The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
TeamPCP Hackers Advertise Mistral AI Code Repositories for Sale
In May 2026, the TeamPCP hacker group infiltrated Mistral AI's codebase management system, exfiltrating nearly 5 gigabytes of internal repositories and source code. This breach was part of the broader 'Mini Shai-Hulud' supply-chain attack, which compromised official packages from TanStack and Mistral AI through stolen CI/CD credentials and legitimate workflows. The attackers are now demanding $25,000 for the stolen data, threatening to leak it publicly if a buyer isn't found within a week. This incident underscores the escalating threat of supply-chain attacks targeting software development processes. Organizations must prioritize securing their CI/CD pipelines and implement robust monitoring to detect unauthorized access promptly.
4 months ago
Kill Chain
May 2026 Cybersecurity Incidents: PAN-OS RCE Exploitation and AI's Role in Vulnerability Detection
In May 2026, multiple critical cybersecurity incidents emerged, notably the exploitation of a buffer overflow vulnerability (CVE-2026-0300) in Palo Alto Networks' PAN-OS User-ID Authentication Portal, allowing unauthenticated attackers to execute arbitrary code with root privileges. Additionally, Anthropic's AI model, Mythos, identified a low-severity vulnerability in the widely-used cURL tool, sparking debates about the efficacy of AI in vulnerability detection. These incidents underscore the persistent challenges in securing network infrastructure and the evolving role of AI in cybersecurity. The active exploitation of the PAN-OS vulnerability highlights the urgency for organizations to apply patches promptly and reassess their exposure to untrusted networks. Simultaneously, the discourse surrounding Mythos's findings emphasizes the need for a balanced approach to integrating AI tools in security workflows, ensuring they complement human expertise without overreliance.
4 months ago
Kill Chain
Malicious 'node-ipc' Versions Compromise Developer Credentials
On May 14, 2026, malicious versions of the widely used npm package 'node-ipc' were published, specifically versions 9.1.6, 9.2.3, and 12.0.1. These versions contained obfuscated backdoor code designed to steal developer credentials, including cloud service keys, SSH keys, and other sensitive information. The malware executed upon requiring the package, exfiltrating data to an attacker-controlled server. The compromised versions were published by an unauthorized account, indicating a potential maintainer account takeover. ([thehackernews.com](https://thehackernews.com/2026/05/stealer-backdoor-found-in-3-node-ipc.html?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting open-source ecosystems. Developers and organizations must remain vigilant, implementing robust security measures to detect and prevent such compromises. The event highlights the necessity for continuous monitoring and verification of third-party dependencies to safeguard against unauthorized code injections.
4 months ago
Kill Chain
Inside the Breach: Unveiling 'The Gentlemen' Ransomware Group's Operations
In early May 2026, the ransomware group known as 'The Gentlemen' suffered a significant data breach when an anonymous entity compromised their internal backend database. This breach exposed approximately 16GB of internal communications, tools, and operational data, which were subsequently offered for sale on underground forums. The leaked information provided unprecedented insight into the group's organizational structure, revealing a hierarchical system led by an individual known as 'zeta88,' who oversees operations, target selection, and ransom negotiations. The group employs a generous affiliate model, offering a 90/10 payout split, and utilizes a variety of tools and techniques, including AI-assisted coding, to enhance their ransomware development and deployment processes. ([darkreading.com](https://www.darkreading.com/threat-intelligence/gentlemen-raas-gang-data-leak?utm_source=openai)) This incident underscores the evolving landscape of cyber threats, highlighting the increasing sophistication and organizational complexity of ransomware groups. The exposure of 'The Gentlemen's' internal operations offers valuable intelligence for cybersecurity professionals, enabling the development of more effective defense strategies against similar threats. Additionally, the breach serves as a reminder of the potential vulnerabilities within cybercriminal organizations themselves, which can be exploited to disrupt their activities. ([blog.checkpoint.com](https://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk/?utm_source=openai))
4 months ago
Kill Chain
GemStuffer: A New Frontier in Supply Chain Attacks Exploiting RubyGems
In May 2026, a campaign named 'GemStuffer' exploited over 150 RubyGems packages to exfiltrate data scraped from UK local government portals. Unlike typical supply chain attacks that aim to distribute malware to developers, this operation utilized the RubyGems registry as a storage and retrieval channel for the exfiltrated data. The attackers published numerous packages containing scripts that collected public data from government websites and then uploaded this data back to RubyGems, effectively using the platform as a 'dead drop' for data storage. This method allowed the threat actors to bypass traditional command-and-control infrastructures, making detection more challenging. ([thecodingzebra.com](https://www.thecodingzebra.com/cybersecurity/gemstuffer-abuses-150-rubygems/?utm_source=openai)) This incident underscores a novel abuse of software package registries, highlighting the need for enhanced monitoring and security measures within these ecosystems. The use of legitimate platforms for data exfiltration represents an evolution in threat actor tactics, emphasizing the importance of vigilance in software supply chain security. ([cyberleveling.com](https://cyberleveling.com/blog/rubygems-gemstuffer-supply-chain-2026?utm_source=openai))
4 months ago
Kill Chain
NGINX Rift: Unveiling the 18-Year-Old CVE-2026-42945 Vulnerability
In May 2026, a critical vulnerability (CVE-2026-42945) was discovered in NGINX's ngx_http_rewrite_module, present since 2008. This heap buffer overflow flaw allows unauthenticated attackers to send crafted HTTP requests, potentially causing worker process crashes or remote code execution, especially on systems with Address Space Layout Randomization (ASLR) disabled. The issue affects NGINX Plus and NGINX Open Source versions up to 1.30.0 and has been patched in subsequent releases. The disclosure of this 18-year-old vulnerability underscores the importance of regular code audits and timely patching. With NGINX's widespread use across the internet, organizations are urged to update their systems promptly to mitigate potential exploitation risks.
4 months ago
Kill Chain
Fragnesia (CVE-2026-46300): Critical Linux Kernel Vulnerability Grants Root Access
On May 13, 2026, security researcher William Bowling of the V12 security team disclosed a critical local privilege escalation vulnerability in the Linux kernel, dubbed 'Fragnesia' and tracked as CVE-2026-46300. This flaw resides in the XFRM ESP-in-TCP subsystem and allows unprivileged local attackers to modify read-only files in the kernel page cache, leading to root access without requiring race conditions. A proof-of-concept exploit has been released, and patches are currently being developed by major Linux distributions. ([almalinux.org](https://almalinux.org/blog/2026-05-13-fragnesia-cve-2026-46300/?utm_source=openai)) This vulnerability is particularly concerning as it follows two similar high-severity Linux kernel flaws—'Copy Fail' and 'Dirty Frag'—disclosed within the past two weeks, indicating a troubling trend of critical vulnerabilities in core kernel components. ([threataft.com](https://threataft.com/articles/fragnesia-linux-kernel-local-privilege-escalation?utm_source=openai))
4 months ago
Kill Chain
Ghostwriter's Geofenced Phishing Attack on Ukrainian Government
In March 2026, the Belarus-aligned threat group known as Ghostwriter initiated a sophisticated cyber attack targeting Ukrainian governmental organizations. The attackers employed spear-phishing emails containing malicious PDF attachments that impersonated the Ukrainian telecommunications company Ukrtelecom. These PDFs included links leading to RAR archives with JavaScript payloads designed to deploy PicassoLoader, which subsequently installed Cobalt Strike for command and control operations. Notably, the attack incorporated geofencing techniques to deliver malicious content exclusively to users with Ukrainian IP addresses, thereby evading detection and analysis by external entities. This campaign underscores Ghostwriter's persistent and adaptive tactics in cyber espionage, particularly against Eastern European targets. ([thehackernews.com](https://thehackernews.com/2026/05/ghostwriter-targets-ukrainian.html?utm_source=openai)) The incident highlights a concerning trend of state-sponsored cyber attacks leveraging advanced evasion techniques and targeting critical governmental infrastructure. Organizations must remain vigilant against such evolving threats, emphasizing the need for robust cybersecurity measures and continuous monitoring to detect and mitigate sophisticated phishing campaigns and malware deployments.
4 months ago
Kill Chain
Securing AI Applications: Addressing Exploitable Misconfigurations
In May 2026, Microsoft Defender Security Research Team identified critical misconfigurations in AI applications deployed on cloud-native platforms. These misconfigurations, including publicly exposed services with weak or missing authentication, were actively exploited by attackers to achieve remote code execution, credential theft, and unauthorized access to sensitive internal tools and data. The incidents underscore the importance of secure configurations in AI deployments to prevent low-effort, high-impact attacks. The prevalence of such exploitable misconfigurations highlights a growing trend where threat actors target improperly configured AI services. This trend necessitates immediate attention to secure deployment practices and continuous monitoring to mitigate potential risks associated with AI workloads.
4 months ago
Kill Chain
Understanding Supply Chain Risks: Lessons from 'postmark-mcp' and ClawHub Incidents
In September 2025, a malicious update to the 'postmark-mcp' package on npm introduced a backdoor that blind carbon copied (BCC) all outgoing emails to an attacker-controlled address, compromising sensitive information. This incident underscores the inherent risks in software supply chains, particularly when malicious code is introduced into widely used packages. Similarly, the ClawHub marketplace faced significant security challenges when numerous malicious skills were uploaded, leading to credential harvesting and data exfiltration. These events highlight the critical need for rigorous vetting and monitoring of third-party components to prevent unauthorized data access and maintain system integrity.
4 months ago
Kill Chain
Anthropic's Mythos AI: Revolutionizing Cybersecurity or Unleashing New Threats?
In April 2026, Anthropic introduced 'Claude Mythos Preview,' an advanced AI model capable of autonomously identifying and exploiting zero-day vulnerabilities across major operating systems and web browsers. This model uncovered thousands of high-severity vulnerabilities, including a 27-year-old bug in OpenBSD and a 2010 flaw in FFmpeg's H.264 codec. Due to its potent capabilities, Anthropic restricted access to Mythos, providing it only to select organizations to mitigate potential misuse. ([tomshardware.com](https://www.tomshardware.com/tech-industry/artificial-intelligence/anthropics-latest-ai-model-identifies-thousands-of-zero-day-vulnerabilities-in-every-major-operating-system-and-every-major-web-browser-claude-mythos-preview-sparks-race-to-fix-critical-bugs-some-unpatched-for-decades?utm_source=openai)) The emergence of Mythos underscores a significant shift in cybersecurity, highlighting the dual-use nature of AI technologies. While such models can bolster defensive measures by rapidly identifying vulnerabilities, they also pose risks if exploited by malicious actors. This development has prompted discussions among policymakers and industry leaders about the need for stringent regulations and responsible deployment of AI in cybersecurity. ([scientificamerican.com](https://www.scientificamerican.com/article/what-is-mythos-and-why-are-experts-worried-about-anthropics-ai-model/?utm_source=openai))
4 months ago
Kill Chain
Critical Exim Vulnerability CVE-2026-45185: Immediate Action Required
In May 2026, a critical vulnerability identified as CVE-2026-45185 was discovered in Exim, a widely used open-source mail transfer agent. This use-after-free flaw in certain GnuTLS configurations allows unauthenticated remote attackers to execute arbitrary code by exploiting the BDAT body parsing path during TLS shutdown. The vulnerability affects Exim versions 4.97 through 4.99.2 when built with GnuTLS and with STARTTLS and CHUNKING enabled. Exploitation could lead to unauthorized access to email data and potential further compromise of affected systems. ([thehackerwire.com](https://www.thehackerwire.com/vulnerability/CVE-2026-45185/?utm_source=openai)) The discovery of this vulnerability underscores the ongoing risks associated with widely deployed open-source software and the importance of timely patching. The incident also highlights the evolving landscape of cyber threats, where attackers increasingly target foundational internet services to gain broad access.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports