✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Fortinet FortiClient EMS Vulnerability: Immediate Action Required
In April 2026, Fortinet disclosed a critical vulnerability (CVE-2026-35616) in its FortiClient Endpoint Management Server (EMS) versions 7.4.5 and 7.4.6. This improper access control flaw allows unauthenticated attackers to execute unauthorized code or commands via crafted requests. The vulnerability has been actively exploited in the wild, prompting Fortinet to release emergency hotfixes and advise customers to update to version 7.4.7. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/?utm_source=openai)) The rapid exploitation of CVE-2026-35616 underscores the increasing trend of attackers targeting endpoint management solutions to gain unauthorized access and control over enterprise networks. Organizations must prioritize timely patching and robust access controls to mitigate such risks.
3 months ago
Kill Chain
Phishing Campaigns Exploit Open Redirects in 2026
In early 2026, multiple phishing campaigns exploited open redirect vulnerabilities in trusted domains to deceive users into visiting malicious websites. Attackers crafted URLs that appeared legitimate by leveraging open redirects in services like Google Meet and Microsoft OAuth, effectively bypassing traditional email and browser security measures. This technique led to increased instances of credential theft and malware distribution, particularly targeting government and public-sector organizations. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/?utm_source=openai)) The prevalence of these attacks underscores the critical need for organizations to identify and remediate open redirect vulnerabilities within their web applications. As threat actors continue to refine their methods, maintaining robust security protocols and user awareness is essential to mitigate the risks associated with such sophisticated phishing tactics.
3 months ago
Kill Chain
React2Shell 2025: Credential Theft Campaign Exploiting CVE-2025-55182
In December 2025, a critical vulnerability known as React2Shell (CVE-2025-55182) was disclosed, affecting React Server Components in versions 19.0.0 through 19.2.0. This flaw allowed unauthenticated remote code execution, enabling attackers to execute arbitrary JavaScript code on vulnerable servers. Exploiting this vulnerability, threat actors initiated a large-scale campaign targeting Next.js applications, compromising at least 766 hosts across various cloud providers. The attackers utilized an automated framework named NEXUS Listener to harvest sensitive data, including database credentials, SSH private keys, API keys, cloud tokens, and environment secrets. The operation was attributed to a threat cluster tracked as UAT-10608. ([articles.uvnetware.com](https://articles.uvnetware.com/news/react2shell-cve-2025-55182/?utm_source=openai)) The React2Shell incident underscores the critical importance of promptly addressing server-side vulnerabilities in widely used frameworks. The rapid exploitation by sophisticated threat actors highlights the need for organizations to implement robust security measures, including timely patching, comprehensive monitoring, and adherence to secure coding practices to mitigate the risk of similar attacks.
3 months ago
Kill Chain
36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants
In April 2026, cybersecurity researchers identified 36 malicious npm packages masquerading as Strapi CMS plugins. These packages exploited Redis and PostgreSQL databases to deploy reverse shells, harvest credentials, and establish persistent implants. The malicious code was embedded within the postinstall script hook, executing upon installation without user interaction, thereby compromising systems with root access in CI/CD environments and Docker containers. The attackers utilized various payloads, including remote code execution via Redis, Docker container escapes, and credential harvesting, indicating a sophisticated and evolving threat. This incident underscores the escalating risks associated with software supply chain attacks, particularly within open-source ecosystems. The attackers' ability to infiltrate widely-used package repositories highlights the urgent need for enhanced security measures in software development pipelines. Organizations are advised to audit their dependencies, implement strict access controls, and monitor for anomalous activities to mitigate such threats.
3 months ago
Kill Chain
Understanding the 2026 Surge in Device Code Phishing Attacks
In early 2026, device code phishing attacks exploiting the OAuth 2.0 Device Authorization Grant flow surged by over 37 times. Attackers initiated device authorization requests to service providers, obtained codes, and deceived victims into entering these codes on legitimate login pages, thereby granting unauthorized access to their accounts. This method, originally designed for devices lacking standard input options, was co-opted by cybercriminals to bypass traditional authentication mechanisms. The proliferation of phishing-as-a-service kits, notably EvilTokens, has significantly contributed to the widespread adoption of this technique, enabling even low-skilled attackers to execute sophisticated phishing campaigns. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/device-code-phishing-attacks-surge-37x-as-new-kits-spread-online/?utm_source=openai)) The rapid escalation of device code phishing underscores a critical shift in cyberattack strategies, emphasizing the need for organizations to reassess and fortify their authentication processes. The commoditization of such attack methods through services like EvilTokens highlights the urgency for enhanced security measures and user education to mitigate the risks associated with these evolving threats.
3 months ago
Kill Chain
European Commission's 2026 Supply-Chain Breach: A Wake-Up Call for Cybersecurity
In March 2026, the European Commission's cloud infrastructure hosting the Europa.eu platform was compromised through a supply-chain attack orchestrated by the cybercriminal group TeamPCP. The attackers exploited a vulnerability in the Trivy security tool to gain unauthorized access to the Commission's Amazon Web Services (AWS) environment. This breach led to the exfiltration of approximately 92 GB of compressed data, including personal information such as names, email addresses, and email content. Subsequently, the data extortion group ShinyHunters published the stolen data on their dark web leak site. The incident affected not only the European Commission but also at least 29 other Union entities utilizing the Europa.eu web hosting service. ([cert.europa.eu](https://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain?utm_source=openai)) This breach underscores the escalating threat posed by supply-chain attacks, where vulnerabilities in third-party tools can serve as entry points for malicious actors. Organizations must enhance their cybersecurity measures, particularly in monitoring and securing their software supply chains, to mitigate such risks.
3 months ago
Kill Chain
Surge in Multi-Extortion Ransomware Attacks in 2026
In early 2026, the University of Mississippi Medical Center (UMMC) and payment processing network BridgePay were severely impacted by multi-extortion ransomware attacks. UMMC's Epic electronic health record system was taken offline across 35 clinics and over 200 telehealth sites, leading to the cancellation of critical medical procedures. Similarly, BridgePay's services were disrupted, affecting numerous financial transactions. These incidents underscore the escalating threat posed by ransomware groups employing double and triple extortion tactics, which involve encrypting data, exfiltrating sensitive information, and threatening public disclosure to pressure victims into paying ransoms. The increasing sophistication of these attacks highlights the urgent need for organizations to implement robust data encryption and access control measures to protect sensitive information and ensure rapid recovery in the event of a breach.
3 months ago
Kill Chain
Insider Threat Extortion: Lessons from the 2023 Daniel Rhyne Case
In November 2023, Daniel Rhyne, a former core infrastructure engineer at a New Jersey-based industrial company, executed an unauthorized access to the company's network. Utilizing an administrator account, Rhyne altered passwords for 13 domain administrator accounts and 301 domain user accounts to 'TheFr0zenCrew!', effectively locking out legitimate users. He also scheduled tasks to change local administrator passwords on 3,284 workstations and 254 servers, and planned shutdowns of random servers and workstations over multiple days in December 2023. On November 25, Rhyne sent a ransom email demanding 20 Bitcoin (approximately $750,000 at the time), threatening to shut down 40 random servers daily over ten days if the ransom was not paid. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/man-admits-to-extortion-plot-locking-coworkers-out-of-thousands-of-windows-devices/amp/?utm_source=openai)) This incident underscores the persistent risk of insider threats, particularly from individuals with elevated access privileges. The case highlights the necessity for organizations to implement robust access controls, continuous monitoring, and comprehensive insider threat detection programs to mitigate such risks.
3 months ago
Kill Chain
Hims & Hers Data Breach: Lessons in Securing Third-Party Platforms
In early February 2026, telehealth company Hims & Hers experienced a data breach when unauthorized individuals accessed their third-party customer service platform, Zendesk. The attackers infiltrated the system between February 4 and February 7, compromising support tickets that contained customer names, contact information, and other personal data. Notably, medical records and doctor communications remained unaffected. The breach was attributed to the ShinyHunters extortion group, which exploited compromised Okta SSO accounts to gain access to Zendesk and exfiltrate millions of support tickets. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hims-and-hers-warns-of-data-breach-after-zendesk-support-ticket-breach/?utm_source=openai)) This incident underscores the escalating threat posed by cybercriminal groups targeting third-party service platforms through sophisticated social engineering and credential compromise techniques. Organizations must enhance their security measures, particularly around SSO systems and third-party integrations, to mitigate such risks.
3 months ago
Kill Chain
TA416's Renewed Cyber Espionage Campaigns Target European Governments
In mid-2025, the China-aligned threat actor TA416 resumed cyber espionage operations targeting European government and diplomatic entities after a two-year hiatus. The group employed sophisticated techniques, including web bug reconnaissance and evolving malware delivery methods, to deploy the PlugX backdoor via DLL sideloading. These campaigns primarily focused on individuals associated with NATO and EU delegations, leveraging compromised accounts and freemail services to distribute malicious payloads. ([proofpoint.com](https://www.proofpoint.com/us/blog/threat-insight/id-come-running-back-eu-again-ta416-resumes-european-government-espionage?utm_source=openai)) This resurgence underscores the persistent threat posed by state-sponsored actors to governmental institutions, highlighting the need for enhanced cybersecurity measures and vigilance against evolving attack vectors. ([proofpoint.com](https://www.proofpoint.com/us/blog/threat-insight/id-come-running-back-eu-again-ta416-resumes-european-government-espionage?utm_source=openai))
3 months ago
Kill Chain
Apple Releases Critical Update to Patch DarkSword Exploit in iOS 18
In March 2026, Apple addressed the DarkSword exploit chain, a sophisticated malware targeting iOS versions 18.4 through 18.7. DarkSword enabled attackers to gain unauthorized access to sensitive user data by exploiting multiple vulnerabilities, primarily through malicious websites. Initially, Apple released patches for iOS 26, leaving many devices running iOS 18 vulnerable. However, on April 1, 2026, Apple extended the security update to iOS 18.7.7, safeguarding users who had not upgraded to the latest OS. ([techcrunch.com](https://techcrunch.com/2026/04/01/apple-releases-security-fix-for-older-iphones-and-ipads-to-protect-against-darksword-attacks/?utm_source=openai)) This incident underscores the evolving threat landscape where advanced exploit kits are increasingly accessible to a broader range of threat actors. The public availability of DarkSword's code on platforms like GitHub has heightened the risk, emphasizing the necessity for timely software updates and robust security measures to protect against such vulnerabilities. ([tomsguide.com](https://www.tomsguide.com/phones/iphones/darksword-exploit-just-went-global-millions-of-iphones-now-wide-open-to-hackers?utm_source=openai))
3 months ago
Kill Chain
TeamPCP's 2026 Supply Chain Attacks: Lessons for Software Security
In March 2026, the cybercriminal group TeamPCP orchestrated a series of sophisticated supply chain attacks targeting widely used open-source software components, including Aqua Security's Trivy, Checkmarx's KICS GitHub Action, and the LiteLLM Python package. By compromising these trusted tools, TeamPCP embedded credential-stealing malware, enabling them to harvest sensitive data such as cloud credentials, SSH keys, and Kubernetes tokens from numerous organizations. The European Commission and AI startup Mercor were among the victims, with the former experiencing a significant data breach involving approximately 92 GB of sensitive information. The rapid succession and scale of these attacks underscore the critical vulnerabilities present in software supply chains and the need for enhanced security measures. ([darkreading.com](https://www.darkreading.com/threat-intelligence/teampcp-attacks-hacker-infighting?utm_source=openai)) The involvement of additional threat actors, notably ShinyHunters and Lapsus$, has further complicated the threat landscape. These groups have been observed leveraging the stolen data for extortion and monetization purposes, indicating a dangerous convergence between supply chain attackers and extortion gangs. This development highlights the evolving nature of cyber threats and the importance of proactive defense strategies to mitigate the risks associated with compromised software dependencies. ([infosecurity-magazine.com](https://www.infosecurity-magazine.com/news/teampcp-exploit-stolen-supply/?utm_source=openai))
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports