Validated Containment Architectures are here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2665 threat reports
Page 78 of 223

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 925936 / 2665 reports
UNC6692's 'Snow' Malware: A New Threat via Microsoft Teams
Impact· HIGH

UNC6692's 'Snow' Malware: A New Threat via Microsoft Teams

In April 2026, the threat group UNC6692 executed a sophisticated social engineering attack targeting enterprise networks. The attackers initiated the campaign by overwhelming victims' email inboxes with spam, creating a sense of urgency. Subsequently, they impersonated IT helpdesk staff via Microsoft Teams, convincing users to install a purported spam-blocking patch. This led to the deployment of a custom malware suite named 'Snow,' comprising components like SnowBelt (a malicious browser extension), SnowGlaze (a tunneling tool), and SnowBasin (a backdoor). These tools facilitated deep network penetration, credential theft, and domain takeover, enabling the exfiltration of sensitive data. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/threat-actor-uses-microsoft-teams-to-deploy-new-snow-malware/?utm_source=openai)) This incident underscores the evolving tactics of cyber adversaries who exploit trusted communication platforms and social engineering to bypass traditional security measures. The use of Microsoft Teams as an attack vector highlights the need for heightened vigilance and robust security protocols in enterprise environments to counteract such sophisticated threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Itron Reports Cybersecurity Breach in Internal Systems
Impact· LOW

Itron Reports Cybersecurity Breach in Internal Systems

In April 2026, Itron, Inc., a leading utility technology company, disclosed a cybersecurity incident where an unauthorized third party accessed certain internal systems. Upon detection on April 13, 2026, Itron activated its cybersecurity response plan, engaged external advisors, and notified law enforcement. The company successfully contained the unauthorized activity, with no observed follow-up incidents. Importantly, customer-hosted systems remained unaffected, and business operations continued without material disruption. Itron anticipates that a significant portion of the incident-related costs will be reimbursed by insurance. ([sec.gov](https://www.sec.gov/Archives/edgar/data/780571/000119312526175249/d125229d8k.htm?utm_source=openai)) This incident underscores the persistent threat of cyberattacks targeting critical infrastructure sectors. As utility companies increasingly digitize operations, they become more attractive targets for cyber adversaries. The swift response and containment by Itron highlight the importance of robust cybersecurity measures and incident response plans in mitigating potential impacts on essential services.

3 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Unpatched PhantomRPC Flaw in Windows Enables Privilege Escalation
Impact· MEDIUM

Unpatched PhantomRPC Flaw in Windows Enables Privilege Escalation

In April 2026, Kaspersky researchers disclosed 'PhantomRPC,' an unpatched vulnerability in Windows' Remote Procedure Call (RPC) mechanism. This flaw allows attackers with limited local access to deploy malicious RPC servers that impersonate legitimate Windows services. When higher-privileged processes connect to these rogue servers, attackers can escalate their privileges to SYSTEM or administrator levels. The vulnerability arises from how RPC handles connections to unavailable services, permitting any process to register an RPC server on the same endpoint as a legitimate service that is not running. Despite the severity, Microsoft has classified the issue as 'moderate' and has not issued a patch or CVE identifier. ([darkreading.com](https://www.darkreading.com/vulnerabilities-threats/unpatched-phantomrpc-flaw-windows-privilege-escalation?utm_source=openai)) The disclosure of PhantomRPC underscores the persistent risks associated with architectural vulnerabilities in widely used operating systems. Organizations must proactively implement monitoring and privilege management strategies to mitigate potential exploitation, especially in the absence of official patches.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
GlassWorm v2 Malware Targets VS Code Extensions in Supply Chain Attack
Impact· HIGH

GlassWorm v2 Malware Targets VS Code Extensions in Supply Chain Attack

In April 2026, cybersecurity researchers identified 73 malicious Visual Studio Code (VS Code) extensions on the Open VSX repository, linked to the GlassWorm v2 malware campaign. These extensions, cloned from legitimate ones, initially appeared benign but later delivered malware through updates. Six extensions were confirmed malicious, while others acted as sleeper agents to build trust before deploying harmful payloads. The attackers employed social engineering tactics, such as typosquatting and mimicking legitimate extension icons and descriptions, to deceive developers into installing these compromised extensions. The malware aimed to steal sensitive data, install remote access trojans, and deploy rogue browser extensions to siphon credentials and other information. This incident underscores the evolving nature of supply chain attacks targeting developer environments and the importance of vigilance when installing third-party extensions. The use of sleeper packages and transitive dependencies highlights the need for robust security measures and thorough vetting processes to prevent such infiltrations.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
GlassWorm Malware Resurfaces: 73 OpenVSX Sleeper Extensions Compromise Developer Security
Impact· HIGH

GlassWorm Malware Resurfaces: 73 OpenVSX Sleeper Extensions Compromise Developer Security

In April 2026, the GlassWorm malware campaign resurfaced, targeting the OpenVSX ecosystem with 73 'sleeper' extensions. Initially benign, these extensions were later updated to deliver malicious payloads, compromising developer environments. Six of these extensions have been activated, while the remaining are considered suspicious. This tactic involves cloning legitimate extensions to deceive developers, leading to the theft of sensitive data such as cryptocurrency wallets and credentials. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/glassworm-malware-attacks-return-via-73-openvsx-sleeper-extensions/?utm_source=openai)) This incident underscores the evolving nature of supply chain attacks, highlighting the need for vigilant monitoring of software dependencies. The use of 'sleeper' extensions that activate malicious behavior post-installation represents a sophisticated method to evade initial detection, posing significant risks to software development environments.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Silk Typhoon Hacker Extradited to US for Cyberespionage
Impact· CRITICAL

Silk Typhoon Hacker Extradited to US for Cyberespionage

In April 2026, Chinese national Xu Zewei was extradited from Italy to the United States to face charges of cyberespionage. Allegedly operating under the direction of China's Ministry of State Security (MSS) and affiliated with the Silk Typhoon hacking group, Xu is accused of conducting cyber intrusions between February 2020 and June 2021. These operations targeted COVID-19 research organizations and exploited vulnerabilities in Microsoft Exchange Server to gain unauthorized access, deploy malware, and exfiltrate sensitive data. The widespread exploitation impacted thousands of organizations globally before patches were available. This incident underscores the persistent threat posed by state-sponsored cyber actors targeting critical infrastructure and sensitive information. The extradition of Xu Zewei highlights the international cooperation in addressing cyber threats and the ongoing need for robust cybersecurity measures to protect against sophisticated espionage campaigns.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Supply Chain Attack: 'elementary-data' Package Compromised to Deliver Infostealer
Impact· HIGH

Supply Chain Attack: 'elementary-data' Package Compromised to Deliver Infostealer

In April 2026, the popular Python package 'elementary-data' (version 0.23.3) was compromised through a GitHub Actions script injection vulnerability. Attackers exploited this flaw to execute malicious code, leading to the unauthorized publication of a backdoored package on PyPI and a malicious Docker image. The compromised package, downloaded over 1.1 million times monthly, contained a secrets stealer targeting SSH keys, cloud credentials, and cryptocurrency wallets. Users who installed this version were advised to rotate all exposed credentials and restore their environments from a known safe point. This incident underscores the critical need for secure CI/CD pipelines and vigilant monitoring of open-source dependencies to prevent supply chain attacks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Sentencing in $230M Cryptocurrency Heist Highlights Social Engineering Threats
Impact· HIGH

Sentencing in $230M Cryptocurrency Heist Highlights Social Engineering Threats

In April 2026, Evan Tangeman, a 22-year-old from Newport Beach, California, was sentenced to 70 months in prison for laundering at least $3.5 million in stolen cryptocurrency. This was part of a larger criminal enterprise that, between October 2023 and May 2025, stole over $263 million through social engineering tactics, including impersonating customer support to gain access to victims' cryptocurrency wallets. The stolen funds financed extravagant lifestyles, with expenditures on luxury cars, high-end real estate, and lavish parties. ([justice.gov](https://www.justice.gov/usao-dc/pr/california-money-launderer-sentenced-dc-70-months-role-scheme-stole-263-million?utm_source=openai)) This case underscores the growing sophistication of cybercriminals in exploiting social engineering techniques to execute large-scale financial thefts. It highlights the urgent need for enhanced security measures and user education to prevent such attacks, especially as the cryptocurrency market continues to expand and attract both legitimate investors and malicious actors.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Deepfake Voice Attacks: The Rising Threat in 2025
Impact· HIGH

Deepfake Voice Attacks: The Rising Threat in 2025

In March 2025, a finance director at a multinational firm in Singapore participated in a Zoom call with individuals appearing as her senior leadership team, including the CFO. Unbeknownst to her, all participants were AI-generated deepfakes. She authorized a $499,000 transfer before the fraud was detected. This incident mirrors a 2024 attack on Arup, where $25.6 million was stolen using similar deepfake techniques. The proliferation of deepfake technology has led to a 680% increase in voice deepfake incidents in 2025, with over 100,000 attacks recorded in the United States alone. The accessibility of these tools, which require minimal audio samples and no technical expertise, underscores the urgent need for organizations to implement robust verification protocols and employee training to mitigate such sophisticated social engineering threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Navigate360 P3 Global Intel Data Breach: A Wake-Up Call for Educational Cybersecurity
Impact· HIGH

Navigate360 P3 Global Intel Data Breach: A Wake-Up Call for Educational Cybersecurity

In March 2026, Navigate360's P3 Global Intel platform, an anonymous tip line used by over 30,000 schools and 5,000 public safety agencies, was reportedly breached by a hacker group known as Internet Yiff Machine. The attackers claimed to have exfiltrated approximately 93 gigabytes of data, including over 8 million law enforcement tips containing sensitive personally identifiable information (PII) of students and informants. This incident has raised significant concerns about the platform's security measures and the anonymity it promises to its users. The breach underscores the growing trend of cyberattacks targeting educational institutions, which have become increasingly frequent and sophisticated. The exposure of sensitive student data not only compromises individual privacy but also erodes trust in systems designed to enhance school safety. This incident highlights the urgent need for robust cybersecurity practices and compliance with data protection regulations within the education sector.

3 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
VECT 2.0 Ransomware: A New Threat to Data Integrity
Impact· CRITICAL

VECT 2.0 Ransomware: A New Threat to Data Integrity

In April 2026, the VECT 2.0 ransomware emerged, targeting Windows, Linux, and ESXi systems. Due to a critical flaw in its encryption implementation, files larger than 131KB are irreversibly destroyed, rendering recovery impossible even for the attackers. This flaw effectively transforms VECT 2.0 into a data wiper rather than traditional ransomware. ([gixtools.net](https://gixtools.net/feeds/items/vect-2-0-ransomware-irreversibly-destroys-files-over-131kb-on-windows-linux-esxi/?utm_source=openai)) The incident underscores the evolving nature of cyber threats, where flawed ransomware can lead to permanent data loss. Organizations must prioritize robust backup strategies and incident response plans to mitigate such risks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical Vulnerability in Hugging Face's LeRobot Exposes Systems to Remote Code Execution
Impact· CRITICAL

Critical Vulnerability in Hugging Face's LeRobot Exposes Systems to Remote Code Execution

In April 2026, a critical vulnerability (CVE-2026-25874) was identified in Hugging Face's open-source robotics platform, LeRobot. This flaw, stemming from unsafe deserialization practices using Python's pickle module over unauthenticated gRPC channels, allows unauthenticated attackers to execute arbitrary code on both policy servers and robot clients. Exploitation can lead to full system compromise, data theft, and potential physical safety risks due to the nature of robotic operations. This incident underscores the persistent risks associated with deserializing untrusted data, especially in AI and robotics platforms. It highlights the necessity for secure coding practices, robust authentication mechanisms, and the importance of timely patching to mitigate such vulnerabilities.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports