiting misconfigured storage and identity controls.
6 months ago
Kill Chain
Inside the Salesloft Drift Supply Chain Breach: How OAuth Token Theft Exposed SaaS Leaders
In August 2023, the threat group UNC6395 exploited a vulnerability in Salesloft’s Drift SaaS marketing platform, targeting OAuth and refresh tokens stored within its Salesforce integration. By leveraging these stolen tokens, attackers performed lateral movement into several customer Salesforce environments, extracting business contact records, support case data, and in some instances, sensitive configuration details and access credentials from high-profile clients such as Zscaler, Palo Alto Networks, Cloudflare, Proofpoint, and Tenable. Salesloft and Salesforce responded by revoking tokens and disabling integrations, while impacted organizations rushed to assess and mitigate the damage. This incident underscores the persistent risk of supply chain compromises targeting SaaS integrations and identity-based authentication mechanisms. As attackers increasingly leverage token theft for stealthy, authorized access, organizations must adopt granular permissions, token security best practices, and rapid credential rotation to safeguard against similar threats.
6 months ago
Kill Chain
FDN3’s Massive Brute-Force Attacks Target VPN & RDP Devices Globally (2025)
Between June and July 2025, Ukrainian autonomous system FDN3 (AS211736) orchestrated large-scale brute-force and password spraying attacks targeting SSL VPN and Remote Desktop Protocol (RDP) devices across multiple regions. The campaign, identified and attributed by French cybersecurity firm Intrinsec, involved distributed login attempts to compromise organizations’ remote access infrastructure using stolen or weak credentials. This led to unauthorized system access, at-risk sensitive data, and the potential for further lateral movement inside target environments. The attack underscored the critical vulnerabilities that arise when VPNs and RDP servers are exposed without adequate security controls. This incident is emblematic of the growing trend of threat actors exploiting internet-facing authentication portals with automated credential attacks. As organizations continue to rely on remote access solutions, adversaries are increasingly targeting SSL VPN and RDP endpoints to gain initial entry—a method further complicated by the prevalence of weak password policies, limited anomaly detection, and insufficient segmentation.
6 months ago
Kill Chain
Nx npm Supply Chain Breach 2025: AI Stealer Exposes Over 1,000 Developer Secrets
In late August 2025, a highly automated supply chain attack compromised the popular Nx build system on npm, enabling unidentified attackers to infect more than 1,000 JavaScript developers within just four hours. Malicious packages, leveraging artificial intelligence through CLI integrations, actively scanned victim environments for GitHub tokens, npm credentials, SSH keys, cloud secrets, and cryptocurrency wallets—exfiltrating roughly 20,000 sensitive files. Instead of using traditional command and control servers, the attackers published victims’ stolen data into public GitHub repositories, complicating detection and enabling rapid collection by threat actors. This incident marks a significant escalation in software supply chain threats by demonstrating the abuse of AI-driven reconnaissance and novel exfiltration via legitimate platforms. The swift, large-scale impact underscores rising attacker sophistication and amplified operational risk, especially as AI and developer tooling become more deeply embedded in build pipelines and cloud-native workflows.
6 months ago
Kill Chain
How a Zero-Click Exploit Unleashed AI Agent Mayhem Across Enterprises
In July 2025, researchers disclosed a critical vulnerability affecting generative AI agents deployed widely across enterprises. This exploit, requiring no user interaction (zero-click), enabled remote attackers to commandeer AI agents and gain broad, unauthorized access to sensitive business data and interdependent cloud applications. By leveraging the AI agents’ elevated privileges and extensive network reach, attackers could move laterally across organizational boundaries, exposing data in transit, triggering egress to attacker-controlled infrastructure, and bypassing traditional segmentation and policy enforcement. The incident resulted in heightened risk for data exfiltration, business interruption, and regulatory scrutiny as organizations scrambled to assess and mitigate exposure. This breach highlights the growing risks of autonomous AI behavior and the challenges of applying conventional network and application security frameworks to evolving AI-driven architectures. The attack underscores the urgent need for robust segmentation, encrypted traffic, and continuous threat monitoring in AI/ML environments, as both threat actors and defenders rapidly adapt to the rise of agentic AI.
6 months ago
Kill Chain
Federal Agency Breached via GeoServer RCE Exploit in 2024
In July 2024, a U.S. federal civilian executive branch agency suffered a significant security breach when attackers exploited a critical remote code execution (RCE) vulnerability (CVE-2024-36401) in an unpatched GeoServer instance. Threat actors gained initial access by leveraging proof-of-concept exploits that had been made public after the vulnerability's disclosure. They moved laterally across the agency’s internal network, breaching additional web and SQL servers, deploying web shells like China Chopper, escalating privileges, and maintaining persistence. The attackers remained undetected for three weeks, only triggering detection when the agency’s EDR tool flagged suspicious malware activity. This breach underscores the growing risk posed by rapid weaponization of new vulnerabilities, particularly those affecting widely used open-source platforms. The incident follows a trend of increased attacks exploiting unpatched systems and weak internal segmentation, emphasizing the urgent need for proactive vulnerability management and robust East-West traffic controls.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports