Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
HoneyMyte APT Unleashes Kernel-Mode Rootkit with ToneShell Backdoor in Southeast Asia
In early 2025, the HoneyMyte APT group launched a targeted cyberespionage campaign against government organizations in Southeast and East Asia, primarily Myanmar and Thailand. Leveraging a stolen digital certificate, HoneyMyte deployed a malicious kernel-mode rootkit disguised as a signed driver to inject the advanced ToneShell backdoor into high-privilege system processes. The attack chain delivered full process, registry, and file protection for malicious activity, making removal and detection by security tools exceedingly challenging. The backdoor enabled covert remote access, data exfiltration, and command execution via communications camouflaged to resemble legitimate encrypted TLS traffic. This incident is a stark example of modern APT evolution, showcasing new levels of stealth and persistence through kernel-level threats and advanced obfuscation. It highlights a broader shift towards supply-chain and trusted-cert abuse, increasing risk for public sector and critical infrastructure targets in the Asia-Pacific region.
8 months ago
Kill Chain
KMSAuto Malware Campaign Leads to 2.8 Million Infections: Lithuanian Hacker Arrested
In early 2024, authorities arrested a Lithuanian national in connection with a large-scale malware campaign leveraging a trojanized version of KMSAuto, a popular software activation tool. The suspect is accused of distributing clipboard-stealing infostealer malware, which disguised itself as a utility for activating Windows and Office software. Over roughly two years, it is estimated that over 2.8 million downloads led to widespread infections, enabling the theft of sensitive data, including cryptocurrency wallet credentials, through malicious clipboard monitoring. This case highlights the persistent risk of malware-laden software masquerading as gray-market utilities, particularly where users bypass official software channels. The campaign demonstrates how threat actors continue to exploit user trust in widely circulated but unofficial tools, underlining the urgent need for supply chain vigilance and robust endpoint protection.
8 months ago
Kill Chain
When Threats Collide: 2025's Multi-Vector Breach Exposes Gaps from Database to Wallet
In December 2025, a rapid succession of cyber incidents targeted multiple sectors, blending attacks on exposed MongoDB instances, large-scale cryptocurrency wallet breaches, Android device spyware campaigns, and insider threat activity within enterprises. Attackers exploited both unpatched vulnerabilities and legitimate remote access mechanisms, leveraging high-speed lateral movements and targeting cloud infrastructures, regulated data, and financial assets. The breaches compromised sensitive customer data and business-critical systems, highlighting a coordinated pivot between vectors such as cloud misconfiguration, mobile malware, and abuse of internal access privileges. This wave underscores a growing convergence of threat vectors and the urgent need for unified defense frameworks. With attackers accelerating their use of automation, targeting east-west traffic, and blending traditional and emerging attack paths, organizations face mounting pressure to enhance multicloud visibility, segmentation, and real-time anomaly response.
8 months ago
Kill Chain
CISA Adds MongoDB CVE-2025-14847 to KEV Catalog Amid Active Exploitation
In December 2025, CISA added CVE-2025-14847 to its Known Exploited Vulnerabilities (KEV) Catalog following confirmation of active exploitation in the wild. The vulnerability, found in MongoDB and MongoDB Server, involves improper handling of length parameter inconsistencies, potentially enabling attackers to compromise data confidentiality and integrity through specially crafted requests. This flaw has become an attractive initial attack vector for threat actors targeting federal and private sector systems. The KEV listing triggers urgent remediation directives for federal agencies and strongly recommends private organizations act quickly to mitigate system and data risks. The designation of this MongoDB vulnerability underlines the continued focus of both attackers and defenders on widely used open-source software. As exploitation of unpatched vulnerabilities accelerates, industry and government face mounting regulatory and operational pressure to prioritize swift vulnerability management amid a rapidly evolving attack landscape.
8 months ago
Kill Chain
MongoDB Global Breach: Exploiting MongoBleed (CVE-2025-14847) for Data Exposure
In December 2025, a major security vulnerability (CVE-2025-14847), dubbed MongoBleed, was exploited globally across more than 87,000 MongoDB instances. This high-severity flaw in the default zlib compression feature of MongoDB servers enabled unauthenticated attackers to remotely leak sensitive information, including credentials and API keys, by sending specially crafted network packets that expose uninitialized heap memory. First disclosed by OX Security and corroborated by Wiz, the vulnerability’s impact is magnified in cloud environments and internet-exposed infrastructure, prompting urgent mitigation actions worldwide. The MongoBleed incident marks a significant escalation in memory exposure and pre-authentication exploitation methods targeting widely adopted cloud database technologies. The attack's broad reach and urgency have galvanized regulators and security teams, emphasizing the need for timely patching, network exposure reduction, and enhanced security policies for infrastructure software.
8 months ago
Kill Chain
n8n Workflow Automation Hit by Critical RCE Vulnerability (CVE-2025-68613)
In December 2025, a critical vulnerability (CVE-2025-68613) was disclosed in the popular open-source workflow automation tool n8n, allowing unauthenticated attackers to execute arbitrary code remotely under specific conditions. The flaw, rated CVSS 9.9, was identified by security researcher Fatih Çelik and reportedly affects thousands of publicly accessible n8n instances globally. By exploiting weak access controls and improper sanitization of user input, threat actors could gain control over affected servers, leading to potential data theft, lateral movement within networks, and disruption of workflow automations. This incident highlights the persistent risks posed by software supply chain vulnerabilities and the urgent need for organizations to monitor and remediate critical flaws in automation platforms. With workflow automation tools increasingly integrated into business operations, their exploitation represents a growing vector for both targeted and opportunistic cyberattacks.
8 months ago
Kill Chain
DoJ Takes Down Fraud Domain Powering $14.6M Account Takeover Scheme
In December 2025, the U.S. Department of Justice (DoJ), working with international partners, seized the domain web3adspanels[.]org at the heart of a large-scale bank account takeover scheme. The criminal group exploited fraudulent search ads to trick users into accessing spoofed bank login portals, harvesting credentials through malicious site components. These stolen credentials enabled attackers to infiltrate legitimate banking sites, drain victim accounts, and inflict confirmed losses of $14.6 million across 19 U.S. victims, including two companies. The backend database hosted by the seized domain contained thousands of login credentials and operated through November 2025. This incident is part of a broader surge in credential-based financial fraud, leveraging sophisticated phishing infrastructure and real-time abuse of search advertising. With attackers refining techniques to bypass user suspicion, enforcement agencies are increasing pressure on such online infrastructure in response to rising losses and evolving digital fraud tactics.
8 months ago
Kill Chain
MongoBleed 2025: Critical MongoDB Vulnerability Exposes Data on 87K Servers
In early June 2025, the MongoBleed vulnerability (CVE-2025-14847) was actively exploited against MongoDB servers worldwide, exposing sensitive database secrets and credentials on over 87,000 publicly accessible systems. Attackers exploited a flaw present in multiple MongoDB versions, allowing unauthorized access to in-transit data and internal database secrets without authentication. The exposure occurred as a result of inadequate encryption and misconfiguration, providing an entry point for lateral movement, data exfiltration, and potentially further compromise of enterprise networks. Organizations in finance, healthcare, SaaS, and retail sectors have been especially impacted by this incident, given their widespread MongoDB adoption for critical workloads. This breach highlights an increasingly common pattern of weaponizing newly disclosed database vulnerabilities at scale by sophisticated threat actors. The incident underscores the urgent need for robust encryption practices, Zero Trust segmentation, and vigilant patch management to protect highly sensitive data and prevent large-scale exposure as regulatory scrutiny and attacker sophistication intensify.
8 months ago
Kill Chain
Active Exploitation of Fortinet SSL VPN 2FA Bypass Shows Criticality of Patch Hygiene
In December 2025, Fortinet disclosed ongoing, active exploitation of a previously known vulnerability (CVE-2020-12812) affecting FortiOS SSL VPN devices. The flaw allows attackers to bypass two-factor authentication (2FA) by manipulating the case sensitivity of usernames when certain configurations are in place, specifically when integrating local users with LDAP groups. This misconfiguration enables unauthorized access for administrative and VPN users, as attackers can skip required 2FA checks and authenticate directly via LDAP. The vulnerability, originally patched in 2020, has resurfaced due to a large number of unpatched and exposed Fortinet devices, with over 9,700 instances still vulnerable worldwide as of January 2026. This incident exemplifies the persistent risk of legacy vulnerabilities, particularly in Internet-facing VPN and perimeter security devices. Attackers are increasingly revisiting older weaknesses to target unpatched infrastructure, elevating the urgency for ongoing patch management and configuration reviews in enterprise environments.
8 months ago
Kill Chain
Critical Vulnerability in LangChain Core Exposes Secrets and Enables Prompt Injection
In December 2025, a critical vulnerability was disclosed in LangChain Core, a widely used Python package within the LangChain open-source ecosystem. Attackers were able to exploit a flaw in the serialization process, resulting in exposure of sensitive secrets and the ability to manipulate large language model (LLM) responses via prompt injection. The underlying vulnerability allowed threat actors to craft malicious payloads, leading to remote code execution in environments where untrusted input could be serialized, posing major risks to organizations relying on LangChain-powered AI workflows. This supply-chain attack path also opened the door for access to credentials and proprietary data. This incident highlights the expanding threat landscape targeting AI infrastructure and software supply chains. With the surge of enterprise adoption of AI and LLMs, vulnerabilities in core AI frameworks are increasingly attractive to threat actors, underscoring regulatory scrutiny and the need for robust code security practices within open-source dependencies.
8 months ago
Kill Chain
Critical MongoDB Flaw Exposes Sensitive Server Memory to Unauthenticated Threats
In December 2025, a critical security flaw (CVE-2025-14847) was publicly disclosed in multiple versions of MongoDB, exposing organizations to the risk of uninitialized memory disclosure by unauthenticated attackers. The flaw stems from improper handling of length parameter inconsistencies within zlib compressed protocol headers, allowing remote, unauthenticated clients to read uninitialized heap memory. Impacted versions span major MongoDB releases 3.6 through 8.2, potentially exposing sensitive data in server memory. MongoDB responded by releasing patches and advised urgent upgrades or the disabling of zlib compression. This incident gains heightened significance as memory disclosure vulnerabilities enable threat actors to harvest sensitive information without authentication. The vulnerability underscores the increasing importance of rigorous software supply chain security and timely patch management amid a growing landscape of data exposure risks in widely used open-source technologies.
8 months ago
Kill Chain
Evasive Panda APT Uses DNS Poisoning for Prolonged Espionage: 2022–2024 Campaign
Between November 2022 and November 2024, the China-linked Evasive Panda APT group conducted a sophisticated cyber espionage campaign targeting entities in Türkiye, China, and India. The attackers leveraged DNS poisoning techniques to redirect requests for popular software updates (such as SohuVA and Tencent QQ) to attacker-controlled infrastructure. Through adversary-in-the-middle attacks, victims received trojanized loaders, which proceeded to fetch and decrypt highly targeted MgBot backdoors. The attack chain involved supply chain and AitM vectors, advanced encryption and obfuscation methods, and allowed persistent compromise and broad data theft, including keylogging and credential exfiltration. This campaign highlights the growing sophistication of APT operations exploiting core network infrastructure such as DNS to evade perimeter defenses. The increased prevalence of similar DNS-manipulation campaigns and targeted malware delivery emphasizes the urgent need for robust segmentation, encrypted traffic, and thorough network and endpoint visibility.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports