Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Workflow Identity Hijacking: The New AI Attack Vector Bypassing Enterprise Security
Security researchers at Noma Labs have identified a new AI attack vector called 'workflow identity hijacking' that exploits authorization design flaws in enterprise AI pipelines. The attack allows threat actors to bypass standard security controls by sending seemingly benign requests through unauthenticated entry points like support emails or web forms. The AI workflow processes these requests using high-privilege service accounts, enabling unauthorized data access and exfiltration without traditional prompt injection techniques. This represents a fundamental shift from model manipulation to identity delegation vulnerabilities in AI systems. This attack vector is particularly relevant now as organizations rapidly deploy AI automation without proper identity scoping and least privilege principles, creating widespread exposure to data breaches through seemingly legitimate AI interactions.
1 week ago
Kill Chain
Critical N-able N-central RCE Vulnerability Exploited: MSP Supply Chain Under Attack
In September 2026, CISA added CVE-2026-86218, a maximum-severity remote code execution vulnerability in N-able N-central, to its Known Exploited Vulnerabilities catalog after evidence of active exploitation in the wild. The pre-authentication static code injection flaw allows attackers to execute arbitrary code without authentication on N-central servers, which are widely used by managed service providers (MSPs) and large IT organizations to manage entire customer environments. Huntress reported investigating a compromise of a customer's fully patched N-central production environment, though the exact exploit vector remains unclear. The vulnerability was patched in N-central 2026.3 Hotfix 4, but organizations must also hunt for indicators of compromise as patching alone may be insufficient. This incident highlights the escalating threat to MSP infrastructure as ransomware groups increasingly target supply chain chokepoints to maximize their reach across multiple organizations simultaneously.
1 week ago
Kill Chain
Microsoft's Record 974-Vulnerability Patch Release Signals AI-Driven Security Era
In September 2026, Microsoft released a record-breaking security update addressing 974 vulnerabilities across its software portfolio, including two actively exploited zero-day flaws (CVE-2026-85880 and CVE-2026-81963). Both zero-days are privilege escalation vulnerabilities affecting Windows Advanced Local Procedure Call and Windows Update Stack respectively, allowing attackers to gain SYSTEM-level privileges. The massive patch release included 723 Windows vulnerabilities, 111 Office flaws, and over 110 critical severity issues, bringing Microsoft's 2026 total to over 2,600 patches - more than double the previous annual record. This unprecedented vulnerability disclosure reflects the acceleration of AI-assisted security research and automated vulnerability discovery tools. The scale demonstrates how artificial intelligence is revolutionizing both offensive security research and defensive patching cycles, fundamentally changing the threat landscape and forcing organizations to adapt their vulnerability management strategies for an era of exponential security disclosure growth.
1 week ago
Kill Chain
cPanel SQL Injection Flaw CVE-2026-67401 Enables Complete Server Takeover
cPanel disclosed CVE-2026-67401, a critical SQL injection vulnerability in its EmailTrack functionality that allows authenticated hosting account holders with mail privileges to escalate to root access on entire servers. The flaw affects all supported versions of cPanel and WHM, enabling attackers to create arbitrary files and execute code with administrative privileges. This represents a complete server compromise where attackers can access all hosting accounts, install malware, steal credentials, and pivot into customer networks. cPanel has released patches across multiple release lines including 11.110, 11.134, 11.136, and 11.138. This incident highlights the continuing trend of hosting platform vulnerabilities that enable tenant-to-host escalation attacks. Following similar cPanel flaws disclosed in April, July, and August 2026, hosting providers face increased scrutiny over multi-tenant security boundaries and the cascading impact of single vulnerabilities affecting thousands of customer websites.
1 week ago
Kill Chain
Chinese AI Companies Accused of Massive Intellectual Property Theft Through Model Distillation
U.S. intelligence agencies NSA, CISA, and FBI have accused Chinese AI companies including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of conducting systematic industrial-scale distillation attacks against American frontier AI models since late 2024. These companies extracted billions of tokens from Anthropic Claude, OpenAI GPT, Google Gemini, and SpaceXAI Grok models through bulk premium subscriptions, API abuse, and proxy networks to circumvent geographic restrictions. The attacks violated terms of service and resulted in significantly reduced development timelines and costs for Chinese AI models while undermining intellectual property protections of U.S. companies. This incident highlights the evolving landscape of AI-powered intellectual property theft and the increasing sophistication of state-sponsored technology transfer operations, demonstrating how legitimate AI research techniques can be weaponized for competitive advantage at national scales.
1 week ago
Kill Chain
Industrial-Scale AI Theft: How Chinese Companies Systematically Extracted US Frontier Model Capabilities
Since late 2024, Chinese artificial intelligence companies including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have conducted systematic industrial-scale knowledge distillation campaigns against U.S. frontier AI models including Claude, GPT, Gemini, and Grok. These companies extracted billions of tokens across millions of API requests, violating terms of service while using sophisticated techniques including chain-of-thought reasoning extraction, automated failover systems, and gray market proxy networks to bypass geographic restrictions. The campaigns represent a core component of Chinese AI development strategy rather than supplementary research, enabling significantly reduced development costs and accelerated model training timelines while threatening U.S. technological leadership in artificial intelligence. This incident highlights the emerging threat of AI model theft through systematic knowledge distillation, representing a new category of intellectual property theft that combines traditional cybersecurity evasion techniques with advanced AI research methodologies, requiring coordinated industry-wide defensive measures.
1 week ago
Kill Chain
Critical AI Security Gap: DeepSeek Harness Sandbox Escape Exposes Autonomous Agent Risks
In August 2026, a critical vulnerability (CVE-2026-82533) was discovered in DeepSeek Harness, an open-source AI coding agent tool with over 216,000 GitHub stars. The flaw allowed sandboxed AI agents to disable their own security sandbox through a single command, bypassing file system protections designed to prevent untrusted code execution. Attackers could exploit this by supplying malicious text that prompted the agent to call the tool's local web interface, switching to 'danger-full-access' mode without approval prompts. The vulnerability stemmed from inadequate authentication on the local interface and improper host header validation, enabling both local sandbox escapes and potential remote exploitation through port forwarding. This incident highlights the growing security challenges in AI development tools as organizations increasingly adopt autonomous coding agents. The vulnerability demonstrates how AI agents can be manipulated to bypass their own safety mechanisms, representing a new class of security risks in the rapidly expanding AI development ecosystem.
1 week ago
Kill Chain
Massive Infostealer Campaign Exposes Thousands of AI Service Tokens, Bypassing MFA Protection
In August 2026, cybersecurity researchers analyzed a 7GB infostealer dump containing data from 5,871 infected machines across 162 countries, revealing thousands of unexpired authentication tokens for AI services including Google, OpenAI, Anthropic, and others. Information stealers like Lumma Stealer and Vidar harvested session tokens, API keys, and JSON Web Tokens (JWTs) that threat actors can replay to bypass credential-based authentication and multi-factor authentication, effectively gaining unauthorized access to premium AI services without traditional login processes. The stolen data included 555 AI-related JWTs and 2,937 encrypted tokens, with 17.7% containing plaintext personally identifiable information, enabling account takeovers, resource theft, and unauthorized AI service usage sold on underground markets. This incident highlights the growing cybercriminal focus on AI credential theft as premium model access costs create strong financial incentives for stealing rather than purchasing legitimate access, while the proliferation of anti-detect browsers and session replay tools makes monetizing these stolen tokens increasingly accessible to threat actors.
1 week ago
Kill Chain
CIA's Operation Absolute Resolve Showcases Cyber Intelligence as Mission-Critical Capability
CIA Deputy Director Michael Ellis revealed that Operation Absolute Resolve, which led to the apprehension of Nicolás Maduro, was enabled by cyber intelligence operations conducted by the agency's Center for Cyber Intelligence. The mission demonstrated how the CIA has reorganized to place cyber operations at the center of intelligence collection, allowing U.S. special operations forces to locate and capture the target within four minutes of landing. The operation reportedly included cyberattacks that caused power outages during the mission, showcasing the integration of cyber capabilities with traditional field operations. This disclosure highlights the evolving role of cyber intelligence in modern military and intelligence operations, as nation-state actors increasingly rely on digital capabilities to support kinetic operations and achieve strategic objectives in contested environments.
1 week ago
Kill Chain
Russian National's $6.3M Bank Account Takeover Scheme Exposes Critical Security Gaps
In November 2023, Russian national Sergei Anatolyevich Filimonov orchestrated a sophisticated bank account takeover scheme that defrauded financial institutions of over $6.3 million. The operation involved creating spoofed banking domains, purchasing sponsored search links to redirect victims, and harvesting over 5,000 customer login credentials. The cybercriminals specifically targeted accounts with large balances, including those belonging to corporate employees in Georgia, and built infrastructure to bypass multi-factor authentication and other security controls. This case exemplifies the growing sophistication of financially motivated cybercriminals who combine social engineering, domain spoofing, and credential harvesting to target high-value accounts. The FBI's identification of $28 million in total attempted losses demonstrates the massive scale these operations can achieve.
1 week ago
Kill Chain
Chinese AI Giants Caught in Massive U.S. Model Distillation Campaign
In 2024, Chinese AI companies including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI engaged in systematic distillation of U.S. frontier AI models according to a joint advisory from NSA, CISA, and FBI. The companies spent billions of tokens across millions of exchanges with models like Claude, ChatGPT, Google Gemini, and xAI's Grok to extract proprietary capabilities and strengthen their domestic AI systems. The attackers used sophisticated evasion techniques including distributed accounts, proxy networks, third-party aggregators, and gray market access to circumvent geographic restrictions and detection mechanisms. This incident highlights the growing threat of AI-enabled economic espionage as artificial intelligence becomes central to national competitiveness, with state-sponsored actors leveraging legitimate AI APIs for large-scale intellectual property theft through automated distillation campaigns.
1 week ago
Kill Chain
Microsoft's Record-Breaking Patch Tuesday: Managing 974 Vulnerabilities in the AI Era
Microsoft released its largest-ever Patch Tuesday update in September 2026, addressing 974 vulnerabilities across its product suite, including two actively exploited zero-day vulnerabilities. The massive security update included CVE-2026-81963 affecting the Windows Update Stack and CVE-2026-85880 affecting Windows Advanced Local Procedure Call, both enabling privilege escalation attacks. Microsoft's use of AI-assisted vulnerability discovery has dramatically increased the volume of disclosed vulnerabilities, with over 100 rated as critical across Windows, Office, SQL Server, and developer tools. Despite the record-breaking number of vulnerabilities, security researchers noted that active exploitation rates have not increased proportionally. This incident highlights the growing challenge organizations face in vulnerability management as AI-driven discovery tools uncover more security flaws at an unprecedented pace. The massive patch volume reflects broader industry trends where automated security research is creating larger attack surfaces while simultaneously improving defensive capabilities through faster identification of potential weaknesses.
1 week ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports