Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Microsoft's Record-Breaking Windows 10 Security Update: 966 Vulnerabilities Patched
Microsoft released Windows 10 KB5122878 as part of the September 2026 extended security update program, addressing a record-breaking 966 vulnerabilities including two actively exploited zero-day flaws. This update targets Windows 10 Enterprise LTSC users and ESU program participants, bringing systems to build 19045.7725 with critical security patches, Secure Boot certificate improvements, and fixes for Remote Desktop audio redirection issues. The massive patch release underscores the ongoing security challenges facing legacy Windows environments as Microsoft phases out mainstream support. This update highlights the critical importance of extended security programs as organizations struggle to migrate from Windows 10 amid escalating cyber threats and the growing attack surface of unpatched legacy systems.
1 week ago
Kill Chain
Slim Spider's Cloud-Native Attack on Brazilian Financial Infrastructure Exposes Critical Security Gaps
In March 2026, the Brazil-based threat actor Slim Spider executed a sophisticated multi-stage attack against a Brazilian financial institution, targeting cryptocurrency custody secrets and instant payment infrastructure. The attackers leveraged custom Bash scripts to steal temporary cloud credentials, enumerated secrets in cloud credential managers, and deployed backdoors mimicking legitimate infrastructure binaries. They successfully infiltrated managed Kubernetes clusters via Azure DevOps, deployed malicious pipelines, and created automated panels for bulk Pix payment fraud. The campaign resulted in the compromise of multiple Brazilian banks and fintech organizations, with devastating potential for cryptocurrency wallet theft and unauthorized financial transactions. This incident represents a critical shift in cybercrime tactics, as threat actors increasingly demonstrate sophisticated cloud-native attack capabilities specifically targeting high-value digital financial assets and instant payment systems across Latin America.
1 week ago
Kill Chain
ClickFix Campaigns Weaponize Trust: How Attackers Abuse Legitimate Services
ClickFix campaigns represent a sophisticated social engineering attack vector where threat actors disguise malicious PowerShell scripts as legitimate software fixes or updates. These campaigns typically begin with phishing emails or compromised websites that present users with fake error messages, prompting them to copy and execute PowerShell commands that appear to resolve technical issues. The attacks leverage trusted platforms like GitHub, Discord, and legitimate cloud services to host malicious payloads, making detection more challenging for traditional security tools. Once executed, the malicious scripts establish persistent access through various techniques including scheduled tasks, registry modifications, and deployment of remote access tools, allowing attackers to maintain long-term presence in compromised environments. ClickFix campaigns have gained significant traction in 2024 as organizations increasingly adopt cloud-first strategies and remote work models, creating expanded attack surfaces that threat actors exploit through social engineering rather than traditional technical vulnerabilities.
1 week ago
Kill Chain
BengalSEO Campaign Weaponizes Search Results for MayaBot Distribution
The BengalSEO campaign represents a sophisticated search engine optimization poisoning operation that has been active since 2015, targeting Bing search results to deliver MayaBot malware and facilitate tech support scams. Operating from Rajasthan, India, the threat actors behind this campaign manipulate search engine results to redirect victims to malicious websites, where they deploy malware or engage in fraudulent technical support schemes. The campaign demonstrates the evolution of SEO poisoning techniques and their effectiveness in reaching unsuspecting users through legitimate search queries. This incident highlights the growing sophistication of search engine manipulation attacks and their integration with traditional malware distribution methods. As organizations increasingly rely on digital visibility and search engine optimization, the weaponization of these same techniques by threat actors represents a significant shift in attack vectors that security teams must address.
1 week ago
Kill Chain
When AI Attacks AI: The 2026 Autonomous Agent Credential Harvesting Campaign
In September 2026, threat actors deployed autonomous AI agent frameworks to conduct large-scale credential harvesting operations, compromising thousands of third-party credentials in under six hours. Google Threat Intelligence Group identified multiple financially motivated groups, including TeamPCP, leveraging AI-assisted tools like DUSTMAKER malware to target AI coding assistants, cloud environments, and supply chains across PyPI, npm, and Docker Hub repositories. The attacks demonstrated unprecedented automation capabilities, with AI systems autonomously managing vulnerability scanning, real-time troubleshooting, and IP rotation without human intervention. This incident represents a critical escalation in AI-enabled cyber threats, coinciding with the rapid adoption of generative AI tools in enterprise environments and the emergence of 'abliterated' open-weight models that bypass safety guardrails.
1 week ago
Kill Chain
AI Reasoning Traces Theft: The 2026 Vulnerability That Exposed AI's Hidden Thoughts
In 2026, security researchers discovered a critical vulnerability affecting major AI providers including OpenAI, Anthropic, and Google, where encrypted reasoning traces from large language models could be stolen and decoded. The attack exploited the interchangeable nature of encrypted reasoning blocks across different sessions and models, allowing adversaries to inject traces into weaker models to extract proprietary reasoning in plaintext. This vulnerability enabled four distinct attack vectors: circumventing anti-distillation mechanisms, large-scale private data extraction, revealing hidden hazardous information, and executing invisible prompt injections. Researchers successfully extracted 367 PII artifacts and 182 credentials from 315,320 reasoning blocks scraped from public repositories, demonstrating the significant privacy and security implications. This incident highlights the emerging risks in AI security as organizations increasingly deploy autonomous AI agents and rely on cloud-based AI services, making AI-specific vulnerabilities a critical new attack surface that traditional security measures may not adequately address.
1 week ago
Kill Chain
July 2024 Water Utility Attacks Expose Critical Infrastructure Blind Spots
In July 2024, over 100 water and wastewater treatment systems across multiple states were compromised through vulnerable industrial controllers connected directly to public cellular networks. CISA identified the widespread campaign targeting Rockwell Allen-Bradley, Schneider Electric, and Siemens equipment, with attackers gaining operational control and causing service disruptions including pump station failures and boil-water advisories. The incidents exposed critical infrastructure gaps where operational technology exists outside traditional IT security boundaries, with many systems invisible to network scans but trackable through carrier invoices. This campaign highlights the urgent need for comprehensive network visibility and microsegmentation in critical infrastructure, as traditional network perimeter defenses fail to protect cellular-connected industrial control systems that operate independently of municipal IT networks.
1 week ago
Kill Chain
N-able N-central CVE-2026-86218: When RMM Platforms Become Attack Vectors
N-able released an emergency hotfix for CVE-2026-86218, a maximum-severity remote code execution vulnerability in its N-central remote monitoring and management platform used by IT departments and MSPs. The flaw allows unprivileged attackers to execute malicious code on exposed N-central instances through low-complexity attacks. With nearly 1,500 N-central servers exposed online and evidence of active exploitation flagged by Huntress cybersecurity, the company urged immediate patching to N-central 2026.3 Hotfix 4. This incident highlights the persistent targeting of remote management platforms that provide privileged access to client networks and infrastructure. RMM platforms continue to be attractive targets as they offer attackers potential access to multiple downstream organizations through a single compromise, making them critical components in supply chain attack scenarios.
1 week ago
Kill Chain
ConnectWise Issues Emergency Alert for Unpatched ScreenConnect Vulnerability
In September 2026, ConnectWise disclosed a critical file transfer vulnerability in ScreenConnect Remote Access that affects both cloud and on-premises deployments. The flaw, which has not yet received a CVE identifier, impacts file transfer behavior in ScreenConnect support and access sessions. ConnectWise released temporary mitigation measures requiring administrators to disable TransferFiles permissions while a permanent patch is developed. With nearly 6,000 ScreenConnect instances exposed online according to Shadowserver, this vulnerability poses significant risk to managed service providers and IT departments. This incident highlights the ongoing targeting of remote access tools by threat actors, particularly as organizations increasingly rely on cloud-hosted management platforms. ScreenConnect has been repeatedly exploited by ransomware groups and state-sponsored attackers, making this unpatched vulnerability a critical concern for enterprise security teams.
1 week ago
Kill Chain
Mathspace Breach Exposes 1M+ Records: How ShinyHunters Weaponized Metabase Vulnerabilities
On August 10, 2026, threat actors exploited a critical SQL injection vulnerability in Mathspace's self-hosted Metabase instance, gaining administrator access and stealing personal data from over 1 million students, staff, and parents across Australia and New Zealand. The attack was executed by the ShinyHunters extortion gang, who downloaded the data on August 27 before the breach was confirmed on September 3. This incident was part of a broader campaign targeting multiple organizations' Metabase installations worldwide, affecting companies including Trezor, Framework, and Tally. This breach highlights the critical importance of securing internal reporting systems and data analytics platforms, as threat actors increasingly target business intelligence tools that often have broad database access. The incident demonstrates how zero-day vulnerabilities in widely-used SaaS tools can be weaponized at scale, creating cascading impacts across multiple organizations simultaneously.
1 week ago
Kill Chain
N-able Issues Critical Fourth Hotfix: CVE-2026-86218 RCE Vulnerability Exposes MSP Infrastructure
N-able released its fourth critical hotfix in five weeks for the N-central remote monitoring and management platform, addressing CVE-2026-86218, a maximum-severity unauthenticated remote code execution vulnerability with a CVSS 4.0 score of 10.0. The flaw affects all on-premises N-central builds before 2026.3.1.14, with conflicting reports from N-able regarding whether the vulnerability has been exploited in the wild. This incident follows a pattern of critical vulnerabilities in the platform, including previous authentication bypasses that enabled attackers to gain administrative access and pivot to managed endpoints through Cloudflare tunnels. The vulnerability has prompted immediate patching requirements for all on-premises customers and demonstrates the ongoing targeting of managed service provider infrastructure by threat actors seeking to compromise multiple organizations through a single entry point.
1 week ago
Kill Chain
ScreenConnect Worm: How Four-Stage VBScript Chains Are Spreading Through Remote Access Tools
In August 2026, cybersecurity researchers at Huntress disclosed a sophisticated worm-like malware campaign that exploited ConnectWise ScreenConnect remote access software to distribute malicious VBScript payloads. The attack utilized three distinct initial access vectors: Quick Assist tech support scams, phishing-delivered MSI installers, and fake Geek Squad refund forms. Once deployed, rogue ScreenConnect clients executed a four-stage VBScript chain (1.vbs through 4.vbs) that performed system reconnaissance, downloaded encrypted payloads from Dropbox, and deployed various malicious tools including additional backdoors, privilege escalation utilities, and cryptocurrency miners. This incident highlights the ongoing evolution of remote access tool abuse as a primary attack vector, particularly relevant as organizations continue to rely heavily on remote support solutions post-pandemic. The worm-like propagation mechanism represents a concerning advancement in malware distribution techniques, automatically infecting new systems that connect to compromised ScreenConnect instances.
1 week ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports