Validated Containment Architectures are here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

2669 threat reports
Page 89 of 223

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Information Technology/IT Threat Reports

Showing 10571068 / 2669 reports
Rockstar Games' 2026 Data Breach: A Wake-Up Call for Third-Party Security
Impact· MEDIUM

Rockstar Games' 2026 Data Breach: A Wake-Up Call for Third-Party Security

In April 2026, Rockstar Games experienced a data breach orchestrated by the hacker group ShinyHunters. The attackers exploited a vulnerability in Anodot, a third-party analytics platform integrated with Rockstar's Snowflake cloud infrastructure, to steal authentication tokens. This allowed unauthorized access to Rockstar's internal data, leading to a ransom demand with a deadline of April 14, 2026. Rockstar confirmed that only a limited amount of non-material company information was accessed, emphasizing no impact on their operations or players. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/rockstar-games-confirms-it-was-hacked-by-malicious-group-shinyhunters-takes-credit-gives-until-april-14-to-pay-ransom-or-risk-leaking-confidential-data-shinyhunters?utm_source=openai)) This incident underscores the growing trend of cyberattacks targeting third-party service integrations, highlighting the critical need for organizations to assess and secure their entire supply chain. The breach also serves as a reminder of the persistent threats posed by groups like ShinyHunters, known for exploiting indirect access points to infiltrate major corporations. ([techspot.com](https://www.techspot.com/news/112038-rockstar-games-hit-ransom-demand-after-third-party.html?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
JanelaRAT: Emerging Threat to Latin American Financial Institutions
Impact· HIGH

JanelaRAT: Emerging Threat to Latin American Financial Institutions

In June 2023, cybersecurity researchers identified JanelaRAT, a sophisticated banking Trojan targeting financial institutions across Latin America. This malware employs a multi-stage infection chain, beginning with phishing emails that lead victims to download malicious files. Once installed, JanelaRAT utilizes DLL side-loading techniques to evade detection, monitors user activity by capturing window titles, and exfiltrates sensitive financial and cryptocurrency data. Its capabilities include keystroke logging, screenshot capturing, and mouse input tracking, all orchestrated through a dynamic command-and-control infrastructure. The malware's design suggests a focus on stealth and adaptability, posing significant risks to the financial sector in the region. ([securelist.com](https://securelist.com/janelarat-financial-threat-in-latin-america/119332/?utm_source=openai)) The emergence of JanelaRAT underscores a growing trend of targeted cyberattacks against financial institutions in Latin America. Its advanced evasion techniques and continuous evolution highlight the need for enhanced cybersecurity measures and vigilance within the industry to protect sensitive financial data from such sophisticated threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
OpenAI's Response to the 2026 Axios Supply Chain Attack
Impact· LOW

OpenAI's Response to the 2026 Axios Supply Chain Attack

In late March 2026, OpenAI identified a security incident involving a compromised version of the Axios library, a widely used third-party developer tool. On March 31, a GitHub Actions workflow utilized in OpenAI's macOS app-signing process downloaded and executed the malicious Axios version 1.14.1. This workflow had access to critical code-signing certificates used for authenticating OpenAI's macOS applications, including ChatGPT Desktop, Codex App, Codex CLI, and Atlas. Despite the potential risk, OpenAI's investigation concluded that there was no evidence of user data access, system compromise, or software alteration. As a precautionary measure, OpenAI revoked and rotated the affected certificates and required all macOS users to update their applications to the latest versions by May 8, 2026, after which older versions would no longer receive support or function properly. This incident underscores the growing threat of supply chain attacks targeting widely used open-source libraries and developer tools. The compromise of a single library can have cascading effects across numerous organizations, highlighting the need for stringent security practices in software development pipelines. Organizations are urged to implement measures such as pinning dependencies to specific versions, conducting regular security audits, and maintaining robust incident response plans to mitigate such risks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
FBI and Indonesian Police Dismantle W3LL Phishing Network Behind $20M Fraud Attempts
Impact· HIGH

FBI and Indonesian Police Dismantle W3LL Phishing Network Behind $20M Fraud Attempts

In April 2026, the FBI Atlanta Field Office, in collaboration with the Indonesian National Police, dismantled a sophisticated global phishing operation centered around the W3LL phishing kit. This toolkit enabled cybercriminals to create counterfeit login pages, deceiving victims into divulging their credentials. Priced at approximately $500, the kit facilitated the theft of thousands of account credentials and was linked to over $20 million in attempted fraud. Authorities detained the alleged developer, identified as G.L., and seized key domains associated with the operation. The W3LL phishing kit was a comprehensive cybercrime platform that allowed criminals to impersonate legitimate login pages, capturing usernames, passwords, and session data. This capability enabled attackers to bypass multi-factor authentication and maintain unauthorized access to accounts. The operation also included an online marketplace, W3LLSTORE, which facilitated the sale of over 25,000 compromised accounts between 2019 and 2023. Even after W3LLSTORE's shutdown in 2023, the phishing activities continued through encrypted messaging platforms, targeting more than 17,000 victims worldwide between 2023 and 2024.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
JanelaRAT Malware: A Growing Threat to Latin American Banks in 2025
Impact· HIGH

JanelaRAT Malware: A Growing Threat to Latin American Banks in 2025

In 2025, Latin American financial institutions, particularly in Brazil and Mexico, faced a significant surge in cyber threats, notably from the JanelaRAT malware. This sophisticated malware, a modified variant of the BX RAT trojan, was designed to steal financial and cryptocurrency data by capturing window titles, tracking mouse inputs, logging keystrokes, taking screenshots, and collecting system metadata. The attackers employed DLL side-loading techniques to evade detection, leveraging legitimate executables to load the malicious payload. The campaign's focus on Latin American banks underscores the region's growing vulnerability to targeted cyber attacks. ([thehackernews.com](https://thehackernews.com/2023/08/new-financial-malware-janelarat-targets.html?utm_source=openai)) The rise of JanelaRAT coincided with a broader increase in cyber threats across Latin America. Reports indicated a 155% increase in social engineering scams and a 225% rise in malware attacks in 2025. ([biocatch.com](https://www.biocatch.com/press-release/latin-american-banks-see-155-increase-in-scam-attempts?hs_amp=true&utm_source=openai)) This trend highlights the evolving tactics of cybercriminals who are increasingly targeting financial institutions in the region, emphasizing the urgent need for enhanced cybersecurity measures and cross-institution collaboration to mitigate these threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Lumma Stealer Disruption: A Landmark Victory Against Infostealer Malware
Impact· HIGH

Lumma Stealer Disruption: A Landmark Victory Against Infostealer Malware

In May 2025, a coordinated effort by the U.S. Department of Justice and Microsoft led to the disruption of Lumma Stealer, a prolific infostealer malware operating under a malware-as-a-service model since late 2022. Lumma Stealer was responsible for exfiltrating sensitive data, including browser credentials and cryptocurrency wallets, from numerous organizations worldwide. The takedown involved seizing over 2,300 malicious domains and dismantling the malware's command-and-control infrastructure, significantly hindering its operations. ([malwarebytes.com](https://www.malwarebytes.com/blog/news/2025/05/lumma-information-stealer-infrastructure-disrupted?utm_source=openai)) This disruption underscores the growing threat posed by infostealer malware and highlights the importance of collaborative efforts between law enforcement and private sector entities in combating cybercrime. Organizations are urged to enhance their cybersecurity measures to protect against similar threats, as the infostealer landscape continues to evolve with new variants and distribution methods. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2025/05/21/lumma-stealer-breaking-down-the-delivery-techniques-and-capabilities-of-a-prolific-infostealer/?msockid=3d81ed128ed2696826fafba28f5168a7&utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
SentinelOne's AI EDR Thwarts Zero-Day Supply Chain Attack Involving Anthropic's Claude AI
Impact· HIGH

SentinelOne's AI EDR Thwarts Zero-Day Supply Chain Attack Involving Anthropic's Claude AI

In March 2026, SentinelOne's AI-driven Endpoint Detection and Response (EDR) system autonomously identified and halted a zero-day supply chain attack involving a trojanized version of LiteLLM, a widely used proxy for LLM API calls. The compromised package, updated by Anthropic's Claude AI coding assistant without human intervention, attempted to execute malicious Python code across multiple customer environments. SentinelOne's Singularity Platform detected and blocked the payload before execution, preventing data theft, persistence, Kubernetes lateral movement, and encrypted exfiltration within hours of the attack's initiation. This incident underscores the escalating sophistication of supply chain attacks, particularly those exploiting AI-driven development tools. The rapid detection and mitigation by autonomous security systems highlight the necessity for organizations to adopt AI-native defenses capable of operating at machine speed to counteract evolving cyber threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Identity-Based Attacks: The Predominant Cyber Threat in 2026
Impact· CRITICAL

Identity-Based Attacks: The Predominant Cyber Threat in 2026

In 2026, identity-based attacks have emerged as the predominant cyber threat, with 67% of incidents involving compromised credentials, session tokens, or other forms of digital identity. Attackers increasingly exploit legitimate access methods, bypassing traditional security measures to infiltrate systems undetected. This shift underscores the critical need for organizations to enhance identity security protocols and adopt continuous monitoring strategies to detect and mitigate unauthorized access. The rise of identity-driven intrusions is further exacerbated by the integration of AI technologies, which enable adversaries to automate and scale their attacks more effectively. As a result, businesses must prioritize robust identity governance and implement advanced detection mechanisms to safeguard against these evolving threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
APT41's 2026 Cloud Credential Theft: A Wake-Up Call for Cloud Security
Impact· HIGH

APT41's 2026 Cloud Credential Theft: A Wake-Up Call for Cloud Security

In early 2026, the Chinese state-sponsored threat group APT41 launched a sophisticated campaign targeting Linux-based cloud environments across AWS, Google Cloud Platform, Microsoft Azure, and Alibaba Cloud. Utilizing an undetectable ELF backdoor, the group harvested cloud credentials and metadata, enabling unauthorized access and potential data exfiltration. The malware employed typosquatting techniques and covert command-and-control channels over SMTP port 25, effectively evading traditional detection mechanisms. This incident underscores the evolving tactics of APT41, highlighting their focus on cloud infrastructure and the challenges in detecting such advanced persistent threats. Organizations must enhance their cloud security measures, monitor for anomalous activities, and implement robust detection strategies to mitigate similar threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
FreePBX 2026: INJ3CTOR3's EncystPHP Web Shell Exploitation
Impact· HIGH

FreePBX 2026: INJ3CTOR3's EncystPHP Web Shell Exploitation

In early 2026, over 900 Sangoma FreePBX instances were compromised through the exploitation of a post-authentication command injection vulnerability, CVE-2025-64328. This flaw allowed attackers, notably the INJ3CTOR3 group, to deploy the EncystPHP web shell, enabling remote command execution and persistent access. The majority of affected systems were located in the United States, with significant numbers also in Brazil, Canada, Germany, and France. The exploitation led to unauthorized outbound calls and potential lateral movement within networks. This incident underscores the critical importance of promptly applying security patches and restricting administrative access to trusted networks. The widespread nature of these attacks highlights the ongoing threat to VoIP infrastructures and the necessity for organizations to implement robust security measures to protect against such vulnerabilities.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Marimo 2026 Pre-Auth RCE Vulnerability Exploited
Impact· CRITICAL

Marimo 2026 Pre-Auth RCE Vulnerability Exploited

In April 2026, a critical pre-authentication remote code execution (RCE) vulnerability, identified as CVE-2026-39987, was discovered in Marimo, a popular open-source Python notebook platform. This flaw allowed unauthenticated attackers to gain full PTY shell access via the /terminal/ws WebSocket endpoint, enabling arbitrary system command execution. Exploitation was observed within 10 hours of public disclosure, with attackers swiftly leveraging the vulnerability to exfiltrate sensitive information. The issue affected all Marimo versions up to 0.20.4 and was addressed in version 0.23.0. ([thehackernews.com](https://thehackernews.com/2026/04/marimo-rce-flaw-cve-2026-39987.html?utm_source=openai)) The rapid exploitation of CVE-2026-39987 underscores the critical need for immediate patching and vigilant monitoring of open-source tools. This incident highlights the growing trend of attackers targeting vulnerabilities in widely-used development platforms, emphasizing the importance of proactive security measures in software development environments.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CPUID 2026 Supply Chain Attack: A Wake-Up Call for Software Security
Impact· MEDIUM

CPUID 2026 Supply Chain Attack: A Wake-Up Call for Software Security

In April 2026, CPUID's official website was compromised for approximately six hours, leading to the distribution of malware through its popular CPU-Z and HWMonitor tools. Attackers exploited a secondary API to redirect download links to malicious installers, which deployed the STX RAT—a remote access trojan designed to steal browser credentials and other sensitive information. The malware utilized advanced evasion techniques, operating primarily in-memory to bypass standard detection mechanisms. CPUID has since resolved the breach and restored the integrity of its download links. This incident underscores the growing trend of supply chain attacks targeting widely-used software utilities. The reuse of infrastructure from previous campaigns, such as the FileZilla incident in March 2026, highlights the persistent threat posed by sophisticated threat actors. Organizations and individuals are advised to exercise caution when downloading software, even from trusted sources, and to implement robust security measures to detect and prevent such compromises.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports