The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Citrix NetScaler 2025 Memory Overread Vulnerability: Immediate Action Required
In June 2025, Citrix disclosed a critical vulnerability (CVE-2025-5777) in NetScaler ADC and NetScaler Gateway, characterized by insufficient input validation leading to memory overread. This flaw allows unauthenticated attackers to remotely access sensitive memory contents, including session tokens and credentials, when the devices are configured as a Gateway or AAA virtual server. The vulnerability affects versions 14.1 before 14.1-43.56 and 13.1 before 13.1-58.32. Citrix released patches on June 17, 2025, urging immediate updates to mitigate potential exploitation. ([support.citrix.com](https://support.citrix.com/external/article/CTX693420/netscaler-adc-and-netscaler-gateway-secu.html?utm_source=openai)) The urgency of addressing this vulnerability is underscored by its active exploitation in the wild, as reported by security agencies and researchers. Organizations are advised to apply the provided patches promptly to prevent unauthorized access and potential data breaches. ([techradar.com](https://www.techradar.com/pro/security/cisa-warns-hackers-are-actively-exploiting-critical-citrixbleed-2?utm_source=openai))
5 months ago
Kill Chain
AI-Enhanced Cyber Threats Surge in 2026
In 2026, the cybersecurity landscape witnessed a significant surge in AI-enhanced cyber threats. Malicious actors leveraged artificial intelligence to automate and accelerate attacks, leading to a 72% increase in AI-powered cyber incidents compared to the previous year. These sophisticated attacks utilized generative AI tools to craft convincing phishing emails, deepfakes, and automated exploit development, drastically reducing the time required to breach systems and exfiltrate data. Organizations across various sectors faced unprecedented challenges in defending against these rapidly evolving threats. This escalation underscores the urgent need for organizations to adopt AI-driven defense mechanisms. Traditional security measures are increasingly inadequate against AI-powered attacks, necessitating the integration of advanced AI-based threat detection and response systems to effectively mitigate these emerging risks.
5 months ago
Kill Chain
Dutch Police 2026 Phishing Attack: A Closer Look at the Security Breach
In March 2026, the Dutch National Police experienced a security breach due to a successful phishing attack. The agency's Security Operations Center promptly detected the incident and blocked the attackers' access. Preliminary investigations indicate that the impact was limited, with no exposure of citizens' data or investigative information. A criminal investigation has been initiated to further assess the breach. This incident underscores the persistent threat of phishing attacks targeting governmental institutions. Despite previous breaches and subsequent security enhancements, such as the 2024 data breach linked to a state actor, the recurrence highlights the need for continuous vigilance and adaptive cybersecurity measures.
5 months ago
Kill Chain
European Commission's AWS Account Breach in 2026: A Wake-Up Call for Cloud Security
In March 2026, the European Commission, the executive body of the European Union, experienced a significant security breach when a threat actor gained unauthorized access to its Amazon Web Services (AWS) cloud environment. The attacker claimed to have exfiltrated over 350 GB of data, including multiple databases containing sensitive information about Commission employees and internal communications. The breach was promptly detected, and the Commission's cybersecurity incident response team initiated an investigation to assess the extent of the intrusion and mitigate potential damages. This incident underscores the escalating risks associated with cloud infrastructure security, especially for governmental organizations handling sensitive data. It highlights the necessity for robust cloud security measures, continuous monitoring, and rapid response capabilities to address emerging threats in the digital landscape.
5 months ago
Kill Chain
Telnyx PyPI Supply Chain Attack: A 2026 Case Study
In March 2026, the Telnyx Python package on the Python Package Index (PyPI) was compromised by the threat actor TeamPCP. Malicious versions 4.87.1 and 4.87.2 were uploaded, embedding malware that exfiltrated sensitive data such as SSH keys, cloud tokens, and cryptocurrency wallets. The attack utilized steganography, hiding the payload within WAV audio files, and affected both Linux/macOS and Windows systems. This incident underscores the escalating threat of supply chain attacks targeting widely used open-source packages, emphasizing the need for enhanced security measures in software development pipelines.
5 months ago
Kill Chain
Fake VS Code Alerts on GitHub Distribute Malware to Developers
In March 2026, a large-scale campaign targeted developers on GitHub by posting fake Visual Studio Code (VS Code) security alerts in the Discussions sections of various projects. These deceptive posts, crafted as vulnerability advisories with titles like 'Severe Vulnerability - Immediate Update Required,' included fake CVE IDs and urgent language. Attackers impersonated real code maintainers or researchers to enhance credibility. The posts contained links to purportedly patched versions of VS Code extensions hosted on external services such as Google Drive. Clicking these links led to a redirection chain that executed a JavaScript reconnaissance script, collecting victims' system information and sending it to the attackers' command-and-control server. This campaign highlights the increasing sophistication of social engineering attacks targeting developers through trusted platforms. Similar tactics have been observed in previous incidents, such as the March 2025 phishing campaign that targeted 12,000 GitHub repositories with fake security alerts, leading to unauthorized access to developers' accounts and repositories. The recurrence of such attacks underscores the need for heightened vigilance and robust security practices within the developer community.
5 months ago
Kill Chain
Critical Security Vulnerabilities in LangChain and LangGraph: Immediate Action Required
In early 2026, multiple security vulnerabilities were identified in LangChain and LangGraph, two widely used open-source frameworks for building applications powered by Large Language Models (LLMs). These vulnerabilities include Server-Side Request Forgery (SSRF) in LangChain versions prior to 1.2.11, Regular Expression Denial-of-Service (ReDoS) in versions up to 0.3.1, and a critical Remote Code Execution (RCE) flaw in LangGraph's caching layer before version 4.0.0. Exploitation of these vulnerabilities could lead to unauthorized access to sensitive data, execution of arbitrary code, and potential system compromise. ([stack.watch](https://stack.watch/product/langchain-ai/langchain/?utm_source=openai)) The discovery of these vulnerabilities underscores the importance of rigorous security practices in the development and maintenance of AI frameworks. As LLM-powered applications become increasingly prevalent, ensuring the security of underlying frameworks is crucial to prevent potential exploitation by malicious actors.
5 months ago
Kill Chain
Open VSX Registry's 2026 GlassWorm Supply Chain Attack: A Wake-Up Call for Extension Security
In January 2026, the Open VSX Registry, a vendor-neutral extension marketplace for Visual Studio Code, experienced a significant supply chain attack. Threat actors compromised a legitimate publisher's account to distribute malicious updates to four popular extensions, collectively downloaded over 22,000 times. These updates deployed the GlassWorm malware, specifically targeting macOS users by exfiltrating sensitive data such as browser cookies, cryptocurrency wallets, and developer credentials. The malware utilized sophisticated evasion techniques, including locale checks and blockchain-based command-and-control mechanisms, to avoid detection and dynamically manage its infrastructure. ([securityweek.com](https://www.securityweek.com/open-vsx-publisher-account-hijacked-in-fresh-glassworm-attack/?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks within open-source ecosystems, highlighting the critical need for robust security measures in extension marketplaces. In response, the Eclipse Foundation, which maintains the Open VSX Registry, has announced plans to implement pre-publication security checks to proactively identify and mitigate malicious extensions before they reach users. ([thehackernews.com](https://thehackernews.com/2026/02/eclipse-foundation-mandates-pre-publish.html?utm_source=openai))
5 months ago
Kill Chain
TeamPCP's Malicious 'telnyx' PyPI Attack Exposes Supply Chain Vulnerabilities
In March 2026, the threat actor group TeamPCP executed a supply chain attack by uploading two malicious versions (4.87.1 and 4.87.2) of the 'telnyx' Python package to the Python Package Index (PyPI). These versions concealed credential-stealing malware within .WAV files, enabling the exfiltration of sensitive data from compromised systems. The attack underscores the vulnerability of open-source repositories to sophisticated supply chain compromises. This incident highlights the escalating trend of attackers targeting widely used open-source packages to distribute malware, emphasizing the need for enhanced vigilance and security measures in software supply chains.
5 months ago
Kill Chain
Coruna iOS Exploit Framework: Evolution from Espionage to Cybercrime
In 2025, the Coruna exploit kit emerged as a sophisticated tool targeting iPhones running iOS versions 13.0 through 17.2.1. Initially observed in February 2025, it was used by a surveillance vendor's client, later appearing in attacks by Russian espionage groups against Ukrainian users, and subsequently by financially motivated Chinese hackers. Coruna comprises five full iOS exploit chains leveraging 23 vulnerabilities, including CVE-2023-32434 and CVE-2023-38606, previously exploited in Operation Triangulation. The kit's evolution suggests a continuous development from earlier frameworks, now capable of compromising modern hardware, including Apple's A17 and M3 chips. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/03/03/coruna-ios-exploit-kit/?utm_source=openai)) The proliferation of Coruna underscores the escalating risk of advanced exploit kits transitioning from state-sponsored espionage to widespread cybercrime. This trend highlights the urgent need for organizations to implement robust security measures, including timely software updates and advanced threat detection systems, to mitigate the risks posed by such sophisticated tools.
5 months ago
Kill Chain
International Operation Dismantles LeakBase Cybercrime Forum in 2026
In early March 2026, an international law enforcement operation led by the FBI and Europol dismantled LeakBase, one of the world's largest cybercrime forums. Established in 2021, LeakBase had over 142,000 members and facilitated the trade of stolen data, including account credentials and financial information. The coordinated effort spanned 14 countries, resulting in the seizure of the forum's domains and databases, as well as multiple arrests and searches targeting the platform's most active users. This operation underscores the growing global collaboration in combating cybercrime and highlights the increasing focus on dismantling platforms that facilitate the sale of stolen data. The takedown of LeakBase serves as a significant deterrent to cybercriminals and emphasizes the importance of international cooperation in addressing the evolving cyber threat landscape.
5 months ago
Kill Chain
Critical Langflow RCE Vulnerability (CVE-2026-33017) Exploited in the Wild
In March 2026, a critical remote code execution (RCE) vulnerability, identified as CVE-2026-33017, was discovered in Langflow, an open-source framework for building AI workflows. This flaw allows unauthenticated attackers to execute arbitrary Python code on affected servers by sending crafted HTTP requests to the unsandboxed flow execution endpoint. The vulnerability affects Langflow versions 1.8.1 and earlier, potentially leading to full system compromise, data theft, and unauthorized access to sensitive information. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-27966/?utm_source=openai)) The rapid exploitation of this vulnerability underscores the increasing targeting of AI development tools by threat actors. Organizations utilizing Langflow are urged to upgrade to version 1.9.0 or later, which addresses this security issue. Additionally, it is recommended to disable or restrict access to the vulnerable endpoint, monitor for suspicious activity, and rotate API keys and credentials to mitigate potential risks. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-27966/?utm_source=openai))
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports