Validated Containment Architectures are here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2659 threat reports
Page 61 of 222

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 721732 / 2659 reports
mdrfckr Campaign Adopts Updated SSH Client in April 2026 Attacks
Impact· HIGH

mdrfckr Campaign Adopts Updated SSH Client in April 2026 Attacks

Between April 14 and April 21, 2026, a DShield sensor detected 24 unique IP addresses executing the 'mdrfckr' campaign, a known botnet operation active since 2018. The attackers utilized the SSH client banner 'SSH-2.0-libssh_0.11.1' and produced the hassh fingerprint '03a80b21afa810682a776a7d42e5e6fb', indicating an evolution in their tooling. The campaign's tactics, including writing a persistent SSH key and executing reconnaissance commands, remained consistent with previous observations. This incident underscores the adaptability of threat actors in updating their tools while maintaining established attack methodologies. Organizations should enhance their detection capabilities to identify new SSH client fingerprints associated with known malicious campaigns.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
FrostyNeighbor's 2026 Cyberattack on Ukrainian Government: A Detailed Analysis
Impact· HIGH

FrostyNeighbor's 2026 Cyberattack on Ukrainian Government: A Detailed Analysis

In March 2026, the Belarus-aligned cyberespionage group FrostyNeighbor launched a sophisticated spear-phishing campaign targeting Ukrainian governmental organizations. The attackers distributed malicious PDF documents impersonating the Ukrainian telecommunications company Ukrtelecom. These PDFs contained links that, upon clicking, led to a multi-stage infection chain. If the victim's IP address was identified as Ukrainian, the server delivered a malicious RAR archive containing a JavaScript-based downloader known as PicassoLoader. This downloader collected system information and, upon validation, deployed a Cobalt Strike beacon, granting the attackers remote control over the compromised systems. ([welivesecurity.com](https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors in Eastern Europe, highlighting the increasing sophistication of phishing campaigns and the use of geofencing to target specific regions. Organizations must remain vigilant against such targeted attacks, especially those employing multi-stage infection chains and advanced payloads like Cobalt Strike.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(low)
Read Report
Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files
Impact· HIGH

Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files

In May 2026, Palo Alto Networks' Unit 42 identified a new variant of the Gremlin Stealer malware, which has evolved from a basic credential harvester into a sophisticated modular toolkit. This variant employs advanced obfuscation techniques, including concealing malicious payloads within embedded resource files and utilizing instruction virtualization to evade detection. Gremlin Stealer targets sensitive information such as payment card details, browser cookies, session tokens, cryptocurrency wallet data, and FTP and VPN credentials, exfiltrating this data to attacker-controlled servers for potential exploitation. The rapid evolution of Gremlin Stealer underscores a broader trend in the cyber threat landscape, where infostealers are becoming more sophisticated and harder to detect. This development highlights the urgent need for organizations to enhance their cybersecurity measures, particularly in monitoring and defending against advanced malware that employs complex evasion tactics.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Fragnesia (CVE-2026-46300): Critical Linux Kernel Privilege Escalation Vulnerability
Impact· HIGH

Fragnesia (CVE-2026-46300): Critical Linux Kernel Privilege Escalation Vulnerability

In May 2026, a critical vulnerability known as Fragnesia (CVE-2026-46300) was discovered in the Linux kernel's XFRM ESP-in-TCP subsystem. This flaw allows unprivileged local attackers to gain root privileges by writing arbitrary bytes to the kernel page cache of read-only files. Security researcher William Bowling identified this issue and released a proof-of-concept exploit demonstrating its potential impact. The vulnerability affects all Linux kernels released before May 13, 2026, and is part of the broader 'Dirty Frag' class of vulnerabilities. The disclosure of Fragnesia underscores the ongoing challenges in securing the Linux kernel against privilege escalation attacks. With public exploits available and patches being rolled out, organizations must prioritize updating their systems to mitigate potential threats. This incident highlights the importance of proactive vulnerability management and the need for continuous monitoring of emerging security flaws.

2 months ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
NGINX Vulnerability CVE-2026-42945: What You Need to Know
Impact· HIGH

NGINX Vulnerability CVE-2026-42945: What You Need to Know

In May 2026, a critical vulnerability (CVE-2026-42945) was discovered in NGINX's ngx_http_rewrite_module, affecting versions 0.6.27 through 1.30.0. This heap buffer overflow flaw can be exploited by unauthenticated attackers using specially crafted HTTP requests, leading to denial-of-service conditions and, under certain configurations, remote code execution. The issue arises when NGINX configurations utilize both 'rewrite' and 'set' directives, a common pattern in API gateways and reverse proxy setups. The discovery of this 18-year-old vulnerability underscores the importance of regular code audits and timely patching. Given NGINX's widespread use across various industries, organizations are urged to update to the latest versions to mitigate potential risks associated with this flaw.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
KongTuke's Innovative Use of Microsoft Teams to Deploy ModeloRAT Malware
Impact· HIGH

KongTuke's Innovative Use of Microsoft Teams to Deploy ModeloRAT Malware

In April 2026, the threat actor KongTuke initiated a campaign leveraging Microsoft Teams to impersonate internal IT support staff. By contacting employees through external Teams chats, they persuaded victims to execute a malicious PowerShell command, leading to the deployment of ModeloRAT malware. This tactic enabled KongTuke to establish persistent access to corporate networks within minutes, facilitating data exfiltration and potential ransomware attacks. This incident underscores a significant shift in cybercriminal strategies, highlighting the exploitation of trusted communication platforms for social engineering. The rapid execution and effectiveness of this method emphasize the need for organizations to reassess and strengthen their security protocols, particularly concerning collaboration tools.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
TeamPCP Hackers Advertise Mistral AI Code Repositories for Sale
Impact· CRITICAL

TeamPCP Hackers Advertise Mistral AI Code Repositories for Sale

In May 2026, the TeamPCP hacker group infiltrated Mistral AI's codebase management system, exfiltrating nearly 5 gigabytes of internal repositories and source code. This breach was part of the broader 'Mini Shai-Hulud' supply-chain attack, which compromised official packages from TanStack and Mistral AI through stolen CI/CD credentials and legitimate workflows. The attackers are now demanding $25,000 for the stolen data, threatening to leak it publicly if a buyer isn't found within a week. This incident underscores the escalating threat of supply-chain attacks targeting software development processes. Organizations must prioritize securing their CI/CD pipelines and implement robust monitoring to detect unauthorized access promptly.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
May 2026 Cybersecurity Incidents: PAN-OS RCE Exploitation and AI's Role in Vulnerability Detection
Impact· CRITICAL

May 2026 Cybersecurity Incidents: PAN-OS RCE Exploitation and AI's Role in Vulnerability Detection

In May 2026, multiple critical cybersecurity incidents emerged, notably the exploitation of a buffer overflow vulnerability (CVE-2026-0300) in Palo Alto Networks' PAN-OS User-ID Authentication Portal, allowing unauthenticated attackers to execute arbitrary code with root privileges. Additionally, Anthropic's AI model, Mythos, identified a low-severity vulnerability in the widely-used cURL tool, sparking debates about the efficacy of AI in vulnerability detection. These incidents underscore the persistent challenges in securing network infrastructure and the evolving role of AI in cybersecurity. The active exploitation of the PAN-OS vulnerability highlights the urgency for organizations to apply patches promptly and reassess their exposure to untrusted networks. Simultaneously, the discourse surrounding Mythos's findings emphasizes the need for a balanced approach to integrating AI tools in security workflows, ensuring they complement human expertise without overreliance.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Malicious 'node-ipc' Versions Compromise Developer Credentials
Impact· HIGH

Malicious 'node-ipc' Versions Compromise Developer Credentials

On May 14, 2026, malicious versions of the widely used npm package 'node-ipc' were published, specifically versions 9.1.6, 9.2.3, and 12.0.1. These versions contained obfuscated backdoor code designed to steal developer credentials, including cloud service keys, SSH keys, and other sensitive information. The malware executed upon requiring the package, exfiltrating data to an attacker-controlled server. The compromised versions were published by an unauthorized account, indicating a potential maintainer account takeover. ([thehackernews.com](https://thehackernews.com/2026/05/stealer-backdoor-found-in-3-node-ipc.html?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting open-source ecosystems. Developers and organizations must remain vigilant, implementing robust security measures to detect and prevent such compromises. The event highlights the necessity for continuous monitoring and verification of third-party dependencies to safeguard against unauthorized code injections.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Inside the Breach: Unveiling 'The Gentlemen' Ransomware Group's Operations
Impact· MEDIUM

Inside the Breach: Unveiling 'The Gentlemen' Ransomware Group's Operations

In early May 2026, the ransomware group known as 'The Gentlemen' suffered a significant data breach when an anonymous entity compromised their internal backend database. This breach exposed approximately 16GB of internal communications, tools, and operational data, which were subsequently offered for sale on underground forums. The leaked information provided unprecedented insight into the group's organizational structure, revealing a hierarchical system led by an individual known as 'zeta88,' who oversees operations, target selection, and ransom negotiations. The group employs a generous affiliate model, offering a 90/10 payout split, and utilizes a variety of tools and techniques, including AI-assisted coding, to enhance their ransomware development and deployment processes. ([darkreading.com](https://www.darkreading.com/threat-intelligence/gentlemen-raas-gang-data-leak?utm_source=openai)) This incident underscores the evolving landscape of cyber threats, highlighting the increasing sophistication and organizational complexity of ransomware groups. The exposure of 'The Gentlemen's' internal operations offers valuable intelligence for cybersecurity professionals, enabling the development of more effective defense strategies against similar threats. Additionally, the breach serves as a reminder of the potential vulnerabilities within cybercriminal organizations themselves, which can be exploited to disrupt their activities. ([blog.checkpoint.com](https://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk/?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
GemStuffer: A New Frontier in Supply Chain Attacks Exploiting RubyGems
Impact· LOW

GemStuffer: A New Frontier in Supply Chain Attacks Exploiting RubyGems

In May 2026, a campaign named 'GemStuffer' exploited over 150 RubyGems packages to exfiltrate data scraped from UK local government portals. Unlike typical supply chain attacks that aim to distribute malware to developers, this operation utilized the RubyGems registry as a storage and retrieval channel for the exfiltrated data. The attackers published numerous packages containing scripts that collected public data from government websites and then uploaded this data back to RubyGems, effectively using the platform as a 'dead drop' for data storage. This method allowed the threat actors to bypass traditional command-and-control infrastructures, making detection more challenging. ([thecodingzebra.com](https://www.thecodingzebra.com/cybersecurity/gemstuffer-abuses-150-rubygems/?utm_source=openai)) This incident underscores a novel abuse of software package registries, highlighting the need for enhanced monitoring and security measures within these ecosystems. The use of legitimate platforms for data exfiltration represents an evolution in threat actor tactics, emphasizing the importance of vigilance in software supply chain security. ([cyberleveling.com](https://cyberleveling.com/blog/rubygems-gemstuffer-supply-chain-2026?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(low)
Read Report
NGINX Rift: Unveiling the 18-Year-Old CVE-2026-42945 Vulnerability
Impact· HIGH

NGINX Rift: Unveiling the 18-Year-Old CVE-2026-42945 Vulnerability

In May 2026, a critical vulnerability (CVE-2026-42945) was discovered in NGINX's ngx_http_rewrite_module, present since 2008. This heap buffer overflow flaw allows unauthenticated attackers to send crafted HTTP requests, potentially causing worker process crashes or remote code execution, especially on systems with Address Space Layout Randomization (ASLR) disabled. The issue affects NGINX Plus and NGINX Open Source versions up to 1.30.0 and has been patched in subsequent releases. The disclosure of this 18-year-old vulnerability underscores the importance of regular code audits and timely patching. With NGINX's widespread use across the internet, organizations are urged to update their systems promptly to mitigate potential exploitation risks.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports