The Containment Era is here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2634 threat reports
Page 28 of 220

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 325336 / 2634 reports
Cordyceps Vulnerabilities Threaten Over 300 GitHub Repositories
Impact· HIGH

Cordyceps Vulnerabilities Threaten Over 300 GitHub Repositories

In June 2026, cybersecurity firm Novee identified a systemic class of vulnerabilities, dubbed 'Cordyceps,' within GitHub Actions workflows. These flaws enable unauthenticated attackers to hijack continuous integration and continuous deployment (CI/CD) pipelines by exploiting insecure configurations in YAML files. The vulnerabilities affect repositories from major organizations, including Microsoft, Google, Apache, Cloudflare, and the Python Software Foundation, potentially compromising software supply chains and exposing sensitive credentials. ([securityweek.com](https://www.securityweek.com/exploitable-ci-cd-vulnerabilities-expose-millions-of-repositories-to-hijacking/?utm_source=openai)) This incident underscores the escalating risks associated with CI/CD pipeline security, especially as AI-driven coding tools proliferate. Organizations must prioritize securing their development workflows to prevent similar supply chain attacks, which are becoming increasingly sophisticated and widespread. ([mallory.ai](https://www.mallory.ai/stories/019ef4cf-b141-7c22-b785-3b7e99e1c73f?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
U.S. Authorities Dismantle Huione Group's Cybercrime Infrastructure in 2026
Impact· HIGH

U.S. Authorities Dismantle Huione Group's Cybercrime Infrastructure in 2026

In June 2026, the U.S. Department of Justice seized a cloud computing account linked to subsidiaries of the Cambodia-based Huione Group, a conglomerate implicated in extensive cyber scams and money laundering activities. This infrastructure supported Huione Guarantee, a Telegram-based marketplace facilitating the sale of stolen personal data, malware-enabled thefts, and laundering of proceeds from various scams, including romance and investment frauds. The operation disrupted a significant node in the global cybercrime ecosystem, which had laundered over $4 billion in illicit funds between August 2021 and January 2025. This action underscores the escalating efforts by U.S. authorities to dismantle transnational cybercriminal networks exploiting digital platforms for large-scale fraud. The seizure highlights the critical need for robust cybersecurity measures and international cooperation to combat the evolving landscape of cyber threats targeting individuals and financial systems worldwide.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft and Partners Execute Unprecedented Takedown of Amadey and StealC Cybercrime Tools
Impact· MEDIUM

Microsoft and Partners Execute Unprecedented Takedown of Amadey and StealC Cybercrime Tools

In June 2026, Microsoft, in collaboration with international law enforcement agencies and industry partners, executed a court-authorized operation to simultaneously disrupt the Amadey botnet and StealC infostealer. These tools, often used in tandem by cybercriminals, were linked to over 140,000 infected computers globally in early May 2026. The operation targeted more than 200 command-and-control servers, significantly hindering the infrastructure supporting these malware families. This coordinated effort marked a strategic shift in cyber defense, emphasizing the importance of disrupting interconnected cybercrime tools to enhance the effectiveness of takedown operations. The success of this operation underscores the necessity for collaborative approaches in combating sophisticated cyber threats that exploit modular, pay-as-you-go models to escalate attacks rapidly.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
LastPass Data Breach via Klue Supply Chain Attack in 2026
Impact· MEDIUM

LastPass Data Breach via Klue Supply Chain Attack in 2026

In June 2026, LastPass experienced a data breach resulting from a supply chain attack on Klue, a third-party market intelligence platform integrated with LastPass's Salesforce environment. Attackers exploited compromised OAuth tokens obtained from Klue to access LastPass customer data, including names, phone numbers, email addresses, physical addresses, support case information, and sales-related data. Importantly, LastPass's core products, services, and customer vaults remained unaffected. ([blog.lastpass.com](https://blog.lastpass.com/posts/klue-supply-chain-incident-and-lastpass-response?utm_source=openai)) This incident underscores the escalating risks associated with third-party integrations and supply chain vulnerabilities. Organizations must reassess their security postures, particularly concerning external partnerships, to mitigate potential threats arising from interconnected systems.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
AI-Driven Acceleration in Vulnerability Exploitation Demands Immediate Action
Impact· HIGH

AI-Driven Acceleration in Vulnerability Exploitation Demands Immediate Action

In June 2026, a report highlighted the dramatic acceleration in the exploitation of software vulnerabilities due to AI advancements. The Zero Day Clock indicated that the average time from vulnerability disclosure to exploitation had decreased from 53 days in 2024 to just 8 hours in 2026. This rapid reduction challenges traditional vulnerability management practices, which relied on longer remediation windows. Organizations now face increased risks as attackers can exploit vulnerabilities almost immediately after disclosure, outpacing conventional patching and mitigation efforts. This development underscores the urgent need for organizations to adopt proactive security measures, such as continuous threat exposure management and automated security validation, to effectively address the evolving threat landscape.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Scattered Spider's 2024 Cyberattack on Transport for London: A Case Study
Impact· HIGH

Scattered Spider's 2024 Cyberattack on Transport for London: A Case Study

In late August 2024, the cybercriminal group Scattered Spider infiltrated Transport for London's (TfL) systems, compromising the Oyster refunds system and causing significant operational disruptions. The attack led to the theft of customer data and forced all 28,000 TfL employees to reset their passwords, resulting in financial damages estimated at £29 million ($38.3 million). This incident underscores the escalating threat posed by cybercriminal groups targeting critical infrastructure. Organizations must enhance their cybersecurity measures to prevent similar breaches and mitigate potential operational and financial impacts.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
New macOS ClickFix Attack Silently Mounts DMGs to Deploy Infostealer
Impact· MEDIUM

New macOS ClickFix Attack Silently Mounts DMGs to Deploy Infostealer

In June 2026, a new macOS ClickFix campaign emerged, utilizing Terminal commands to silently download, mount, and execute info-stealing malware from malicious disk image (DMG) files. This attack infects Mac devices with the Atomic macOS Stealer (AMOS), which exfiltrates browser credentials, cryptocurrency wallet data, Keychain information, messaging app data, and user documents. The campaign begins with a fake CAPTCHA page instructing users to open Terminal and paste a malicious command, leading to the automatic execution of the malware. This method represents an evolution in ClickFix attacks, combining social engineering with automated malware deployment to enhance stealth and effectiveness. The significance of this incident lies in the increasing sophistication of social engineering attacks targeting macOS users. By leveraging trusted system utilities and deceptive prompts, attackers can bypass traditional security measures and user vigilance. This trend underscores the need for enhanced user education, robust endpoint protection, and continuous monitoring to detect and mitigate such evolving threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Xsolis Data Breach 2026: A Wake-Up Call for Healthcare Cybersecurity
Impact· HIGH

Xsolis Data Breach 2026: A Wake-Up Call for Healthcare Cybersecurity

In January 2026, healthcare technology company Xsolis experienced a data breach affecting nearly 1.4 million individuals. The breach resulted from a targeted phishing attack on January 20, 2026, which allowed unauthorized access to Xsolis's network. The attackers accessed files containing sensitive personal and health information, including names, addresses, dates of birth, Social Security numbers, health insurance details, and medical treatment information. Xsolis detected the unauthorized activity on January 22, 2026, promptly contained the breach, and initiated an investigation with external cybersecurity experts. The company has since notified affected individuals and implemented additional security measures to prevent future incidents. This incident underscores the persistent threat of phishing attacks in the healthcare sector, highlighting the critical need for robust cybersecurity measures and employee training to protect sensitive patient data. The breach also raises concerns about potential identity theft and fraud for the affected individuals, emphasizing the importance of vigilance and proactive monitoring of personal information.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
WhatsApp Phishing Campaign Installs ManageEngine RMM Tool via VBScript
Impact· CRITICAL

WhatsApp Phishing Campaign Installs ManageEngine RMM Tool via VBScript

In June 2026, a sophisticated phishing campaign was identified targeting users of WhatsApp Desktop and WhatsApp Web across multiple countries, including Malaysia, Brazil, India, Mexico, Singapore, the U.K., Spain, Taiwan, and Australia. Attackers utilized compromised WhatsApp accounts to distribute malicious Visual Basic Script (VBScript) files disguised as legitimate business documents, such as invoices and billing statements. Upon execution, these scripts installed ManageEngine Endpoint Central, a legitimate Remote Monitoring and Management (RMM) tool, granting attackers full remote control over the victim's system. This unauthorized access enabled the exfiltration of sensitive data, installation of additional malware, and potential lateral movement within corporate networks. This incident underscores a concerning trend in cyber threats where attackers leverage legitimate software tools to evade detection and maintain persistent access within compromised systems. The use of social engineering tactics, such as distributing malware through trusted communication platforms like WhatsApp, highlights the evolving nature of phishing campaigns and the necessity for organizations to enhance their security awareness training and implement robust endpoint protection measures.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Malicious npm Packages Masquerade as PostCSS Tools to Deploy Windows RAT
Impact· HIGH

Malicious npm Packages Masquerade as PostCSS Tools to Deploy Windows RAT

In June 2026, cybersecurity researchers identified a series of malicious npm packages masquerading as legitimate PostCSS tools. These packages, including 'aes-decode-runner-pro', 'postcss-minify-selector', and 'postcss-minify-selector-parser', were designed to deliver a Windows-based Remote Access Trojan (RAT) upon installation. The packages were published over the past month by an npm user named 'abdrizak'. The malicious code was heavily obfuscated, leveraging techniques like Base64 and XOR encoding, as well as minification, to resist analysis and detection efforts. Upon installation, the packages retrieved a malicious script from a remote server, executing it silently to deploy the RAT on Windows systems. ([research.jfrog.com](https://research.jfrog.com/post/from-postcss-typosquat-to-windows-rat/?utm_source=openai)) This incident underscores the persistent threat of supply chain attacks within the npm ecosystem. Attackers continue to exploit the trust in widely used open-source packages to distribute malware, highlighting the need for enhanced vigilance and security measures among developers and organizations.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
AIR's Experiment Unveils Critical Security Gaps in AI Agent Skill Marketplaces
Impact· LOW

AIR's Experiment Unveils Critical Security Gaps in AI Agent Skill Marketplaces

In June 2026, security firm AIR conducted an experiment to highlight vulnerabilities in AI agent skill marketplaces. They created a fake AI agent skill named 'brand-landingpage,' which purported to assist users in building landing pages using Google's Stitch design tool. This skill was submitted to a popular skill marketplace and promoted via an Instagram ad, ultimately reaching approximately 26,000 agents, including those on corporate accounts. Notably, all security scanners tested by AIR marked the skill as safe. The payload was intentionally benign, merely collecting users' email addresses to demonstrate the ease with which malicious skills could bypass existing security measures. This incident underscores the pressing need for enhanced security protocols in AI agent skill ecosystems, as traditional trust signals such as GitHub stars and scanner verdicts proved insufficient in detecting potential threats. The reliance on external links within skills, which can be altered post-review, presents a significant risk, emphasizing the necessity for continuous monitoring and comprehensive vetting processes to safeguard against supply chain attacks in AI environments.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
FortiBleed: Unprecedented Credential Harvesting Targets FortiGate Firewalls
Impact· CRITICAL

FortiBleed: Unprecedented Credential Harvesting Targets FortiGate Firewalls

In June 2026, a Russian-speaking initial access broker initiated 'FortiBleed,' a large-scale credential-harvesting operation targeting over 430,000 FortiGate firewalls globally. The campaign involved deploying custom sniffers on compromised devices to capture cleartext and hashed credentials, which were then used to infiltrate Active Directory domains and other services. This incident underscores the critical need for organizations to secure their network devices, as attackers increasingly exploit firewall vulnerabilities to gain unauthorized access. The widespread impact of FortiBleed highlights the importance of regular security assessments and prompt patch management.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports