Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Malicious VSCode Extensions Breach Puts Developer Supply Chains at Risk
In December 2025, two malicious Visual Studio Code extensions—Bitcoin Black and Codo AI—were uncovered on Microsoft’s official VSCode Marketplace, executing a supply chain attack that targeted developers. Published by an entity named 'BigBlack', these extensions installed information-stealing malware by abusing extension privileges. The malware leveraged DLL hijacking and covert batch scripts to steal credentials, browser session cookies, cryptocurrency wallet data, and system information from infected developer machines, storing exfiltrated data for later retrieval. The incident highlights how even widely trusted software platforms can host weaponized add-ons capable of compromising sensitive environments. This breach exemplifies the growing risks posed by open-source and third-party software supply chain compromises, especially targeting developer tools. The ease with which unvetted code can be distributed through official registries underscores the need for rigorous extension security and policy enforcement in enterprise environments.
8 months ago
Kill Chain
Poland Arrests Ukrainians in 2024 Espionage Cyber Incident
In June 2024, Polish authorities arrested three Ukrainian nationals accused of using sophisticated hacking equipment to carry out cyberattacks targeting Polish IT systems, with particular emphasis on the theft of 'computer data of particular importance to national defense.' The suspects were apprehended while allegedly attempting to damage government information technology infrastructure, utilizing encrypted communications and advanced attack tools likely designed to evade monitoring and facilitate data exfiltration. The incident underscores heightened tensions in the region and reveals vulnerabilities within national networks, with Polish law enforcement quickly intervening to mitigate further impact. This breach is emblematic of a broader escalation in nation-state cyber operations across Europe, featuring cross-border actors relying on advanced techniques to infiltrate sensitive targets. The event highlights the urgent need for robust east-west traffic security, encrypted communications, and real-time anomaly detection controls to guard national interests and critical IT environments.
8 months ago
Kill Chain
Ransomware: FinCEN Reports Over $2.1B Paid to Gangs (2022–2024)
Between 2022 and early 2024, ransomware gangs operating globally extorted over $2.1 billion from victims, according to an official report by the Financial Crimes Enforcement Network (FinCEN). Activity surged markedly in 2023, driven by large-scale campaigns from prolific threat groups such as ALPHV/BlackCat and LockBit. Attackers commonly gained initial access through phishing, vulnerable VPNs, or exposed remote services, rapidly leveraging lateral movement and data exfiltration before deploying file-encrypting malware to maximize leverage. As a result, numerous organizations across multiple sectors experienced severe operational disruption, financial losses, reputational damage, and in some cases, regulatory scrutiny. This incident underscores the growing reach and impact of organized ransomware, even as some law enforcement takedowns in late 2023 and 2024 caused temporary disruption to top gangs. The pattern highlights evolving attacker strategies, heightened regulatory attention, and the need for proactive cyber defense and comprehensive incident response preparedness.
8 months ago
Kill Chain
Sneeit WordPress Plugin Hit by Critical RCE: 2025 Exploitation Wave
In August 2025, a critical remote code execution (RCE) vulnerability (CVE-2025-6389) in the widely used Sneeit Framework WordPress plugin (versions <=8.3) was discovered to be actively exploited in the wild. Attackers leveraged this flaw—scoring 9.8 on CVSS—to gain remote access to vulnerable sites, potentially executing arbitrary code, deploying malware, and further compromising user data or site integrity. The vendor responded by releasing version 8.4 with an urgent security patch, but over 1,700 active installations remain at risk. The Sneeit incident underscores a broader trend of rapid weaponization of WordPress plugin flaws by opportunistic threat actors, intensifying risk for websites lacking prompt patching and robust security controls. As attackers increasingly target web applications and supply chain components, organizations must reinforce visibility, detection, and vulnerability management strategies.
8 months ago
Kill Chain
2025 Cyberattack Wave: USB Malware, React2Shell & AI Tool Exploits Expose Security Gaps
In December 2025, organizations worldwide faced a surge of multi-vector cyberattacks exploiting recent vulnerabilities in USB devices, popular developer frameworks like React (notably the React2Shell bug), and emerging AI-powered coding environments. Attackers leveraged unpatched software, social engineering, and compromised USB devices to distribute malware and establish lateral movement within networks. The campaign capitalized on the rapid deployment of new technologies and lagging security controls, resulting in data breaches, financial theft via sophisticated WhatsApp worms, and the infiltration of development pipelines. This spate of incidents underscores the escalating convergence of traditional malware vectors and AI-driven exploits, exposing significant gaps in current security postures. As organizations accelerate digital transformation and adopt generative AI tools, adversaries are rapidly evolving, testing defenses across cloud, hybrid, and on-premises ecosystems.
8 months ago
Kill Chain
JS#SMUGGLER Campaign: How Compromised Websites Delivered NetSupport RAT in 2025
In December 2025, cybersecurity researchers discovered a widespread campaign called JS#SMUGGLER leveraging compromised websites to deliver NetSupport RAT, a versatile remote access trojan. The attack chain involved injecting obfuscated JavaScript loaders onto legitimate sites, which delivered device-aware, multi-stage payloads via hidden iframes, HTML application (HTA) loaders, and encrypted PowerShell scripts. This sophisticated approach enabled attackers to remotely control infected hosts, exfiltrate sensitive data, and evade detection through in-memory and fileless techniques. The campaign targeted enterprise users indiscriminately and was attributed to yet-uncategorized threat actors, though infrastructure overlap with SmartApeSG was noted. The incident is a timely reminder of advancing web-based malware deployment tactics, blending script obfuscation, evasive loaders, and context-aware delivery. As enterprises increasingly rely on web interfaces and remote access, defenders face mounting pressure to detect, segment, and monitor east-west and egress network activity in real time to thwart lateral movement and data theft.
8 months ago
Kill Chain
Wave of Android Malware Hits Polish Bank Customers—FvncBot, SeedSnatcher & ClayRat Evolve
In late 2025, security researchers from Intel 471, CYFIRMA, and Zimperium uncovered two new Android malware families—FvncBot and SeedSnatcher—alongside an upgraded ClayRat variant. FvncBot, disguised as a banking security app targeting mBank customers in Poland, used sophisticated credential theft and evasive techniques to breach users’ devices, while SeedSnatcher enabled wide-scale stealth data exfiltration. ClayRat, already known in cybercriminal circles, has evolved to feature enhanced capabilities for data theft and persistence. These malware strains are distributed through phishing campaigns and malicious app stores targeting finance sector customers and exploiting gaps in mobile device controls and user awareness. The campaigns resulted in substantial risk of unauthorized transactions, identity theft, and broader exposure of banking and personal data. The coordinated discovery highlights a dramatic escalation in the capabilities of mobile-targeted malware, especially those aimed at financial institutions in Eastern Europe. The incident exemplifies the rapid, continuous innovation by threat actors seeking to monetize weaknesses in endpoint security and exploit unsuspecting app users, raising the urgency for organizations to modernize mobile and app-layer security postures.
8 months ago
Kill Chain
Active Exploitation of React2Shell: How Chinese APTs Breached the Supply Chain in 2025
In December 2025, security researchers identified a critical vulnerability, CVE-2025-55182 (React2Shell), actively exploited in the wild by suspected Chinese threat actors Earth Lamia and Jackpot Panda. The flaw impacts React Server Components in several Meta-maintained packages (versions 19.0 to 19.2.0), allowing attackers to execute arbitrary code on backend servers via unsafe deserialization at API endpoints. First reported by AWS Threat Intelligence on December 4, evidence ties multiple untracked clusters and IP addresses to coordinated supply-chain attacks targeting organizations operating modern web stacks. In successful compromises, attackers gained full backend access, posing serious risks to enterprise data and operations. This incident underscores the rapid weaponization of supply-chain vulnerabilities and the growing sophistication of state-aligned APTs exploiting core software dependencies. React2Shell highlights the urgent need for rigorous patch management, attack surface monitoring, and proactive defense as critical technologies become frequent entry points for advanced adversaries.
8 months ago
Kill Chain
React2Shell Vulnerability Triggers Mass Breach Across 30+ Organizations in 2025
In early 2025, researchers discovered that over 77,000 internet-exposed IP addresses are vulnerable to a critical Remote Code Execution (RCE) flaw in the React2Shell framework (CVE-2025-55182). Threat actors rapidly exploited this vulnerability to breach at least 30 organizations across sectors such as finance, healthcare, and technology. Attackers leveraged the exploit to gain remote control, exfiltrate data, and potentially deploy malware across impacted systems, highlighting significant risks to operational resilience and data privacy. The compromised firms are now racing to contain lateral movement and mitigate exposure amid ongoing incident response. This incident illustrates a growing trend of attackers rapidly weaponizing newly disclosed vulnerabilities in popular frameworks for mass exploitation. It underscores the urgent need for timely patch management, robust segmentation, and comprehensive monitoring to counter the escalating threat from opportunistic RCE attacks targeting exposed internet-facing assets.
8 months ago
Kill Chain
Escalating Credential Attacks on Palo Alto GlobalProtect VPNs: 2024 Threat Review
In early 2024, cybersecurity analysts observed a widespread campaign targeting Palo Alto Networks’ GlobalProtect VPN portals and SonicWall SonicOS API endpoints with aggressive login attempts and scanning activity. Threat actors used automated tools to conduct credential stuffing and exploit potential vulnerabilities in exposed VPN portals, aiming to gain unauthorized network access. While no specific breaches were confirmed, the campaign's scope affected numerous organizations globally relying on these remote access solutions, highlighting the heightened risk to large enterprises and managed service providers leveraging vulnerable or misconfigured VPN infrastructure. This incident illustrates the surge in identity-driven and credential-based attacks exploiting remote access technologies, especially as hybrid and remote workforces remain prevalent. The rapid evolution and broad targeting underscore the urgent need for continuous VPN hardening, robust access governance, and threat monitoring to preempt similar intrusion attempts impacting business continuity.
8 months ago
Kill Chain
Critical React2Shell Flaw (CVE-2025-55182) Added to CISA KEV After Confirmed Exploitation
In June 2025, a critical remote code execution (RCE) vulnerability, CVE-2025-55182, impacting React Server Components (RSC) was added to CISA's Known Exploited Vulnerabilities catalog following confirmed reports of active exploitation. Attackers leveraged the flaw, known as 'React2Shell,' to execute arbitrary code on vulnerable servers by exploiting inadequate input validation, enabling lateral movement and potential compromise of sensitive systems and data. Several organizations in sectors reliant on JavaScript-based web infrastructures were affected, resulting in service disruptions and the risk of unauthorized data access and exfiltration. This incident highlights a broader trend in targeting supply chain and open-source components within modern web development stacks. The increasing frequency and sophistication of attacks on widely adopted frameworks like React underscore the urgency for rapid vulnerability remediation, improved code validation, and enterprise adoption of proactive threat detection to mitigate future large-scale RCE campaigns.
8 months ago
Kill Chain
AI IDEsaster: 30+ Vulnerabilities Expose Developer Environments to Prompt Injection & RCE (2025)
In December 2025, over 30 serious security flaws—collectively named "IDEsaster"—were uncovered in popular AI-powered Integrated Development Environments (IDEs) by researcher Ari Marzouk (MaccariTA). Exploiting these vulnerabilities, attackers could inject malicious prompts, leading to unauthorized data exfiltration and remote code execution within developer environments. The flaws stemmed from unsafe integrations of AI features, including insufficient sandboxing and lack of network traffic controls, exposing sensitive code and credentials to threat actors. Notably, vulnerabilities allowed for lateral movement and direct access to code repositories, risking business continuity and intellectual property. This incident is especially significant as AI adoption in coding workflows accelerates, creating new attack vectors. The surge in prompt injection and AI supply chain threats, paired with evolving attacker tactics targeting developer tools, highlights the urgent need for organizations to strengthen segmentation, monitoring, and AI risk governance.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports