✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Packagist Supply Chain Attack Highlights Cross-Ecosystem Vulnerabilities
In May 2026, a coordinated supply chain attack compromised eight packages on Packagist, the PHP package repository. The attackers inserted malicious code into the `package.json` files of these Composer packages, targeting projects that incorporate JavaScript build tools alongside PHP code. This code executed a post-installation script that downloaded and ran a Linux binary from a GitHub repository, potentially allowing unauthorized access and control over affected systems. The malicious packages have since been removed from Packagist. This incident underscores the evolving tactics of threat actors who exploit cross-ecosystem dependencies to infiltrate software supply chains. Developers and organizations must remain vigilant, ensuring comprehensive security reviews of all dependencies, including those that span multiple programming languages and ecosystems.
2 months ago
Kill Chain
Critical Vulnerability in LiteSpeed cPanel Plugin Exploited for Root Access
In May 2026, a critical vulnerability (CVE-2026-48172) was discovered in the LiteSpeed User-End cPanel Plugin versions 2.3 through 2.4.4, allowing attackers to execute arbitrary scripts with root privileges. This flaw, stemming from incorrect privilege assignment in the 'lsws.redisAble' function, has been actively exploited in the wild, posing significant risks to affected systems. LiteSpeed has addressed this issue in version 2.4.5 and recommends immediate updates to mitigate potential threats. ([thehackernews.com](https://thehackernews.com/2026/05/litespeed-cpanel-plugin-cve-2026-48172.html?utm_source=openai)) The exploitation of this vulnerability underscores the persistent threat posed by privilege escalation attacks, emphasizing the need for organizations to maintain rigorous patch management practices. As cyber threats continue to evolve, staying vigilant and promptly addressing known vulnerabilities is crucial to safeguarding system integrity and data security.
2 months ago
Kill Chain
Laravel-Lang PHP Packages Compromised in May 2026 Supply Chain Attack
In May 2026, a significant software supply chain attack targeted multiple PHP packages maintained by the Laravel-Lang organization. The attacker gained unauthorized access to the organization's GitHub repositories and rewrote every existing git tag across several popular Composer packages, including `laravel-lang/lang`, `laravel-lang/http-statuses`, `laravel-lang/attributes`, and `laravel-lang/actions`. This mass retagging introduced malicious code designed to exfiltrate Continuous Integration (CI) secrets to an attacker-controlled domain. The rapid succession of these tag modifications suggests a comprehensive compromise of Laravel-Lang's release process, potentially through stolen organization-level credentials or compromised release infrastructure. ([stepsecurity.io](https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks within the open-source ecosystem. By compromising widely-used packages, attackers can infiltrate numerous downstream projects, leading to widespread security breaches. The Laravel-Lang attack highlights the critical need for robust security measures in software development pipelines, including stringent access controls, regular audits of release processes, and vigilant monitoring for unauthorized changes to code repositories.
2 months ago
Kill Chain
From Edge Appliance to Enterprise Compromise: Analyzing the 2026 Multi-Stage Linux Intrusion
In May 2026, a sophisticated cyber intrusion was identified, where attackers exploited vulnerabilities in F5 BIG-IP Access Policy Manager (APM) and Atlassian Confluence to gain unauthorized access to enterprise networks. The attackers initially compromised an internet-facing F5 BIG-IP appliance, leveraging a critical remote code execution vulnerability (CVE-2025-53521) to establish a foothold. They then moved laterally to an internal Linux host and exploited an unpatched Confluence server, obtaining credentials that facilitated further attacks against Active Directory. This multi-stage attack underscores the evolving threat landscape, where adversaries target edge appliances and internal applications to bypass traditional security controls. Organizations are urged to prioritize patch management, especially for internet-facing devices, and to implement robust monitoring across all network segments to detect and mitigate such complex attack chains.
2 months ago
Kill Chain
FBI Issues Warning on Kali365 Phishing Platform Targeting Microsoft 365 Users
In April 2026, the FBI identified 'Kali365,' a Phishing-as-a-Service (PhaaS) platform that enables cybercriminals to hijack Microsoft 365 access tokens by exploiting OAuth device code authorizations. Distributed primarily via Telegram, Kali365 allows attackers to bypass multi-factor authentication (MFA) without intercepting user credentials. This method grants persistent access to Microsoft 365 services, including Outlook, Teams, and OneDrive, facilitating data theft, fraud, extortion, and potential ransomware attacks. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260521?utm_source=openai)) The emergence of Kali365 underscores a significant shift in phishing tactics, with attackers increasingly leveraging device code phishing to circumvent traditional security measures. This trend highlights the urgent need for organizations to reassess and strengthen their authentication protocols and user education to mitigate evolving threats. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/22/kali365-microsoft-365-phishing-fbi-warning/?utm_source=openai))
2 months ago
Kill Chain
Authorities Arrest KimWolf Botnet Operator in 2026
In May 2026, U.S. and Canadian authorities arrested Jacob Butler, a 23-year-old Canadian national known online as "Dort," for operating the KimWolf botnet. This botnet infected nearly two million devices worldwide, including digital photo frames, web cameras, and Android-based TV boxes. Butler allegedly sold access to this network through a DDoS-for-hire service, facilitating over 25,000 attacks that reached up to 30 terabits per second, causing financial losses exceeding $1 million for some victims. The KimWolf botnet was also linked to attacks targeting Department of Defense Information Network IP addresses. ([justice.gov](https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos?utm_source=openai)) The arrest underscores the escalating threat posed by large-scale botnets exploiting Internet of Things (IoT) devices. The KimWolf botnet's rapid expansion and its use in record-breaking DDoS attacks highlight the need for enhanced security measures and international cooperation to combat cybercrime. ([techradar.com](https://www.techradar.com/pro/security/a-massive-new-ddos-botnet-has-already-snared-1-8-million-devices-heres-what-we-know?utm_source=openai))
2 months ago
Kill Chain
Ubiquiti Patches Critical UniFi OS Vulnerabilities - May 2026
In May 2026, Ubiquiti released patches for three critical vulnerabilities in UniFi OS, identified as CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910. These flaws allowed remote attackers to make unauthorized system changes, access underlying system files, and execute command injection attacks without requiring authentication. The vulnerabilities were reported through Ubiquiti's bug bounty program and could be exploited in low-complexity attacks. At the time of disclosure, nearly 100,000 UniFi OS endpoints were exposed online, with approximately 50,000 located in the United States. This incident underscores the persistent targeting of network infrastructure by cybercriminals and state-sponsored actors. Organizations must prioritize timely patching and robust security measures to mitigate risks associated with such vulnerabilities.
2 months ago
Kill Chain
Former US Executives Admit to Aiding Tech Support Scammers
In May 2026, Adam Young and Harrison Gevirtz, former executives of C.A. Cloud Attribution, Ltd., pleaded guilty to concealing a tech support fraud scheme that operated from early 2017 to April 2022. Their company provided services to clients engaged in telemarketing and tech support scams, which involved deceptive pop-up ads and impersonation of companies like Microsoft and Apple to defraud victims worldwide. Despite knowing their clients' fraudulent activities, Young and Gevirtz failed to report them and instead facilitated their operations by advising on methods to evade detection. This case underscores the critical need for vigilance against tech support scams, which continue to exploit individuals globally. The involvement of corporate executives in such schemes highlights the importance of ethical business practices and the necessity for companies to implement robust compliance measures to prevent complicity in fraudulent activities.
2 months ago
Kill Chain
Dutch Authorities Dismantle Hosting Firm Enabling Cyberattacks
In May 2026, the Dutch Fiscal Information and Investigation Service (FIOD) arrested two individuals and seized 800 servers associated with Stark Industries, a web hosting company implicated in facilitating cyberattacks, interference operations, and disinformation campaigns. The suspects, aged 57 and 39, were linked to providing infrastructure that supported actions undermining democracy and security, including information manipulation and disruption of public and economic systems. Stark Industries, founded in February 2022, was added to the European Union's list of sanctioned entities in May 2025. Following the sanctions, the company's infrastructure was transferred to a newly established Dutch entity, WorkTitans B.V., operating under the brand THE.Hosting, which investigators believe acted as a front for the sanctioned organization. The FIOD's coordinated raids in Dronten, Schiphol-Rijk, Enschede, and Almere resulted in the confiscation of servers, laptops, phones, and administrative records. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/netherlands-seizes-800-servers-of-hosting-firm-enabling-cyberattacks/amp/?utm_source=openai)) This incident underscores the persistent threat posed by cybercriminals leveraging hosting services to conduct malicious activities. The involvement of entities like WorkTitans B.V. highlights the challenges in enforcing sanctions and the need for continuous vigilance against infrastructure providers that may serve as conduits for cyberattacks. Organizations must remain proactive in monitoring and securing their networks against such threats.
2 months ago
Kill Chain
Ghostwriter's Prometheus Phishing Campaign Targets Ukrainian Government
In May 2026, the Belarus-aligned threat actor known as Ghostwriter (also referred to as UAC-0057 and UNC1151) launched a phishing campaign targeting Ukrainian government entities. The attackers utilized compromised accounts to send emails containing PDF attachments that, when interacted with, led to the deployment of a multi-stage malware chain. This chain involved the execution of JavaScript files (OYSTERFRESH and OYSTERSHUCK) designed to install the OYSTERBLUES payload, which harvested system information and facilitated the deployment of Cobalt Strike, a tool commonly used for post-exploitation activities. The campaign exploited lures related to Prometheus, a Ukrainian online learning platform, to enhance the credibility of the phishing emails. ([thehackernews.com](https://thehackernews.com/2026/05/ghostwriter-targets-ukraine-government.html?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors employing sophisticated phishing techniques to infiltrate government networks. The use of legitimate platforms as lures and the deployment of multi-stage malware highlight the evolving tactics of such groups, emphasizing the need for robust cybersecurity measures and user awareness to mitigate these risks.
2 months ago
Kill Chain
Global Takedown of 'First VPN' Disrupts Cybercriminal Operations
In May 2026, an international law enforcement operation led by France and the Netherlands, with support from Europol and Eurojust, dismantled 'First VPN,' a virtual private network service extensively used by cybercriminals to conceal their activities. The operation, known as 'Operation Saffron,' resulted in the seizure of 33 servers across 27 countries and the shutdown of multiple domains associated with the service. Authorities also interviewed a key suspect in Ukraine. 'First VPN' was marketed on Russian-speaking cybercrime forums, offering anonymity and non-cooperation with authorities, making it a favored tool among ransomware groups and other malicious actors. ([europol.europa.eu](https://www.europol.europa.eu/media-press/newsroom/news/cybercriminal-vpn-used-ransomware-actors-dismantled-in-global-crackdown?utm_source=openai)) The takedown of 'First VPN' is significant as it disrupts a critical infrastructure component relied upon by numerous cybercriminals. This action not only exposes the identities of its users but also serves as a deterrent to similar illicit services. The intelligence gathered is expected to aid ongoing investigations and enhance global cybersecurity efforts. ([eurojust.europa.eu](https://www.eurojust.europa.eu/news/eurojust-coordinated-investigation-shuts-down-criminal-vpn-network?utm_source=openai))
2 months ago
Kill Chain
CISA Contractor's GitHub Repository Exposes Sensitive Government Credentials
In May 2026, a contractor for the U.S. Cybersecurity and Infrastructure Security Agency (CISA) inadvertently exposed sensitive credentials by publishing them in a public GitHub repository named 'Private-CISA'. The repository contained plaintext passwords, AWS GovCloud keys, and internal documentation detailing CISA's software deployment processes. This exposure raised significant concerns about operational security and the potential for unauthorized access to critical government systems. ([techradar.com](https://www.techradar.com/pro/security/cisa-contractor-apparently-leaked-highly-sensitive-government-aws-keys-on-github?utm_source=openai)) This incident underscores the critical importance of stringent access controls and the need for robust monitoring of code repositories to prevent accidental exposure of sensitive information. It also highlights the necessity for organizations to implement comprehensive security training for all personnel, including contractors, to mitigate the risk of similar breaches.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports