✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
VENOM Phishing Campaign: A Wake-Up Call for Executive Security
Between November 2025 and March 2026, a sophisticated phishing campaign utilizing the previously undocumented VENOM phishing-as-a-service (PhaaS) platform targeted C-suite executives across over 20 industries. Attackers impersonated Microsoft SharePoint notifications, embedding QR codes to lure victims into credential theft schemes. The campaign employed advanced evasion techniques, including adversary-in-the-middle (AiTM) attacks and device code abuse, effectively bypassing multi-factor authentication (MFA) and establishing persistent access to compromised accounts. ([abnormal.ai](https://abnormal.ai/resources/venom-phaas-c-suite-microsoft-credential-theft-report?utm_source=openai)) This incident underscores a growing trend of highly targeted phishing attacks against high-level executives, highlighting the need for organizations to reassess their security postures. The emergence of sophisticated PhaaS platforms like VENOM indicates an evolution in cybercriminal tactics, emphasizing the urgency for enhanced defenses against such advanced threats. ([abnormal.ai](https://abnormal.ai/resources/venom-phaas-c-suite-microsoft-credential-theft-report?utm_source=openai))
3 months ago
Kill Chain
ClipBanker Malware 2025: Trojanized Proxifier Leads to Crypto Theft
In early 2025, cybersecurity researchers identified a sophisticated malware campaign involving the ClipBanker Trojan, which was distributed through a trojanized version of the Proxifier software. Users searching for Proxifier were led to a GitHub repository hosting a malicious installer. Upon execution, this installer initiated a complex infection chain, ultimately deploying ClipBanker—a malware designed to monitor clipboard activity and replace cryptocurrency wallet addresses with those controlled by attackers, leading to unauthorized fund transfers. ([securelist.com](https://securelist.com/clipbanker-malware-distributed-via-trojanized-proxifier/119341/?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals who exploit trusted platforms and software to distribute malware. The use of trojanized legitimate applications highlights the need for heightened vigilance and the importance of downloading software exclusively from official sources to mitigate such risks.
3 months ago
Kill Chain
Critical RCE Vulnerability Discovered in Apache ActiveMQ Classic
In April 2026, a critical remote code execution (RCE) vulnerability, identified as CVE-2026-34197, was discovered in Apache ActiveMQ Classic's Jolokia JMX-HTTP bridge. This flaw allows authenticated attackers to execute arbitrary code on the server by exploiting improper input validation within the Jolokia endpoint. The vulnerability affects all versions of Apache ActiveMQ Classic and has remained undetected for over 13 years. ([cryptika.com](https://www.cryptika.com/claude-uncovers-13-year-old-rce-flaw-in-apache-activemq-in-just-10-minutes/?utm_source=openai)) The discovery of this longstanding vulnerability underscores the persistent risks associated with legacy software components and the importance of regular security assessments. Organizations utilizing Apache ActiveMQ Classic are urged to apply the latest patches promptly to mitigate potential exploitation.
3 months ago
Kill Chain
UAT-10362's LucidRook Malware Targets Taiwanese NGOs in Spear-Phishing Attacks
In October 2025, a previously undocumented threat actor, UAT-10362, launched spear-phishing campaigns targeting Taiwanese non-governmental organizations (NGOs) and universities. The attackers distributed a new Lua-based malware named LucidRook, which embeds a Lua interpreter and Rust-compiled libraries within a dynamic-link library (DLL) to download and execute staged Lua bytecode payloads. The malware exhibits region-specific anti-analysis checks, activating only in Traditional Chinese language environments associated with Taiwan. The campaigns utilized malicious LNK and EXE files disguised as antivirus software, leveraging compromised FTP servers and out-of-band application security testing (OAST) services for command-and-control infrastructure. ([blog.talosintelligence.com](https://blog.talosintelligence.com/new-lua-based-malware-lucidrook/?utm_source=openai)) This incident underscores the evolving sophistication of cyber threats targeting specific regions and sectors. The use of multi-language modular design, layered anti-analysis features, and reliance on compromised or public infrastructure indicates a high level of operational maturity by UAT-10362. Organizations, especially those in Taiwan, should enhance their cybersecurity measures to detect and mitigate such advanced persistent threats.
3 months ago
Kill Chain
APT28's 2025 SOHO Router DNS Hijacking: A Wake-Up Call for Network Security
In August 2025, the Russian state-sponsored group APT28 (also known as Forest Blizzard) initiated a large-scale cyber-espionage campaign targeting small office/home office (SOHO) routers, primarily from TP-Link and MikroTik. By exploiting known vulnerabilities, such as CVE-2023-50224, the attackers gained unauthorized access to these routers and modified their DNS settings to redirect traffic through malicious servers under their control. This allowed them to intercept and steal credentials for web and email services, including Microsoft Outlook, from over 200 organizations and 5,000 consumer devices across more than 120 countries. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/07/soho-router-compromise-leads-to-dns-hijacking-and-adversary-in-the-middle-attacks/?utm_source=openai)) The campaign, which peaked in December 2025, underscores the critical need for securing network infrastructure, especially SOHO devices that may lack robust security measures. The U.S. Department of Justice, in collaboration with the FBI and international partners, conducted Operation Masquerade to disrupt this malicious network, highlighting the ongoing threat posed by state-sponsored cyber activities and the importance of proactive defense strategies. ([justice.gov](https://www.justice.gov/opa/pr/justice-department-conducts-court-authorized-disruption-dns-hijacking-network-controlled?utm_source=openai))
3 months ago
Kill Chain
DISGOMOJI Malware: A New Era of Emoji-Based Cyber Attacks
In 2024, the Pakistan-based Advanced Persistent Threat (APT) group UTA0137 launched a cyber-espionage campaign targeting Indian government entities. The group deployed a sophisticated malware named DISGOMOJI, written in Golang and designed for Linux systems. DISGOMOJI uniquely utilized Discord for command-and-control (C2) communications, employing emojis to execute commands such as taking screenshots, exfiltrating files, and terminating processes. The malware was delivered via spear-phishing emails containing a ZIP archive with a Golang ELF binary. Upon execution, the binary downloaded a lure file and the DISGOMOJI payload, establishing a dedicated Discord channel for each infected system, allowing individualized interaction with each victim. This campaign underscores the evolving tactics of state-sponsored threat actors in leveraging unconventional methods to evade detection and maintain persistent access to targeted systems. The use of emojis in C2 communications highlights a broader trend of adversaries adopting more visual and adaptive forms of interaction to obfuscate their activities and complicate monitoring efforts.
3 months ago
Kill Chain
Critical Vulnerability in Ivanti EPMM: CVE-2026-1340
In January 2026, a critical code injection vulnerability, CVE-2026-1340, was discovered in Ivanti Endpoint Manager Mobile (EPMM). This flaw allows unauthenticated remote code execution, enabling attackers to execute arbitrary code on affected systems without authentication. The vulnerability affects EPMM versions up to and including 12.7.0.0. Exploitation of this vulnerability can lead to complete system compromise, data theft, and potential lateral movement within enterprise networks. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-1340/?utm_source=openai)) The inclusion of CVE-2026-1340 in CISA's Known Exploited Vulnerabilities Catalog underscores the urgency for organizations to address this issue promptly. ([datacomm.com](https://www.datacomm.com/feed-post/cve-2026-1281-cve-2026-1340-ivanti-endpoint-manager-mobile-epmm-zero-day-vulnerabilities-exploited-2/?utm_source=openai))
3 months ago
Kill Chain
Cisco's 2026 Trivy Supply Chain Breach: A Wake-Up Call for Development Security
In March 2026, Cisco's internal development environment was breached through a sophisticated supply chain attack involving the Trivy vulnerability scanner. Threat actors, identified as TeamPCP, compromised Trivy's GitHub Actions pipeline, injecting credential-stealing malware into official releases. This allowed them to harvest credentials from organizations using Trivy, including Cisco. Leveraging these stolen credentials, the attackers infiltrated Cisco's build systems and developer workstations, exfiltrating over 300 private GitHub repositories containing source code for AI-powered products and unreleased items. Additionally, customer repositories belonging to banks, business process outsourcing firms, and U.S. government agencies were among those exfiltrated. AWS keys were also stolen and used for unauthorized activities across Cisco's cloud accounts. Cisco has since isolated affected systems, initiated reimaging, and is performing wide-scale credential rotation to contain the breach. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/?utm_source=openai)) This incident underscores the escalating threat posed by supply chain attacks, where compromising a widely-used tool can have cascading effects across multiple organizations. The breach highlights the critical need for organizations to scrutinize the security of third-party tools integrated into their development pipelines and to implement robust monitoring and incident response strategies to detect and mitigate such sophisticated attacks.
3 months ago
Kill Chain
AWS AgentCore IAM God Mode Vulnerability Exposes Critical Security Risks
In April 2026, a security analysis revealed that the Amazon Bedrock AgentCore Starter Toolkit's default IAM roles granted overly permissive access, allowing AI agents to perform actions across all resources within an AWS account. This misconfiguration enabled potential attackers to exfiltrate proprietary ECR images, access other agents' memories, invoke code interpreters, and extract sensitive data. The issue stemmed from the toolkit's auto-create logic, which favored deployment ease over the principle of least privilege. Following disclosure, AWS updated its documentation to warn users that the default roles are intended for development and testing purposes only and are not recommended for production deployments. This incident underscores the critical importance of adhering to the principle of least privilege in IAM configurations, especially as organizations increasingly deploy AI agents in cloud environments. Overly permissive roles can lead to significant security risks, including data breaches and unauthorized access to sensitive resources.
3 months ago
Kill Chain
Critical RCE Vulnerability Discovered in Apache ActiveMQ Classic
In April 2026, a critical remote code execution (RCE) vulnerability, CVE-2026-34197, was discovered in Apache ActiveMQ Classic, a widely used open-source message broker. This flaw, present for over 13 years, allows authenticated attackers to execute arbitrary commands on the broker's Java Virtual Machine (JVM) by exploiting the Jolokia JMX-HTTP bridge. The vulnerability affects versions before 5.19.4 and from 6.0.0 up to 6.2.3. Exploitation involves sending a crafted request that forces the broker to load a remote Spring XML file, leading to command execution during its initialization. The discovery underscores the importance of proactive vulnerability management and the potential of AI tools in identifying complex security flaws. Organizations using affected ActiveMQ versions are urged to upgrade to versions 5.19.5 or 6.2.3 to mitigate this risk. ([ubuntu.com](https://ubuntu.com/security/CVE-2026-34197?utm_source=openai))
3 months ago
Kill Chain
New macOS Malware Campaign Exploits Script Editor in ClickFix Attack
In April 2026, a new macOS malware campaign emerged, leveraging the Script Editor application to deliver the Atomic Stealer (AMOS) malware. Attackers employed a variation of the ClickFix technique, directing users to malicious websites that prompted them to open Script Editor via the 'applescript://' URL scheme. This method executed obfuscated commands to download and run AMOS, which exfiltrated sensitive data including Keychain information, browser credentials, and cryptocurrency wallets. This incident underscores the evolving tactics of threat actors targeting macOS systems, particularly through trusted applications like Script Editor. The shift from Terminal-based to Script Editor-based ClickFix attacks highlights the need for continuous vigilance and user education to recognize and avoid such sophisticated social engineering schemes.
3 months ago
Kill Chain
Hims & Hers Data Breach: Lessons in Third-Party Security
In early February 2026, telehealth company Hims & Hers Health experienced a data breach when unauthorized individuals accessed support tickets through their third-party customer service platform, Zendesk. The breach, occurring between February 4 and February 7, exposed personal information such as names and contact details of customers. Importantly, no medical records or doctor communications were compromised. The company promptly secured the platform and initiated an investigation upon discovering the suspicious activity on February 5. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hims-and-hers-warns-of-data-breach-after-zendesk-support-ticket-breach/?utm_source=openai)) This incident underscores the vulnerabilities associated with third-party service providers and the critical need for robust security measures. As cyber threats targeting support systems increase, organizations must enhance their security protocols to protect sensitive customer data and maintain trust.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports