The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Critical SSO Vulnerability in Cisco Webex Services Exposes User Impersonation Risk
In April 2026, Cisco disclosed a critical vulnerability (CVE-2026-20184) in its Webex Services, specifically affecting the integration of single sign-on (SSO) with Control Hub. This flaw, due to improper certificate validation, allowed unauthenticated remote attackers to impersonate any user within the service by supplying a crafted token. Exploiting this vulnerability could grant unauthorized access to legitimate Cisco Webex services, posing significant security risks. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL?utm_source=openai)) Cisco has addressed this vulnerability in the Webex service. However, organizations using SSO integration must upload a new identity provider (IdP) SAML certificate to Control Hub to prevent service interruption. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL?utm_source=openai))
5 months ago
Kill Chain
Unveiling the Hidden Threat: Shadow Admins in Active Directory
In April 2026, security researchers highlighted the escalating threat of 'shadow admins' within Active Directory (AD) environments. These are user accounts that, while not members of traditional administrative groups, possess elevated privileges due to misconfigurations or oversight. Such accounts can be exploited by attackers to gain unauthorized access, leading to potential domain-wide compromises. The increasing complexity of IT infrastructures, including cloud integrations and virtualization, has amplified the prevalence and risk associated with shadow admins. The significance of this issue is underscored by the growing trend of attackers leveraging indirect privilege paths to infiltrate systems. Organizations are urged to conduct thorough audits of their AD configurations, implement the principle of least privilege, and employ continuous monitoring to detect and remediate shadow admin accounts promptly.
5 months ago
Kill Chain
Critical Windows Task Host Vulnerability (CVE-2025-60710) Exploited in the Wild
In November 2025, Microsoft disclosed CVE-2025-60710, a privilege escalation vulnerability in the Windows Task Host component affecting Windows 11 and Windows Server 2025. This flaw allows local attackers with basic user permissions to gain SYSTEM privileges through low-complexity attacks, potentially leading to full control over compromised devices. The vulnerability arises from improper link resolution before file access, commonly referred to as 'link following'. On April 13, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-60710 to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. This inclusion underscores the critical need for organizations to apply the available patches promptly to mitigate potential security risks.
5 months ago
Kill Chain
Critical Nginx UI Vulnerability (CVE-2026-33032) Enables Unauthenticated Server Takeover
In March 2026, a critical vulnerability (CVE-2026-33032) was discovered in Nginx UI, a web-based management interface for the Nginx web server. This flaw allowed unauthenticated remote attackers to invoke Model Context Protocol (MCP) tools without credentials, enabling actions such as restarting Nginx, and creating, modifying, or deleting configuration files. The root cause was an unprotected '/mcp_message' endpoint that, due to an empty default IP whitelist treated as 'allow all,' permitted unrestricted access. Exploitation of this vulnerability could lead to complete server takeover, allowing attackers to intercept traffic, harvest credentials, and disrupt services. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-33032?utm_source=openai)) The vulnerability was actively exploited in the wild, with approximately 2,600 publicly exposed instances identified, primarily in China, the United States, Indonesia, Germany, and Hong Kong. ([thehackernews.com](https://thehackernews.com/2026/04/critical-nginx-ui-vulnerability-cve.html?utm_source=openai)) A patch was released in version 2.3.4 on March 15, 2026, addressing the issue by adding the missing authentication check to the '/mcp_message' endpoint. ([securityaffairs.com](https://securityaffairs.com/190841/hacking/cve-2026-33032-severe-nginx-ui-bug-grants-unauthenticated-server-access.html?utm_source=openai))
5 months ago
Kill Chain
n8n Webhooks Exploited in Phishing Campaigns Since October 2025
In October 2025, threat actors began exploiting n8n, a widely-used AI workflow automation platform, to conduct sophisticated phishing campaigns. By creating malicious webhooks on n8n's trusted infrastructure, attackers were able to bypass traditional security filters and deliver malware or perform device fingerprinting through automated emails. This abuse allowed them to distribute malicious payloads and gather sensitive information from targeted devices. ([thehackernews.com](https://thehackernews.com/2026/04/n8n-webhooks-abused-since-october-2025.html?utm_source=openai)) The exploitation of legitimate automation platforms like n8n underscores a growing trend where attackers leverage trusted services to evade detection. This incident highlights the need for organizations to scrutinize third-party integrations and enhance monitoring of automated workflows to prevent similar abuses. ([blog.talosintelligence.com](https://blog.talosintelligence.com/the-n8n-n8mare/?utm_source=openai))
5 months ago
Kill Chain
Comprehensive Analysis of the 2026 Threat Detection Report
In 2025, Red Canary analyzed over 110,000 threats across more than 4.5 million identities, endpoints, and cloud assets, revealing significant shifts in the cyber threat landscape. Key findings include a surge in identity-related attacks, with adversaries targeting credentials through info stealers, consent phishing, and OAuth abuse. Browsers have become primary attack vectors, serving as both the main workspace for users and a conduit for malicious payloads via compromised extensions and token theft. Additionally, the abuse of Remote Monitoring and Management (RMM) tools has escalated, with adversaries leveraging these tools for unauthorized access and control. ([redcanary.com](https://redcanary.com/blog/threat-detection/2026-threat-detection-report/?utm_source=openai)) These trends underscore the evolving tactics of cyber adversaries and the necessity for organizations to implement layered security controls. The interconnected nature of identity compromise, browser exploitation, and social engineering highlights the importance of comprehensive defense strategies combining device trust, user authentication, and behavioral monitoring to mitigate these emerging threats. ([redcanary.com](https://redcanary.com/resources/videos/secops-weekly-inside-the-2026-threat-detection-report/?utm_source=openai))
5 months ago
Kill Chain
Microsoft's April 2026 Patch Tuesday: Addressing Critical Vulnerabilities and Zero-Day Exploits
In April 2026, Microsoft released a substantial Patch Tuesday update addressing 167 vulnerabilities across its product suite, marking it as the second-largest patch release in the company's history. This update included two zero-day vulnerabilities: CVE-2026-32201, a spoofing flaw in Microsoft SharePoint Server that was actively exploited in the wild, and CVE-2026-33825, an elevation of privilege issue in Microsoft Defender that had been publicly disclosed prior to patching. Additionally, eight critical vulnerabilities were addressed, affecting components such as Windows Internet Key Exchange (IKE) Service Extensions and Microsoft Word. The prevalence of elevation of privilege vulnerabilities, accounting for 57% of the patches, underscores the critical need for organizations to prioritize these updates to mitigate potential security risks. ([notebookcheck.net](https://www.notebookcheck.net/Microsoft-April-2026-Patch-Tuesday-fixes-167-vulnerabilities-and-two-zero-days.1274388.0.html?utm_source=openai)) The urgency of this update is heightened by the active exploitation of CVE-2026-32201 and the public disclosure of CVE-2026-33825, which could lead to increased targeting by threat actors. Organizations are advised to promptly apply these patches to protect their systems from potential attacks leveraging these vulnerabilities. ([notebookcheck.net](https://www.notebookcheck.net/Microsoft-April-2026-Patch-Tuesday-fixes-167-vulnerabilities-and-two-zero-days.1274388.0.html?utm_source=openai))
5 months ago
Kill Chain
Strengthening Defenses Against the Rise of EDR Killers Utilizing BYOVD Techniques
In early 2026, security researchers observed a significant increase in the use of EDR (Endpoint Detection and Response) killers employing the Bring Your Own Vulnerable Driver (BYOVD) technique. This method involves attackers introducing legitimate, signed drivers with known vulnerabilities into target systems to disable security defenses. ESET's analysis identified nearly 90 unique EDR killer tools exploiting 35 vulnerable drivers, enabling ransomware groups to neutralize security measures before deploying their payloads. The proliferation of these tools, available through underground marketplaces and public proof-of-concept exploits, has heightened concerns among cybersecurity professionals. ([darkreading.com](https://www.darkreading.com/vulnerabilities-threats/edr-killer-ecosystem-expansion-requires-stronger-byovd-defenses/?utm_source=openai)) The current relevance of this incident lies in the evolving threat landscape, where the commodification of EDR killers has made sophisticated attack techniques accessible to a broader range of cybercriminals. This trend underscores the urgent need for organizations to implement robust defenses against BYOVD attacks, including monitoring for unauthorized driver installations and enhancing endpoint security measures. ([darkreading.com](https://www.darkreading.com/vulnerabilities-threats/edr-killer-ecosystem-expansion-requires-stronger-byovd-defenses/?utm_source=openai))
5 months ago
Kill Chain
Microsoft and Salesforce Address Critical AI Security Flaws
In April 2026, security researchers identified critical prompt injection vulnerabilities in Microsoft Copilot and Salesforce Agentforce, which could allow attackers to exfiltrate sensitive data. In Microsoft's case, malicious code inserted into SharePoint forms could trigger Copilot to send customer data to unauthorized emails. Similarly, Salesforce's Agentforce was susceptible to prompt injections via public-facing lead forms, enabling unauthorized access to CRM data. Both companies have since patched these vulnerabilities. ([darkreading.com](https://www.darkreading.com/cloud-security/microsoft-salesforce-patch-ai-agent-data-leak-flaws/?utm_source=openai)) This incident underscores the persistent threat of prompt injection attacks in AI systems, highlighting the need for robust input validation and security measures to prevent unauthorized data access and exfiltration.
5 months ago
Kill Chain
Protecting AI Infrastructure: Lessons from the March 2026 Reconnaissance Scans
In March 2026, cybersecurity researchers identified a series of reconnaissance scans targeting AI model-related files and services, including Claude, OpenClaw, Hugging Face, and OpenAI. These scans, originating from IP address 81.168.83.103, began on March 10, 2026, and have been ongoing. The activity involves probing for specific AI model configuration and credential files, as well as scanning ports commonly associated with web content. While no active exploitation has been reported, the scans appear aimed at discovering AI model deployments or related sensitive files. ([isc.sans.edu](https://isc.sans.edu/diary/Scanning%2Bfor%2BAI%2BModels/32896/?utm_source=openai)) This incident underscores the growing interest of threat actors in AI infrastructure, highlighting the need for organizations to secure AI model deployments and associated files. The trend of targeting AI systems is expected to continue, necessitating proactive measures to protect sensitive AI-related data.
5 months ago
Kill Chain
Microsoft's April 2026 Patch Tuesday: Addressing Critical SharePoint Vulnerabilities
In April 2026, Microsoft released a significant Patch Tuesday update addressing 167 vulnerabilities across its product suite, including an actively exploited zero-day in SharePoint Server (CVE-2026-32201). This spoofing vulnerability allowed unauthorized attackers to perform cross-site scripting (XSS) attacks, potentially leading to data exfiltration and unauthorized access. The update also included fixes for another zero-day in Microsoft Defender and several critical remote code execution flaws. ([notebookcheck.net](https://www.notebookcheck.net/Microsoft-April-2026-Patch-Tuesday-fixes-167-vulnerabilities-and-two-zero-days.1274388.0.html?utm_source=openai)) The scale and severity of this update underscore the increasing sophistication and frequency of cyber threats targeting widely used enterprise platforms. Organizations are urged to prioritize patching to mitigate risks associated with these vulnerabilities, especially given the active exploitation of the SharePoint flaw. ([crowdstrike.com](https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-april-2026/?utm_source=openai))
5 months ago
Kill Chain
OpenClaw's ClawBleed Vulnerability: A Wake-Up Call for AI Security
In early 2026, a critical security vulnerability, designated as CVE-2026-25253 and dubbed "ClawBleed," was discovered in OpenClaw, a widely-used open-source AI personal assistant. This flaw allowed attackers to execute arbitrary code on a user's system by exploiting the application's handling of the `gatewayUrl` parameter, leading to unauthorized WebSocket connections and token exposure. The vulnerability affected all OpenClaw versions prior to 2026.1.29, potentially compromising over 40,000 instances exposed on the internet. ([clawly.org](https://www.clawly.org/news/cve-2026-25253-openclaw-credential-theft?utm_source=openai)) The "ClawBleed" incident underscores the escalating security challenges associated with autonomous AI agents. As these systems gain deeper integration into personal and organizational infrastructures, they present attractive targets for cyber adversaries. This event highlights the urgent need for robust security measures, including prompt patching, stringent access controls, and comprehensive monitoring, to mitigate the risks posed by such vulnerabilities.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports