✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Vercel Security Breach 2026: Context.ai OAuth Compromise
In April 2026, Vercel, a cloud development platform, experienced a security breach originating from a compromised third-party AI tool, Context.ai. An attacker exploited this tool to gain unauthorized access to a Vercel employee's Google Workspace account, subsequently infiltrating Vercel's internal systems. This intrusion led to the exposure of non-sensitive environment variables, including API keys and database credentials. The threat actor, identifying as ShinyHunters, has demanded a $2 million ransom for the stolen data. Vercel has engaged incident response experts, notified law enforcement, and advised affected customers to rotate credentials and audit deployments. The company's open-source projects, such as Next.js and Turbopack, remain unaffected. This incident underscores the critical importance of stringent third-party application security and the potential risks associated with OAuth permissions. Organizations are urged to review and tighten their third-party integrations and access controls to prevent similar supply chain attacks.
3 months ago
Kill Chain
Checkmarx KICS Supply Chain Breach: A 2026 Case Study
In April 2026, Checkmarx's KICS analysis tool suffered a significant supply chain attack. Threat actors compromised Docker images and VS Code extensions associated with KICS, embedding malware designed to harvest sensitive data from developer environments. The malware targeted credentials such as GitHub tokens, cloud service keys, and SSH keys, exfiltrating them to domains mimicking legitimate Checkmarx infrastructure. The breach was active between April 22, 2026, 14:17:59 UTC and April 22, 2026, 15:41:31 UTC, during which malicious artifacts were distributed through official channels. This incident underscores the escalating trend of supply chain attacks targeting development tools, emphasizing the need for enhanced security measures in software distribution pipelines. Organizations must remain vigilant, as such attacks can lead to widespread credential theft and unauthorized access to critical systems.
3 months ago
Kill Chain
Critical Vulnerability in Breeze Cache WordPress Plugin (CVE-2026-3844)
In April 2026, a critical vulnerability (CVE-2026-3844) was discovered in the Breeze Cache WordPress plugin, affecting versions up to 2.4.4. This flaw allows unauthenticated attackers to upload arbitrary files via the 'fetch_gravatar_from_remote' function, potentially leading to remote code execution and full site compromise. The issue is exploitable only when the 'Host Files Locally - Gravatars' feature is enabled, which is disabled by default. Cloudways, the plugin's developer, released version 2.4.5 to address this vulnerability. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hackers-exploit-file-upload-bug-in-breeze-cache-wordpress-plugin/?utm_source=openai)) The active exploitation of this vulnerability underscores the persistent targeting of WordPress plugins by threat actors. Website administrators are urged to promptly update to the latest plugin version or disable the affected feature to mitigate risks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hackers-exploit-file-upload-bug-in-breeze-cache-wordpress-plugin/?utm_source=openai))
3 months ago
Kill Chain
Bitwarden CLI npm Package Compromised in Supply Chain Attack
In April 2026, attackers compromised Bitwarden's CLI by uploading a malicious version (2026.4.0) to npm, available between 5:57 PM and 7:30 PM ET on April 22. The malicious package contained credential-stealing malware that harvested developer secrets, including npm tokens, GitHub authentication tokens, SSH keys, and cloud credentials. The malware exfiltrated this data by creating public GitHub repositories under the victim's account. Bitwarden confirmed the incident, stating that the breach was limited to the npm distribution channel for the CLI and did not affect end-user vault data or production systems. The company revoked compromised access, deprecated the malicious release, and initiated remediation steps immediately. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/bitwarden-cli-npm-package-compromised-to-steal-developer-credentials/?utm_source=openai)) This incident underscores the growing threat of supply chain attacks targeting developer tools and CI/CD pipelines. Organizations must enhance their security measures to protect against such vulnerabilities, as similar attacks have been linked to the threat actor known as TeamPCP, who previously targeted developer packages in other supply chain attacks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/bitwarden-cli-npm-package-compromised-to-steal-developer-credentials/?utm_source=openai))
3 months ago
Kill Chain
GopherWhisper APT Exploits Go-Based Backdoors to Target Mongolian Government
In January 2025, ESET researchers identified a previously undocumented China-aligned advanced persistent threat (APT) group named GopherWhisper targeting Mongolian governmental institutions. The group employs a suite of tools primarily written in Go, including injectors and loaders, to deploy various backdoors such as LaxGopher, RatGopher, and BoxOfFriends. GopherWhisper leverages legitimate services like Discord, Slack, Microsoft 365 Outlook, and file.io for command-and-control (C&C) communications and data exfiltration. The group's activities have been ongoing since at least November 2023, compromising at least 12 systems within a Mongolian government entity. ([globenewswire.com](https://www.globenewswire.com/news-release/2026/04/23/3279634/0/en/ESET-Research-discovers-new-China-aligned-group-GopherWhisper-It-abuses-messaging-services-Discord-Slack-and-Outlook-to-spy.html?utm_source=openai)) This incident underscores the evolving tactics of state-sponsored threat actors who exploit widely used communication platforms to evade detection. The use of Go-based malware highlights a trend towards more versatile and cross-platform attack tools, posing significant challenges for traditional security measures. Organizations must adapt their defenses to address these sophisticated techniques.
3 months ago
Kill Chain
Bitwarden CLI Compromised in Checkmarx Supply Chain Attack
In April 2026, Bitwarden's Command Line Interface (CLI) version 2026.4.0 was compromised through a supply chain attack linked to the Checkmarx campaign. Attackers exploited a GitHub Action within Bitwarden's CI/CD pipeline to inject malicious code into the npm package, specifically targeting the 'bw1.js' file. This code executed during installation, leading to the theft of sensitive information such as GitHub and npm tokens, SSH keys, environment variables, shell history, and cloud credentials. The malicious package was available between 5:57 PM and 7:30 PM ET on April 22, 2026, before being identified and removed. Bitwarden confirmed that no end-user vault data or production systems were compromised. ([community.bitwarden.com](https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting CI/CD pipelines, emphasizing the need for robust security measures in software development processes. Organizations are urged to review and fortify their CI/CD workflows to prevent similar breaches.
3 months ago
Kill Chain
UNC6692's Deceptive Use of Microsoft Teams to Deploy SNOW Malware
In April 2026, the threat group UNC6692 executed a sophisticated social engineering campaign targeting corporate employees via Microsoft Teams. By impersonating IT helpdesk staff, they convinced victims to accept chat invitations, leading to the deployment of a custom malware suite known as SNOW. This malware facilitated unauthorized access, data exfiltration, and potential ransomware deployment, significantly compromising organizational security. This incident underscores a growing trend of attackers exploiting trusted communication platforms like Microsoft Teams to bypass traditional security measures. The use of social engineering combined with custom malware highlights the need for enhanced vigilance and robust security protocols to protect against such evolving threats.
3 months ago
Kill Chain
Chinese APT GopherWhisper Exploits Cloud Services in Mongolian Cyber Espionage
In April 2026, ESET researchers uncovered a Chinese advanced persistent threat (APT) group named GopherWhisper targeting Mongolian government institutions. Active since at least November 2023, GopherWhisper deployed multiple custom backdoors—LaxGopher, CompactGopher, RatGopher, BoxOfFriends, and SSLORDoor—each utilizing different cloud services like Slack, Discord, Microsoft Outlook, and file.io for command-and-control communications and data exfiltration. This campaign compromised at least 12 systems within a Mongolian governmental institution, with indications of broader impact across the region. This incident underscores a growing trend of APT groups leveraging legitimate cloud services to evade detection and maintain persistent access. Organizations must enhance their monitoring of cloud-based communications and implement robust security measures to detect and mitigate such sophisticated threats.
3 months ago
Kill Chain
Anthropic's Claude Code Memory Vulnerability: A Wake-Up Call for AI Security
In March 2026, Cisco researchers identified a critical vulnerability in Anthropic's Claude Code AI coding assistant, where compromised memory files allowed attackers to persistently infect projects and sessions. This flaw enabled the insertion of hard-coded secrets into production code, selection of insecure packages, and propagation of these changes to other development team members. Anthropic has since addressed the issue, but the incident underscores the inherent risks associated with AI memory files and context data. The exploitation of AI memory files highlights a growing trend where attackers target the persistent state of AI systems to manipulate outputs and maintain unauthorized access. This incident serves as a cautionary tale for organizations integrating AI tools, emphasizing the need for robust security measures to protect against such vulnerabilities.
3 months ago
Kill Chain
Zealot AI: A Glimpse into Autonomous Cloud Attacks
In April 2026, Palo Alto Networks' Unit 42 unveiled 'Zealot,' an AI-driven, multi-agent system capable of autonomously executing end-to-end cloud attacks. In a controlled environment, Zealot rapidly identified and exploited vulnerabilities within a misconfigured Google Cloud Platform, achieving data exfiltration in mere minutes. This proof-of-concept underscores the potential for AI to accelerate cyberattacks beyond human response capabilities. The demonstration highlights the urgent need for organizations to enhance their security postures. As AI technologies evolve, they not only offer defensive advantages but also equip adversaries with tools to conduct swift and sophisticated attacks, emphasizing the importance of proactive and automated defense mechanisms.
3 months ago
Kill Chain
Microsoft Releases Emergency Patch for Critical ASP.NET Core Vulnerability CVE-2026-40372
In April 2026, Microsoft identified a critical vulnerability (CVE-2026-40372) in ASP.NET Core's Data Protection API, which could allow unauthenticated attackers to escalate privileges to SYSTEM level by forging authentication cookies. This flaw, present in versions 10.0.0 through 10.0.6, stemmed from improper verification of cryptographic signatures, enabling attackers to bypass authentication mechanisms and gain unauthorized access to sensitive data. Microsoft promptly released an out-of-band update (version 10.0.7) to address this issue and advised users to update their systems immediately. This incident underscores the importance of timely patch management and vigilance in monitoring for security updates. The rapid response by Microsoft highlights the evolving nature of software vulnerabilities and the necessity for organizations to stay informed about potential threats to maintain robust security postures.
3 months ago
Kill Chain
Harvester's Linux GoGra Backdoor Exploits Microsoft Graph API
In April 2026, the state-sponsored Harvester group deployed a Linux variant of its GoGra backdoor, utilizing the Microsoft Graph API and Outlook mailboxes for covert command-and-control communications. This sophisticated malware exploits legitimate Microsoft infrastructure to evade detection, targeting telecommunications, government, and IT organizations in South Asia. The Linux GoGra backdoor shares significant code similarities with its Windows counterpart, indicating a concerted effort by Harvester to expand its cross-platform capabilities. The emergence of this Linux variant underscores a growing trend among threat actors to develop multi-platform malware that leverages trusted cloud services for stealthy operations. Organizations must enhance their monitoring of cloud API interactions and implement robust security measures to detect and mitigate such advanced threats.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports