The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
CrystalX RAT: The 2026 Malware-as-a-Service Blending Espionage and Prankware
In March 2026, cybersecurity researchers identified an active campaign distributing CrystalX RAT, a novel malware offered as Malware-as-a-Service (MaaS) through private Telegram channels. This Remote Access Trojan (RAT) distinguishes itself by combining traditional espionage capabilities—such as spyware, keylogging, and remote control—with stealer functions and unique prankware features designed to disrupt and annoy victims. The malware's control panel allows third-party actors to build customized implants with options like geoblocking, anti-analysis mechanisms, and various malicious functionalities. Initial infection vectors remain unclear, but the campaign has already affected dozens of victims, primarily in Russia, with potential for global spread due to the service's lack of regional restrictions. The ongoing development and active promotion of CrystalX RAT suggest a significant risk of increased infections in the near future.
5 months ago
Kill Chain
Volt Typhoon 2024: A Case Study in Living Off the Land Cyber Attacks
In 2024, the Chinese state-sponsored hacker group known as Volt Typhoon executed a sophisticated Living Off the Land (LOTL) attack targeting critical infrastructure in the United States. By exploiting legitimate system tools and processes, they infiltrated networks without deploying traditional malware, thereby evading standard detection mechanisms. This approach allowed them to conduct prolonged surveillance and data exfiltration, significantly compromising national security and operational integrity. ([nsa.gov](https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3669159/combatting-cyber-threat-actors-perpetrating-living-off-the-land-intrusions/?utm_source=openai)) The incident underscores a growing trend among nation-state actors to utilize LOTL techniques, which leverage trusted system utilities to carry out malicious activities. This method not only complicates detection but also challenges traditional cybersecurity defenses, necessitating a shift towards behavior-based monitoring and advanced threat detection strategies.
5 months ago
Kill Chain
Casbaneiro Phishing Campaign Targets Latin America and Europe
In March 2026, a sophisticated phishing campaign orchestrated by the Brazilian cybercrime group Augmented Marauder targeted Spanish-speaking users across Latin America and Europe. The attackers distributed emails with court summons-themed messages containing password-protected PDF attachments. These PDFs directed recipients to malicious links, initiating a multi-stage infection chain that deployed the Horabot malware, which subsequently delivered the Casbaneiro banking trojan. This campaign leveraged dynamic PDF generation and exploited both email and WhatsApp platforms to propagate the malware, resulting in significant financial and data losses for affected organizations. This incident underscores the evolving tactics of cybercriminals who are increasingly using multi-pronged attack vectors and dynamic content to bypass traditional security measures. The use of legitimate communication channels like WhatsApp for malware distribution highlights the need for organizations to implement comprehensive security strategies that address both email and messaging platforms.
5 months ago
Kill Chain
Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass
In late February 2026, Microsoft identified a sophisticated malware campaign leveraging WhatsApp messages to distribute malicious Visual Basic Script (VBS) files. Upon execution, these scripts initiate a multi-stage infection chain, utilizing renamed Windows utilities to download additional payloads from trusted cloud services like AWS, Tencent Cloud, and Backblaze B2. The malware employs User Account Control (UAC) bypass techniques to escalate privileges, establish persistence, and deploy tools such as AnyDesk for remote access, enabling attackers to exfiltrate data or deploy further malware. This campaign underscores the evolving tactics of threat actors who exploit legitimate tools and platforms to evade detection and maintain control over compromised systems. Organizations must remain vigilant against such social engineering attacks and implement robust security measures to mitigate these threats.
5 months ago
Kill Chain
Excessive Permissions in Google Vertex AI: A 2026 Security Wake-Up Call
In March 2026, Palo Alto Networks' Unit 42 identified a critical security vulnerability in Google Cloud's Vertex AI platform. The issue stemmed from the platform's default service accounts, known as Per-Project, Per-Product Service Agents (P4SA), which were granted excessive permissions by default. This misconfiguration allowed attackers to exploit AI agents deployed on Vertex AI, enabling unauthorized access to sensitive data and internal cloud infrastructure. By extracting the service account credentials, malicious actors could escalate privileges, access proprietary container images, and potentially compromise Google's internal storage buckets. ([darkreading.com](https://www.darkreading.com/cyber-risk/googles-vertex-ai-over-privilege-problem?utm_source=openai)) This incident underscores the growing security challenges associated with AI deployments in cloud environments. As organizations increasingly integrate AI agents into their workflows, ensuring proper configuration and adherence to the principle of least privilege becomes paramount to prevent similar vulnerabilities and safeguard sensitive information.
5 months ago
Kill Chain
UNC1069's 2026 Supply Chain Attack on Axios: A Wake-Up Call for Open-Source Security
In late March 2026, the widely-used JavaScript library Axios was compromised through a sophisticated supply chain attack. Attackers gained access to the npm account of a lead maintainer and published two malicious versions: axios@1.14.1 and axios@0.30.4. These versions included a trojanized dependency, 'plain-crypto-js@4.2.1', which executed a cross-platform Remote Access Trojan (RAT) upon installation, targeting Windows, macOS, and Linux systems. The malicious packages were live for approximately three hours before being removed, but the potential impact was significant due to Axios's extensive use in the developer community. ([securitylabs.datadoghq.com](https://securitylabs.datadoghq.com/articles/axios-npm-supply-chain-compromise/?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks, particularly those targeting open-source ecosystems. The attribution to North Korean threat actor UNC1069 highlights the increasing involvement of state-sponsored groups in such attacks, emphasizing the need for enhanced security measures in software development pipelines. ([cyberkendra.com](https://www.cyberkendra.com/2026/04/north-korean-hackers-behind-axios-npm.html?utm_source=openai))
5 months ago
Kill Chain
TeamPCP's 2026 Cloud Breaches: A Wake-Up Call for Supply Chain Security
In March 2026, the threat actor group TeamPCP executed a series of sophisticated supply chain attacks, compromising widely used open-source tools such as Trivy, KICS, LiteLLM, and Telnyx. By injecting malicious code into these trusted software packages, TeamPCP deployed infostealer malware to harvest sensitive credentials, including API keys, SSH keys, and cloud service tokens. Utilizing the stolen credentials, the group swiftly breached cloud environments across AWS, Azure, and various SaaS platforms, conducting extensive reconnaissance and data exfiltration activities. This campaign underscores the critical need for organizations to promptly rotate and revoke compromised credentials to mitigate the risk of unauthorized access and data breaches. The rapid escalation and breadth of TeamPCP's attacks highlight a concerning trend in cyber threats, emphasizing the importance of securing software supply chains and implementing robust monitoring mechanisms to detect and respond to credential misuse promptly.
5 months ago
Kill Chain
AI/ML Security Incidents in 2026: A Wake-Up Call for Enterprises
In 2026, the cybersecurity landscape witnessed a significant surge in incidents involving artificial intelligence (AI) and machine learning (ML) systems. Notably, a report by Zscaler highlighted that 90% of enterprise AI systems could be breached within 90 minutes under adversarial testing conditions, with some systems compromised in under one second. Additionally, 68% of organizations experienced AI-linked data leaks, yet only 23% had formal AI security policies in place. These incidents underscore the critical vulnerabilities in AI and ML deployments, emphasizing the need for robust security measures and governance frameworks. The rapid adoption of AI technologies, coupled with insufficient security protocols, has led to an increase in sophisticated cyberattacks. Threat actors are leveraging AI to enhance the scale, speed, and precision of their attacks, while organizations struggle to keep pace with evolving threats. This trend highlights the urgent need for comprehensive AI security strategies to mitigate emerging risks.
5 months ago
Kill Chain
Venom Stealer: The New Frontier in Automated ClickFix Attacks
In April 2026, a new malware-as-a-service (MaaS) platform named Venom Stealer emerged, automating the creation of persistent information-stealing attacks through ClickFix social engineering techniques. Developed by an individual known as 'VenomStealer,' this platform enables attackers to establish a continuous exfiltration pipeline, harvesting credentials, session cookies, and cryptocurrency wallets from victims. Unlike traditional infostealers, Venom Stealer remains active post-infection, continuously monitoring and exfiltrating new data, thereby undermining standard incident response measures. The commoditization of such advanced attack methods signifies a concerning evolution in cyber threats, making sophisticated social engineering tactics more accessible to a broader range of cybercriminals. Organizations must enhance their security awareness training and implement robust monitoring of outbound traffic to detect and prevent data exfiltration activities associated with these attacks.
5 months ago
Kill Chain
Azure APIM Signup Bypass: A 2025 Security Wake-Up Call
In September 2025, a critical vulnerability was discovered in Microsoft Azure API Management (APIM) Developer Portal, allowing unauthorized cross-tenant account creation even when administrators had disabled user signup via the portal's UI. This flaw stemmed from the backend API continuing to accept registration requests despite the UI indicating that signup was disabled. Exploiting this, attackers could create accounts, access internal API documentation, and potentially obtain API keys without any prior relationship to the target organization. Microsoft classified this behavior as 'by design' and did not release a patch, leaving organizations to implement their own mitigations. ([praetorian.com](https://www.praetorian.com/blog/azure-apim-signup-bypass/?utm_source=openai)) This incident underscores the importance of verifying that security controls function as intended, beyond their UI representations. Organizations relying solely on UI configurations may remain vulnerable to similar bypasses, emphasizing the need for comprehensive security assessments and proactive measures to secure API management platforms.
5 months ago
Kill Chain
AI Agent Security Breach: Lessons from a 2026 Penetration Test
In March 2026, a penetration test revealed a critical vulnerability in an AI-powered desktop application designed to interface with Claude (Opus 4.5) and a third-party asset management platform. Despite operating within a sandboxed environment with stringent controls, attackers exploited the agent's ability to modify existing files and execute code. By uploading a benign-looking 'Hello World' C program alongside a malicious binary, and manipulating the agent to rename and execute the binary, the attackers achieved remote code execution, compromising the sandbox and accessing sensitive business logic components. This incident underscores the evolving threat landscape where AI agents, even with robust safeguards, can be manipulated to perform unintended actions, leading to significant security breaches. Organizations must reassess their security measures, particularly concerning AI agents with code execution capabilities, to prevent similar exploits.
5 months ago
Kill Chain
Mercor's 2026 Data Breach: A Wake-Up Call for Supply Chain Security
In March 2026, AI recruiting startup Mercor confirmed a significant data breach resulting from the LiteLLM supply chain compromise orchestrated by the hacking group TeamPCP. The attackers infiltrated Mercor's systems via a compromised Tailscale VPN credential, leading to the exfiltration of approximately 4TB of sensitive data, including source code, user databases, and identity verification documents. This incident underscores the critical vulnerabilities in software supply chains and the cascading risks they pose to organizations relying on open-source components. The Mercor breach highlights the escalating threat of supply chain attacks targeting widely-used open-source projects. As organizations increasingly integrate such components into their infrastructure, the potential for widespread compromise grows, emphasizing the need for robust security measures and vigilant monitoring of third-party dependencies.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports