Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
OpenClaw 2026 Infostealer Vidar Breach: A Wake-Up Call for AI Security
In February 2026, cybersecurity researchers identified a significant security breach involving OpenClaw, an open-source AI agent platform. An infostealer malware, likely a variant of Vidar, infiltrated a user's system and exfiltrated sensitive OpenClaw configuration files. These files contained critical data, including API keys for AI services, OAuth tokens for platforms like Gmail and Slack, and detailed operational guidelines of the AI agent. The theft of these credentials enabled attackers to remotely access and control the victim's OpenClaw instance, potentially leading to unauthorized actions and data exfiltration. This incident underscores the evolving threat landscape where infostealer malware targets AI agent configurations, highlighting the urgent need for enhanced security measures in AI integrations. As AI agents become more embedded in professional workflows, they present attractive targets for cybercriminals aiming to exploit their access to sensitive data and systems.
7 months ago
Kill Chain
Major Password Managers Exposed: Critical Vulnerabilities Affect Millions
In February 2026, researchers from ETH Zurich and Università della Svizzera italiana identified critical vulnerabilities in three major cloud-based password managers: Bitwarden, LastPass, and Dashlane. The study revealed 25 distinct attacks that could compromise user vaults, ranging from integrity violations to complete access to all stored passwords. These vulnerabilities exploit flaws in key escrow mechanisms, item-level encryption, sharing features, and backward compatibility with legacy code. Collectively, these password managers serve over 60 million users and nearly 125,000 businesses. ([thehackernews.com](https://thehackernews.com/2026/02/study-uncovers-25-password-recovery.html?utm_source=openai)) This incident underscores the importance of scrutinizing the security claims of widely-used password management solutions. As cyber threats evolve, organizations must ensure that their security tools are resilient against sophisticated attacks, especially those targeting foundational security mechanisms like zero-knowledge encryption.
7 months ago
Kill Chain
Flickr's 2026 Data Breach: A Wake-Up Call for Third-Party Security
In early February 2026, Flickr, a prominent photo-sharing platform, identified a security vulnerability within a third-party email service provider's system. This flaw potentially exposed user data, including names, email addresses, usernames, account types, IP addresses, general locations, and Flickr activity. Importantly, passwords and payment card information remained secure. Upon discovery on February 5, Flickr promptly disabled access to the compromised system and initiated a comprehensive investigation to assess the breach's scope and impact. ([forbes.com](https://www.forbes.com/sites/daveywinder/2026/02/06/photo-sharing-platform-flickr-issues-data-breach-warning/?utm_source=openai)) This incident underscores the critical importance of robust security measures and vigilant monitoring of third-party service providers. As organizations increasingly rely on external vendors, ensuring these partners adhere to stringent security protocols is essential to safeguard sensitive user information and maintain trust.
7 months ago
Kill Chain
SmarterMail 2026 Ransomware Attack via RCE Vulnerability
In early 2026, a critical vulnerability (CVE-2026-24423) was discovered in SmarterTools' SmarterMail email server, allowing unauthenticated remote code execution via the ConnectToHub API. This flaw was actively exploited by ransomware actors, leading to unauthorized access and potential data breaches. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog, urging immediate patching by February 26, 2026. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-warns-of-smartermail-rce-flaw-used-in-ransomware-attacks/?utm_source=openai)) The exploitation of this vulnerability underscores the increasing targeting of email servers by cybercriminals, emphasizing the need for organizations to promptly apply security updates and monitor for unusual activities to mitigate potential threats.
7 months ago
Kill Chain
dYdX Supply Chain Attack Exposes Cryptocurrency Wallets to Theft
In early February 2026, dYdX, a decentralized cryptocurrency exchange, experienced a significant supply chain attack. Malicious actors compromised legitimate npm and PyPI packages—@dydxprotocol/v4-client-js and dydx-v4-client, respectively—by publishing infected versions using legitimate developer credentials. These compromised packages were designed to steal wallet credentials and, in the case of the PyPI package, deploy a remote access trojan (RAT) for executing arbitrary commands on affected systems. The attack underscores the vulnerabilities inherent in software supply chains and the potential for widespread impact when trusted distribution channels are exploited. This incident highlights a persistent pattern of adversaries targeting dYdX-related assets through trusted distribution channels, following similar attacks in 2022 and 2024. The coordinated cross-ecosystem deployment and sophisticated obfuscation techniques suggest that threat actors had direct access to publishing infrastructure, emphasizing the need for enhanced security measures in software development and distribution processes.
7 months ago
Kill Chain
Moltbook's 2026 Security Breach: A Cautionary Tale of Cloud Misconfiguration
In late January 2026, Moltbook, an AI-exclusive social platform, suffered a significant security breach due to a misconfigured Supabase database. This vulnerability exposed sensitive data, including 1.5 million AI agent API tokens, 35,000 email addresses, and private messages. The misconfiguration allowed unauthorized access and modification of agent records, leading to potential impersonation and data manipulation. Promptly addressing the issue, Moltbook resolved the vulnerability within hours of disclosure. ([techradar.com](https://www.techradar.com/pro/security/ai-agent-social-media-network-moltbook-is-a-security-disaster-millions-of-credentials-and-other-details-left-unsecured?utm_source=openai)) This incident underscores the critical importance of robust security configurations in cloud-based platforms, especially those handling sensitive user data. It highlights the risks associated with rapid deployment of AI-driven services without comprehensive security assessments, emphasizing the need for stringent access controls and regular security audits to prevent similar breaches.
7 months ago
Kill Chain
Critical OS Command Injection Vulnerability in React Native CLI's Metro Development Server
In November 2025, a critical vulnerability (CVE-2025-11953) was identified in the React Native Community CLI's Metro Development Server. This flaw allowed unauthenticated attackers to execute arbitrary commands on the host system by sending specially crafted POST requests to the server's '/open-url' endpoint. The vulnerability affected versions 4.8.0 through 20.0.0-alpha.2 and was patched in version 20.0.0. Developers were advised to update their installations promptly or restrict the server's network exposure to mitigate the risk. ([research.jfrog.com](https://research.jfrog.com/vulnerabilities/react-native-cli-command-injection-jfsa-2025-001495618/?utm_source=openai)) The incident underscores the importance of securing development tools and environments, as vulnerabilities in such tools can serve as entry points for attackers. It also highlights the need for developers to stay vigilant about applying security patches and configuring development servers securely to prevent unauthorized access.
7 months ago
Kill Chain
Zendesk 2026 Spam Campaign: A Wake-Up Call for Securing Support Systems
In January 2026, a massive global spam campaign exploited unsecured Zendesk support systems, allowing attackers to flood users' inboxes with automated 'ticket received' emails. By abusing Zendesk instances that permitted unverified users to submit support tickets, attackers generated numerous fake tickets using large email lists. This resulted in victims receiving confirmation emails from legitimate Zendesk domains, enabling the messages to bypass spam filters and inundate users' inboxes. Affected organizations included major companies such as Discord, Tinder, Riot Games, Dropbox, CD Projekt, NordVPN, and various Tennessee state departments. Notably, the spam emails did not contain malware or phishing links but featured bizarre and seemingly pointless messages, such as fake law enforcement takedown requests and promotional offers. Zendesk acknowledged the issue and responded by implementing new safety measures, including enhanced monitoring and stricter activity limits to detect and halt spam efforts more effectively. The campaign began on January 18, 2026, but its current status remains unclear. ([techradar.com](https://www.techradar.com/pro/security/zendesk-tickets-hijacked-in-massive-spam-campaign?utm_source=openai)) This incident underscores the critical importance of securing customer support platforms against abuse. The exploitation of Zendesk's ticketing system highlights a broader trend where attackers leverage legitimate services to conduct spam campaigns, thereby evading traditional security measures. Organizations must proactively assess and fortify their support systems to prevent similar abuses, ensuring that such platforms do not become vectors for large-scale spam or other malicious activities.
7 months ago
Kill Chain
Betterment's 2026 Data Breach: A Social Engineering Wake-Up Call
In January 2026, Betterment, a prominent fintech firm, experienced a data breach resulting from a social engineering attack targeting third-party platforms used for marketing and operations. Unauthorized access was gained on January 9, allowing attackers to obtain personal information—including names, email addresses, postal addresses, phone numbers, and dates of birth—of approximately 1.4 million customers. The attackers exploited this access to send fraudulent cryptocurrency-related messages, falsely promising to triple users' crypto investments if they transferred funds to attacker-controlled wallets. Betterment detected the breach on the same day, revoked unauthorized access, and initiated a comprehensive investigation with cybersecurity experts. Importantly, no customer accounts, passwords, or login credentials were compromised during the incident. ([techcrunch.com](https://techcrunch.com/2026/01/12/fintech-firm-betterment-confirms-data-breach-after-hackers-send-fake-crypto-scam-notification-to-users/?utm_source=openai)) This incident underscores the escalating threat of social engineering attacks within the fintech sector, particularly those targeting third-party service integrations. The breach highlights the critical need for robust security measures, employee training, and vigilant monitoring of external platforms to prevent unauthorized access and protect sensitive customer information.
7 months ago
Kill Chain
La Sapienza University Ransomware Attack: A 2026 Case Study
In early February 2026, La Sapienza University in Rome, one of Europe's largest educational institutions, experienced a significant cyberattack attributed to the pro-Russian group Femwar02. The attackers deployed the BabLock (also known as Rorschach) ransomware, leading to the encryption of critical data and the disruption of numerous IT services. In response, the university proactively shut down its network systems to safeguard data integrity and initiated restoration efforts with the assistance of Italy's National Cybersecurity Agency. ([techcrunch.com](https://techcrunch.com/2026/02/05/one-of-europes-largest-universities-knocked-offline-for-days-after-cyberattack/?utm_source=openai)) This incident underscores the escalating threat of sophisticated ransomware attacks targeting educational institutions, highlighting the urgent need for enhanced cybersecurity measures and preparedness within the sector.
7 months ago
Kill Chain
Ransomware Gangs Exploit ISPsystem VMs for Stealthy Payload Delivery
In early 2026, cybersecurity researchers uncovered that multiple ransomware groups, including LockBit, Qilin, Conti, BlackCat/ALPHV, and Ursnif, were exploiting virtual machines (VMs) provisioned by ISPsystem's VMmanager to host and deliver malicious payloads. These attackers utilized default Windows VM templates with identical hostnames, allowing them to blend malicious infrastructure with legitimate systems, thereby complicating detection and takedown efforts. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ransomware-gang-uses-ispsystem-vms-for-stealthy-payload-delivery/?utm_source=openai)) This incident highlights a growing trend where cybercriminals leverage legitimate virtualization platforms to obfuscate their operations. The ease of deploying VMs with default configurations presents a significant security risk, emphasizing the need for organizations to scrutinize and secure their virtual infrastructure to prevent such abuses. ([sophos.com](https://www.sophos.com/en-us/blog/malicious-use-of-virtual-machine-infrastructure?utm_source=openai))
7 months ago
Kill Chain
Spain's Ministry of Science 2026 Data Breach: A Wake-Up Call for Government Cybersecurity
In early February 2026, Spain's Ministry of Science, Innovation, and Universities experienced a significant cybersecurity incident. A threat actor known as 'GordonFreeman' claimed to have exploited an Insecure Direct Object Reference (IDOR) vulnerability, combined with leaked credentials, to gain full administrative access to the ministry's systems. The attacker allegedly exfiltrated sensitive data, including personal records, email addresses, enrollment applications, and official documents. In response, the ministry partially shut down its IT systems, affecting various services for researchers, universities, and students, and suspended all ongoing administrative procedures to assess and mitigate the breach. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/spains-ministry-of-science-shuts-down-systems-after-breach-claims/?utm_source=openai)) This incident underscores the critical importance of robust access controls and vulnerability management within governmental institutions. The exploitation of an IDOR vulnerability highlights the need for comprehensive security assessments and prompt remediation of identified weaknesses. Additionally, the breach serves as a reminder of the persistent threats posed by cyber actors targeting sensitive governmental data, emphasizing the necessity for continuous monitoring and incident response preparedness.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports