Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
React2Shell (CVE-2025-55182) Exploitation in 2025
In December 2025, a critical vulnerability known as React2Shell (CVE-2025-55182) was disclosed, affecting React Server Components (RSC) versions 19.0 through 19.2.0. This flaw allowed unauthenticated remote code execution (RCE) via malicious HTTP POST requests, enabling attackers to execute arbitrary code on vulnerable servers. Within hours of disclosure, state-sponsored threat groups, including China's Earth Lamia and Jackpot Panda, as well as North Korean actors, began exploiting the vulnerability to deploy malware, establish persistent backdoors, and conduct cyber-espionage activities. The rapid exploitation underscored the severity of the vulnerability and the need for immediate remediation. ([aws.amazon.com](https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/?utm_source=openai)) The widespread use of React in web applications, including major platforms like Facebook, Netflix, and Airbnb, amplifies the potential impact of this vulnerability. Organizations are urged to update to patched versions 19.0.1, 19.1.2, and 19.2.1 to mitigate the risk. ([techradar.com](https://www.techradar.com/pro/security/experts-warn-this-worst-case-scenario-react-vulnerability-could-soon-be-exploited-so-patch-now?utm_source=openai))
7 months ago
Kill Chain
Infy APT 2026: Iranian State-Sponsored Cyber Espionage Resurfaces
In early 2026, the Iranian state-sponsored Advanced Persistent Threat (APT) group known as Infy, or 'Prince of Persia,' resumed operations following a period of inactivity during Iran's internet blackout in January. The group deployed updated versions of their malware tools, Foudre and Tonnerre, to target entities across Iran, Iraq, Turkey, India, Canada, and Europe. Notably, Infy utilized a new command-and-control (C2) infrastructure, incorporating both HTTP and Telegram for communication, and exploited a 1-day vulnerability in WinRAR to deliver their payloads. This resurgence underscores Infy's continued commitment to cyber espionage activities aligned with Tehran's strategic interests. ([thehackernews.com](https://thehackernews.com/2026/02/infy-hackers-resume-operations-with-new.html?utm_source=openai)) The re-emergence of Infy highlights the persistent threat posed by state-sponsored cyber actors who continuously evolve their tactics to evade detection. Organizations, especially those in the targeted regions, must remain vigilant and enhance their cybersecurity measures to defend against such sophisticated threats.
7 months ago
Kill Chain
GitHub Codespaces RCE Vulnerability: What Developers Need to Know
In early February 2026, security researchers identified multiple attack vectors within GitHub Codespaces that allow remote code execution (RCE) when users open malicious repositories or pull requests. The vulnerability exploits how Visual Studio Code-integrated configuration files are automatically processed, enabling attackers to execute arbitrary commands, exfiltrate GitHub tokens, and access sensitive resources without explicit user approval. Microsoft has currently deemed this behavior as 'by design,' and no CVE has been assigned. ([scworld.com](https://www.scworld.com/news/vs-code-config-files-abused-to-launch-rces-via-github-codespaces?utm_source=openai)) This incident underscores the growing trend of attackers leveraging trusted development environments to execute malicious code, highlighting the need for enhanced security measures and user awareness in cloud-based development platforms.
7 months ago
Kill Chain
Aisuru/Kimwolf Botnet's Unprecedented 31.4 Tbps DDoS Attack in 2025
In December 2025, the Aisuru/Kimwolf botnet launched a record-breaking distributed denial-of-service (DDoS) attack, peaking at 31.4 terabits per second (Tbps) and 200 million requests per second. This unprecedented assault targeted multiple companies, primarily in the telecommunications sector, and Cloudflare's own infrastructure. The attack, part of a campaign dubbed "The Night Before Christmas," was successfully mitigated by Cloudflare's automated systems, preventing significant disruptions. ([techradar.com](https://www.techradar.com/pro/security/the-biggest-ddos-attack-ever-has-been-detected-but-fortunately-you-probably-barely-noticed-it?utm_source=openai)) This incident underscores the escalating scale and sophistication of DDoS attacks, highlighting the urgent need for robust cybersecurity measures. The rapid growth of botnets like Aisuru/Kimwolf, which exploit vulnerabilities in IoT devices, poses a significant threat to global internet infrastructure. ([tomshardware.com](https://www.tomshardware.com/service-providers/network-providers/botnet-smashes-ddos-traffic-record-at-31-4-tb-s-equivalent-to-streaming-2-2-million-netflix-4k-movies-at-once-attack-was-large-enough-to-take-entire-countries-offline?utm_source=openai))
7 months ago
Kill Chain
Windows Screensaver Malware Attack 2026: A New Vector for Remote Access Exploitation
In early February 2026, cybersecurity researchers identified a spear-phishing campaign exploiting Windows screensaver files (.scr) to deploy remote access tools (RATs) on corporate networks. Attackers sent business-themed phishing emails containing links to download files disguised as routine documents, which were actually malicious screensaver files. When executed, these files installed legitimate remote monitoring and management (RMM) tools, such as SimpleHelp, providing attackers with persistent remote access to compromised systems. This method allowed adversaries to bypass traditional security controls, as screensaver files are often overlooked as potential threats. The campaign underscores the evolving tactics of threat actors who leverage unconventional file types and legitimate software to infiltrate networks, emphasizing the need for organizations to reassess and strengthen their security postures against such sophisticated social engineering attacks.
7 months ago
Kill Chain
DragonForce Ransomware Cartel: A New Era of Cyber Threats in 2025
In March 2025, the DragonForce ransomware group rebranded itself as a cartel, allowing affiliates to create their own brands while utilizing DragonForce's infrastructure and tools. This strategic shift led to increased collaboration among ransomware groups, notably with LockBit and Qilin, aiming to consolidate power and enhance operational effectiveness. The cartel model facilitated larger, more coordinated ransomware campaigns, employing advanced tactics such as double extortion, exploitation of known vulnerabilities, and the use of sophisticated tools like Cobalt Strike and Mimikatz. This evolution resulted in a significant uptick in ransomware incidents, impacting various sectors globally, including government entities, retail operations, manufacturing companies, and construction firms. The formation of such cartels underscores a concerning trend in the cyber threat landscape, where ransomware groups are increasingly collaborating to amplify their reach and impact. This development necessitates heightened vigilance and adaptive defense strategies from organizations to mitigate the evolving threats posed by these alliances.
7 months ago
Kill Chain
Iranian Cyber Espionage Intensifies: Middle East Expatriates Targeted in 2026
In early 2026, Iranian state-sponsored cyber actors intensified their espionage activities targeting Middle Eastern expatriates, Syrians, and Israelis. Utilizing sophisticated social engineering techniques, these actors created credible fake personas on multiple platforms, engaging targets over extended periods to build trust. Once rapport was established, they employed spear-phishing campaigns, often delivering malicious links or documents under the guise of legitimate communications. These operations aimed to steal sensitive information, monitor communications, and track the movements of individuals of interest. The impact of these campaigns has been significant, compromising personal and professional data, and posing threats to the safety and privacy of the targeted individuals. The use of advanced social engineering tactics underscores the evolving nature of cyber threats emanating from state-sponsored actors. This incident highlights the urgent need for heightened vigilance and robust cybersecurity measures, especially for individuals and organizations operating in or related to the Middle East. The increasing sophistication of these attacks, coupled with their targeted nature, reflects a broader trend of state actors leveraging cyber capabilities for intelligence gathering and influence operations.
7 months ago
Kill Chain
Phishing Campaign 2026: Malformed URLs Bypass Security Measures
In early February 2026, a sophisticated phishing campaign emerged, utilizing malformed URLs to bypass traditional email security measures. Attackers embedded URLs with irregular parameter structures in phishing emails, leading recipients to malicious websites. This technique effectively evaded detection systems that rely on standard URL parsing and validation, thereby increasing the likelihood of successful credential theft and malware distribution. The campaign underscores the evolving tactics of cybercriminals in circumventing established security protocols. The resurgence of such techniques highlights the need for organizations to continuously adapt their security strategies. As attackers refine their methods to exploit weaknesses in URL parsing and detection, it becomes imperative for security systems to incorporate advanced analysis capabilities to identify and mitigate these sophisticated threats.
7 months ago
Kill Chain
Microsoft's 2026 Breakthrough in AI Language Model Backdoor Detection
In February 2026, Microsoft unveiled a novel approach to detect backdoors in open-weight language models, addressing the growing concern of model poisoning where adversaries embed hidden behaviors during training. This research introduces a scalable scanner capable of identifying backdoored models by analyzing distinctive attention patterns and output behaviors, thereby enhancing trust in AI systems. The significance of this development is underscored by prior findings that even minimal malicious data can implant backdoors in large language models, emphasizing the urgency for robust detection mechanisms. Microsoft's initiative represents a proactive step towards securing AI deployments against such covert threats.
7 months ago
Kill Chain
Notepad++ Supply Chain Attack: A Wake-Up Call for Software Security
Between June and December 2025, Notepad++, a widely used text editor, was compromised through a sophisticated supply chain attack attributed to Chinese state-sponsored hackers. The attackers infiltrated the hosting provider's infrastructure, allowing them to intercept and redirect update traffic to malicious servers. This enabled the delivery of backdoored versions of Notepad++ to selected users, primarily targeting sectors such as government, telecommunications, and critical infrastructure. The breach was identified in early February 2026, prompting immediate security enhancements and advisories for users to update to version 8.9.1 or later. This incident underscores the escalating threat of supply chain attacks, where adversaries exploit trusted software distribution channels to infiltrate target systems. Organizations are urged to reassess and fortify their software update mechanisms, implement stringent verification processes, and remain vigilant against such sophisticated attack vectors.
7 months ago
Kill Chain
Coinbase Insider Breach 2025: A Cautionary Tale of Insider Threats in the Financial Sector
In May 2025, Coinbase, the largest U.S.-based cryptocurrency exchange, disclosed a significant data breach affecting approximately 69,461 customers. The breach, which occurred on December 26, 2024, was orchestrated by cybercriminals who bribed overseas customer support agents to gain unauthorized access to sensitive customer information. The compromised data included names, addresses, phone numbers, email addresses, masked Social Security numbers, masked bank account numbers, government-issued ID images, and account transaction histories. Notably, no passwords, private keys, or funds were exposed, and Coinbase Prime accounts remained unaffected. The attackers demanded a $20 million ransom, which Coinbase refused to pay, instead offering a $20 million bounty for information leading to the attackers' arrest. The company estimated remediation costs between $180 million and $400 million and pledged to reimburse affected customers. This incident underscores the critical importance of robust insider threat detection and prevention measures, especially in the financial sector. The breach highlights the vulnerabilities associated with third-party service providers and the need for stringent access controls and monitoring. As insider threats continue to pose significant risks, organizations must prioritize comprehensive security strategies to safeguard sensitive customer data and maintain trust.
7 months ago
Kill Chain
Home Depot's 2024 GitHub Token Leak: A Cautionary Tale in Credential Management
In early 2024, a Home Depot employee inadvertently published a private GitHub access token, exposing the company's internal systems for over a year. This token granted unauthorized access to hundreds of private source code repositories, cloud infrastructure, order fulfillment, and inventory management systems. Despite multiple attempts by security researcher Ben Zimmermann to alert Home Depot, the token remained active until December 2025, when media intervention prompted its revocation. This incident underscores the critical need for robust credential management and proactive security measures to prevent unauthorized access to sensitive systems. The prolonged exposure highlights systemic gaps in credential governance and the importance of timely response to security disclosures.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports