The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Unveiling a Ransomware Network Through Brute Force Attack Analysis
In March 2026, the Huntress Tactical Response Team investigated a routine brute-force alert on an exposed Remote Desktop Protocol (RDP) server. This led to the discovery of a successful login from multiple IP addresses, indicating a coordinated attack. Further analysis revealed the attackers' unusual behavior of manually searching for credentials within files, deviating from typical automated methods. This investigation uncovered a geo-distributed infrastructure and a suspicious VPN service, suggesting a sophisticated ransomware-as-a-service operation facilitated by initial access brokers. This incident underscores the evolving tactics of ransomware operators, highlighting the importance of vigilant monitoring and comprehensive security measures. The attackers' manual credential-hunting approach and the use of distributed infrastructure reflect a shift towards more targeted and persistent threats, necessitating adaptive defense strategies.
6 months ago
Kill Chain
Global Operation Dismantles Tycoon2FA Phishing Platform
In March 2026, a coordinated international operation led by Europol and Microsoft successfully dismantled Tycoon2FA, a prominent phishing-as-a-service (PhaaS) platform active since August 2023. Tycoon2FA enabled cybercriminals to bypass multi-factor authentication (MFA) by intercepting live authentication sessions, capturing credentials, one-time passcodes, and session cookies in real time. This service was responsible for tens of millions of phishing emails each month, targeting over 500,000 organizations globally, including schools, hospitals, and public institutions. The takedown involved seizing 330 domains that formed the platform's core infrastructure, significantly disrupting its operations and mitigating further harm. ([blogs.microsoft.com](https://blogs.microsoft.com/on-the-issues/2026/03/04/how-a-global-coalition-disrupted-tycoon/?utm_source=openai)) The dismantling of Tycoon2FA underscores the evolving sophistication of cyber threats, particularly the commoditization of tools that facilitate large-scale MFA bypass attacks. This incident highlights the critical need for organizations to adopt phishing-resistant authentication mechanisms and enhance their cybersecurity posture to defend against such advanced threats. ([newsroom.trendmicro.com](https://newsroom.trendmicro.com/2026-03-04-TrendAI-TM-Helps-Drive-Global-Takedown-of-Tycoon-2FA-MFA-Bypass-Phishing-Service?utm_source=openai))
6 months ago
Kill Chain
UMMC's 2026 Ransomware Attack: A Wake-Up Call for Healthcare Cybersecurity
In February 2026, the University of Mississippi Medical Center (UMMC) experienced a significant ransomware attack attributed to the Medusa ransomware group. The attack led to the closure of 35 clinics and the cancellation of elective procedures, severely disrupting healthcare services. UMMC's electronic health record system and communication networks were compromised, necessitating a shift to manual operations. The medical center collaborated with federal authorities, including the FBI, to investigate and mitigate the attack. After nine days, UMMC restored its systems and resumed normal operations. ([nationaltoday.com](https://nationaltoday.com/us/ms/jackson/news/2026/03/04/ummc-resumes-operations-after-ransomware-attack/?utm_source=openai)) This incident underscores the escalating threat of ransomware attacks targeting critical infrastructure, particularly in the healthcare sector. The Medusa group's double extortion tactics, involving data encryption and threats to release sensitive information, highlight the urgent need for robust cybersecurity measures to protect patient data and ensure uninterrupted medical services. ([aha.org](https://www.aha.org/news/headline/2025-03-14-advisory-warns-medusa-ransomware-activity?utm_source=openai))
6 months ago
Kill Chain
HungerRush Faces 2026 Customer Data Extortion Threat
In early March 2026, customers of restaurants utilizing the HungerRush point-of-sale (POS) platform reported receiving extortion emails from a threat actor. The emails warned that both restaurant and customer data would be exposed if HungerRush did not comply with the attacker's demands. HungerRush, a provider of restaurant technology solutions, serves over 16,000 establishments, including notable chains like Sbarro and Jet's Pizza. The attacker initiated the campaign by sending emails from support@hungerrush.com, urging the company to address the extortion threats to prevent potential data exposure. This incident underscores the evolving tactics of cybercriminals, who are now directly targeting end-users to pressure service providers. The approach not only threatens customer trust but also highlights the critical need for robust cybersecurity measures and rapid incident response protocols within the restaurant technology sector.
6 months ago
Kill Chain
FBI Dismantles LeakBase Cybercrime Forum in Coordinated International Operation
In early March 2026, the FBI, in collaboration with international law enforcement agencies, dismantled LeakBase, a major cybercriminal forum with over 142,000 members. LeakBase facilitated the trade of stolen data and hacking tools, hosting an extensive archive of compromised databases containing hundreds of millions of account credentials. The coordinated operation, known as 'Operation Leak,' involved synchronized actions across 14 countries, including domain seizures, arrests, and evidence collection. This takedown underscores the escalating global efforts to combat cybercrime networks and disrupt platforms that enable the proliferation of stolen data and cyberattack tools. The seizure of LeakBase serves as a stark warning to cybercriminals about the increasing reach and effectiveness of international law enforcement collaborations.
6 months ago
Kill Chain
LastPass Users Targeted in Sophisticated Phishing Attack
In early March 2026, LastPass users were targeted by a sophisticated phishing campaign. Attackers sent emails impersonating LastPass support, claiming unauthorized attempts to change users' account email addresses. These emails included links labeled 'report suspicious activity' and 'disconnect and lock vault,' directing recipients to a counterfeit LastPass login page designed to harvest credentials. The phishing emails often appeared as forwarded internal conversations to create a sense of urgency and legitimacy. LastPass confirmed that their systems remained uncompromised and emphasized that they would never request users' master passwords via email. This incident underscores the evolving tactics of cybercriminals who exploit trust in established brands to deceive users. The use of realistic email threads and urgent security alerts highlights the need for continuous vigilance and user education to recognize and resist such social engineering attacks.
6 months ago
Kill Chain
Critical Unauthenticated Command Injection Vulnerability in VMware Aria Operations
In February 2026, a critical command injection vulnerability (CVE-2026-22719) was identified in VMware Aria Operations, allowing unauthenticated attackers to execute arbitrary commands during support-assisted product migrations. This flaw, with a CVSS score of 8.1, could lead to remote code execution, potentially compromising the entire system. Broadcom released patches to address this issue, but reports indicate active exploitation in the wild. ([thehackernews.com](https://thehackernews.com/2026/03/cisa-adds-actively-exploited-vmware.html?utm_source=openai)) The inclusion of CVE-2026-22719 in CISA's Known Exploited Vulnerabilities catalog underscores the urgency for organizations to apply the provided patches promptly. Delayed remediation increases the risk of unauthorized access and system compromise, especially during migration processes. ([securityweek.com](https://www.securityweek.com/vmware-aria-operations-vulnerability-exploited-in-the-wild/?utm_source=openai))
6 months ago
Kill Chain
Critical Zero-Click RCE Vulnerability in FreeScout: Immediate Action Required
In March 2026, a critical zero-click remote code execution (RCE) vulnerability, identified as CVE-2026-28289, was discovered in FreeScout, an open-source help desk platform. This flaw allows unauthenticated attackers to execute arbitrary code on servers by sending a specially crafted email to a FreeScout-configured mailbox. The vulnerability arises from a Time-of-Check to Time-of-Use (TOCTOU) flaw in the filename sanitization function, enabling the upload of malicious .htaccess files with zero-width space characters to bypass security checks. Exploitation can lead to full server compromise, data breaches, and potential lateral movement within networks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/mail2shell-zero-click-attack-lets-hackers-hijack-freescout-mail-servers/?utm_source=openai)) The emergence of CVE-2026-28289 underscores the evolving sophistication of cyber threats, particularly those requiring no user interaction. Organizations utilizing FreeScout are urged to update to version 1.8.207 immediately to mitigate this risk. This incident highlights the critical need for continuous monitoring and prompt patch management to defend against rapidly developing vulnerabilities.
6 months ago
Kill Chain
Malicious Laravel Packages Deploy PHP RAT
In March 2026, cybersecurity researchers identified malicious PHP packages on Packagist, masquerading as Laravel utilities, which deployed a cross-platform remote access trojan (RAT) functional on Windows, macOS, and Linux systems. The packages—nhattuanbl/lara-helper, nhattuanbl/simple-queue, and nhattuanbl/lara-swagger—were published by the user 'nhattuanbl' and contained obfuscated code that, once installed, connected to a command-and-control server, granting attackers full remote access to compromised hosts. This access allowed for execution of shell commands, file manipulation, and system reconnaissance, posing significant security risks to affected applications. ([thehackernews.com](https://thehackernews.com/2026/03/fake-laravel-packages-on-packagist.html?utm_source=openai)) This incident underscores the growing threat of supply chain attacks targeting open-source ecosystems. Developers are urged to exercise caution when incorporating third-party packages, especially from less-known sources, and to implement rigorous security audits to detect and mitigate such vulnerabilities.
6 months ago
Kill Chain
Understanding the 2026 Google Workspace OAuth Attack
In March 2026, a sophisticated phishing campaign exploited OAuth redirection mechanisms to compromise Google Workspace accounts. Attackers crafted malicious OAuth applications that, when users attempted to authenticate, redirected them from trusted identity providers to attacker-controlled sites, leading to malware downloads. This method allowed adversaries to bypass traditional phishing defenses by leveraging legitimate authentication flows. The incident underscores the evolving tactics of threat actors who exploit standard protocol behaviors to gain unauthorized access, highlighting the need for organizations to implement stringent OAuth governance and cross-domain detection strategies.
6 months ago
Kill Chain
Critical Command Injection Vulnerability in VMware Aria Operations
In February 2026, a critical command injection vulnerability (CVE-2026-22719) was identified in VMware Aria Operations, allowing unauthenticated attackers to execute arbitrary commands during support-assisted product migrations. This flaw, with a CVSS score of 8.1, could lead to remote code execution and full system compromise. Broadcom released patches and workarounds to address the issue. ([support.broadcom.com](https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947?utm_source=openai)) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog on March 3, 2026, indicating active exploitation in the wild. Federal agencies are mandated to apply the fixes by March 24, 2026. ([thehackernews.com](https://thehackernews.com/2026/03/cisa-adds-actively-exploited-vmware.html?utm_source=openai))
6 months ago
Kill Chain
Perplexity Comet Browser's 'PleaseFix' Vulnerabilities Expose Critical Security Flaws
In March 2026, Zenity Labs disclosed critical vulnerabilities in Perplexity's AI-powered Comet browser, collectively termed 'PleaseFix.' These flaws allowed attackers to exploit indirect prompt injections, enabling unauthorized access to local files and credential theft without user interaction. By embedding malicious prompts in trusted content, such as calendar invites, attackers could manipulate the AI agent to perform unauthorized actions, including exfiltrating sensitive data and compromising password managers like 1Password. Perplexity addressed these vulnerabilities following responsible disclosure, implementing fixes to prevent autonomous access to local file systems and unauthorized credential manipulation. This incident underscores the inherent security challenges in agentic AI systems, highlighting the need for robust safeguards against prompt injection attacks and the importance of continuous monitoring and updating of AI-driven applications to mitigate emerging threats.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports