✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Microsoft Defender Zero-Day Vulnerabilities: CVE-2026-41091 and CVE-2026-45498
In May 2026, Microsoft disclosed two zero-day vulnerabilities in its Defender security platform: CVE-2026-41091 and CVE-2026-45498. CVE-2026-41091 is a privilege escalation flaw in the Microsoft Malware Protection Engine, allowing attackers to gain SYSTEM privileges through improper link resolution. CVE-2026-45498 is a denial-of-service vulnerability in the Microsoft Defender Antimalware Platform, enabling threat actors to disrupt Windows devices. Both vulnerabilities were actively exploited before patches were released. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added these vulnerabilities to its Known Exploited Vulnerabilities Catalog, mandating federal agencies to apply patches by June 3, 2026. This incident underscores the critical need for organizations to maintain up-to-date security measures and promptly address vulnerabilities in widely used security tools.
2 months ago
Kill Chain
Chinese Hackers Deploy New Malware Targeting Telecom Providers
In mid-2022, the Chinese state-sponsored group Calypso, also known as Red Lamassu, initiated a cyber-espionage campaign targeting telecommunications providers across the Asia Pacific and parts of the Middle East. The attackers employed two newly discovered malware strains: Showboat, a modular Linux post-exploitation framework, and JMFBackdoor, a Windows-based espionage implant. Showboat facilitates long-term persistence, data exfiltration, and lateral movement within networks by acting as a SOCKS5 proxy. JMFBackdoor offers capabilities such as remote command execution, file management, and system manipulation. The initial infection vectors remain unknown, but the threat actors utilized telecom-themed domains to impersonate their targets. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/chinese-hackers-target-telcos-with-new-linux-windows-malware/amp/?utm_source=openai)) This incident underscores a growing trend of sophisticated cyber-espionage campaigns targeting critical infrastructure sectors, particularly telecommunications. The use of advanced malware like Showboat and JMFBackdoor highlights the evolving tactics of state-sponsored actors and the necessity for robust cybersecurity measures to protect sensitive information and maintain operational integrity.
2 months ago
Kill Chain
International Operation Dismantles 'First VPN' Used by Cybercriminals
In May 2026, an international law enforcement operation led by France and the Netherlands, with support from Europol and Eurojust, dismantled 'First VPN,' a virtual private network service extensively used by cybercriminals to conceal ransomware attacks, data theft, and other serious offenses. The operation resulted in the seizure of 33 servers across 27 countries, the shutdown of associated domains, and the identification of numerous users. The administrator of the service was interviewed during a house search in Ukraine. 'First VPN' had been promoted on Russian-speaking cybercrime forums as a tool for anonymity, offering services designed specifically for criminal use. ([europol.europa.eu](https://www.europol.europa.eu/media-press/newsroom/news/cybercriminal-vpn-used-ransomware-actors-dismantled-in-global-crackdown?utm_source=openai)) This takedown underscores the increasing effectiveness of international cooperation in combating cybercrime infrastructure. It highlights the critical need for organizations to remain vigilant against services that facilitate illicit activities and to ensure robust cybersecurity measures are in place to protect against such threats.
2 months ago
Kill Chain
Unauthorized Access to Anthropic's Mythos AI Model Highlights Emerging Cybersecurity Risks
In April 2026, Anthropic's advanced AI model, Mythos, designed for identifying and exploiting software vulnerabilities, was accessed by unauthorized users through a third-party vendor. This breach raised significant concerns about the potential misuse of AI in cyberattacks, as Mythos has demonstrated the capability to uncover critical flaws across major operating systems and web browsers. The incident underscores the risks associated with AI-driven vulnerability discovery tools falling into the wrong hands, potentially enabling adversaries to exploit software weaknesses at an unprecedented scale. The unauthorized access to Mythos highlights the urgent need for robust security measures and governance frameworks to prevent the misuse of powerful AI tools in cybersecurity. As AI continues to evolve, organizations must reassess their security postures to address the accelerated pace of vulnerability discovery and exploitation facilitated by such technologies.
2 months ago
Kill Chain
GitHub Breach 2026: Lessons from the TeamPCP VS Code Extension Attack
In May 2026, GitHub experienced a significant security breach when an employee's device was compromised through a malicious Visual Studio Code (VS Code) extension. This attack, attributed to the threat group TeamPCP, led to the exfiltration of approximately 3,800 internal repositories. The attackers advertised the stolen data for sale on a cybercrime forum, seeking at least $50,000. GitHub responded by removing the malicious extension, isolating the affected endpoint, and rotating critical credentials to mitigate further risk. This incident underscores the escalating threat of supply chain attacks targeting development tools and environments. The use of poisoned extensions to infiltrate systems highlights the need for heightened vigilance and robust security measures within the software development lifecycle.
2 months ago
Kill Chain
Chinese APTs Deploy 'Showboat' Linux Backdoor in Central Asia Telco Attacks
In May 2026, Chinese state-aligned Advanced Persistent Threat (APT) groups were discovered using a Linux-based post-exploitation framework named 'Showboat' to infiltrate telecommunications companies in Central Asia. The malware enables attackers to scan and infect devices on local area networks (LANs) that are not connected to the public Internet, facilitating long-term espionage activities. Notably, the APT group Calypso has been identified leveraging Showboat alongside a Windows backdoor called 'JFMBackdoor' to target entities in Afghanistan, Kazakhstan, Turkey, and India. This incident underscores the evolving tactics of Chinese APTs in targeting critical infrastructure sectors, particularly telecommunications, using cross-platform malware to maintain persistent access and conduct intelligence gathering. The discovery of Showboat highlights the need for enhanced cybersecurity measures to detect and mitigate such sophisticated threats.
2 months ago
Kill Chain
GitHub Breach: Lessons in Securing Developer Tools Against Supply Chain Attacks
In May 2026, GitHub experienced a significant security breach when an employee's device was compromised through a malicious version of the Nx Console Visual Studio Code (VS Code) extension. This supply chain attack, orchestrated by the cybercriminal group TeamPCP, led to unauthorized access and exfiltration of approximately 3,800 internal repositories. The attackers exploited the compromised extension to harvest sensitive data, including source code and operational information. GitHub promptly detected the intrusion, removed the malicious extension, isolated the affected endpoint, and initiated an internal investigation to assess the full impact and prevent further unauthorized access. This incident underscores the escalating threat of supply chain attacks targeting developer tools and extensions. The rapid proliferation of such attacks highlights the critical need for organizations to implement stringent security measures, conduct regular audits of third-party tools, and foster a culture of security awareness among developers to mitigate potential vulnerabilities.
2 months ago
Kill Chain
Critical Linux Kernel Vulnerability Discovered After Nine Years
In May 2026, cybersecurity researchers disclosed a nine-year-old vulnerability in the Linux kernel, identified as CVE-2026-46333, also known as 'ssh-keysign-pwn'. This flaw allows unprivileged local users to access sensitive files and execute arbitrary commands with root privileges on default installations of major distributions like Debian, Fedora, and Ubuntu. The vulnerability originates from improper privilege management in the kernel's __ptrace_may_access() function, introduced in November 2016. Exploitation can lead to the disclosure of critical files such as /etc/shadow and SSH host private keys, posing significant security risks. The discovery of this long-standing vulnerability underscores the importance of continuous security assessments and prompt patching in open-source software. With a proof-of-concept exploit publicly available, organizations are urged to apply the latest kernel updates immediately to mitigate potential threats.
2 months ago
Kill Chain
Mini Shai Hulud: @antv npm Supply Chain Attack Exposes CI/CD Credentials
In May 2026, a supply chain attack targeted the @antv npm package ecosystem. A threat actor compromised an @antv maintainer account, publishing malicious versions of popular data-visualization packages. This led to widespread impact, as the malicious code propagated through dependencies like echarts-for-react, affecting CI/CD pipelines and cloud workloads. The payload, a 499 KB obfuscated JavaScript file, executed silently during npm install, aiming to steal credentials from GitHub Actions environments. Key features included multi-platform credential theft, process memory scraping, privilege escalation, dual-channel data exfiltration, and SLSA provenance forgery, indicating a sophisticated focus on CI/CD environments. This incident underscores the escalating threat of supply chain attacks, particularly targeting CI/CD environments. The attack's sophistication, including SLSA provenance forgery, highlights the need for enhanced security measures in software development pipelines to prevent unauthorized access and data breaches.
2 months ago
Kill Chain
Trivy Supply Chain Compromise: A Wake-Up Call for Security Tool Integrity
In March 2026, Aqua Security's open-source vulnerability scanner, Trivy, was compromised in a sophisticated supply chain attack. Threat actors injected credential-stealing malware into Trivy's official releases, affecting the core scanner binary and associated GitHub Actions. This breach enabled attackers to harvest sensitive data from organizations relying on Trivy for security assessments. The campaign, attributed to the group TeamPCP, expanded to other security tools, including Checkmarx KICS and LiteLLM, indicating a targeted approach against security infrastructure. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/03/24/detecting-investigating-defending-against-trivy-supply-chain-compromise/?utm_source=openai)) This incident underscores the escalating trend of supply chain attacks targeting security tools, exploiting the trust placed in them by organizations. The compromise of widely used security applications highlights the need for enhanced vigilance and robust security measures within the software supply chain to prevent similar breaches.
2 months ago
Kill Chain
Showboat Linux Malware Targets Middle East Telecoms in 2026
In mid-2022, a telecommunications provider in the Middle East was targeted by a sophisticated cyber espionage campaign involving a new Linux malware named Showboat. This modular post-exploitation framework is capable of spawning remote shells, transferring files, and functioning as a SOCKS5 proxy. The malware's design allows attackers to establish a persistent foothold within compromised systems, facilitating unauthorized access to internal networks and sensitive data. The campaign has been attributed to China-linked threat actors, with command-and-control infrastructure traced back to Chengdu, Sichuan province. The attackers likely exploited vulnerabilities or default remote access accounts to deploy the malware, underscoring the critical need for robust security measures in telecommunications infrastructure. This incident highlights a concerning trend of state-sponsored cyber espionage targeting critical infrastructure sectors, particularly telecommunications. The use of advanced, stealthy malware like Showboat demonstrates the evolving capabilities of threat actors and the importance of proactive defense strategies. Organizations must prioritize the implementation of comprehensive security protocols, regular system audits, and employee training to mitigate the risks posed by such sophisticated attacks.
2 months ago
Kill Chain
GitHub's 2026 Internal Repositories Breach: A Supply Chain Attack by TeamPCP
In May 2026, GitHub experienced a significant security breach when an employee's device was compromised through a malicious Visual Studio Code extension. This intrusion led to the exfiltration of approximately 3,800 internal repositories containing proprietary source code. The threat actor group known as TeamPCP claimed responsibility for the attack, offering the stolen data for sale on cybercrime forums with a starting price of $50,000. GitHub's investigation confirmed the breach but found no evidence that customer data stored outside its internal repositories was affected. This incident underscores the escalating threat of supply chain attacks targeting development environments. The use of compromised development tools to infiltrate organizations highlights the need for enhanced vigilance and security measures within software supply chains. Organizations must prioritize the integrity of their development tools and implement robust monitoring to detect and prevent such sophisticated attacks.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports