The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Beware of 'InstallFix' Attacks: Fake Claude Code Sites Spreading Malware
In March 2026, a cyberattack campaign known as 'InstallFix' targeted developers by creating fake installation pages for Anthropic's Claude Code, an AI coding assistant. These counterfeit sites, promoted through Google-sponsored ads, closely mimicked legitimate pages and instructed users to execute malicious commands in their terminals. This led to the deployment of Amatera Stealer malware, which harvested sensitive information such as browser credentials and cryptocurrency wallets, potentially compromising enterprise development environments. This incident underscores the growing trend of attackers exploiting the widespread practice of copying and pasting commands from online sources. It highlights the urgent need for heightened vigilance and verification of software installation sources to prevent similar social engineering attacks.
6 months ago
Kill Chain
BlackSanta Malware: A New Era of Targeted Cyber Threats in HR Workflows
In early 2026, Russian-speaking threat actors initiated the 'BlackSanta' campaign, targeting human resources (HR) workflows to deploy sophisticated malware capable of disabling endpoint detection and response (EDR) systems. The attack begins with resume-themed ISO files delivered through recruitment channels, which, when opened, execute malicious shortcuts that trigger a multi-stage infection chain. This chain includes obfuscated PowerShell commands extracting payloads from steganographic images and sideloading malicious DLLs via legitimate applications. Once executed, the malware performs extensive validation to evade analysis environments before deploying the 'BlackSanta' EDR killer. This component loads legitimate but exploitable kernel drivers to gain low-level system access, subsequently disabling security protections, including antivirus processes, EDR agents, and system logging. This enables attackers to exfiltrate sensitive data over encrypted HTTPS channels with minimal detection risk. The campaign underscores the increasing sophistication of cyber threats targeting operational business workflows, particularly in HR environments. Organizations are advised to apply rigorous security measures to HR systems, including enhanced endpoint protections, monitoring for unusual activity, and increasing security awareness among recruiting teams to mitigate such attacks.
6 months ago
Kill Chain
CISA Adds Three Known Exploited Vulnerabilities to Catalog
On March 9, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. These vulnerabilities include CVE-2021-22054, a Server-Side Request Forgery (SSRF) in VMware Workspace ONE UEM; CVE-2025-26399, an unauthenticated deserialization flaw in SolarWinds Web Help Desk's AjaxProxy component; and CVE-2026-1603, an authentication bypass in Ivanti Endpoint Manager (EPM). Each of these flaws presents significant risks, such as unauthorized access, remote code execution, and credential disclosure, potentially leading to full enterprise compromise. The inclusion of these vulnerabilities in the KEV Catalog underscores the persistent threat posed by unpatched software. Organizations are urged to prioritize remediation efforts to mitigate the risks associated with these actively exploited vulnerabilities.
6 months ago
Kill Chain
Critical Vulnerabilities in AI/ML Platforms: Lessons from the 2025 Security Breach
In mid-2025, a significant security vulnerability was discovered in three widely used open-source Python libraries—NeMo (by NVIDIA), Uni2TS (by Salesforce), and FlexTok (by Apple)—which are integral to various AI and ML platforms. These libraries, collectively downloaded over 10 million times via the HuggingFace platform, were found to execute arbitrary code embedded within model metadata, making them susceptible to remote code execution if exploited by attackers. The vulnerabilities were identified in April 2025 and resolved by July 2025, with corresponding CVEs assigned and severity scores ranging from 7.8 to 9.8 out of 10. As of December 2025, there have been no indications of these flaws being exploited in the wild. ([techradar.com](https://www.techradar.com/pro/security/python-libraries-used-in-top-ai-and-ml-tools-hacked-nvidia-salesforce-and-other-libraries-all-at-risk?utm_source=openai)) This incident underscores the critical importance of securing AI and ML infrastructure, especially as these technologies become increasingly integrated into business operations. The rapid adoption of AI tools without adequate security measures can expose organizations to significant risks, including data breaches and unauthorized access. It highlights the necessity for continuous monitoring, timely patching, and the implementation of robust security protocols to safeguard against emerging threats in the AI landscape.
6 months ago
Kill Chain
Critical SQL Injection Vulnerability in FortiClient EMS 7.4.4
In February 2026, a critical SQL injection vulnerability (CVE-2026-21643) was discovered in Fortinet's FortiClient Endpoint Management Server (EMS) version 7.4.4. This flaw allows unauthenticated attackers to execute arbitrary code or commands via specially crafted HTTP requests, potentially leading to full system compromise. Fortinet promptly released version 7.4.5 to address this issue, urging all users to upgrade immediately. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-21643?utm_source=openai)) This incident underscores the persistent threat posed by SQL injection vulnerabilities, especially in widely used enterprise security solutions. Organizations are reminded of the importance of timely patch management and vigilant monitoring to mitigate such risks.
6 months ago
Kill Chain
Google Cloud 2026: Surge in Vulnerability Exploitation
In the latter half of 2025, Google observed a significant shift in cloud attack vectors, with 44.5% of intrusions exploiting newly disclosed vulnerabilities in third-party software, while attacks leveraging weak credentials decreased to 27%. Notably, remote code execution flaws like React2Shell (CVE-2025-55182) and the XWiki vulnerability (CVE-2025-24893) were frequently targeted, with attackers deploying cryptominers within 48 hours of vulnerability disclosure. This trend underscores the urgency for organizations to promptly patch vulnerabilities and enhance their security posture to mitigate rapid exploitation risks. The accelerated exploitation of software vulnerabilities highlights the evolving tactics of threat actors and the necessity for organizations to adopt proactive vulnerability management and robust security measures to safeguard cloud environments against emerging threats.
6 months ago
Kill Chain
Ericsson US Data Breach: Lessons in Third-Party Risk Management
In April 2025, Ericsson Inc., the U.S. subsidiary of the Swedish telecommunications company, experienced a data breach through one of its service providers. Unauthorized access occurred between April 17 and April 22, 2025, compromising sensitive personal information of employees and customers, including names, addresses, Social Security numbers, driver's license numbers, financial data, medical information, and dates of birth. The breach was detected on April 28, 2025, prompting an investigation that concluded on February 23, 2026, confirming the extent of the data exposure. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ericsson-us-discloses-data-breach-after-service-provider-hack/?utm_source=openai)) This incident underscores the critical importance of robust third-party risk management and supply chain security. As organizations increasingly rely on external service providers, ensuring these partners adhere to stringent cybersecurity standards is essential to prevent similar breaches and protect sensitive data.
6 months ago
Kill Chain
Malicious npm Package Poses as OpenClaw Installer, Deploys RAT on macOS
In early March 2026, a malicious npm package named '@openclaw-ai/openclawai' was discovered posing as an installer for OpenClaw. Uploaded on March 3, 2026, by a user named 'openclaw-ai', the package was downloaded 178 times before detection. Upon installation, it executed a postinstall script that deployed a remote access trojan (RAT) capable of stealing sensitive data, including system credentials, browser data, cryptocurrency wallets, SSH keys, Apple Keychain databases, and iMessage history. The malware also established persistence, allowing continuous remote access and data exfiltration. This incident underscores the growing trend of supply chain attacks targeting open-source ecosystems, exploiting the trust developers place in widely-used package managers like npm. The sophistication of the attack, including social engineering tactics and advanced persistence mechanisms, highlights the urgent need for enhanced security measures in software development pipelines.
6 months ago
Kill Chain
UNC4899's $1.5 Billion Cryptocurrency Heist: Lessons for the Industry
In February 2025, the North Korean state-sponsored hacking group UNC4899, also known as TraderTraitor, orchestrated a sophisticated cyberattack resulting in the theft of approximately $1.5 billion from the cryptocurrency exchange Bybit. The attackers compromised a developer's macOS workstation at Safe{Wallet}, a multisignature wallet platform, by deploying a malicious Docker project. This initial breach allowed them to hijack AWS session tokens, bypass multi-factor authentication, and inject malicious JavaScript into Safe{Wallet}'s application. Consequently, they manipulated a routine Ethereum transfer from Bybit's cold wallet to its hot wallet, redirecting the funds to addresses under their control. ([blog.it-expert.net](https://blog.it-expert.net/summaries/The-Feed_2025-03-10.html?utm_source=openai)) This incident underscores the escalating threat posed by state-sponsored cyber actors targeting the cryptocurrency sector. The use of advanced social engineering tactics, exploitation of cloud infrastructure vulnerabilities, and sophisticated supply chain attacks highlight the need for enhanced security measures and vigilance within the industry. ([thehackernews.com](https://thehackernews.com/2025/07/n-korean-hackers-used-job-lures-cloud.html?utm_source=openai))
6 months ago
Kill Chain
OpenClaw 2026 Supply Chain Attack: Lessons in AI Security
In early 2026, OpenClaw, a widely adopted open-source AI assistant, became the target of a sophisticated supply chain attack. Cybercriminals infiltrated ClawHub, OpenClaw's marketplace for third-party skills, embedding 341 malicious skills among legitimate offerings. These malicious skills, often disguised as tools for crypto traders and finance professionals, were designed to steal user credentials and deploy malware upon installation. The attack exploited the trust users placed in ClawHub's ecosystem, leading to unauthorized access and data breaches. ([tech.yahoo.com](https://tech.yahoo.com/cybersecurity/articles/hackers-poison-popular-ai-assistant-171427799.html?utm_source=openai)) This incident underscores the escalating risks associated with AI assistants and their extensible platforms. As organizations increasingly integrate AI agents into their workflows, the potential for supply chain attacks grows, emphasizing the need for rigorous security assessments of third-party integrations and heightened vigilance against emerging threats.
6 months ago
Kill Chain
Velvet Tempest's Use of 'ClickFix' in Recent Cyber Intrusion
Between February 3 and 16, 2026, the threat group Velvet Tempest (also known as DEV-0504) conducted a sophisticated cyber intrusion targeting a U.S. non-profit organization with over 3,000 endpoints and 2,500 users. Utilizing a malvertising campaign, they employed the 'ClickFix' technique, deceiving victims into executing obfuscated commands via the Windows Run dialog. This led to the deployment of DonutLoader and the CastleRAT backdoor, facilitating credential harvesting and extensive reconnaissance. Notably, while Velvet Tempest is known for deploying various ransomware strains, including Ryuk, REvil, and Conti, the Termite ransomware was not executed in this particular incident. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/termite-ransomware-breaches-linked-to-clickfix-castlerat-attacks/?utm_source=openai)) This incident underscores the evolving tactics of ransomware affiliates, highlighting the use of social engineering techniques like 'ClickFix' to gain initial access. The absence of immediate ransomware deployment suggests a strategic shift towards prolonged network infiltration and data exfiltration, posing significant challenges for detection and mitigation.
6 months ago
Kill Chain
Microsoft Reports Surge in AI-Powered Cyberattacks in 2026
In March 2026, Microsoft reported a significant increase in cyberattacks leveraging artificial intelligence (AI) across all stages of the attack lifecycle. Threat actors utilized generative AI tools for tasks such as reconnaissance, phishing, infrastructure development, malware creation, and post-compromise activities. Notably, North Korean groups like Jasper Sleet (Storm-0287) and Coral Sleet (Storm-1877) employed AI to craft realistic digital personas, enabling them to infiltrate Western organizations under the guise of remote IT workers. This strategic use of AI allowed attackers to accelerate operations, scale malicious activities, and lower technical barriers, resulting in more sophisticated and efficient cyberattacks. The current relevance of this incident lies in the escalating trend of AI-powered cyber threats. As AI technologies become more accessible, both state-sponsored and financially motivated actors are increasingly integrating AI into their operations. This evolution necessitates that organizations enhance their cybersecurity measures to detect and mitigate AI-driven attacks effectively.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports