The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Europol Dismantles 'First VPN' Used by Cybercriminals
In May 2026, a coordinated international operation led by French and Dutch authorities, with support from Europol and Eurojust, successfully dismantled 'First VPN,' a virtual private network service extensively utilized by cybercriminals to conceal their identities and illicit activities. The operation resulted in the seizure of 33 servers, the shutdown of multiple domains, and the identification of thousands of users linked to cybercrime, including ransomware attacks and data theft. ([europol.europa.eu](https://www.europol.europa.eu/media-press/newsroom/news/cybercriminal-vpn-used-ransomware-actors-dismantled-in-global-crackdown?utm_source=openai)) The takedown of 'First VPN' underscores the increasing effectiveness of international law enforcement collaboration in targeting cybercriminal infrastructure. This action not only disrupts a critical tool for cybercriminals but also provides authorities with valuable intelligence to pursue ongoing investigations into various cyber offenses. ([eurojust.europa.eu](https://www.eurojust.europa.eu/news/eurojust-coordinated-investigation-shuts-down-criminal-vpn-network?utm_source=openai))
4 months ago
Kill Chain
AI Uncovers Critical macOS Kernel Vulnerability in Record Time
In May 2026, cybersecurity firm Calif utilized Anthropic's advanced AI model, Mythos Preview, to identify and exploit a kernel memory corruption vulnerability in Apple's macOS 26.4.1 running on M5 silicon. This exploit enabled privilege escalation from an unprivileged user to root access by chaining two vulnerabilities, effectively bypassing Apple's Memory Integrity Enforcement (MIE) system, a hardware-assisted security feature introduced in 2025 to mitigate memory-based exploits. The discovery underscores the potential of AI in rapidly uncovering critical system vulnerabilities, as the exploit was developed within five days. ([9to5mac.com](https://9to5mac.com/2026/05/14/calif-team-details-how-anthropic-mythos-helped-build-a-working-macos-exploit-in-five-days/?utm_source=openai)) This incident highlights the evolving cybersecurity landscape where AI tools can both uncover and potentially exploit system vulnerabilities at unprecedented speeds. Organizations must reassess their security postures to address the dual-edged nature of AI in cybersecurity, balancing its defensive capabilities against the risks of adversarial use. ([techradar.com](https://www.techradar.com/pro/security/this-work-is-a-glimpse-of-what-is-coming-security-team-lays-out-how-anthropic-mythos-helped-build-a-working-macos-exploit-in-five-days?utm_source=openai))
4 months ago
Kill Chain
CISA Security Leak: A Wake-Up Call for Credential Management
In May 2026, a contractor for the U.S. Cybersecurity and Infrastructure Security Agency (CISA) inadvertently exposed highly sensitive credentials by maintaining a public GitHub repository named 'Private-CISA.' This repository contained plaintext passwords, AWS GovCloud keys, and internal documentation detailing CISA's software development and deployment processes. Security researcher Guillaume Valadon discovered the leak, describing it as the most severe government data exposure he had encountered. The repository had been publicly accessible since at least November 2025, raising significant concerns about operational security and potential unauthorized access to critical systems. This incident underscores the persistent risks associated with improper handling of sensitive credentials and the importance of stringent access controls. It highlights the need for organizations, especially those in critical infrastructure sectors, to enforce robust security practices, conduct regular audits, and ensure that contractors adhere to strict data protection protocols to prevent similar breaches.
4 months ago
Kill Chain
GitHub's 2026 Security Breach: A Supply Chain Attack via Malicious Nx Console Extension
In May 2026, GitHub experienced a significant security breach when an employee inadvertently installed a malicious version of the Nx Console Visual Studio Code extension. This compromised extension, linked to the TanStack npm supply-chain attack orchestrated by the TeamPCP threat group, granted unauthorized access to approximately 3,800 internal repositories. The attackers exfiltrated internal source code and sensitive operational data, subsequently offering the stolen data for sale at a minimum of $50,000. GitHub promptly responded by securing the compromised device, rotating critical secrets, and initiating a comprehensive investigation to assess the full impact of the breach. This incident underscores the escalating threat posed by sophisticated supply chain attacks targeting trusted development tools and platforms. The exploitation of widely used extensions like Nx Console highlights the necessity for heightened vigilance and robust security measures within the software development ecosystem to prevent similar breaches in the future.
4 months ago
Kill Chain
Microsoft Defender Zero-Day Vulnerabilities: CVE-2026-41091 and CVE-2026-45498
In May 2026, Microsoft disclosed two zero-day vulnerabilities in its Defender security platform: CVE-2026-41091 and CVE-2026-45498. CVE-2026-41091 is a privilege escalation flaw in the Microsoft Malware Protection Engine, allowing attackers to gain SYSTEM privileges through improper link resolution. CVE-2026-45498 is a denial-of-service vulnerability in the Microsoft Defender Antimalware Platform, enabling threat actors to disrupt Windows devices. Both vulnerabilities were actively exploited before patches were released. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added these vulnerabilities to its Known Exploited Vulnerabilities Catalog, mandating federal agencies to apply patches by June 3, 2026. This incident underscores the critical need for organizations to maintain up-to-date security measures and promptly address vulnerabilities in widely used security tools.
4 months ago
Kill Chain
Chinese Hackers Deploy New Malware Targeting Telecom Providers
In mid-2022, the Chinese state-sponsored group Calypso, also known as Red Lamassu, initiated a cyber-espionage campaign targeting telecommunications providers across the Asia Pacific and parts of the Middle East. The attackers employed two newly discovered malware strains: Showboat, a modular Linux post-exploitation framework, and JMFBackdoor, a Windows-based espionage implant. Showboat facilitates long-term persistence, data exfiltration, and lateral movement within networks by acting as a SOCKS5 proxy. JMFBackdoor offers capabilities such as remote command execution, file management, and system manipulation. The initial infection vectors remain unknown, but the threat actors utilized telecom-themed domains to impersonate their targets. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/chinese-hackers-target-telcos-with-new-linux-windows-malware/amp/?utm_source=openai)) This incident underscores a growing trend of sophisticated cyber-espionage campaigns targeting critical infrastructure sectors, particularly telecommunications. The use of advanced malware like Showboat and JMFBackdoor highlights the evolving tactics of state-sponsored actors and the necessity for robust cybersecurity measures to protect sensitive information and maintain operational integrity.
4 months ago
Kill Chain
International Operation Dismantles 'First VPN' Used by Cybercriminals
In May 2026, an international law enforcement operation led by France and the Netherlands, with support from Europol and Eurojust, dismantled 'First VPN,' a virtual private network service extensively used by cybercriminals to conceal ransomware attacks, data theft, and other serious offenses. The operation resulted in the seizure of 33 servers across 27 countries, the shutdown of associated domains, and the identification of numerous users. The administrator of the service was interviewed during a house search in Ukraine. 'First VPN' had been promoted on Russian-speaking cybercrime forums as a tool for anonymity, offering services designed specifically for criminal use. ([europol.europa.eu](https://www.europol.europa.eu/media-press/newsroom/news/cybercriminal-vpn-used-ransomware-actors-dismantled-in-global-crackdown?utm_source=openai)) This takedown underscores the increasing effectiveness of international cooperation in combating cybercrime infrastructure. It highlights the critical need for organizations to remain vigilant against services that facilitate illicit activities and to ensure robust cybersecurity measures are in place to protect against such threats.
4 months ago
Kill Chain
Unauthorized Access to Anthropic's Mythos AI Model Highlights Emerging Cybersecurity Risks
In April 2026, Anthropic's advanced AI model, Mythos, designed for identifying and exploiting software vulnerabilities, was accessed by unauthorized users through a third-party vendor. This breach raised significant concerns about the potential misuse of AI in cyberattacks, as Mythos has demonstrated the capability to uncover critical flaws across major operating systems and web browsers. The incident underscores the risks associated with AI-driven vulnerability discovery tools falling into the wrong hands, potentially enabling adversaries to exploit software weaknesses at an unprecedented scale. The unauthorized access to Mythos highlights the urgent need for robust security measures and governance frameworks to prevent the misuse of powerful AI tools in cybersecurity. As AI continues to evolve, organizations must reassess their security postures to address the accelerated pace of vulnerability discovery and exploitation facilitated by such technologies.
4 months ago
Kill Chain
GitHub Breach 2026: Lessons from the TeamPCP VS Code Extension Attack
In May 2026, GitHub experienced a significant security breach when an employee's device was compromised through a malicious Visual Studio Code (VS Code) extension. This attack, attributed to the threat group TeamPCP, led to the exfiltration of approximately 3,800 internal repositories. The attackers advertised the stolen data for sale on a cybercrime forum, seeking at least $50,000. GitHub responded by removing the malicious extension, isolating the affected endpoint, and rotating critical credentials to mitigate further risk. This incident underscores the escalating threat of supply chain attacks targeting development tools and environments. The use of poisoned extensions to infiltrate systems highlights the need for heightened vigilance and robust security measures within the software development lifecycle.
4 months ago
Kill Chain
Chinese APTs Deploy 'Showboat' Linux Backdoor in Central Asia Telco Attacks
In May 2026, Chinese state-aligned Advanced Persistent Threat (APT) groups were discovered using a Linux-based post-exploitation framework named 'Showboat' to infiltrate telecommunications companies in Central Asia. The malware enables attackers to scan and infect devices on local area networks (LANs) that are not connected to the public Internet, facilitating long-term espionage activities. Notably, the APT group Calypso has been identified leveraging Showboat alongside a Windows backdoor called 'JFMBackdoor' to target entities in Afghanistan, Kazakhstan, Turkey, and India. This incident underscores the evolving tactics of Chinese APTs in targeting critical infrastructure sectors, particularly telecommunications, using cross-platform malware to maintain persistent access and conduct intelligence gathering. The discovery of Showboat highlights the need for enhanced cybersecurity measures to detect and mitigate such sophisticated threats.
4 months ago
Kill Chain
GitHub Breach: Lessons in Securing Developer Tools Against Supply Chain Attacks
In May 2026, GitHub experienced a significant security breach when an employee's device was compromised through a malicious version of the Nx Console Visual Studio Code (VS Code) extension. This supply chain attack, orchestrated by the cybercriminal group TeamPCP, led to unauthorized access and exfiltration of approximately 3,800 internal repositories. The attackers exploited the compromised extension to harvest sensitive data, including source code and operational information. GitHub promptly detected the intrusion, removed the malicious extension, isolated the affected endpoint, and initiated an internal investigation to assess the full impact and prevent further unauthorized access. This incident underscores the escalating threat of supply chain attacks targeting developer tools and extensions. The rapid proliferation of such attacks highlights the critical need for organizations to implement stringent security measures, conduct regular audits of third-party tools, and foster a culture of security awareness among developers to mitigate potential vulnerabilities.
4 months ago
Kill Chain
Critical Linux Kernel Vulnerability Discovered After Nine Years
In May 2026, cybersecurity researchers disclosed a nine-year-old vulnerability in the Linux kernel, identified as CVE-2026-46333, also known as 'ssh-keysign-pwn'. This flaw allows unprivileged local users to access sensitive files and execute arbitrary commands with root privileges on default installations of major distributions like Debian, Fedora, and Ubuntu. The vulnerability originates from improper privilege management in the kernel's __ptrace_may_access() function, introduced in November 2016. Exploitation can lead to the disclosure of critical files such as /etc/shadow and SSH host private keys, posing significant security risks. The discovery of this long-standing vulnerability underscores the importance of continuous security assessments and prompt patching in open-source software. With a proof-of-concept exploit publicly available, organizations are urged to apply the latest kernel updates immediately to mitigate potential threats.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports