Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Fulton County 2026: FBI's Controversial Election Document Seizure
In January 2026, the FBI conducted a raid on Fulton County's election offices in Georgia, seizing ballots and election-related documents from the 2020 presidential election. The operation, overseen by Director of National Intelligence Tulsi Gabbard, was based on allegations of record-keeping deficiencies and potential vote manipulation. However, these claims had been previously investigated and debunked by state officials. The raid has raised significant concerns about federal overreach and the integrity of election processes. ([apnews.com](https://apnews.com/article/9dfecd778c09134e9aa0bba2848718f5?utm_source=openai)) This incident underscores the ongoing challenges in balancing election security with federal authority, highlighting the need for clear protocols and transparency to maintain public trust in the electoral system.
7 months ago
Kill Chain
Figure Technology Solutions Data Breach: A 2026 Case Study
In January 2026, Figure Technology Solutions, a blockchain-based fintech lender, suffered a data breach exposing the personal information of approximately 967,200 customers. The breach was executed by the cybercriminal group ShinyHunters through a social engineering attack that deceived an employee into granting unauthorized access. The compromised data includes full names, email addresses, phone numbers, physical addresses, and dates of birth. ShinyHunters subsequently published 2.5GB of this data online after Figure declined to meet their ransom demands. This incident underscores the increasing prevalence of social engineering tactics targeting financial institutions, highlighting the critical need for robust employee training and advanced security measures to prevent unauthorized access. Organizations must remain vigilant against such sophisticated attacks to protect sensitive customer information and maintain trust.
7 months ago
Kill Chain
Critical SmarterMail Vulnerabilities Exploited in 2026
In January 2026, SmarterTools' SmarterMail software was found to have two critical vulnerabilities: CVE-2026-24423, an unauthenticated remote code execution flaw, and CVE-2026-23760, an authentication bypass issue. These vulnerabilities allowed attackers to execute arbitrary code and reset administrator passwords without authentication, leading to full system compromise. Exploitation began shortly after disclosure, with threat actors sharing exploit code and compromised credentials on underground forums. ([scworld.com](https://www.scworld.com/news/smartermail-vulnerabilities-exploited-in-ransomware-campaigns?utm_source=openai)) The rapid weaponization of these vulnerabilities underscores the increasing speed at which attackers exploit newly disclosed flaws. Organizations must prioritize timely patching and enhance monitoring of email infrastructure to prevent similar breaches. ([scworld.com](https://www.scworld.com/news/smartermail-vulnerabilities-exploited-in-ransomware-campaigns?utm_source=openai))
7 months ago
Kill Chain
AI Assistants: The New Frontier for Stealthy Malware Communication
In February 2026, cybersecurity researchers from Check Point Research identified a novel method by which AI assistants with web browsing capabilities, such as Microsoft Copilot and xAI's Grok, can be exploited to facilitate covert command-and-control (C2) communications for malware. By manipulating these AI platforms to fetch attacker-controlled URLs, threat actors can establish stealthy communication channels that blend seamlessly into legitimate enterprise traffic, thereby evading traditional detection mechanisms. This technique underscores the evolving landscape of cyber threats, where everyday AI tools are repurposed for malicious activities. The discovery highlights a significant shift in cyberattack methodologies, emphasizing the need for organizations to reassess their security postures in the context of AI integration. As AI assistants become more prevalent in enterprise environments, the potential for their misuse in cyberattacks increases, necessitating enhanced monitoring and adaptive defense strategies to mitigate such risks.
7 months ago
Kill Chain
Dell RecoverPoint Zero-Day Exploited by UNC6201
In mid-2024, a critical zero-day vulnerability (CVE-2026-22769) in Dell's RecoverPoint for Virtual Machines was exploited by the China-linked cyberespionage group UNC6201. This flaw, involving hardcoded credentials, allowed unauthenticated remote attackers to gain root-level access, facilitating lateral movement, persistent access, and deployment of malware such as BRICKSTORM and the newer GRIMBOLT backdoor. The attackers also employed 'ghost NICs' to stealthily pivot within virtualized environments, complicating detection and response efforts. The exploitation of this vulnerability underscores the persistent threat posed by state-sponsored actors targeting critical infrastructure. Organizations are urged to apply Dell's remediation measures promptly to mitigate potential risks associated with this exploit.
7 months ago
Kill Chain
Critical Flaws in Popular VS Code Extensions Put Millions at Risk
In February 2026, critical vulnerabilities were discovered in four widely used Visual Studio Code (VS Code) extensions—Live Server, Code Runner, Markdown Preview Enhanced, and Microsoft Live Preview—collectively installed over 125 million times. These flaws could allow attackers to steal local files and execute remote code by exploiting weaknesses in the extensions' handling of web content and local server configurations. Notably, CVE-2025-65717 in Live Server enables file exfiltration via malicious websites, while CVE-2025-65716 in Markdown Preview Enhanced permits arbitrary code execution through crafted markdown files. Despite disclosure in June 2025, three of these vulnerabilities remained unpatched as of February 2026, leaving developers exposed to significant security risks. ([thehackernews.com](https://thehackernews.com/2026/02/critical-flaws-found-in-four-vs-code.html?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting development environments. The exploitation of trusted tools like VS Code extensions highlights the need for developers to exercise caution when installing and updating extensions, and for maintainers to prioritize timely security patches to mitigate potential compromises.
7 months ago
Kill Chain
The Rise of RMM Tool Exploitation in Cyber Attacks
In early 2025, cybersecurity researchers observed a significant increase in cyberattacks leveraging legitimate Remote Monitoring and Management (RMM) tools such as AnyDesk, ScreenConnect, and SimpleHelp. Threat actors exploited these tools to gain unauthorized access to systems, maintain persistence, and execute malicious activities without deploying traditional malware. This method allowed attackers to blend seamlessly into normal IT operations, making detection challenging. The impact was widespread, affecting various sectors including healthcare, finance, and education, leading to data breaches, financial losses, and operational disruptions. This trend underscores a shift in cybercriminal tactics towards 'Living-off-the-Land' techniques, where adversaries misuse trusted tools to evade detection. The rise in RMM abuse highlights the need for organizations to enhance monitoring of legitimate software usage and implement stringent access controls to mitigate such threats.
7 months ago
Kill Chain
UNC3886's 2025 Cyber Attack on Singapore's Telecom Sector
In July 2025, Singapore's four major telecommunications providers—Singtel, StarHub, M1, and SIMBA Telecom—were targeted by the Chinese state-sponsored cyber espionage group UNC3886. The attackers employed sophisticated techniques, including rootkits and zero-day exploits in firewalls, to gain unauthorized access to parts of the telecom networks. Despite these efforts, the intrusion did not disrupt services or result in the exfiltration of sensitive customer data. The Singaporean government, in collaboration with the affected telcos, launched Operation Cyber Guardian, a coordinated response involving over 100 personnel from various agencies, to contain and mitigate the threat. ([channelnewsasia.com](https://www.channelnewsasia.com/singapore/unc3886-cyberattack-targets-singapore-telcos-threat-contained-5916906?utm_source=openai)) This incident underscores the persistent and evolving nature of cyber threats targeting critical infrastructure. The use of advanced tools and tactics by UNC3886 highlights the need for continuous vigilance and robust cybersecurity measures within the telecommunications sector to safeguard against potential future attacks.
7 months ago
Kill Chain
Microsoft Office Equation Editor Exploit: A 2026 Malware Campaign
In February 2026, a sophisticated malware campaign exploited the Microsoft Office Equation Editor vulnerability (CVE-2017-11882) to deliver malicious payloads. Attackers distributed emails with attachments that, when opened, triggered the exploit, leading to the download and execution of harmful scripts and DLLs. Notably, the campaign reused a JPEG image embedding the final payload, a technique observed in previous attacks, indicating a pattern of leveraging known vulnerabilities and methods. This incident underscores the persistent threat posed by unpatched vulnerabilities and the reuse of attack techniques. Organizations must prioritize timely patching and remain vigilant against evolving malware delivery methods to mitigate such risks.
7 months ago
Kill Chain
Anthropic's Git MCP Server Vulnerabilities: A Wake-Up Call for AI Security
In January 2026, Anthropic addressed critical vulnerabilities in its Git MCP server, a key component of the Model Context Protocol enabling AI tools to interact with code repositories. Security researchers identified three significant flaws: a path validation bypass (CVE-2025-68145), an unrestricted git_init issue (CVE-2025-68143), and an argument injection flaw in git_diff (CVE-2025-68144). These vulnerabilities, particularly when combined with the Filesystem MCP server, could allow remote code execution or file tampering via prompt injection. Reported in June 2025, these issues were patched by Anthropic in December 2025 with version 2025.12.18. While no active exploitation has been confirmed, this incident highlights the growing risks associated with integrating complex AI systems, where safe components may become vulnerable when used together. The event also references a prior incident from November 2025, where Anthropic's Claude AI was manipulated in a cyberespionage campaign targeting major global entities, underscoring the broader cybersecurity challenges linked to rapid AI adoption.
7 months ago
Kill Chain
Chinese APT UNC6201 Exploits Dell RecoverPoint Zero-Day Vulnerability
In mid-2024, the Chinese state-sponsored threat group UNC6201 exploited a critical zero-day vulnerability (CVE-2026-22769) in Dell's RecoverPoint for Virtual Machines. This flaw, stemming from hardcoded administrator credentials in Apache Tomcat, allowed unauthenticated remote attackers to gain full system access and establish root-level persistence. The attackers deployed malware such as Brickstorm and later Grimbolt, facilitating long-term espionage and data exfiltration. ([cyberscoop.com](https://cyberscoop.com/china-brickstorm-grimbolt-dell-zero-day/?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors targeting critical infrastructure. The prolonged undetected exploitation highlights the necessity for robust vulnerability management and continuous monitoring to detect and mitigate such sophisticated attacks. ([cyberscoop.com](https://cyberscoop.com/china-brickstorm-grimbolt-dell-zero-day/?utm_source=openai))
7 months ago
Kill Chain
Poland's Crackdown on Phobos Ransomware: A 2026 Update
In February 2026, Polish authorities arrested a 47-year-old man in the Małopolska region, suspected of affiliating with the Phobos ransomware group. The arrest was part of 'Operation Aether,' an international effort coordinated by Europol targeting Phobos ransomware infrastructure and affiliates. During the operation, law enforcement seized computers and mobile phones containing stolen credentials, credit card numbers, and server access data, which could be used to facilitate ransomware attacks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/poland-arrests-suspect-linked-to-phobos-ransomware-operation/?utm_source=openai)) This arrest underscores the ongoing global efforts to dismantle ransomware operations and highlights the persistent threat posed by groups like Phobos. Organizations are reminded to bolster their cybersecurity defenses, particularly around Remote Desktop Protocol (RDP) configurations, to mitigate the risk of such attacks.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports