✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Forest Blizzard's 2026 SOHO Router DNS Hijacking: A Wake-Up Call for Network Security
In April 2026, the Russian state-sponsored group Forest Blizzard exploited vulnerabilities in small office/home office (SOHO) routers to perform DNS hijacking and adversary-in-the-middle (AiTM) attacks. By compromising these routers, they redirected DNS requests through attacker-controlled servers, enabling interception of sensitive communications. This campaign affected over 200 organizations and 5,000 consumer devices, primarily targeting sectors such as government, IT, telecommunications, and energy. The attackers leveraged the compromised infrastructure to collect intelligence and potentially facilitate further malicious activities. This incident underscores the critical need for securing SOHO devices, as they can serve as entry points for sophisticated cyberattacks. Organizations must prioritize regular firmware updates, enforce strong authentication measures, and monitor network traffic for anomalies to mitigate such threats.
3 months ago
Kill Chain
Storm-1175's Rapid Exploitation of Web Vulnerabilities in 2026
In early 2026, the financially motivated cybercriminal group Storm-1175 executed high-velocity ransomware campaigns by exploiting recently disclosed vulnerabilities in web-facing systems. The group rapidly transitioned from initial access to data exfiltration and deployment of Medusa ransomware, often within 24 hours. These attacks significantly impacted healthcare, education, professional services, and finance sectors across Australia, the United Kingdom, and the United States. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/?utm_source=openai)) This incident underscores the critical need for organizations to promptly apply security patches and enhance monitoring of web-facing assets. The rapid exploitation of vulnerabilities by threat actors like Storm-1175 highlights the importance of proactive defense measures to mitigate the risk of ransomware attacks.
3 months ago
Kill Chain
Fortinet's FortiClient EMS Zero-Day Vulnerability Exploited in 2026
In early April 2026, Fortinet disclosed a critical zero-day vulnerability (CVE-2026-35616) in its FortiClient Endpoint Management Server (EMS), which was actively exploited in the wild. This improper access control flaw allowed unauthenticated attackers to execute unauthorized code or commands via crafted requests. Fortinet released an emergency hotfix for versions 7.4.5 and 7.4.6, with plans for a comprehensive patch in version 7.4.7. The vulnerability was added to CISA's known exploited vulnerability catalog, highlighting its severity and widespread impact. The rapid exploitation of CVE-2026-35616 underscores a growing trend of attackers targeting zero-day vulnerabilities in widely used security solutions. Organizations must remain vigilant, ensuring timely application of patches and hotfixes to mitigate such threats. This incident also emphasizes the importance of robust access controls and continuous monitoring to detect and respond to unauthorized activities promptly.
3 months ago
Kill Chain
GrafanaGhost: Unveiling the Critical AI Prompt Injection Vulnerability in Grafana
In April 2026, security researchers at Noma Security disclosed a critical vulnerability in Grafana, termed 'GrafanaGhost.' This exploit enables attackers to silently exfiltrate sensitive data by circumventing Grafana's AI defenses through prompt injection techniques. The attack does not require user interaction or authentication; it leverages crafted URLs to inject hidden instructions that Grafana's AI processes, leading to unauthorized data transmission to attacker-controlled servers. The vulnerability affects Grafana instances widely used for monitoring real-time financial metrics, infrastructure health data, and customer records, posing significant risks to enterprise data security. This incident underscores the escalating threat of AI prompt injection attacks, where adversaries manipulate AI systems to perform unintended actions. As AI integration in enterprise environments grows, such vulnerabilities highlight the urgent need for robust AI-specific security measures to prevent data breaches and maintain system integrity.
3 months ago
Kill Chain
Fortinet EMS Vulnerability CVE-2026-35616: Immediate Action Required
In April 2026, a critical vulnerability (CVE-2026-35616) was discovered in Fortinet's FortiClient Enterprise Management Server (EMS). This flaw allowed unauthenticated attackers to bypass authentication controls and execute arbitrary code via specially crafted requests. Fortinet released emergency hotfixes to address the issue, urging immediate application to prevent exploitation. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) mandated federal agencies to patch affected systems by April 9, 2026, highlighting the significant risk posed by this vulnerability. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-fortinet-flaw-exploited-in-attacks-by-friday/?utm_source=openai)) The exploitation of CVE-2026-35616 underscores the persistent threat of zero-day vulnerabilities in widely used enterprise solutions. Organizations are reminded of the critical importance of timely patch management and proactive security measures to mitigate such risks.
3 months ago
Kill Chain
BKA Unmasks REvil Leaders Behind 130 German Ransomware Attacks
In April 2026, Germany's Federal Criminal Police Office (BKA) unmasked the identities of two key figures associated with the REvil ransomware-as-a-service (RaaS) operation. Daniil Maksimovich Shchukin, known online as 'UNKN,' and Anatoly Sergeevitsch Kravchuk were linked to 130 ransomware attacks across Germany, resulting in over €35.4 million in damages. The REvil group, active from 2019 to 2021, targeted high-profile organizations, demanding substantial ransoms in exchange for decrypting and not leaking data. ([thehackernews.com](https://thehackernews.com/2026/04/bka-identifies-revil-leaders-behind-130.html?utm_source=openai)) This revelation underscores the persistent threat posed by sophisticated ransomware groups and highlights the importance of international cooperation in cybercrime investigations. Organizations must remain vigilant, as the tactics employed by groups like REvil continue to evolve, posing significant risks to global cybersecurity.
3 months ago
Kill Chain
Understanding the BlueHammer Windows Zero-Day Exploit
In April 2026, a security researcher operating under the alias 'Chaotic Eclipse' publicly disclosed a Windows zero-day vulnerability named 'BlueHammer.' This local privilege escalation flaw allows attackers to gain SYSTEM-level access by exploiting a combination of time-of-check to time-of-use (TOCTOU) and path confusion vulnerabilities. The researcher released proof-of-concept (PoC) code on GitHub, expressing dissatisfaction with Microsoft's handling of the disclosure process. As of the disclosure date, no official patch has been released, leaving systems vulnerable to potential exploitation. The public release of the BlueHammer exploit underscores the ongoing challenges in vulnerability disclosure and patch management. Organizations must remain vigilant, as unpatched zero-day vulnerabilities can be rapidly weaponized by threat actors, leading to significant security breaches and operational disruptions.
3 months ago
Kill Chain
Qilin and Warlock Ransomware Utilize BYOVD to Disable EDR Tools
In April 2026, cybersecurity researchers from Cisco Talos and Trend Micro identified that the Qilin and Warlock ransomware groups are employing the 'Bring Your Own Vulnerable Driver' (BYOVD) technique to disable endpoint detection and response (EDR) tools on compromised systems. This method involves deploying malicious DLLs, such as 'msimg32.dll,' to initiate multi-stage infection chains that terminate over 300 EDR drivers from various security vendors. By leveraging vulnerable drivers like 'rwdrv.sys' and 'hlpdrv.sys,' these ransomware groups effectively neutralize security defenses, facilitating the encryption of files and demanding ransoms from victims. ([thehackernews.com](https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html?utm_source=openai)) The adoption of BYOVD tactics by Qilin and Warlock underscores a significant evolution in ransomware strategies, highlighting the increasing sophistication of threat actors in circumventing traditional security measures. This trend necessitates enhanced vigilance and the implementation of advanced security protocols to detect and mitigate such evasive techniques.
3 months ago
Kill Chain
North Korean Hackers Compromise Axios JavaScript Library in 2026 Supply Chain Attack
In late March 2026, the widely-used JavaScript library Axios, with over 100 million weekly downloads, was compromised in a sophisticated supply chain attack. Threat actors, identified as the North Korean group UNC1069, gained access to a maintainer's npm account and released two malicious versions of the package: axios@1.14.1 and axios@0.30.4. These versions included a trojan-laden dependency, 'plain-crypto-js@4.2.1', which executed a post-install script to deploy a cross-platform Remote Access Trojan (RAT) targeting macOS, Windows, and Linux systems. The malware connected to a command-and-control server, retrieved system-specific payloads, and erased its tracks to evade detection. The malicious packages were available for approximately three hours before removal, potentially affecting numerous developers and organizations. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/axios-npm-package-compromised-in-supply-chain-attack-that-deployed-a-cross-platform-rat?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks, where trusted software components are weaponized to distribute malware. The rapid detection and removal of the compromised packages highlight the importance of vigilant monitoring and swift response mechanisms. Organizations are urged to review their software supply chain security practices, implement robust access controls, and ensure the integrity of their development environments to mitigate such risks.
3 months ago
Kill Chain
TeamPCP's 2026 Supply Chain Attack on LiteLLM: A Wake-Up Call for Open-Source Security
In March 2026, the threat group TeamPCP executed a sophisticated supply chain attack targeting LiteLLM, a widely used Python package facilitating unified access to various large language models. By compromising LiteLLM's PyPI repository credentials—initially obtained through a prior breach of the Trivy security scanner—TeamPCP published malicious versions 1.82.7 and 1.82.8. These versions contained malware designed to harvest sensitive credentials, including SSH keys, cloud access tokens, and Kubernetes secrets, and to establish persistent backdoors within affected systems. The compromised packages were available for approximately three hours before removal, during which they were downloaded extensively, potentially impacting thousands of systems. This incident underscores the escalating threat posed by supply chain attacks, particularly those targeting widely adopted open-source tools integral to AI and cloud infrastructures. The rapid propagation and depth of access achieved by TeamPCP highlight the critical need for organizations to implement stringent security measures within their software development pipelines and to maintain vigilant monitoring of third-party dependencies.
3 months ago
Kill Chain
Germany Unmasks Leader of REvil and GandCrab Ransomware Groups
In April 2026, German authorities identified 31-year-old Russian national Daniil Maksimovich Shchukin as 'UNKN,' the alleged leader of the notorious ransomware groups GandCrab and REvil. Between 2019 and 2021, Shchukin and his associate, 43-year-old Anatoly Sergeevitsch Kravchuk, reportedly executed at least 130 cyberattacks in Germany, extorting nearly €2 million and causing over €35 million in economic damages. These groups pioneered the double extortion tactic, demanding ransom for decrypting systems and additional payment to prevent data leaks. This revelation underscores the persistent threat posed by sophisticated ransomware operations and highlights the importance of international collaboration in combating cybercrime. Organizations must remain vigilant, as the identification of such key figures does not eliminate the risk of future attacks employing similar tactics.
3 months ago
Kill Chain
UAT-10608's Exploitation of React2Shell: A Wake-Up Call for Cybersecurity
In early April 2026, a threat cluster identified as UAT-10608 launched a global credential theft campaign targeting public-facing Next.js applications vulnerable to the React2Shell flaw (CVE-2025-55182). Exploiting this pre-authentication remote code execution vulnerability, attackers deployed an automated tool named 'NEXUS Listener' to exfiltrate credentials, SSH keys, cloud tokens, and environment secrets from compromised systems. This campaign resulted in the compromise of at least 766 hosts across multiple industries and geographic regions. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/automated-credential-harvesting-campaign-react2shell?utm_source=openai)) The React2Shell vulnerability, disclosed in December 2025, allows unauthenticated attackers to execute arbitrary code on servers running vulnerable versions of React Server Components. Despite the availability of patches, many organizations have yet to update their systems, leaving them susceptible to such attacks. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2025/12/15/defending-against-the-cve-2025-55182-react2shell-vulnerability-in-react-server-components/?msockid=3159dd8396d16eca0085cb7697616f99&utm_source=openai))
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports