The Containment Era is here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2638 threat reports
Page 35 of 220

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 409420 / 2638 reports
Inside the Modern SOC: Navigating 2026's Identity-Based Cyber Threats
Impact· HIGH

Inside the Modern SOC: Navigating 2026's Identity-Based Cyber Threats

In 2025, Unit 42 responded to over 750 major cyber incidents across various industries and countries. A significant trend observed was the rapid acceleration of attack timelines, with some adversaries moving from initial access to data exfiltration in just 72 minutes—a fourfold increase from the previous year. This surge is largely attributed to the integration of AI by threat actors, enhancing their speed and efficiency. Additionally, identity-based attacks have become predominant, with 65% of initial accesses driven by techniques such as social engineering and credential misuse. ([paloaltonetworks.com](https://www.paloaltonetworks.com/blog/2026/02/unit-42-global-ir-report/?utm_source=openai)) The current cybersecurity landscape underscores the urgency for organizations to adapt to these evolving threats. The rise in AI-driven attacks and the exploitation of identity vulnerabilities necessitate a reevaluation of security strategies. Implementing robust identity and access management, enhancing monitoring capabilities, and adopting AI-driven defense mechanisms are crucial steps to mitigate these accelerated and sophisticated threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
ShinyHunters Breach Infinite Campus: 137,000 School Staff Accounts Exposed
Impact· MEDIUM

ShinyHunters Breach Infinite Campus: 137,000 School Staff Accounts Exposed

In March 2026, the ShinyHunters extortion group infiltrated Infinite Campus's Salesforce instance, compromising personal information of over 137,000 school staff members. The stolen data included names, email addresses, phone numbers, physical addresses, and support tickets. Infinite Campus, a leading EdTech provider serving over 3,200 school districts across the United States, confirmed the breach but stated that the majority of the exposed information was publicly available directory data. This incident underscores the escalating trend of cybercriminals targeting educational institutions and their service providers. The breach highlights the critical need for robust security measures and vigilant monitoring of third-party platforms to safeguard sensitive information in the education sector.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
North Korean Hackers Exploit Developer Tools in Sophisticated Phishing Campaign
Impact· HIGH

North Korean Hackers Exploit Developer Tools in Sophisticated Phishing Campaign

In early 2026, a North Korean state-sponsored threat actor, identified as UNK_DeadDrop, launched a sophisticated phishing campaign targeting software developers across nearly 100 organizations, primarily in the United States. The attackers sent over 250 emails between April and May, masquerading as recruitment offers or code review requests. These emails directed recipients to clone malicious GitHub or GitLab repositories, which, when opened in code editors like Visual Studio Code, executed embedded malware. This approach enabled the attackers to steal cryptocurrency wallets and sensitive developer credentials. ([theregister.com](https://www.theregister.com/security/2026/06/08/suspected-norks-send-250-fake-dev-job-pitches-to-steal-crypto/5252526?utm_source=openai)) This incident underscores a significant evolution in cyberattack methodologies, where adversaries exploit trusted developer tools and workflows to deliver malware. The campaign's scale and sophistication highlight the increasing targeting of the tech industry by state-sponsored actors, emphasizing the need for heightened vigilance and robust security measures within development environments. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Authentication Bypass in SimpleHelp: CVE-2026-48558
Impact· CRITICAL

Critical Authentication Bypass in SimpleHelp: CVE-2026-48558

In June 2026, a critical vulnerability (CVE-2026-48558) was discovered in SimpleHelp remote management software versions 5.5.15 and earlier, as well as 6.0 pre-release versions. This flaw allows unauthenticated attackers to create privileged technician accounts by exploiting improper validation of identity tokens in the OpenID Connect (OIDC) authentication flow. Consequently, attackers can gain unauthorized access to managed endpoints, execute scripts, and perform administrative actions without user interaction. SimpleHelp addressed this issue by releasing patched versions 5.5.16 and 6.0 RC2 on June 9, 2026. Organizations are urged to update their systems promptly to mitigate potential exploitation risks. This incident underscores the critical importance of robust authentication mechanisms and thorough validation processes in remote management tools. The exploitation of OIDC vulnerabilities highlights a growing trend where attackers target identity and access management systems to gain unauthorized access, emphasizing the need for continuous vigilance and timely patch management.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical LiteLLM Vulnerabilities Expose AI Gateways to Unauthenticated RCE
Impact· HIGH

Critical LiteLLM Vulnerabilities Expose AI Gateways to Unauthenticated RCE

In May 2026, a critical vulnerability chain was discovered in LiteLLM, an open-source AI gateway widely used to interface with over 100 large language model providers. The primary flaw, CVE-2026-42271, is a command injection vulnerability affecting versions 1.74.2 through 1.83.6. This vulnerability allows authenticated users, including those with low-privilege internal-user keys, to execute arbitrary commands on the host system by exploiting two Model Context Protocol (MCP) test endpoints. When combined with CVE-2026-48710, an authentication bypass in the Starlette web framework, attackers can achieve unauthenticated remote code execution, granting them full control over the server. This chain of vulnerabilities exposes sensitive API keys and secrets stored by the proxy, potentially compromising connected AI systems and enabling lateral movement within enterprise networks. The active exploitation of these vulnerabilities underscores the increasing targeting of AI gateway infrastructures by threat actors. Organizations relying on LiteLLM are urged to upgrade to version 1.83.7 or later, which addresses these issues by implementing stricter authorization controls and updating dependencies. Additionally, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-42271 to its Known Exploited Vulnerabilities catalog, emphasizing the urgency for immediate remediation to prevent potential breaches and data exfiltration.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Palo Alto Networks PAN-OS GlobalProtect VPN Authentication Bypass Vulnerability (CVE-2026-0257)
Impact· CRITICAL

Palo Alto Networks PAN-OS GlobalProtect VPN Authentication Bypass Vulnerability (CVE-2026-0257)

In May 2026, Palo Alto Networks disclosed CVE-2026-0257, a high-severity authentication bypass vulnerability in the GlobalProtect portal and gateway components of PAN-OS software. This flaw allows unauthenticated remote attackers to forge valid session cookies, enabling unauthorized VPN connections into corporate networks. Active exploitation of this vulnerability was observed starting May 17, 2026, with attackers attempting to access GlobalProtect portals. While no post-access behavior or lateral movement has been identified, the potential for unauthorized access to sensitive internal resources poses a significant risk. The inclusion of CVE-2026-0257 in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog underscores the urgency for organizations to address this issue. The active exploitation highlights a broader trend of attackers targeting VPN infrastructures to gain unauthorized access, emphasizing the need for robust authentication mechanisms and timely patch management to mitigate such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Unveiling the Threat: 152 Malicious Chrome Extensions Compromise User Security
Impact· MEDIUM

Unveiling the Threat: 152 Malicious Chrome Extensions Compromise User Security

In June 2026, cybersecurity researchers uncovered a network of 152 Google Chrome extensions, primarily offering live wallpaper functionalities, that were distributing potentially unwanted programs (PUPs). These extensions, spanning 38 separate Chrome Web Store publisher accounts and three brand backends—tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com—had collectively amassed 105,000 installations. Despite claiming not to collect user data, the extensions' privacy policies revealed the logging of IP addresses, ISPs, click counts, and referrers, with data shared with Google AdSense, DoubleClick, and third-party ad partners. Additionally, some extensions manipulated browser behavior to simulate organic search traffic, thereby fabricating the origin of their own traffic. This incident underscores the persistent threat posed by malicious browser extensions, which can compromise user privacy and security. The deceptive practices employed highlight the need for vigilant monitoring of browser add-ons and the importance of scrutinizing privacy policies, even for seemingly benign applications.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Google Patches Actively Exploited Chrome Zero-Day Vulnerability CVE-2026-11645
Impact· HIGH

Google Patches Actively Exploited Chrome Zero-Day Vulnerability CVE-2026-11645

In June 2026, Google addressed a high-severity zero-day vulnerability, CVE-2026-11645, in its Chrome browser. This flaw, an out-of-bounds read and write issue in the V8 JavaScript engine, allowed remote attackers to execute arbitrary code via crafted HTML pages. The vulnerability was actively exploited in the wild, prompting Google to release an emergency update to mitigate the risk. Users were urged to update to version 149.0.7827.103 to secure their systems. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/06/09/google-chrome-zero-day-cve-2026-11645/?utm_source=openai)) This incident underscores the persistent targeting of widely used software by threat actors and highlights the critical importance of timely software updates. The exploitation of such vulnerabilities can lead to significant data breaches and system compromises, emphasizing the need for robust cybersecurity practices.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Former IT Employee Sentenced for Prolonged Cyberattacks on School District
Impact· HIGH

Former IT Employee Sentenced for Prolonged Cyberattacks on School District

In June 2026, Ezekiel Dean Potter, a former senior IT support specialist at Saydel Community School District in Des Moines, Iowa, was sentenced to 21 months in prison for conducting a series of unauthorized cyberattacks against his former employer. After his termination in April 2023, Potter retained access credentials and over the next 21 months, he deleted the district's Facebook page, disrupted access to educational platforms, and reset employee usernames and passwords, causing significant operational disruptions and financial losses estimated at tens of thousands of dollars. This incident underscores the critical importance of promptly revoking access credentials of departing employees and implementing robust monitoring systems to detect unauthorized access. The case highlights the potential risks posed by insider threats and the necessity for organizations to enforce strict access control policies to safeguard their digital assets.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
ShinyHunters' Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
Impact· CRITICAL

ShinyHunters' Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)

Between May 27 and June 9, 2026, the cyber extortion group ShinyHunters exploited a zero-day vulnerability (CVE-2026-35273) in Oracle's PeopleSoft software, specifically targeting the Environment Management Hub (EMHub). This critical flaw allowed unauthenticated remote code execution, leading to the compromise of over 100 organizations, predominantly in the higher education sector. The attackers exfiltrated sensitive data from approximately 300 PeopleSoft instances, including personal and financial information of students and staff. Oracle released a security advisory and patch on June 10, 2026, urging immediate action to mitigate the risk. ([darkreading.com](https://www.darkreading.com/vulnerabilities-threats/shinyhunters-oracle-zero-day-higher-ed?utm_source=openai)) This incident underscores the increasing targeting of educational institutions by cybercriminals exploiting unpatched vulnerabilities in widely used enterprise software. The rapid exploitation of zero-day vulnerabilities highlights the necessity for organizations to implement proactive vulnerability management and incident response strategies to protect sensitive data and maintain operational integrity.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Anthropic Halts AI Models Fable 5 and Mythos 5 Following U.S. Government Directive
Impact· HIGH

Anthropic Halts AI Models Fable 5 and Mythos 5 Following U.S. Government Directive

In June 2026, the U.S. government issued an export control directive requiring Anthropic to suspend access to its advanced AI models, Fable 5 and Mythos 5, for all foreign nationals, including those within the United States. This directive, citing national security concerns, led Anthropic to disable these models globally to ensure compliance. The order also affected foreign national employees of Anthropic, highlighting the broad scope of the government's action. ([tomshardware.com](https://www.tomshardware.com/tech-industry/artificial-intelligence/us-export-control-order-forces-anthropic-to-disable-claude-fable-5-and-mythos-5-worldwide?utm_source=openai)) This incident underscores the increasing regulatory scrutiny over advanced AI technologies and their potential implications for national security. Organizations developing or utilizing such technologies must stay vigilant to evolving compliance requirements and assess the impact of governmental directives on their operations and international collaborations.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in Splunk Enterprise: CVE-2026-20253
Impact· CRITICAL

Critical Vulnerability in Splunk Enterprise: CVE-2026-20253

In June 2026, a critical vulnerability (CVE-2026-20253) was identified in Splunk Enterprise versions below 10.2.4 and 10.0.7, allowing unauthenticated users to perform arbitrary file operations via a PostgreSQL sidecar service endpoint lacking authentication controls. This flaw could lead to remote code execution, data destruction, and full system compromise. Splunk has released patches to address this issue, urging immediate updates to mitigate potential exploitation. The disclosure of CVE-2026-20253 underscores the ongoing risks associated with unauthenticated access points in enterprise software. Organizations are advised to review their security postures, apply the latest patches promptly, and implement robust access controls to prevent similar vulnerabilities from being exploited.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports