✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Shai-Hulud 2.0: Unveiling the 2025 npm Supply Chain Attack
In November 2025, the Shai-Hulud 2.0 supply chain attack emerged as a significant threat to the npm ecosystem. Attackers compromised hundreds of npm packages by injecting malicious preinstall scripts that executed before installation completion. These scripts harvested sensitive data, including credentials and configuration secrets, from developer environments and CI/CD pipelines, exfiltrating them to attacker-controlled repositories. The malware exhibited worm-like behavior, autonomously spreading by publishing malicious versions of accessible packages, thereby propagating across the npm ecosystem. Major projects such as Zapier, Ethereum Name Service (ENS), PostHog, and Postman were affected, with over 25,000 repositories compromised within a few hours. ([blog.checkpoint.com](https://blog.checkpoint.com/research/shai-hulud-2-0-inside-the-second-coming-the-most-aggressive-npm-supply-chain-attack-of-2025/?utm_source=openai)) This incident underscores the escalating sophistication of supply chain attacks targeting open-source ecosystems. The rapid propagation and automation observed in Shai-Hulud 2.0 highlight the urgent need for enhanced security measures in software development pipelines. Organizations must prioritize securing their development environments, implement robust monitoring, and adopt best practices to mitigate the risks associated with such pervasive threats.
2 months ago
Kill Chain
CERT-In's 12-Hour Patching Mandate: A Response to AI-Driven Cyber Threats
In May 2026, the Indian Computer Emergency Response Team (CERT-In) issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of identification. This directive aims to mitigate threats from adversaries leveraging artificial intelligence (AI) tools and large language models (LLMs) to automate vulnerability discovery and exploitation, thereby accelerating the scale and speed of cyber attacks. CERT-In emphasized that AI-assisted cyber exploitation reduces the time required for adversaries to identify, weaponize, and exploit vulnerabilities, exposed services, weak identities, insecure APIs, and misconfigured systems. As organizations become increasingly dependent on interconnected digital infrastructure, cloud ecosystems, software supply chains, operational technologies, and AI-enabled platforms, the potential impact of AI-enabled cyber threats continues to increase across sectors. ([thehackernews.com](https://thehackernews.com/2026/05/cert-in-mandates-12-hour-patching-for.html?utm_source=openai)) This development underscores the evolving cyber threat landscape, where AI technologies are being harnessed to compress attack timelines and bypass traditional security controls. Organizations are urged to adopt proactive cybersecurity measures, including continuous threat assessment, proactive exposure reduction, and operational preparedness, to effectively counter these AI-assisted threats.
2 months ago
Kill Chain
Understanding and Mitigating MFA Prompt Bombing Attacks in 2026
In May 2026, a significant cybersecurity threat emerged involving Multi-Factor Authentication (MFA) prompt bombing attacks. Cybercriminals exploited push-based MFA systems by repeatedly sending authentication requests to users, aiming to induce fatigue and prompt them to approve unauthorized access. This method effectively bypassed traditional MFA protections, leading to unauthorized access to sensitive systems and data. The attacks primarily targeted organizations utilizing push-based MFA for services like Microsoft 365, VPNs, and other cloud applications, resulting in compromised accounts and potential data breaches. The prevalence of MFA prompt bombing underscores the evolving tactics of threat actors who leverage social engineering to circumvent security measures. This trend highlights the necessity for organizations to adopt more resilient authentication methods, such as number-matching codes or hardware tokens, and to implement comprehensive user education programs to recognize and resist such attacks.
2 months ago
Kill Chain
Cybercriminals Exploit Claude AI Popularity to Distribute Malware
In early 2026, cybercriminals launched a sophisticated campaign targeting users seeking to download Anthropic's Claude AI tool. By creating fraudulent websites that closely mimicked the official Claude download pages, attackers distributed trojanized installers. These malicious installers appeared legitimate but secretly deployed malware, such as PlugX and ACR Stealer, granting attackers remote access to victims' systems and enabling the theft of sensitive information, including credentials and financial data. The campaign exploited users' trust in search engine results and official-looking websites, leading to widespread infections across both Windows and macOS platforms. This incident underscores a growing trend where threat actors leverage the popularity of AI tools to execute social engineering attacks. The use of fake installation guides and malicious advertisements highlights the need for heightened vigilance among users and organizations. As AI tools become more integrated into daily operations, ensuring the authenticity of download sources and implementing robust cybersecurity measures are imperative to prevent similar attacks.
2 months ago
Kill Chain
FBI Issues Warning on Kali365 Phishing Service Exploiting Microsoft 365 Accounts
In April 2026, the FBI identified 'Kali365,' a Phishing-as-a-Service (PhaaS) platform distributed via Telegram, enabling cybercriminals to hijack Microsoft 365 accounts. By exploiting Microsoft's OAuth 2.0 Device Authorization grant flow, attackers trick users into entering device codes on legitimate Microsoft pages, granting unauthorized access to services like Outlook, Teams, and OneDrive. This method bypasses multi-factor authentication (MFA) and does not require stealing user credentials. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/fbi-warns-of-kali365-phishing-service-targeting-microsoft-365-accounts/?utm_source=openai)) The emergence of Kali365 underscores a significant shift in cyber threats, where sophisticated phishing tools are now accessible to less-skilled attackers. This trend highlights the urgent need for organizations to reassess and strengthen their authentication protocols and user education to mitigate evolving phishing tactics. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260521?utm_source=openai))
2 months ago
Kill Chain
Dutch Authorities Dismantle Cyberattack Infrastructure Linked to Russian Operations
In May 2026, Dutch authorities arrested two individuals, aged 57 and 39, for allegedly providing IT infrastructure used by Russian entities to conduct cyberattacks and disinformation campaigns within the European Union. The arrests followed investigations into Stark Industries Solutions, a hosting provider sanctioned by the EU in 2025 for facilitating Russian cyber operations. The suspects, associated with MIRhosting and WorkTitans BV, were charged with violating sanctions laws by making economic resources available to sanctioned entities. During the operation, over 800 servers were seized from data centers in Dronten and Schiphol-Rijk. ([krebsonsecurity.com](https://krebsonsecurity.com/2026/05/netherlands-seizes-800-servers-arrests-2-for-aiding-cyberattacks/?utm_source=openai)) This incident underscores the persistent challenges in enforcing sanctions against entities that support state-sponsored cyber activities. Despite previous sanctions, the rebranding and asset transfers by Stark Industries highlight the adaptability of such organizations in evading regulatory measures. The case emphasizes the need for continuous monitoring and robust enforcement mechanisms to prevent the circumvention of international sanctions.
2 months ago
Kill Chain
TrapDoor Supply Chain Attack Compromises npm, PyPI, and Crates.io Ecosystems
In May 2026, a coordinated supply chain attack named 'TrapDoor' targeted the npm, PyPI, and Crates.io ecosystems, distributing credential-stealing malware through over 34 malicious packages across more than 384 versions. The campaign began on May 22, 2026, with attackers publishing these packages in rapid succession. The malware specifically aimed at developers in the cryptocurrency, DeFi, Solana, and AI sectors, seeking to exfiltrate sensitive information such as crypto wallets, SSH keys, cloud credentials, browser data, and environment variables. The attack employed various methods, including postinstall hooks, remote JavaScript payloads executed during package imports, and malicious build.rs scripts, to infiltrate developer environments and establish persistence. ([thehackernews.com](https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks within open-source ecosystems, highlighting the need for enhanced vigilance and security measures among developers and organizations. The sophisticated techniques used in the TrapDoor campaign reflect a broader trend of attackers exploiting trusted software repositories to distribute malware, emphasizing the importance of robust supply chain security practices.
2 months ago
Kill Chain
TeamPCP's Supply Chain Attack: A Wake-Up Call for Software Security
In May 2026, the cybercriminal group TeamPCP executed a sophisticated supply chain attack targeting multiple software ecosystems. The campaign involved compromising the Nx Console VS Code extension, leading to the exfiltration of approximately 3,800 internal GitHub repositories. Additionally, TeamPCP trojanized Microsoft's durabletask Python SDK on PyPI and injected malicious code into 639 versions of 323 npm packages within the @antv ecosystem. These attacks resulted in significant credential theft and potential data loss across affected organizations. This incident underscores the escalating threat posed by supply chain attacks, particularly those targeting widely used development tools and libraries. The rapid succession and scale of these compromises highlight the need for enhanced vigilance and security measures within software development and deployment pipelines.
2 months ago
Kill Chain
Ghost CMS Vulnerability Exploited in Widespread ClickFix Campaign
In May 2026, a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS versions 3.24.0 through 6.19.0 was exploited in a large-scale campaign known as ClickFix. Threat actors leveraged this flaw to gain unauthorized access to over 700 domains, including prominent institutions like Harvard University, Oxford University, and DuckDuckGo. By extracting admin API keys, attackers injected malicious JavaScript into website articles, leading to further exploitation and potential data exfiltration. This incident underscores the persistent threat posed by unpatched vulnerabilities in widely used content management systems. The exploitation of CVE-2026-26980 highlights the importance of timely software updates and robust security practices to prevent unauthorized access and maintain the integrity of web platforms.
2 months ago
Kill Chain
ShinyHunters Ransomware Attack on Charter Communications - May 2026
In May 2026, the cybercriminal group ShinyHunters executed a ransomware attack against Charter Communications, Inc., a major U.S. telecommunications and cable company known for its Spectrum services. The attack involved unauthorized access to Charter's systems, leading to the encryption of critical data and disruption of services. ShinyHunters demanded a ransom for the decryption keys, threatening to leak sensitive customer and corporate information if their demands were not met. The breach was publicly disclosed on May 23, 2026, highlighting significant vulnerabilities in Charter's cybersecurity defenses. This incident underscores the escalating threat posed by sophisticated ransomware groups like ShinyHunters, who have been increasingly targeting large corporations across various sectors. The attack on Charter Communications serves as a stark reminder of the importance of robust cybersecurity measures and the need for organizations to proactively defend against evolving cyber threats.
2 months ago
Kill Chain
Laravel Lang Supply Chain Attack: A Wake-Up Call for Open-Source Security
In May 2026, attackers compromised the Laravel Lang GitHub organization by rewriting existing git tags across multiple repositories, including laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. This manipulation redirected developers to malicious commits in attacker-controlled forks, leading to the installation of credential-stealing malware via Composer. The malware targeted sensitive information such as cloud credentials, SSH keys, and browser data, posing significant risks to developers and organizations relying on these packages. This incident underscores the evolving nature of supply chain attacks, highlighting the need for enhanced security measures in software development pipelines. The exploitation of GitHub's tagging system to distribute malware emphasizes the importance of verifying package integrity and monitoring for unusual repository activities to prevent similar breaches.
2 months ago
Kill Chain
Packagist Supply Chain Attack Highlights Cross-Ecosystem Vulnerabilities
In May 2026, a coordinated supply chain attack compromised eight packages on Packagist, the PHP package repository. The attackers inserted malicious code into the `package.json` files of these Composer packages, targeting projects that incorporate JavaScript build tools alongside PHP code. This code executed a post-installation script that downloaded and ran a Linux binary from a GitHub repository, potentially allowing unauthorized access and control over affected systems. The malicious packages have since been removed from Packagist. This incident underscores the evolving tactics of threat actors who exploit cross-ecosystem dependencies to infiltrate software supply chains. Developers and organizations must remain vigilant, ensuring comprehensive security reviews of all dependencies, including those that span multiple programming languages and ecosystems.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports