✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Operation TrueChaos: Exploiting Trust in Software Updates
In early 2026, a sophisticated cyber espionage campaign, dubbed Operation TrueChaos, targeted government entities in Southeast Asia by exploiting a zero-day vulnerability (CVE-2026-3502) in the TrueConf video conferencing software. Attackers compromised the software's update mechanism, allowing them to distribute malicious updates that facilitated malware deployment across multiple agencies. This method enabled the attackers to bypass traditional security measures, leading to unauthorized access and potential data exfiltration. This incident underscores a growing trend where threat actors exploit trusted software supply chains to infiltrate secure environments. Organizations must reassess and fortify their internal trust mechanisms, especially concerning software updates, to mitigate such sophisticated attack vectors.
4 months ago
Kill Chain
Trivy Supply Chain Attack: A Wake-Up Call for CI/CD Security
In March 2026, Aqua Security's Trivy vulnerability scanner was compromised in a sophisticated supply chain attack orchestrated by the threat actor group TeamPCP. The attackers exploited previously stolen credentials to inject credential-stealing malware into Trivy's official releases and GitHub Actions, affecting versions 0.69.4, 0.69.5, and 0.69.6. This malicious code exfiltrated sensitive information, including cloud credentials and SSH keys, from CI/CD pipelines to attacker-controlled servers. The incident underscores the critical need for robust security measures in software supply chains to prevent such breaches. ([arstechnica.com](https://arstechnica.com/security/2026/03/widely-used-trivy-scanner-compromised-in-ongoing-supply-chain-attack/?utm_source=openai)) This attack highlights a growing trend of targeting trusted security tools to infiltrate development environments, emphasizing the importance of continuous monitoring and stringent access controls in CI/CD pipelines. Organizations must remain vigilant against evolving supply chain threats to safeguard their software development processes.
4 months ago
Kill Chain
WhatsApp Malware Campaign 2026: Unveiling the VBS Payloads and MSI Backdoors
In late February 2026, a sophisticated malware campaign exploited WhatsApp messages to distribute malicious Visual Basic Script (VBS) files. Upon execution, these scripts initiated a multi-stage infection chain, creating hidden directories and deploying renamed legitimate Windows utilities to retrieve additional payloads from trusted cloud services like AWS, Tencent Cloud, and Backblaze B2. The attackers employed techniques such as User Account Control (UAC) bypasses and registry modifications to escalate privileges and establish persistence, ultimately installing malicious Microsoft Installer (MSI) packages that enabled remote access to compromised systems. This campaign underscores the evolving tactics of threat actors who leverage trusted communication platforms and cloud services to evade detection and maintain control over infected devices. The incident highlights a growing trend where cybercriminals exploit widely used messaging applications and cloud infrastructures to disseminate malware, making detection and mitigation more challenging. Organizations must enhance their security measures to address these sophisticated attack vectors and protect against similar threats.
4 months ago
Kill Chain
Understanding CVE-2025-33073: NTLM Reflection Vulnerability in Windows SMB Client
In June 2025, Microsoft disclosed CVE-2025-33073, a critical vulnerability in the Windows SMB client that allows attackers to perform NTLM reflection attacks, leading to privilege escalation to SYSTEM level on affected systems. This flaw enables authenticated attackers to coerce a Windows host into authenticating to a malicious SMB server, which then reflects the authentication back to the victim, granting elevated privileges. The vulnerability affects Windows systems where SMB signing is not enforced, including various versions of Windows 10, 11, and Windows Server. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2025/10/21/cisa-warns-of-windows-smb-flaw-under-active-exploitation-cve-2025-33073/?utm_source=openai)) The exploitation of CVE-2025-33073 underscores the persistent risks associated with NTLM relay attacks and the importance of enforcing SMB signing across all systems. Organizations are urged to apply the security updates released by Microsoft in June 2025 and to review their network configurations to mitigate potential exploitation paths. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2025/10/21/cisa-warns-of-windows-smb-flaw-under-active-exploitation-cve-2025-33073/?utm_source=openai))
4 months ago
Kill Chain
Critical Vulnerability in strongSwan: Integer Underflow Leads to Denial of Service
In March 2026, a critical integer underflow vulnerability (CVE-2026-25075) was identified in strongSwan versions 4.5.0 through 6.0.4, specifically within the EAP-TTLS AVP parser. This flaw allows unauthenticated remote attackers to crash the charon IKE daemon by sending crafted AVP data with invalid length fields during IKEv2 authentication, leading to a denial of service. The vulnerability arises from improper validation of AVP length fields, resulting in excessive memory allocation or NULL pointer dereference. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-25075?utm_source=openai)) The discovery of this vulnerability underscores the importance of rigorous input validation in security protocols. Organizations utilizing affected versions of strongSwan are urged to upgrade to version 6.0.5 or later to mitigate potential service disruptions. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-25075?utm_source=openai))
4 months ago
Kill Chain
LiteLLM Supply Chain Compromise: A Wake-Up Call for Open-Source Security
In March 2026, the LiteLLM Python package, a widely used tool for managing large language model (LLM) APIs, was compromised in a supply chain attack attributed to the threat actor group TeamPCP. Malicious versions 1.82.7 and 1.82.8 were published on the Python Package Index (PyPI), containing code designed to exfiltrate sensitive credentials, including SSH keys, cloud tokens, and Kubernetes secrets. The attack exploited the package's role as a credential proxy, potentially exposing a vast array of systems to unauthorized access. The compromised versions have since been removed from PyPI, and users are advised to verify their installations, rotate all potentially exposed credentials, and monitor for any unauthorized activity. ([netspi.com](https://www.netspi.com/blog/executive-blog/ai-ml-pentesting/litellm-supply-chain-compromise/?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting open-source software repositories. The LiteLLM compromise highlights the critical need for organizations to implement stringent security measures within their software development and deployment pipelines to mitigate the risks associated with third-party dependencies.
4 months ago
Kill Chain
Critical Privilege Escalation Vulnerabilities in Google Cloud's Vertex AI Expose Organizations to Security Risks
In January 2026, security researchers identified critical privilege escalation vulnerabilities in Google Cloud's Vertex AI platform. These flaws allowed low-privileged users to gain high-privilege Service Agent roles, potentially leading to unauthorized access to sensitive data and resources. The vulnerabilities were found in the Vertex AI Agent Engine and Ray on Vertex AI, where default configurations enabled attackers to escalate permissions from 'Viewer' to project-wide access. Google acknowledged that the services were 'working as intended,' indicating that these risks persist in default deployments. ([cyberpress.org](https://cyberpress.org/privilege-escalation-bug-in-google-vertex-ai/?utm_source=openai)) This incident underscores the importance of scrutinizing default configurations in cloud services, as they can inadvertently expose organizations to significant security risks. The ability for low-privileged users to escalate their permissions highlights the need for robust access controls and continuous monitoring to prevent unauthorized access and potential data breaches.
4 months ago
Kill Chain
DeepLoad 2026: Unveiling the AI-Powered Credential Stealer
In March 2026, a sophisticated malware campaign named 'DeepLoad' was identified, targeting enterprise IT environments to steal user credentials. Delivered through deceptive 'QuickFix' social engineering tactics, such as fake browser prompts, DeepLoad employs AI-generated code to evade detection at multiple stages. The malware obfuscates its payload with extensive junk code, executes behind overlooked Windows processes, and spreads via connected USB drives, ensuring persistence and complicating remediation efforts. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/ai-powered-deepload-steals-credentials-evades-detection/?utm_source=openai)) This incident underscores a growing trend where cybercriminals leverage artificial intelligence to enhance malware capabilities, making traditional static detection methods less effective. Organizations must adapt by implementing behavioral and runtime detection strategies to counteract these evolving threats. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/ai-powered-deepload-steals-credentials-evades-detection/?utm_source=openai))
4 months ago
Kill Chain
European Commission's 2026 Data Breach: A Wake-Up Call for Cloud Security
In March 2026, the European Commission confirmed a significant data breach following a cyberattack on its Europa.eu web platform, attributed to the ShinyHunters extortion gang. The attackers reportedly accessed at least one of the Commission's Amazon Web Services (AWS) accounts, exfiltrating over 350 GB of data, including multiple databases and confidential documents. While the attack did not disrupt the functionality of Europa websites, the Commission is actively investigating the full impact and has notified affected Union entities. This incident underscores the escalating threat posed by cyber extortion groups like ShinyHunters, who have been increasingly targeting high-profile organizations through sophisticated attacks on cloud infrastructures. The breach highlights the critical need for robust cloud security measures and proactive threat detection to safeguard sensitive governmental data against such evolving cyber threats.
4 months ago
Kill Chain
Critical Fortinet FortiClientEMS Vulnerability Exploited in the Wild
In February 2026, a critical SQL injection vulnerability, CVE-2026-21643, was identified in Fortinet's FortiClientEMS version 7.4.4. This flaw allows unauthenticated attackers to execute arbitrary code via specially crafted HTTP requests, potentially leading to full system compromise. Fortinet released a patch in version 7.4.5 to address this issue. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-21643/?utm_source=openai)) As of March 2026, reports indicate active exploitation of this vulnerability in the wild, underscoring the urgency for organizations to apply the available patch promptly.
4 months ago
Kill Chain
Critical F5 BIG-IP RCE Vulnerability Discovered in 2026
In March 2026, F5 Networks reclassified a previously identified denial-of-service (DoS) vulnerability in its BIG-IP Access Policy Manager (APM) as a critical remote code execution (RCE) flaw, designated CVE-2025-53521. This vulnerability allows unauthenticated attackers to execute arbitrary code on systems with specific configurations, leading to potential deployment of webshells and unauthorized access. The flaw affects BIG-IP APM systems with access policies configured on virtual servers. The reclassification underscores the evolving nature of cybersecurity threats, where initial assessments may underestimate the severity of vulnerabilities. Organizations relying on BIG-IP APM for access management are urged to apply the latest patches promptly to mitigate the risk of exploitation.
4 months ago
Kill Chain
Apple Introduces Terminal Warning in macOS to Combat ClickFix Attacks
In March 2026, Apple released macOS Tahoe 26.4, introducing a security feature designed to combat 'ClickFix' attacks—a social engineering tactic where users are deceived into pasting malicious commands into the Terminal under the guise of troubleshooting or verification processes. This new mechanism delays the execution of potentially harmful commands pasted into the Terminal and presents a warning message to the user, highlighting the associated risks and advising caution. Users have the option to cancel the action or proceed if they understand the command's implications. The implementation of this feature underscores the growing prevalence of ClickFix attacks targeting macOS users. By integrating this warning system, Apple aims to enhance user awareness and prevent inadvertent execution of malicious commands, thereby strengthening the overall security posture of macOS systems.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports