✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Fake Ledger Live App on Apple App Store Leads to $9.5M Crypto Theft
In April 2026, a counterfeit version of the Ledger Live app was discovered on Apple's Mac App Store, leading to the theft of approximately $9.5 million in cryptocurrency from over 50 users. The malicious app, submitted under the developer name 'Leva Heal Limited,' deceived users into entering their seed phrases, granting attackers full access to their wallets. The stolen funds were laundered through more than 150 deposit addresses on KuCoin, linked to a centralized mixing service called 'AudiA6.' Apple has since removed the fraudulent app from the App Store. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/fake-ledger-live-app-on-apples-app-store-stole-95m-in-crypto/?utm_source=openai)) This incident underscores the persistent threat of sophisticated phishing attacks targeting cryptocurrency users. It highlights the critical need for vigilance when downloading financial applications, even from official app stores, and the importance of never sharing seed phrases or recovery keys.
3 months ago
Kill Chain
Kraken Faces Insider Threat and Extortion Attempt in 2026
In April 2026, Kraken, a leading cryptocurrency exchange, disclosed two incidents where support staff improperly accessed internal systems, exposing limited client support data. Approximately 2,000 accounts, representing 0.02% of Kraken's user base, were affected. Following these incidents, a criminal group attempted to extort Kraken by threatening to release videos showcasing the internal systems with client data. Kraken confirmed that no core systems were breached, client funds remained secure, and the company refused to comply with the extortion demands. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/crypto-exchange-kraken-extorted-by-hackers-after-insider-breach/?utm_source=openai)) This incident underscores the persistent threat of insider access within organizations, particularly in the cryptocurrency sector. It highlights the importance of robust internal controls, employee monitoring, and rapid response mechanisms to mitigate insider threats and protect sensitive client information.
3 months ago
Kill Chain
Microsoft Bolsters RDP Security to Thwart Phishing Threats
In April 2026, Microsoft released security updates for Windows 10 and Windows 11 to enhance protections against phishing attacks exploiting Remote Desktop Protocol (RDP) files. These updates introduce new security warnings and disable risky shared resources by default when opening RDP files, aiming to prevent unauthorized access and data theft facilitated through malicious RDP configurations. ([learn.microsoft.com](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/understanding-security-warnings?utm_source=openai)) This initiative addresses the increasing abuse of RDP files in phishing campaigns, where attackers use them to gain control over victims' systems and access sensitive information. By implementing these protections, Microsoft aims to mitigate the risks associated with such attacks and enhance overall system security. ([learn.microsoft.com](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/understanding-security-warnings?utm_source=openai))
3 months ago
Kill Chain
Anthropic's Claude Mythos AI: A Game-Changer in Cybersecurity
In April 2026, Anthropic unveiled its advanced AI model, Claude Mythos, capable of autonomously identifying and exploiting thousands of zero-day vulnerabilities across major operating systems and web browsers. This unprecedented capability led Anthropic to restrict public access to Mythos, collaborating instead with select organizations under Project Glasswing to address these vulnerabilities responsibly. The model's proficiency in discovering long-standing flaws, including a 27-year-old bug in OpenBSD, underscores the transformative impact of AI in cybersecurity. The emergence of AI models like Claude Mythos signifies a paradigm shift in vulnerability management, compressing the timeline from discovery to exploitation. This development necessitates immediate adaptation by security teams to enhance their defensive strategies and operational models to keep pace with rapidly evolving AI-driven threats.
3 months ago
Kill Chain
CISA Highlights Active Exploitation of Vulnerabilities in Fortinet, Microsoft, and Adobe Products
On April 13, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. These vulnerabilities affect Fortinet FortiClient EMS, Adobe Acrobat Reader, Microsoft Windows Common Log File System Driver, Microsoft Exchange Server, Host Process for Windows Tasks, and Microsoft Visual Basic for Applications. Notably, CVE-2026-21643, an SQL injection vulnerability in Fortinet FortiClient EMS, has been actively exploited since March 24, 2026. Additionally, Microsoft reports that threat actor Storm-1175 has been leveraging CVE-2023-21529 in Exchange Server to deliver Medusa ransomware. ([thehackernews.com](https://thehackernews.com/2026/04/cisa-adds-6-known-exploited-flaws-in.html?utm_source=openai)) The inclusion of these vulnerabilities underscores the persistent threat posed by both newly discovered and older security flaws. Organizations are urged to prioritize patching these vulnerabilities to mitigate potential risks, as unpatched systems remain prime targets for cyber adversaries. ([bytevanguard.com](https://bytevanguard.com/2026/04/14/cisa-kev-update-from-a-2012-bug-to-2026-flaws/?utm_source=openai))
3 months ago
Kill Chain
ShowDoc 2025 Remote Code Execution Vulnerability
In April 2025, a critical vulnerability (CVE-2025-0520) was identified in ShowDoc, a widely used documentation management tool. This flaw, present in versions prior to 2.8.7, allowed attackers to upload and execute arbitrary PHP files due to improper validation of file extensions, leading to remote code execution. Despite the release of a patch in October 2020, many instances remained unpatched, resulting in active exploitation by threat actors. ([thehackernews.com](https://thehackernews.com/2026/04/showdoc-rce-flaw-cve-2025-0520-actively.html?utm_source=openai)) The exploitation of this vulnerability underscores the persistent risk posed by unpatched software. Organizations are urged to promptly apply security updates to mitigate such threats and protect sensitive data from unauthorized access.
3 months ago
Kill Chain
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
On April 13, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) expanded its Known Exploited Vulnerabilities (KEV) Catalog by adding seven new vulnerabilities, including issues in Microsoft Visual Basic for Applications, Adobe Acrobat, Microsoft Exchange Server, and Fortinet products. These vulnerabilities have been actively exploited by malicious actors, posing significant risks to federal enterprises. CISA's Binding Operational Directive (BOD) 22-01 mandates that Federal Civilian Executive Branch (FCEB) agencies remediate these vulnerabilities by specified deadlines to protect against active threats. Although BOD 22-01 applies specifically to FCEB agencies, CISA strongly urges all organizations to prioritize timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practices. This proactive approach is essential to reduce exposure to cyberattacks and safeguard organizational networks against known exploited vulnerabilities.
3 months ago
Kill Chain
Oracle WebLogic Server 2026 Authentication Bypass Vulnerability: What You Need to Know
In January 2026, a critical vulnerability (CVE-2026-21962) was identified in Oracle's WebLogic Server Proxy Plug-in, affecting versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. This flaw allows unauthenticated attackers with network access via HTTP to bypass authentication mechanisms, potentially leading to unauthorized access and modification of critical data. The vulnerability has a CVSS score of 10.0, indicating its severity and the urgency for remediation. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-21962?utm_source=openai)) The exploitation of this vulnerability underscores the increasing sophistication of cyber threats targeting middleware components. Organizations relying on Oracle's WebLogic Server are urged to apply the latest patches promptly to mitigate potential risks associated with this authentication bypass flaw.
3 months ago
Kill Chain
AI-Driven Cybercrime Surge in 2026: A New Era of Threats
In 2026, the cybersecurity landscape witnessed a significant transformation with the emergence of AI-driven cybercrime. Threat actors leveraged artificial intelligence to automate and scale their attacks, resulting in a 1,500% surge in AI-enabled cyber incidents. These sophisticated attacks encompassed credential theft, ransomware, and identity-based intrusions, causing substantial harm to individuals and organizations worldwide. The rapid adoption of AI by cybercriminals enabled them to exploit vulnerabilities at unprecedented speeds, often within hours of disclosure, and to conduct large-scale, coordinated attacks with minimal human intervention. ([oecd.ai](https://oecd.ai/en/incidents/2026-03-11-3607?utm_source=openai)) This escalation underscores the urgent need for organizations to reassess their cybersecurity strategies. Traditional defense mechanisms are increasingly inadequate against AI-enhanced threats. The convergence of AI, automation, and cybercrime necessitates a proactive approach, emphasizing real-time threat intelligence, advanced detection systems, and robust incident response capabilities to mitigate the evolving risks posed by AI-driven cyberattacks. ([techradar.com](https://www.techradar.com/pro/security/in-2026-cybercrime-has-reached-a-point-of-total-convergence-new-research-claims-ai-attacks-are-taking-over-so-how-can-your-business-stay-safe?utm_source=openai))
3 months ago
Kill Chain
Storm Infostealer 2026: A New Era of Cyber Threats
In early 2026, a new infostealer malware named 'Storm' emerged, enabling attackers to bypass traditional security measures by exfiltrating encrypted browser data to remote servers for decryption. This method allows the malware to harvest sensitive information such as saved passwords, session cookies, and cryptocurrency wallets without triggering endpoint security alerts. Storm's capabilities extend to automating session hijacking, granting attackers authenticated access to various platforms without the need for passwords or multi-factor authentication. The malware is offered as a subscription service, with packages starting at $300 for a 7-day demo and up to $1,800 for a full team license supporting 100 operators. Notably, data exfiltration continues even after subscriptions expire. The emergence of such turnkey hacking tools underscores the growing accessibility of sophisticated cyberattacks, posing serious risks to organizations relying solely on basic endpoint protections. Advanced behavioral and network analytics are essential for detecting such threats.
3 months ago
Kill Chain
OpenAI's 2026 Supply Chain Attack: Lessons in Software Security
In March 2026, OpenAI's macOS code-signing workflow was compromised due to a supply chain attack involving the widely used JavaScript library, Axios. The attackers, identified as the North Korean threat group UNC1069, gained access to the Axios maintainer's account and published malicious versions of the package. These versions were inadvertently incorporated into OpenAI's GitHub Actions workflow, potentially exposing code-signing certificates used for macOS applications such as ChatGPT Desktop, Codex, Codex CLI, and Atlas. Although OpenAI's investigation found no evidence of certificate misuse or compromise of user data, the company proactively revoked and rotated the affected certificates to mitigate any potential risks. This incident underscores the escalating threat of supply chain attacks targeting widely used open-source libraries. Organizations must remain vigilant, as such attacks can infiltrate even well-secured development pipelines, leading to potential downstream compromises. The involvement of state-sponsored actors like UNC1069 highlights the need for enhanced security measures and continuous monitoring of software dependencies to protect against sophisticated cyber threats.
3 months ago
Kill Chain
Booking.com Data Breach 2026: What You Need to Know
In April 2026, Booking.com, a leading online travel platform, experienced a data breach where unauthorized third parties accessed customers' reservation information. The compromised data included full names, email addresses, postal addresses, phone numbers, and communications shared with property providers. Upon detection, Booking.com promptly reset reservation PINs and notified affected users via email, advising them to remain vigilant against potential phishing attempts. ([techcrunch.com](https://techcrunch.com/2026/04/13/booking-com-confirms-hackers-accessed-customers-data/?utm_source=openai)) This incident underscores the persistent threat of cyberattacks targeting the travel and hospitality industry, emphasizing the need for robust data protection measures. As cybercriminals increasingly exploit personal data for fraudulent activities, organizations must enhance their security protocols to safeguard customer information.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports