✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Hims & Hers Data Breach: A Wake-Up Call for Third-Party Service Security
In early February 2026, telehealth company Hims & Hers experienced a data breach when unauthorized actors accessed its third-party customer service platform between February 4 and February 7. The attackers obtained customer support tickets containing personal information, including names and contact details. The company detected the intrusion on February 5 and promptly secured the affected system. While medical records and provider communications remained unaffected, the breach exposed sensitive customer data. ([techcrunch.com](https://techcrunch.com/2026/04/02/telehealth-giant-hims-hers-says-its-customer-support-system-was-hacked/?utm_source=openai)) This incident underscores the growing trend of cyberattacks targeting third-party service providers, exploiting their access to sensitive data. Organizations must reassess and strengthen their vendor risk management and cybersecurity measures to prevent similar breaches.
3 months ago
Kill Chain
Understanding the 2026 Surge in AI-Driven Credential Theft
In 2026, the cybersecurity landscape witnessed a significant surge in AI-driven credential theft, with attackers leveraging artificial intelligence to automate and scale their operations. This escalation led to a 160% increase in credential-based attacks, resulting in the theft of 1.8 billion login credentials from 5.8 million compromised endpoints. The use of AI enabled threat actors to conduct sophisticated phishing campaigns, exploit vulnerabilities rapidly, and bypass traditional security measures, posing substantial risks to organizations worldwide. The current relevance of this incident is underscored by the continued evolution of AI technologies, which have lowered the barrier to entry for cybercriminals and increased the speed and efficiency of attacks. Organizations must adapt their security strategies to address these advanced threats, emphasizing continuous identity assessment, behavioral anomaly detection, and the implementation of phishing-resistant authentication methods to mitigate the risks associated with AI-driven credential theft.
3 months ago
Kill Chain
CPUID's 2026 Supply Chain Breach: A Wake-Up Call for Software Security
In April 2026, CPUID's website was compromised through a secondary API, leading to the distribution of trojanized versions of CPU-Z and HWMonitor. For approximately six hours between April 9 and April 10, attackers altered download links to serve malicious executables, exposing millions of users to potential malware infections. The malicious files, notably named HWiNFO_Monitor_Setup.exe, utilized advanced evasion techniques, including multi-stage, in-memory execution and NTDLL proxying from a .NET assembly, to bypass detection by endpoint detection and response (EDR) systems and antivirus software. CPUID has since identified and rectified the breach, confirming that their original signed binaries remained uncompromised. This incident underscores the escalating threat of supply chain attacks targeting widely used utilities. The attackers' sophisticated methods highlight the need for enhanced vigilance and robust security measures in software distribution channels. Organizations must prioritize the integrity of their software supply chains to prevent similar breaches and protect end-users from malicious software distribution.
3 months ago
Kill Chain
Qualys 2026 Report Highlights Urgent Need for Automated Vulnerability Management
In March 2026, Qualys released a comprehensive analysis of over one billion remediation records from the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, spanning 10,000 organizations over four years. The study revealed that despite a 6.5-fold increase in remediation efforts since 2022, 63% of critical vulnerabilities remained unpatched after seven days, up from 56% in previous years. Alarmingly, 88% of 52 high-profile weaponized vulnerabilities were patched slower than they were exploited, with half being weaponized before any patch was available. This indicates a systemic failure in current vulnerability management practices to keep pace with the rapid exploitation timelines of threat actors. The findings underscore the urgent need for organizations to adopt autonomous, closed-loop risk operations to effectively mitigate vulnerabilities in real-time. The traditional manual remediation processes are proving inadequate against the accelerating threat landscape, necessitating a paradigm shift towards automated and proactive security measures.
3 months ago
Kill Chain
GlassWorm Campaign 2026: Unveiling the Zig Dropper Threat to Developer IDEs
In April 2026, the GlassWorm campaign introduced a new attack vector targeting developers by distributing a malicious Visual Studio Code (VS Code) extension named "specstudio.code-wakatime-activity-tracker." This extension, masquerading as the legitimate WakaTime tool, included a Zig-compiled native binary designed to stealthily infect all integrated development environments (IDEs) on a developer's machine. Once installed, the binary identified and compromised various IDEs, including VS Code, VSCodium, Positron, and AI-powered coding tools like Cursor and Windsurf. The attack involved downloading a second-stage malicious extension from an attacker-controlled GitHub account, which exfiltrated sensitive data and deployed a remote access trojan (RAT) that installed an information-stealing Google Chrome extension. ([thehackernews.com](https://thehackernews.com/2026/04/glassworm-campaign-uses-zig-dropper-to.html?utm_source=openai)) This incident underscores the evolving sophistication of supply chain attacks targeting developer environments. The use of native binaries compiled in Zig to propagate malware across multiple IDEs highlights the need for enhanced vigilance and security measures within the software development community. Developers are advised to scrutinize extensions before installation and monitor their systems for unauthorized changes to prevent similar compromises.
3 months ago
Kill Chain
APT28's PRISMEX Malware Campaign: A Threat to Global Security
In early 2026, the Russian state-sponsored group APT28, also known as Fancy Bear, launched a sophisticated cyber-espionage campaign targeting Ukraine and its NATO allies. The operation, active since at least September 2025 and intensifying in January 2026, involved the deployment of a modular malware suite named PRISMEX. This suite utilized advanced steganography, Component Object Model (COM) hijacking, and exploited newly disclosed vulnerabilities, including CVE-2026-21509 and CVE-2026-21513, to infiltrate defense supply chains and critical infrastructure sectors. The campaign's strategic focus on supply chains and operational planning capabilities underscores a shift toward operational disruption, potentially paving the way for more destructive activities. ([thehackernews.com](https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html?utm_source=openai)) The PRISMEX campaign highlights the persistent and evolving threat posed by APT28, emphasizing the necessity for organizations to adopt proactive cybersecurity measures. The rapid weaponization of vulnerabilities and the use of sophisticated techniques like steganography and cloud service abuse demonstrate the group's advanced capabilities. This incident serves as a critical reminder for entities within targeted sectors to enhance their security postures and remain vigilant against such advanced persistent threats. ([thehackernews.com](https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html?utm_source=openai))
3 months ago
Kill Chain
Cirro Cloud Security Breach 2026: Lessons Learned and Future Precautions
In 2026, Cirro, a cloud security tool, experienced a significant security incident where attackers exploited vulnerabilities in its platform, leading to unauthorized access to sensitive client data. The breach was initiated through a compromised administrative account, allowing threat actors to navigate internal systems undetected for several days. This intrusion resulted in the exfiltration of confidential information, affecting numerous organizations relying on Cirro for cloud security solutions. The incident underscores the critical importance of robust access controls and continuous monitoring in cloud environments. As cloud adoption accelerates, the frequency and sophistication of such breaches have increased, highlighting the need for organizations to implement comprehensive security measures and stay vigilant against evolving cyber threats.
3 months ago
Kill Chain
FBI Dismantles APT28's Global Router-Based Espionage Network
In April 2026, the FBI, in collaboration with international partners, executed Operation Masquerade to dismantle a sophisticated cyberespionage campaign orchestrated by APT28, also known as Fancy Bear or Forest Blizzard. This Russian state-sponsored group had compromised over 18,000 TP-Link routers across more than 120 countries, infiltrating over 200 organizations. By exploiting vulnerabilities in these routers, APT28 altered DNS settings to redirect internet traffic through attacker-controlled servers, enabling the interception of sensitive data, including credentials for Microsoft Outlook and Office 365 services. The operation involved sending commands to reset the compromised routers' DNS settings, effectively severing the attackers' access and mitigating further data exfiltration. ([justice.gov](https://www.justice.gov/opa/pr/justice-department-conducts-court-authorized-disruption-dns-hijacking-network-controlled?utm_source=openai)) This incident underscores the escalating threat posed by nation-state actors targeting network infrastructure to conduct large-scale espionage. The use of DNS hijacking to perform adversary-in-the-middle attacks highlights the need for organizations to secure all network devices, including SOHO routers, and to implement robust monitoring and response strategies to detect and mitigate such sophisticated threats. ([ncsc.gov.uk](https://www.ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dns-hijacking-operations?utm_source=openai))
3 months ago
Kill Chain
Bitcoin Depot's 2026 Security Breach: A Wake-Up Call for Cryptocurrency Security
In March 2026, Bitcoin Depot, a leading Bitcoin ATM operator, experienced a significant security breach when attackers infiltrated its IT systems and obtained credentials for digital asset settlement accounts. This unauthorized access enabled the transfer of approximately 50.9 Bitcoin, valued at $3.665 million at the time, from company-controlled wallets. The breach was detected on March 23, prompting Bitcoin Depot to activate incident response protocols, engage external cybersecurity experts, and notify law enforcement. Importantly, the company reported that customer platforms and data remained unaffected by this incident. This breach underscores the persistent vulnerabilities within the cryptocurrency sector, particularly concerning the security of internal corporate systems. The incident highlights the critical need for robust credential management and comprehensive security measures to protect digital assets. As the cryptocurrency market continues to expand, organizations must prioritize the implementation of stringent security protocols to mitigate the risk of such attacks.
3 months ago
Kill Chain
Figure Technology Solutions Data Breach: A Wake-Up Call for Fintech Security
In February 2026, Figure Technology Solutions, a leading fintech company specializing in blockchain-enabled lending services, experienced a significant data breach. The incident began when an employee was deceived by a sophisticated voice phishing (vishing) attack, leading to unauthorized access to the company's systems. The cybercriminal group ShinyHunters claimed responsibility, exfiltrating approximately 2.5 gigabytes of sensitive customer data, including full names, addresses, dates of birth, phone numbers, Social Security numbers, and loan information. This breach affected nearly one million customers, exposing them to potential identity theft and financial fraud. ([crowdfundinsider.com](https://www.crowdfundinsider.com/2026/02/262975-figure-technology-faces-major-data-breach-impacting-nearly-one-million-customers/?utm_source=openai)) This incident underscores the escalating threat of social engineering attacks targeting financial institutions. Despite advancements in cybersecurity measures, human factors remain a critical vulnerability. The breach highlights the necessity for comprehensive security protocols, including robust employee training and advanced authentication mechanisms, to mitigate the risks associated with sophisticated phishing campaigns.
3 months ago
Kill Chain
ChipSoft Ransomware Attack: A Wake-Up Call for Healthcare Cybersecurity
In April 2026, ChipSoft, a leading Dutch healthcare software provider serving approximately 70% of the country's hospitals, suffered a ransomware attack. The incident led to the company's website going offline and raised concerns about potential unauthorized access to patient records. In response, several hospitals disconnected their systems as a precautionary measure. The full extent of the data breach remains under investigation. This attack underscores the escalating threat of ransomware targeting critical healthcare infrastructure. The incident highlights the urgent need for robust cybersecurity measures and comprehensive incident response plans to protect sensitive patient data and ensure the continuity of healthcare services.
3 months ago
Kill Chain
LucidRook Malware Targets Taiwanese NGOs and Universities in 2025
In October 2025, the threat actor group UAT-10362 launched spear-phishing campaigns targeting non-governmental organizations (NGOs) and universities in Taiwan. These attacks utilized a newly identified Lua-based malware named 'LucidRook,' which was delivered through malicious LNK and EXE files disguised as legitimate software. Once executed, LucidRook embedded a Lua interpreter within a dynamic-link library (DLL) to download and execute staged Lua bytecode payloads, enabling the attackers to update functionality without modifying the core malware. The malware performed system reconnaissance, collecting information such as user and computer names, installed applications, and running processes, which was then encrypted and exfiltrated via FTP to attacker-controlled infrastructure. ([blog.talosintelligence.com](https://blog.talosintelligence.com/new-lua-based-malware-lucidrook/?utm_source=openai)) This incident underscores the evolving sophistication of cyber threats, particularly those targeting educational and non-governmental sectors. The use of modular malware like LucidRook, capable of dynamic updates and extensive obfuscation, highlights the need for organizations to enhance their cybersecurity measures, including employee training on phishing tactics and the implementation of advanced threat detection systems.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports