The Containment Era is here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2638 threat reports
Page 48 of 220

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 565576 / 2638 reports
Zapier Exploit Chain Reveals Critical Cloud Security Vulnerabilities
Impact· HIGH

Zapier Exploit Chain Reveals Critical Cloud Security Vulnerabilities

In May 2026, researchers from Token Security identified a critical vulnerability in Zapier's platform, demonstrating how a series of misconfigurations and over-permissioned roles could lead to a full platform takeover. The exploit chain began with the ability to execute code within Zapier's 'Code by Zapier' feature, allowing attackers to perform sandbox reconnaissance and extract credentials from memory. This access enabled lateral movement to Zapier's private repositories, where a high-privilege NPM token was discovered, potentially allowing the publication of malicious code to all authenticated users. Zapier promptly addressed the issue by revoking the leaked token and tightening IAM roles, with full remediation confirmed by March 2026. This incident underscores the critical importance of securing cloud integrations and managing permissions effectively. As cloud services become increasingly complex, even minor misconfigurations can be exploited to orchestrate significant breaches, highlighting the need for continuous security assessments and robust access controls.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Major Supply Chain Attacks Target Nx Console and GitHub Repositories in 2026
Impact· CRITICAL

Major Supply Chain Attacks Target Nx Console and GitHub Repositories in 2026

In May 2026, two significant supply chain attacks targeted the developer ecosystem. The first involved a compromised version of the Nx Console Visual Studio Code extension (v18.95.0), which was live for approximately 18 minutes on May 18, 2026. This malicious extension exfiltrated credentials from developer machines, leading to unauthorized access and exfiltration of approximately 3,800 internal GitHub repositories. The second attack, dubbed 'Megalodon,' occurred on the same day and compromised over 5,500 GitHub repositories by injecting malicious GitHub Actions workflows designed to harvest CI/CD secrets and cloud credentials. These incidents underscore the escalating threat landscape targeting software development pipelines and the critical need for robust security measures in CI/CD environments. The rapid execution and widespread impact of these attacks highlight the urgency for organizations to implement stringent supply chain security practices and continuous monitoring to detect and mitigate such threats promptly.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Kimsuky's Advanced Cyber Attacks: A New Era of AI-Driven Threats
Impact· HIGH

Kimsuky's Advanced Cyber Attacks: A New Era of AI-Driven Threats

In March and April 2026, the North Korean state-sponsored threat actor Kimsuky launched sophisticated cyber attacks targeting South Korean military and corporate entities. Utilizing advanced social engineering tactics, they spoofed security software installation pages and crafted fake Webex meeting pages to distribute malware. These campaigns delivered variants of the HTTPSpy remote access trojan, enabling extensive control over compromised systems, including command execution, file manipulation, and data exfiltration. Notably, Kimsuky employed legitimate tools like Visual Studio Code's remote tunneling feature and DWAgent for post-exploitation activities, enhancing their ability to evade detection. The increasing integration of artificial intelligence in cyber attack methodologies, as demonstrated by Kimsuky's use of large language models to develop malware like HelloDoor, signifies a significant evolution in threat actor capabilities. This trend underscores the urgent need for organizations to adopt advanced, behavior-based detection systems and regularly update threat intelligence to effectively counter these sophisticated and rapidly evolving cyber threats.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Malicious Sicoob NuGet Package Compromises Banking Credentials
Impact· HIGH

Malicious Sicoob NuGet Package Compromises Banking Credentials

In May 2026, cybersecurity researchers discovered a malicious NuGet package named 'Sicoob.Sdk' that impersonated a C# software development kit for Sicoob, one of Brazil's largest cooperative financial systems. Versions 2.0.0 through 2.0.4 of this package were found to exfiltrate sensitive information, including client IDs and PFX certificates, which are crucial for secure communications. This incident underscores the growing trend of supply chain attacks targeting software development ecosystems to steal sensitive data. The discovery of 'Sicoob.Sdk' aligns with a series of recent supply chain attacks where malicious packages infiltrate trusted repositories. For instance, the 'TrapDoor' campaign targeted npm, PyPI, and Crates.io ecosystems to distribute credential-stealing malware. These incidents highlight the urgent need for enhanced vigilance and security measures within software supply chains to protect against such threats.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
AI Agents Exploit Marimo Vulnerability CVE-2026-39987
Impact· CRITICAL

AI Agents Exploit Marimo Vulnerability CVE-2026-39987

In May 2026, an unidentified threat actor exploited a critical vulnerability (CVE-2026-39987) in Marimo, an open-source Python notebook platform, to gain unauthorized access to a publicly accessible Marimo instance. Utilizing a large language model (LLM) agent, the attacker extracted cloud credentials, retrieved an SSH private key from AWS Secrets Manager, and conducted multiple SSH sessions to exfiltrate the schema and full contents of an internal PostgreSQL database within a short timeframe. This incident underscores the rapid weaponization of AI-driven tools in cyberattacks, enabling sophisticated post-exploitation activities with minimal prior knowledge of the target environment. Organizations must prioritize patching known vulnerabilities and enhance monitoring to detect and mitigate such advanced threats promptly.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
GREYVIBE's AI-Powered Cyberattacks on Ukraine: A 2025 Case Study
Impact· HIGH

GREYVIBE's AI-Powered Cyberattacks on Ukraine: A 2025 Case Study

In August 2025, a previously undocumented threat actor named GREYVIBE initiated a series of cyberattacks targeting Ukrainian military, government, civilian, and business entities. Operating from the Russian time zone and aligning with Kremlin state interests, GREYVIBE employed multiple attack vectors, including spear-phishing emails, fake CAPTCHA pages, and fraudulent websites, to deliver custom-developed malware such as PhantomRelay and LegionRelay. Notably, the group leveraged generative artificial intelligence (GenAI) and large language models (LLMs) to enhance their operations, facilitating rapid development of obfuscators, loaders, and malware. ([thehackernews.com](https://thehackernews.com/2026/05/new-russian-linked-greyvibe-targets.html?utm_source=openai)) The integration of AI technologies in cyberattacks signifies a concerning evolution in threat actor capabilities, enabling even low-to-moderately sophisticated groups to execute complex operations. This trend underscores the urgent need for organizations to adopt advanced cybersecurity measures to detect and mitigate AI-assisted threats. ([t.co](https://t.co/WAHU7GJnZC?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Typosquatted npm Packages Lead to Cloud and CI/CD Credential Theft
Impact· HIGH

Typosquatted npm Packages Lead to Cloud and CI/CD Credential Theft

In May 2026, a threat actor using the alias 'vpmdhaj' published 14 malicious npm packages that mimicked popular OpenSearch and ElasticSearch libraries. These packages, once installed, executed scripts to harvest sensitive credentials, including AWS keys, HashiCorp Vault tokens, and CI/CD pipeline secrets, from the host environment. The attack leveraged typosquatting and spoofed metadata to appear legitimate, facilitating unauthorized access and potential lateral movement within cloud infrastructures. This incident underscores the escalating threat of supply chain attacks targeting open-source ecosystems. Organizations must remain vigilant, as such attacks can lead to significant data breaches and operational disruptions. Implementing stringent package validation processes and monitoring for anomalous activities are crucial to mitigating these risks.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
ESET APT Activity Report Q4 2025–Q1 2026: Key Cyber Threats Unveiled
Impact· HIGH

ESET APT Activity Report Q4 2025–Q1 2026: Key Cyber Threats Unveiled

Between October 2025 and March 2026, ESET researchers observed significant activities from various Advanced Persistent Threat (APT) groups. China-aligned actors conducted espionage campaigns targeting maritime, energy, and political sectors, notably in Venezuela and Syria. Iran-aligned groups experienced a decline in activity due to domestic internet restrictions, while proxy and hacktivist actors increased attacks on Israel and the United States. North Korea-aligned groups focused on developers and the cryptocurrency ecosystem, employing social engineering tactics for financial gain and potential supply-chain compromises. Russia-aligned actors intensified operations against Ukraine, deploying new wipers and targeting critical infrastructure, with notable incidents extending to NATO member states like Poland. Lesser-known clusters also emerged, including browser-in-the-browser phishing attacks and Android spyware targeting Arabic-speaking users. This period underscores the evolving tactics of APT groups and the necessity for robust cybersecurity measures to counteract these sophisticated threats.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Google Engineer Arrested for Insider Trading on Polymarket
Impact· MEDIUM

Google Engineer Arrested for Insider Trading on Polymarket

In May 2026, Michele Spagnuolo, a 36-year-old Google security engineer, was arrested in New York for allegedly using confidential internal data to profit on the Polymarket prediction platform. Spagnuolo accessed nonpublic 'Year in Search' data to place bets on the most searched individuals of 2025, resulting in over $1.2 million in gains. He faces charges including commodities fraud, wire fraud, and money laundering, with potential sentences totaling up to 50 years in prison. This incident underscores the growing scrutiny of insider trading within emerging financial platforms like prediction markets. It highlights the critical need for robust internal controls and monitoring to prevent the misuse of proprietary information, especially as digital platforms become increasingly integrated into financial activities.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Romanian Hacker Sentenced for Breaching Oregon Government Network
Impact· MEDIUM

Romanian Hacker Sentenced for Breaching Oregon Government Network

In June 2021, Catalin Dragomir, a Romanian national operating under the alias "inthematrixl," unlawfully accessed the Oregon Department of Emergency Management's network. He extracted personally identifiable information, including names, email addresses, dates of birth, and passport numbers, and sold this data alongside unauthorized network access to potential buyers. Dragomir extended his cybercriminal activities by compromising nearly a dozen other U.S. networks, resulting in cumulative losses exceeding $250,000. Following his arrest in Romania in November 2024 and subsequent extradition to the United States in January 2025, Dragomir pleaded guilty to charges of aggravated identity theft and obtaining information from a protected computer. In May 2026, he was sentenced to 56 months in federal prison and ordered to forfeit approximately 23 Monero (XMR) cryptocurrency, valued at roughly $8,500. This case underscores the persistent threat posed by cybercriminals targeting government infrastructures and the critical need for robust cybersecurity measures to protect sensitive data. The incident also highlights the importance of international cooperation in apprehending and prosecuting cyber offenders.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Carnival Cruise Data Breach 2026: A Wake-Up Call for Cybersecurity
Impact· HIGH

Carnival Cruise Data Breach 2026: A Wake-Up Call for Cybersecurity

In April 2026, Carnival Corporation, the world's largest cruise line operator, experienced a significant data breach affecting nearly 6 million individuals. The breach was initiated through a social engineering attack, where an unauthorized actor deceived an employee to gain access to a limited portion of the company's IT system. The attackers, identified as the ShinyHunters extortion gang, claimed responsibility for the breach, stating they stole documents containing over 8.7 million records with personally identifiable information and terabytes of internal corporate data. The compromised data includes names, dates of birth, email addresses, genders, geographic locations, and loyalty program details. Carnival promptly blocked the unauthorized activity and began working with third-party security experts to strengthen their security measures and conduct a thorough investigation. This incident underscores the persistent threat posed by sophisticated cybercriminal groups like ShinyHunters, who employ advanced social engineering tactics to infiltrate organizations. The breach highlights the critical need for robust cybersecurity protocols, employee training to recognize and resist social engineering attempts, and comprehensive incident response strategies to mitigate the impact of such attacks.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Gogs Zero-Day Vulnerability Exposes Code Repositories to Remote Code Execution
Impact· HIGH

Critical Gogs Zero-Day Vulnerability Exposes Code Repositories to Remote Code Execution

In May 2026, a critical zero-day vulnerability was discovered in Gogs, a self-hosted Git service. This argument injection flaw allows authenticated users to execute arbitrary code on servers running Gogs versions 0.14.2 and 0.15.0+dev. Exploitation involves creating a pull request with a malicious branch name that injects the --exec flag into git rebase during the 'Rebase before merging' operation. This vulnerability enables attackers to compromise the server, access all repositories, extract credentials, and potentially pivot to other systems. The incident underscores the persistent risks associated with self-hosted code repositories, especially those with default configurations that permit open registration. Organizations relying on Gogs should assess their exposure, apply available patches promptly, and consider implementing stricter access controls to mitigate similar threats.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports