Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
North Korean WaterPlum Campaign: How Fake AI Job Offers Led to $11M Cryptocurrency Heist
North Korean threat actors operating under WaterPlum (aka Contagious Interview) have compromised over 30,000 devices across 100+ countries by posing as legitimate AI, cryptocurrency, and NFT company recruiters targeting software developers and IT professionals. The campaign, linked to North Korea's 313 General Bureau, uses fake job opportunities to deliver malware and establish persistent access for cryptocurrency theft and data exfiltration. The operation has successfully stolen approximately $11 million in cryptocurrency from over 7,000 wallets while maintaining extensive overlap with broader North Korean IT worker infiltration efforts. This incident highlights the evolution of North Korean cyber operations beyond traditional state-sponsored espionage toward systematic financial crime integrated with legitimate IT workforce infiltration, representing a new paradigm where threat actors blend cybercriminal activities with long-term economic penetration strategies.
1 day ago
Kill Chain
Scattered Spider Core Member Pleads Guilty to Multi-Million Dollar Cryptocurrency Theft Spree
Ahmed Hossam Eldin Elbadawy, a 24-year-old Texas resident and core member of the Scattered Spider cybercrime group, pleaded guilty to wire fraud conspiracy and aggravated identity theft charges in December 2023. Operating from 2021 to 2023, Elbadawy and his co-conspirators used social engineering tactics to compromise credentials at major companies across entertainment, telecom, technology, and cryptocurrency sectors. The group targeted high net worth individuals with virtual currency accounts, successfully stealing over $8.6 million in cryptocurrency, including individual thefts of $6.35 million, $571,000, and $1.7 million. Prosecutors are seeking forfeiture of over $17.6 million in Bitcoin and Ethereum, plus luxury assets including vehicles, watches, and designer goods. This case highlights the continued evolution of financially motivated cybercrime groups like Scattered Spider, which has grown to thousands of members despite law enforcement actions against early leaders. The group's sophisticated social engineering techniques and focus on cryptocurrency theft represent a persistent threat to organizations holding digital assets.
1 day ago
Kill Chain
Rapuncel Infostealer Campaign Exploits Fake GitHub Repos to Bypass Security
In September 2026, cybercriminals launched a sophisticated malware campaign using SEO-optimized fake GitHub repositories impersonating LastPass and 39 other legitimate software companies. The attack delivers the previously undocumented Rapuncel infostealer along with a Microsoft-signed kernel driver capable of disabling 145 antivirus and EDR products. Victims searching for popular software like LastPass Authenticator are redirected through malicious GitHub repos to download ZIP archives containing the malware, which steals credentials from 25 browsers, 30 cryptocurrency wallets, and sensitive documents while maintaining persistence across system reboots. This incident highlights the growing sophistication of supply chain attacks targeting trusted development platforms like GitHub, demonstrating how threat actors exploit SEO manipulation and legitimate code-signing certificates to bypass security controls and establish persistent access to victim systems.
2 days ago
Kill Chain
Four Linux Kernel Flaws Enable Root Access: The AI-Assisted Vulnerability Era Begins
In September 2026, security researcher Asim Manizada disclosed four Linux kernel vulnerabilities that enable local privilege escalation to root access. The flaws, dubbed DirtyAH6, TUNderflow, PPPoEject, and DiagSpill, affect various networking components and were discovered using AI-assisted vulnerability research techniques. While kernel maintainers have patched all vulnerabilities, the public release of working exploit code significantly raises the risk for systems running outdated kernels, particularly in multi-user environments where attackers seek to escalate from limited user accounts to full administrative control. This disclosure represents a concerning trend of AI-accelerated vulnerability discovery in critical infrastructure components. As threat actors increasingly adopt similar AI-assisted techniques for offensive purposes, the time between vulnerability discovery and exploitation continues to shrink, demanding faster patch deployment cycles and enhanced kernel hardening strategies across enterprise environments.
2 days ago
Kill Chain
OAuth Consent Abuse: The SaaS Security Threat That MFA Can't Stop
OAuth consent abuse represents a growing threat vector where attackers bypass multifactor authentication by exploiting legitimate authorization flows in SaaS and cloud environments. Threat actors send convincing links that lead users to real OAuth authorization screens, requesting permissions for seemingly harmless applications like productivity connectors or reporting tools. Once users approve these requests, attackers gain persistent API access to email systems, file repositories, source code, and business platforms without needing passwords or deploying malware. The attack leverages trusted domains and legitimate OAuth processes, making it difficult for traditional security tools to detect malicious activity occurring through approved APIs. This attack method is particularly relevant now as organizations increasingly rely on SaaS platforms and cloud-based workflows, creating more opportunities for OAuth-based persistence. The technique highlights critical gaps in authorization governance, where security teams focus heavily on authentication controls like MFA while overlooking post-login consent decisions that can grant extensive third-party access to enterprise data.
2 days ago
Kill Chain
First Documented AI Agent Cyberattack Targets Spanish Organization in 2026
In September 2026, a Spanish organization reported to Spain's Data Protection Agency (AEPD) that an attacker used an autonomous AI agent powered by a well-known language model to breach corporate personal data stores. The AI system discovered and exploited loose credentials and an enterprise application vulnerability, enabling the modification of personal data records and unauthorized access to corporate invoices. This represents one of the first documented cases of an agentic AI conducting an end-to-end cyberattack with minimal human oversight, demonstrating the AI's ability to chain vulnerabilities and accelerate attack timelines. This incident marks a paradigm shift in cybersecurity threats, as predicted by Spain's National Cryptologic Center earlier in 2026. The use of autonomous AI agents in cyberattacks is rapidly becoming mainstream, fundamentally changing the threat landscape by enabling continuous, machine-speed reconnaissance and exploitation without traditional human-paced decision points.
2 days ago
Kill Chain
Critical Docker Sandboxes Vulnerability Exposes AI Development Environments to Host Escape Attacks
In September 2026, Docker disclosed two critical vulnerabilities in Docker Sandboxes affecting macOS systems. CVE-2026-77179 (CVSS 9.4) allowed malicious code running inside AI coding agent virtual machines to escape sandbox restrictions and access or modify files anywhere on the host system with VMM user privileges. The flaw exploited a symlink-following vulnerability in the virtio-fs host server component. A second vulnerability, CVE-2026-79994 (CVSS 8.7), enabled unauthorized access to Unix domain sockets outside the authorized workspace. Both flaws were patched in version 0.42.0 released September 7, 2026. This incident highlights the growing security risks in AI development environments as organizations increasingly adopt AI coding agents and automated development tools. The vulnerabilities expose critical gaps in container isolation and demonstrate how AI agents can be weaponized through prompt injection attacks to compromise host systems.
2 days ago
Kill Chain
September 2026: When AI Became Both Weapon and Target in Massive Multi-Vector Campaign
September 2026 witnessed an unprecedented surge in multi-vector cyberattacks, with threat actors exploiting everything from AI agent vulnerabilities to traditional infrastructure weaknesses. Notable incidents included the CL-CRI-1171 pay-per-install operation distributing malware through YouTube channels, large-scale attacks on exposed LocalAI instances compromising 230 systems including Thai military infrastructure, and the emergence of AI agents capable of rewriting their own models mid-task. Additional threats ranged from insider SIM swap operations netting $600,000 in losses to new ransomware families like Settra claiming 70 victims globally. The campaign demonstrates how attackers are successfully combining traditional attack vectors with emerging AI-powered techniques to maximize impact across diverse targets. This surge reflects the growing sophistication of cybercriminal ecosystems that are rapidly adapting to exploit both legacy vulnerabilities and cutting-edge AI technologies, creating a perfect storm of traditional and next-generation threats.
2 days ago
Kill Chain
WeaselBiscuit Malware: How North Korean Hackers Weaponized 13 npm Packages
In September 2026, cybersecurity researchers discovered WeaselBiscuit, a new JavaScript stealer distributed through 13 malicious npm packages targeting software developers. The malware, attributed to North Korean threat actors behind the Contagious Interview campaign, represents a streamlined variant of the BeaverTail and OtterCookie families. Upon npm import, WeaselBiscuit executes in-memory, harvests Chrome extension storage data across multiple platforms, and can log clipboard contents and keystrokes on Windows systems. The attack demonstrates the ongoing evolution of DPRK supply chain attacks targeting the developer ecosystem. This incident highlights the increasing sophistication of supply chain attacks targeting open-source repositories, particularly as threat actors refine their tooling to evade detection while maintaining core data theft capabilities.
2 days ago
Kill Chain
Critical Linux Kernel Vulnerabilities Added to CISA KEV Catalog
CISA has added two critical Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog in September 2026, following evidence of active exploitation in the wild. CVE-2025-39964, a race condition vulnerability, and CVE-2026-53266, an out-of-bounds write vulnerability, both target the Linux kernel and can grant attackers total system control post-exploitation. These additions reinforce the agency's Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize rapid remediation of high-risk vulnerabilities on publicly exposed assets that could lead to complete system compromise. The identification of these actively exploited kernel vulnerabilities highlights the ongoing evolution of threat actor tactics targeting foundational infrastructure components. As organizations increasingly adopt cloud-native and hybrid architectures, kernel-level vulnerabilities represent critical attack surfaces that can bypass traditional security controls and enable privilege escalation across entire computing environments.
2 days ago
Kill Chain
PhantomRaven: The AI-Generated Malware Infiltrating Developer Ecosystems
A financially motivated threat actor has been distributing PhantomRaven, a JavaScript-based information stealer, through malicious npm packages since November 2022. The attacker used slopsquatting and typosquatting techniques to upload over 100 malicious packages to the npm registry, targeting developers' authentication tokens, CI/CD secrets, and GitHub credentials. CrowdStrike analysis indicates the malware was likely generated using large language models, evidenced by verbose comments and placeholder code patterns. The threat actor claims to be a bug bounty hunter and uses stolen credentials to identify vulnerabilities for legitimate disclosure programs rather than selling data on criminal marketplaces. This incident highlights the growing trend of threat actors leveraging AI tools to accelerate malware development and the increasing sophistication of supply chain attacks targeting developer ecosystems. The use of remote dynamic dependencies to evade security detection represents an evolution in package-based attack methodologies.
2 days ago
Kill Chain
Plugin4Shell Exposes Critical Supply Chain Risks in AI Coding Agents
In September 2026, security firm Air Security disclosed Plugin4Shell, a supply chain vulnerability affecting four major AI coding agents including Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. The flaw allows repository owners to swap legitimate plugin code with malicious versions even when agents have locked plugins to specific reviewed commit hashes. Attackers exploit this by creating branch names that mimic commit hashes on platforms like Bitbucket, causing agents to install different code while reporting the correct locked version. Since plugins run with the same privileges as users, malicious code can access files, credentials, and connected systems. Anthropic and OpenAI have patched their agents, while GitHub Copilot remains unpatched and Google will not fix the retiring Gemini CLI. This incident highlights the growing security challenges in AI development toolchains as organizations increasingly rely on AI coding assistants with plugin ecosystems, making supply chain integrity critical for protecting sensitive development environments and intellectual property.
2 days ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports