✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Anthropic's Mythos AI: A New Era in EU Cybersecurity
In June 2026, Anthropic agreed to grant the European Union's cybersecurity agency, ENISA, access to its advanced AI model, Mythos, under Project Glasswing. This collaboration aims to enhance the EU's capability in identifying and mitigating software vulnerabilities. Mythos has demonstrated the ability to autonomously detect and exploit thousands of zero-day vulnerabilities across major operating systems and web browsers, raising both opportunities and concerns regarding AI's role in cybersecurity. The inclusion of ENISA in Project Glasswing underscores the EU's commitment to leveraging cutting-edge technology to bolster its cyber defenses. This development highlights the growing importance of international cooperation in addressing the dual-use nature of advanced AI tools in cybersecurity. As AI models like Mythos become more prevalent, organizations must stay vigilant and adapt their security strategies to mitigate potential risks associated with AI-assisted vulnerability discovery and exploitation.
1 month ago
Kill Chain
Dashlane Brute-Force Attack Highlights Need for Enhanced 2FA Security
In late May 2026, Dashlane, a prominent password management service, experienced a brute-force attack targeting its two-factor authentication (2FA) system. Attackers attempted to register new devices on user accounts by rapidly submitting numerous numeric combinations to bypass 2FA protections. This led to the temporary suspension of several user accounts as a security measure. While Dashlane's internal systems remained uncompromised, the attackers managed to download encrypted vaults from fewer than 20 personal plan users. These vaults, however, remain secure unless the attackers can decipher the users' master passwords. ([thehackernews.com](https://thehackernews.com/2026/06/dashlane-discloses-brute-force-attack.html?utm_source=openai)) This incident underscores the evolving sophistication of cyber threats, particularly against authentication mechanisms. Organizations must continually assess and fortify their security protocols to mitigate such risks. The event also highlights the importance of user education on creating strong, unique master passwords to enhance the security of encrypted data.
1 month ago
Kill Chain
CISA Flags CVE-2024-21182: Immediate Action Required for Oracle WebLogic Server Users
In July 2024, Oracle disclosed CVE-2024-21182, a critical vulnerability in Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0. This flaw allows unauthenticated attackers with network access via T3 or IIOP protocols to gain unauthorized access to critical data. The vulnerability has a CVSS score of 7.5, indicating high severity. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2024-21182?utm_source=openai)) On June 1, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2024-21182 to its Known Exploited Vulnerabilities Catalog, confirming active exploitation in the wild. Organizations using affected versions are urged to apply vendor-provided patches immediately to mitigate potential risks. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2024-21182?utm_source=openai))
1 month ago
Kill Chain
Critical Authentication Bypass Vulnerability in Palo Alto Networks PAN-OS (CVE-2026-0257)
In May 2026, Palo Alto Networks disclosed CVE-2026-0257, an authentication bypass vulnerability in its PAN-OS software's GlobalProtect portal and gateway. Initially rated medium severity, the flaw allows remote attackers to forge authentication cookies and establish unauthorized VPN connections. Rapid7 observed active exploitation starting May 17, leading to a reassessment of the vulnerability as critical. The Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities catalog on May 29. ([cyberscoop.com](https://cyberscoop.com/palo-alto-networks-cve-2026-0257-exploited-vulnerability/?utm_source=openai)) This incident underscores the rapid escalation of seemingly moderate vulnerabilities into critical threats, emphasizing the need for organizations to promptly apply patches and follow mitigation strategies to protect their networks from unauthorized access. ([cyberscoop.com](https://cyberscoop.com/palo-alto-networks-cve-2026-0257-exploited-vulnerability/?utm_source=openai))
1 month ago
Kill Chain
WordPress Malware Campaign Exploits Steam Profiles - 2026
In July 2025, a sophisticated malware campaign was discovered targeting nearly 2,000 WordPress websites. Attackers exploited vulnerabilities to inject malicious code that fetched encoded payloads from comments on Steam Community profiles. These payloads, concealed using invisible Unicode characters, directed the compromised sites to load external JavaScript from malicious domains, ultimately installing backdoors for remote code execution. The campaign's reliance on Steam's platform allowed it to evade traditional detection methods by blending malicious traffic with legitimate communications. This incident underscores the evolving tactics of cybercriminals who leverage trusted platforms to obfuscate their command-and-control infrastructure. The use of invisible Unicode characters for payload encoding highlights the need for advanced detection mechanisms capable of identifying such covert techniques. Organizations must remain vigilant and implement robust security measures to protect against these sophisticated threats.
1 month ago
Kill Chain
Dashlane Users Experience Account Suspensions Amid Brute-Force Attack Attempts
In late May 2026, Dashlane, a prominent password management service, detected a series of brute-force attacks targeting user accounts. These attacks involved repeated login attempts from unfamiliar locations and devices, prompting Dashlane's automated security protocols to temporarily suspend the affected accounts to prevent unauthorized access. The company confirmed that its internal systems remained uncompromised and that the suspensions were precautionary measures to safeguard user data. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/dashlane-password-manager-users-locked-out-by-brute-force-attacks/?utm_source=openai)) This incident underscores the persistent threat of brute-force attacks in the cybersecurity landscape. It highlights the importance of robust security measures, such as multi-factor authentication and vigilant monitoring, to protect user accounts from unauthorized access attempts.
1 month ago
Kill Chain
Red Hat npm Packages Compromised in 2026 Supply Chain Attack
In June 2026, Red Hat's '@redhat-cloud-services' npm namespace was compromised, leading to the distribution of over 30 backdoored packages containing the 'Miasma' malware. This supply chain attack targeted developer credentials, cloud secrets, SSH keys, and CI/CD tokens. The attackers allegedly gained access through a compromised Red Hat employee's GitHub account, injecting malicious code into multiple repositories. Red Hat promptly removed the affected packages and reported no impact on customer or partner environments. This incident underscores the escalating threat of supply chain attacks in the software development ecosystem. The use of sophisticated malware like 'Miasma' highlights the need for enhanced security measures in CI/CD pipelines and vigilant monitoring of open-source dependencies to prevent unauthorized access and data breaches.
1 month ago
Kill Chain
Miasma Attack: Red Hat npm Packages Compromised in June 2026
In June 2026, a sophisticated supply chain attack, dubbed 'Miasma,' compromised over 30 npm packages under the @redhat-cloud-services scope. The attackers infiltrated Red Hat's GitHub Actions OIDC pipeline, injecting a credential-stealing worm into these packages. Upon installation, the malware executed a preinstall script that harvested sensitive information, including GitHub Actions secrets, npm tokens, cloud credentials, Kubernetes tokens, SSH keys, and Git credentials. The stolen data was exfiltrated to attacker-controlled servers, facilitating further propagation of the malware. This incident underscores the escalating threat of supply chain attacks targeting trusted software repositories. The open-sourcing of the Mini Shai-Hulud malware by the cybercriminal group TeamPCP has lowered the barrier for such attacks, enabling a broader range of threat actors to execute similar campaigns. Organizations must enhance their security measures to protect against these evolving threats.
1 month ago
Kill Chain
Investigating Suspicious AI Workflows in Microsoft Entra Agent ID
In May 2026, a security incident was identified involving a Microsoft Entra Agent ID user account named MrRoboto4@ContosoCorp.onmicrosoft.com. This agent user sent a suspicious Teams message containing a potentially malicious link to https://domoarigato.ai/. The message was reported by a human user, prompting an investigation. Analysis revealed that the agent user had been granted extensive permissions, allowing it to perform actions typically reserved for human users, such as sending messages and emails. The agent's activities were executed via the Graph API from an external IP address, highlighting potential security gaps in monitoring and controlling AI-driven workflows within enterprise environments. This incident underscores the growing security challenges posed by AI agents operating autonomously within organizational systems. As enterprises increasingly integrate AI agents to automate tasks, ensuring proper identity management, access controls, and monitoring mechanisms for these non-human entities becomes critical to prevent unauthorized actions and potential breaches.
1 month ago
Kill Chain
ShinyHunters' 2026 Data Breaches: A Wake-Up Call for Cybersecurity
In May 2026, the cybercriminal group ShinyHunters executed a series of data breaches targeting multiple organizations, including DentaQuest, a prominent dental benefits administrator in the United States. The attackers employed sophisticated social engineering techniques, such as voice phishing, to compromise employee credentials and gain unauthorized access to sensitive systems. This led to the exfiltration of substantial volumes of personal and proprietary data, which ShinyHunters subsequently threatened to release unless ransom demands were met. The breaches have raised significant concerns regarding data security practices and the effectiveness of current defensive measures against such targeted attacks. The recent surge in ShinyHunters' activities underscores a troubling trend in cybercrime, where threat actors increasingly leverage social engineering to bypass technical defenses. Organizations across various sectors are now facing heightened risks of data breaches, emphasizing the urgent need for enhanced security protocols, employee training, and robust incident response strategies to mitigate the impact of such sophisticated cyber threats.
1 month ago
Kill Chain
Malicious npm Package 'codexui-android' Compromises OpenAI Codex Tokens
In May 2026, a malicious supply chain attack targeted developers using OpenAI Codex through a seemingly legitimate npm package named 'codexui-android'. This package, advertised as a remote web UI for OpenAI Codex, amassed over 29,000 weekly downloads. Approximately a month after its initial release, the package began exfiltrating users' Codex authentication tokens to an attacker-controlled server, granting unauthorized access to developers' accounts. The malicious code was embedded into a functional npm package that had undergone active development, making it particularly insidious. The associated GitHub repository remained clean, further complicating detection. ([thehackernews.com](https://thehackernews.com/2026/06/openai-codex-authentication-tokens.html?utm_source=openai)) This incident underscores the growing sophistication of supply chain attacks, where threat actors leverage trusted development tools to infiltrate systems. The use of a functional and actively developed package to distribute malicious code highlights the need for heightened vigilance in the software development community. Developers are urged to scrutinize third-party packages, even those with established reputations, to mitigate the risk of credential theft and unauthorized access.
1 month ago
Kill Chain
Operation Dragon Weave: Unveiling a Sophisticated Cyber Espionage Campaign
Operation Dragon Weave is a cyber espionage campaign identified in May 2026, targeting officials and citizens in the Czech Republic and Taiwan. The attackers employed spear-phishing emails with ZIP attachments to initiate an infection chain that utilized a Rust-based loader to deploy the AdaptixC2 agent, known as AZUREVEIL. This agent facilitated data exfiltration and remote control by leveraging Microsoft Azure Blob Storage for command-and-control communications, effectively blending malicious traffic with legitimate cloud activity. The campaign specifically targeted sectors such as government, research, academia, technology, and financial services, indicating a strategic focus on sensitive information. The use of AdaptixC2 in this campaign underscores a growing trend where open-source penetration testing tools are repurposed by threat actors for malicious activities. This incident highlights the need for organizations to enhance their detection capabilities and adopt proactive defense measures to counter sophisticated attack vectors that exploit legitimate cloud services for covert operations.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports