The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Understanding the REMUS Infostealer: A 2026 Cybersecurity Threat
In early 2026, the REMUS infostealer emerged as a significant threat in the cybercrime landscape. Evolving from the Lumma Stealer family, REMUS introduced advanced capabilities such as session theft, targeting password managers, and utilizing blockchain-based command-and-control mechanisms. Its rapid development and commercialization reflect a shift towards malware-as-a-service (MaaS) models, enabling continuous updates and operational scalability. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/inside-the-remus-infostealer-session-theft-maas-and-rapid-evolution/?utm_source=openai)) The emergence of REMUS underscores the increasing sophistication of cyber threats, highlighting the need for organizations to enhance their security measures against evolving malware tactics and the growing prevalence of MaaS platforms.
4 months ago
Kill Chain
Node-ipc npm Package Compromised: A Wake-Up Call for Open-Source Security
In May 2026, malicious versions of the widely used node-ipc npm package were published, introducing credential-stealing malware into applications. The compromised versions—9.1.6, 9.2.3, and 12.0.1—contained obfuscated code that, upon execution, harvested sensitive information such as cloud credentials, SSH keys, and CI/CD secrets. This data was exfiltrated through DNS TXT queries to attacker-controlled infrastructure. The attack was facilitated by the compromise of a maintainer's account, allowing unauthorized publication of these malicious versions. ([stepsecurity.io](https://www.stepsecurity.io/blog/node-ipc-npm-supply-chain-attack?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting open-source ecosystems. Developers and organizations must remain vigilant, implementing robust security measures to detect and prevent such compromises, as the reliance on third-party packages continues to grow.
4 months ago
Kill Chain
Pwn2Own Berlin 2026: Critical Zero-Day Exploits in Microsoft Exchange and Windows 11
During the second day of Pwn2Own Berlin 2026, security researchers demonstrated 15 unique zero-day vulnerabilities across multiple products, including Microsoft Exchange, Windows 11, and Red Hat Enterprise Linux for Workstations. Notably, Cheng-Da Tsai of the DEVCORE Research Team earned $200,000 by chaining three bugs to achieve remote code execution with SYSTEM privileges on Microsoft Exchange. Additionally, Siyeon Wi exploited an integer overflow bug to hack Windows 11, and Ben Koo of Team DDOS escalated privileges to root on Red Hat Enterprise Linux for Workstations, earning $7,500 and $10,000 respectively. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/windows-11-and-microsoft-edge-hacked-on-first-day-of-pwn2own-berlin-2026/?utm_source=openai)) This incident underscores the persistent vulnerabilities in widely used enterprise software and highlights the critical need for organizations to prioritize timely patching and robust security measures to mitigate the risks associated with zero-day exploits.
4 months ago
Kill Chain
Turla's Kazuar Backdoor Evolves into Modular P2P Botnet
In May 2026, the Russian state-sponsored hacking group Turla, also known as Secret Blizzard, transformed its custom backdoor, Kazuar, into a modular peer-to-peer (P2P) botnet designed for stealth and persistent access to compromised hosts. This evolution includes three distinct modules: Kernel, Bridge, and Worker, each serving specific roles to enhance flexibility and reduce detection. The Kernel module coordinates tasks and manages communication, the Bridge module acts as a proxy to the command-and-control server, and the Worker module performs data collection and system monitoring. This modular architecture allows Turla to maintain long-term access to targeted systems, primarily within government, diplomatic, and defense sectors in Europe and Central Asia. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/05/14/kazuar-anatomy-of-a-nation-state-botnet/?utm_source=openai)) The significance of this development lies in the increasing sophistication of state-sponsored cyber threats. Turla's adoption of a modular P2P botnet architecture exemplifies a trend towards more resilient and stealthy malware, posing heightened challenges for detection and mitigation. Organizations must enhance their cybersecurity measures to address these evolving threats effectively.
4 months ago
Kill Chain
Critical Nginx UI Vulnerability (CVE-2026-33032) Exposes Servers to Full Takeover
In March 2026, a critical vulnerability (CVE-2026-33032) was discovered in Nginx UI, a web-based management interface for Nginx servers. This flaw, present in versions up to 2.3.5, allows unauthenticated remote attackers to gain full control over the Nginx service by exploiting the /mcp_message endpoint, which lacks proper authentication and has an empty default IP whitelist. Attackers can restart the server, modify configurations, and trigger automatic reloads, leading to complete service takeover. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-33032?utm_source=openai)) The urgency to address this vulnerability is heightened by active exploitation in the wild, with numerous exposed instances globally. Organizations using affected versions are strongly advised to update to the latest release or implement recommended mitigations to prevent potential breaches and service disruptions. ([network-security-magazine.com](https://www.network-security-magazine.com/network-security/network-security-news/nginx-ui-cve-2026-33032-actively-exploited/?utm_source=openai))
4 months ago
Kill Chain
OpenAI's Response to the TanStack npm Supply Chain Attack
In May 2026, OpenAI disclosed that two employee devices were compromised due to a supply chain attack involving the TanStack npm library, part of the broader 'Mini Shai-Hulud' campaign. The attackers published 84 malicious versions across 42 TanStack packages, leading to unauthorized access and credential-focused exfiltration activities. OpenAI's investigation confirmed that only limited credential material was exfiltrated, with no evidence of user data, production systems, or intellectual property being compromised. ([openai.com](https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack/?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting widely used open-source libraries, emphasizing the need for robust security measures in software development and deployment processes. Organizations are urged to enhance their monitoring and validation of third-party components to mitigate such risks.
4 months ago
Kill Chain
mdrfckr Campaign Adopts Updated SSH Client in April 2026 Attacks
Between April 14 and April 21, 2026, a DShield sensor detected 24 unique IP addresses executing the 'mdrfckr' campaign, a known botnet operation active since 2018. The attackers utilized the SSH client banner 'SSH-2.0-libssh_0.11.1' and produced the hassh fingerprint '03a80b21afa810682a776a7d42e5e6fb', indicating an evolution in their tooling. The campaign's tactics, including writing a persistent SSH key and executing reconnaissance commands, remained consistent with previous observations. This incident underscores the adaptability of threat actors in updating their tools while maintaining established attack methodologies. Organizations should enhance their detection capabilities to identify new SSH client fingerprints associated with known malicious campaigns.
4 months ago
Kill Chain
FrostyNeighbor's 2026 Cyberattack on Ukrainian Government: A Detailed Analysis
In March 2026, the Belarus-aligned cyberespionage group FrostyNeighbor launched a sophisticated spear-phishing campaign targeting Ukrainian governmental organizations. The attackers distributed malicious PDF documents impersonating the Ukrainian telecommunications company Ukrtelecom. These PDFs contained links that, upon clicking, led to a multi-stage infection chain. If the victim's IP address was identified as Ukrainian, the server delivered a malicious RAR archive containing a JavaScript-based downloader known as PicassoLoader. This downloader collected system information and, upon validation, deployed a Cobalt Strike beacon, granting the attackers remote control over the compromised systems. ([welivesecurity.com](https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors in Eastern Europe, highlighting the increasing sophistication of phishing campaigns and the use of geofencing to target specific regions. Organizations must remain vigilant against such targeted attacks, especially those employing multi-stage infection chains and advanced payloads like Cobalt Strike.
4 months ago
Kill Chain
Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files
In May 2026, Palo Alto Networks' Unit 42 identified a new variant of the Gremlin Stealer malware, which has evolved from a basic credential harvester into a sophisticated modular toolkit. This variant employs advanced obfuscation techniques, including concealing malicious payloads within embedded resource files and utilizing instruction virtualization to evade detection. Gremlin Stealer targets sensitive information such as payment card details, browser cookies, session tokens, cryptocurrency wallet data, and FTP and VPN credentials, exfiltrating this data to attacker-controlled servers for potential exploitation. The rapid evolution of Gremlin Stealer underscores a broader trend in the cyber threat landscape, where infostealers are becoming more sophisticated and harder to detect. This development highlights the urgent need for organizations to enhance their cybersecurity measures, particularly in monitoring and defending against advanced malware that employs complex evasion tactics.
4 months ago
Kill Chain
Fragnesia (CVE-2026-46300): Critical Linux Kernel Privilege Escalation Vulnerability
In May 2026, a critical vulnerability known as Fragnesia (CVE-2026-46300) was discovered in the Linux kernel's XFRM ESP-in-TCP subsystem. This flaw allows unprivileged local attackers to gain root privileges by writing arbitrary bytes to the kernel page cache of read-only files. Security researcher William Bowling identified this issue and released a proof-of-concept exploit demonstrating its potential impact. The vulnerability affects all Linux kernels released before May 13, 2026, and is part of the broader 'Dirty Frag' class of vulnerabilities. The disclosure of Fragnesia underscores the ongoing challenges in securing the Linux kernel against privilege escalation attacks. With public exploits available and patches being rolled out, organizations must prioritize updating their systems to mitigate potential threats. This incident highlights the importance of proactive vulnerability management and the need for continuous monitoring of emerging security flaws.
4 months ago
Kill Chain
NGINX Vulnerability CVE-2026-42945: What You Need to Know
In May 2026, a critical vulnerability (CVE-2026-42945) was discovered in NGINX's ngx_http_rewrite_module, affecting versions 0.6.27 through 1.30.0. This heap buffer overflow flaw can be exploited by unauthenticated attackers using specially crafted HTTP requests, leading to denial-of-service conditions and, under certain configurations, remote code execution. The issue arises when NGINX configurations utilize both 'rewrite' and 'set' directives, a common pattern in API gateways and reverse proxy setups. The discovery of this 18-year-old vulnerability underscores the importance of regular code audits and timely patching. Given NGINX's widespread use across various industries, organizations are urged to update to the latest versions to mitigate potential risks associated with this flaw.
4 months ago
Kill Chain
KongTuke's Innovative Use of Microsoft Teams to Deploy ModeloRAT Malware
In April 2026, the threat actor KongTuke initiated a campaign leveraging Microsoft Teams to impersonate internal IT support staff. By contacting employees through external Teams chats, they persuaded victims to execute a malicious PowerShell command, leading to the deployment of ModeloRAT malware. This tactic enabled KongTuke to establish persistent access to corporate networks within minutes, facilitating data exfiltration and potential ransomware attacks. This incident underscores a significant shift in cybercriminal strategies, highlighting the exploitation of trusted communication platforms for social engineering. The rapid execution and effectiveness of this method emphasize the need for organizations to reassess and strengthen their security protocols, particularly concerning collaboration tools.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports