✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Cisco Webex SSO Vulnerability Exposes Users to Impersonation Attacks
In April 2026, Cisco disclosed a critical vulnerability (CVE-2026-20184) in the single sign-on (SSO) integration of its Webex Services platform. This flaw allowed unauthenticated, remote attackers to impersonate any user by exploiting improper certificate validation. Successful exploitation could grant unauthorized access to legitimate Cisco Webex services. Cisco addressed the vulnerability in the Webex service; however, customers using SSO integration were required to upload a new SAML certificate for their identity provider to the Control Hub to prevent service interruptions. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL?utm_source=openai)) This incident underscores the critical importance of robust certificate validation processes in SSO integrations. As organizations increasingly adopt cloud-based collaboration tools, ensuring the security of authentication mechanisms becomes paramount to prevent unauthorized access and potential data breaches.
3 months ago
Kill Chain
ATHR: AI-Powered Vishing Platform Revolutionizes Automated Attacks
In April 2026, cybersecurity researchers identified 'ATHR,' a sophisticated cybercrime platform that automates voice phishing (vishing) attacks using AI-driven voice agents. The platform orchestrates the entire attack chain: sending deceptive emails that prompt victims to call a provided number, which connects them to AI agents impersonating legitimate support staff. These agents guide victims through a simulated security verification process to extract sensitive information, such as six-digit verification codes, enabling unauthorized access to accounts on services like Google, Microsoft, and Coinbase. The emergence of ATHR underscores a significant evolution in social engineering tactics, leveraging AI to enhance the scale and believability of vishing attacks. This development highlights the urgent need for organizations to bolster their defenses against AI-powered social engineering threats, as traditional detection methods may be insufficient against such advanced techniques.
3 months ago
Kill Chain
Marimo 2026: Exploitation of CVE-2026-39987 to Deploy NKAbuse Malware via Hugging Face
In April 2026, attackers exploited a critical vulnerability (CVE-2026-39987) in Marimo, a reactive Python notebook platform, to deploy a new variant of NKAbuse malware. The flaw allowed unauthenticated remote code execution via the /terminal/ws WebSocket endpoint, enabling attackers to gain full shell access and execute arbitrary commands. Within 10 hours of the vulnerability's disclosure, threat actors began exploiting it to deploy malware hosted on Hugging Face Spaces, a platform for sharing AI applications. The attackers created a typosquatted Space named 'vsccode-modetx' to host a dropper script and a malicious binary named 'kagent,' which mimicked legitimate tools to evade detection. The payload, a variant of the NKAbuse malware, utilized the NKN blockchain for command and control communications, allowing remote execution of shell commands on infected systems. This incident underscores the rapid weaponization of newly disclosed vulnerabilities and the increasing targeting of AI and machine learning development environments by sophisticated threat actors. Organizations using Marimo are urged to upgrade to version 0.23.0 or later immediately to mitigate this critical security risk.
3 months ago
Kill Chain
Unpatched 'RedSun' Zero-Day in Microsoft Defender Poses Immediate Threat
In April 2026, security researcher Chaotic Eclipse publicly disclosed a zero-day vulnerability in Microsoft Defender, named 'RedSun.' This flaw allows local attackers to escalate privileges to SYSTEM level by exploiting a logic error in Defender's handling of specific file metadata. The vulnerability affects Windows 10, Windows 11, and Windows Server systems with Defender enabled. The researcher released a proof-of-concept (PoC) exploit on GitHub, demonstrating the ease of exploitation. Microsoft has not yet issued a patch for this vulnerability, leaving systems at risk. The public disclosure of 'RedSun' underscores the critical need for timely vulnerability management and the potential consequences of strained relationships between researchers and vendors. Organizations should monitor for updates and consider implementing additional security measures to mitigate the risk posed by this unpatched flaw.
3 months ago
Kill Chain
PowMix Botnet: A New Threat to Czech Organizations in 2025
In December 2025, Cisco Talos identified a new botnet named PowMix targeting the workforce in the Czech Republic. The attackers distributed malicious documents impersonating legitimate brands and regulatory frameworks to lure victims, particularly those in human resources, legal, and recruitment sectors. PowMix employs randomized command-and-control (C2) beaconing intervals and embeds encrypted heartbeat data into C2 URL paths that mimic legitimate REST API URLs, making detection challenging. Additionally, it can dynamically update its C2 domain within the botnet configuration file. Notably, PowMix shares tactical similarities with the earlier ZipLine campaign, including payload delivery mechanisms and misuse of cloud platforms like Heroku for C2 operations. ([blog.talosintelligence.com](https://blog.talosintelligence.com/powmix-botnet-targets-czech-workforce/?utm_source=openai)) This incident underscores the evolving sophistication of botnets, highlighting the need for organizations to enhance their cybersecurity measures. The use of randomized C2 intervals and legitimate-looking URLs indicates a trend towards more evasive malware, emphasizing the importance of advanced detection techniques and continuous monitoring to mitigate such threats.
3 months ago
Kill Chain
LummaC2 Infostealer's Impact on Latin America in 2025
In 2025, LummaC2, also known as Lumma Stealer, emerged as a significant cybersecurity threat in Latin America and the Caribbean. This malware-as-a-service (MaaS) infostealer targeted various industries by exfiltrating sensitive data from browsers and cryptocurrency wallets. Its distribution methods included phishing, malvertising, and abuse of trusted platforms, making it accessible to threat actors with minimal technical skills. The widespread use of LummaC2 led to substantial data breaches and financial losses across the region. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2025/05/21/lumma-stealer-breaking-down-the-delivery-techniques-and-capabilities-of-a-prolific-infostealer/?utm_source=openai)) The prominence of LummaC2 underscores the evolving cyber threat landscape in Latin America, highlighting the need for enhanced cybersecurity measures. The region's rapid digitalization, coupled with persistent gaps in resources and workforce development, continues to expose it to sophisticated cyber threats. ([publications.iadb.org](https://publications.iadb.org/en/2025-cybersecurity-report-vulnerability-and-maturity-challenges-bridging-gaps-latin-america-and?utm_source=openai))
3 months ago
Kill Chain
JanaWare Ransomware: A Persistent Threat to Turkish Homes and SMBs
Since at least 2020, a localized ransomware campaign has been targeting individuals and small to medium-sized businesses (SMBs) in Turkey. The attackers employ phishing emails containing malicious Java archive files that, when executed, deploy a customized variant of the Adwind Remote Access Trojan (RAT). This malware disables security defenses and delivers a ransomware payload known as 'JanaWare,' which encrypts files and demands ransoms between $200 and $400. ([acronis.com](https://www.acronis.com/en/tru/posts/new-janaware-ransomware-targets-turkey-via-adwind-rat/?utm_source=openai)) The campaign's longevity and focus on smaller targets highlight a growing trend where cybercriminals opt for low-value, high-volume attacks. Such operations often evade detection and persist longer due to the limited cybersecurity resources of SMBs and the underreporting of smaller incidents. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/6-year-ransomware-campaign-turkish-homes-smbs/?utm_source=openai))
3 months ago
Kill Chain
UAC-0247's AGINGFLY Malware Targets Ukrainian Healthcare and Government Sectors
Between March and April 2026, the Ukrainian Computer Emergency Response Team (CERT-UA) identified a surge in cyberattacks targeting healthcare institutions, emergency services, and local government bodies. The threat actor, designated as UAC-0247, employed phishing emails disguised as humanitarian aid offers to deliver malicious LNK files. These files exploited Windows utilities to execute remote code, leading to the deployment of multi-stage loaders and custom malware, notably the AGINGFLY backdoor. AGINGFLY facilitated persistent remote control, enabling attackers to steal credentials from Chromium-based browsers and WhatsApp, and to deploy additional tools like SILENTLOOP and RAVENSHELL for further exploitation. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-agingfly-malware-used-in-attacks-on-ukraine-govt-hospitals/?utm_source=openai)) This campaign underscores a concerning evolution in cyber threats, with attackers leveraging sophisticated social engineering tactics and dynamic malware to infiltrate critical infrastructure. The focus on healthcare and government sectors highlights the urgent need for enhanced cybersecurity measures to protect sensitive data and maintain operational integrity in essential services.
3 months ago
Kill Chain
Critical SSO Vulnerability in Cisco Webex Services Exposes User Impersonation Risk
In April 2026, Cisco disclosed a critical vulnerability (CVE-2026-20184) in its Webex Services, specifically affecting the integration of single sign-on (SSO) with Control Hub. This flaw, due to improper certificate validation, allowed unauthenticated remote attackers to impersonate any user within the service by supplying a crafted token. Exploiting this vulnerability could grant unauthorized access to legitimate Cisco Webex services, posing significant security risks. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL?utm_source=openai)) Cisco has addressed this vulnerability in the Webex service. However, organizations using SSO integration must upload a new identity provider (IdP) SAML certificate to Control Hub to prevent service interruption. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL?utm_source=openai))
3 months ago
Kill Chain
Unveiling the Hidden Threat: Shadow Admins in Active Directory
In April 2026, security researchers highlighted the escalating threat of 'shadow admins' within Active Directory (AD) environments. These are user accounts that, while not members of traditional administrative groups, possess elevated privileges due to misconfigurations or oversight. Such accounts can be exploited by attackers to gain unauthorized access, leading to potential domain-wide compromises. The increasing complexity of IT infrastructures, including cloud integrations and virtualization, has amplified the prevalence and risk associated with shadow admins. The significance of this issue is underscored by the growing trend of attackers leveraging indirect privilege paths to infiltrate systems. Organizations are urged to conduct thorough audits of their AD configurations, implement the principle of least privilege, and employ continuous monitoring to detect and remediate shadow admin accounts promptly.
3 months ago
Kill Chain
Critical Windows Task Host Vulnerability (CVE-2025-60710) Exploited in the Wild
In November 2025, Microsoft disclosed CVE-2025-60710, a privilege escalation vulnerability in the Windows Task Host component affecting Windows 11 and Windows Server 2025. This flaw allows local attackers with basic user permissions to gain SYSTEM privileges through low-complexity attacks, potentially leading to full control over compromised devices. The vulnerability arises from improper link resolution before file access, commonly referred to as 'link following'. On April 13, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-60710 to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. This inclusion underscores the critical need for organizations to apply the available patches promptly to mitigate potential security risks.
3 months ago
Kill Chain
Critical Nginx UI Vulnerability (CVE-2026-33032) Enables Unauthenticated Server Takeover
In March 2026, a critical vulnerability (CVE-2026-33032) was discovered in Nginx UI, a web-based management interface for the Nginx web server. This flaw allowed unauthenticated remote attackers to invoke Model Context Protocol (MCP) tools without credentials, enabling actions such as restarting Nginx, and creating, modifying, or deleting configuration files. The root cause was an unprotected '/mcp_message' endpoint that, due to an empty default IP whitelist treated as 'allow all,' permitted unrestricted access. Exploitation of this vulnerability could lead to complete server takeover, allowing attackers to intercept traffic, harvest credentials, and disrupt services. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-33032?utm_source=openai)) The vulnerability was actively exploited in the wild, with approximately 2,600 publicly exposed instances identified, primarily in China, the United States, Indonesia, Germany, and Hong Kong. ([thehackernews.com](https://thehackernews.com/2026/04/critical-nginx-ui-vulnerability-cve.html?utm_source=openai)) A patch was released in version 2.3.4 on March 15, 2026, addressing the issue by adding the missing authentication check to the '/mcp_message' endpoint. ([securityaffairs.com](https://securityaffairs.com/190841/hacking/cve-2026-33032-severe-nginx-ui-bug-grants-unauthenticated-server-access.html?utm_source=openai))
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports