Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

3202 threat reports
Page 210 of 267

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Information Technology/IT Threat Reports

Showing 25092520 / 3202 reports
Shai Hulud 2.0: The npm Supply Chain Worm Disrupting DevOps
Impact· high

Shai Hulud 2.0: The npm Supply Chain Worm Disrupting DevOps

In September 2023, a sophisticated supply-chain attack dubbed Shai Hulud 2.0 targeted the JavaScript ecosystem by compromising over 800 Node Package Manager (npm) packages. The malware leveraged stolen npm tokens to spread and infect trusted packages with a worm-like, two-stage payload. Upon download, it harvested GitHub and cloud credentials, aggressively scanned files for secrets, and exfiltrated stolen data via malicious public GitHub repositories. If unable to gain access tokens for exfiltration, the malware triggered a destructive file-wiping payload, disrupting both individual developers and organizations. Widespread impact was observed across Russia, India, Brazil, Vietnam, and more. This incident underscores the escalating risk of deep supply-chain compromise through open-source ecosystems and highlights attackers' evolving Tactics, Techniques, and Procedures (TTPs). It demonstrates the urgent need for enhanced monitoring, credential protection, and robust controls within software supply chains.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Picklescan Bugs Expose PyTorch Supply Chain: Malicious Models Bypass Security
Impact· low

Critical Picklescan Bugs Expose PyTorch Supply Chain: Malicious Models Bypass Security

In December 2025, severe vulnerabilities were revealed in Picklescan, an open-source security tool designed to scan Python pickle files for malicious code, particularly those used with PyTorch models. Attackers were able to exploit three critical flaws, bypassing Picklescan’s intended protections to execute arbitrary code during model loading processes. This effectively enabled the distribution of malicious machine learning models that could compromise developer and production environments. The risk was amplified due to Picklescan’s popularity in data science and AI workflows, potentially impacting organizations across multiple sectors relying on PyTorch. The incident is a stark reminder of the growing risk posed by supply-chain vulnerabilities in open-source AI and machine learning tooling, especially as the adoption of MLOps and automated model deployment platforms accelerates. Organizations now face increased regulatory scrutiny and operational risks tied to software supply chain security in the era of AI-driven applications.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Brazil Faces 2025 Banking Trojan Crisis Spread via WhatsApp and NFC Relay Fraud
Impact· medium

Brazil Faces 2025 Banking Trojan Crisis Spread via WhatsApp and NFC Relay Fraud

In late 2025, Brazil was struck by a sophisticated banking trojan campaign perpetrated by the threat actor Water Saci. Leveraging WhatsApp as a wormable transmission channel, attackers delivered highly obfuscated HTA and PDF payloads to users. Once opened, these files initiated a new Python-based trojan variant, enabling credential theft and fraudulent banking transactions. The attack chain also included NFC relay tactics (RelayNFC), amplifying transactional fraud by hijacking contactless payment operations. The campaign evaded detection using advanced scripting and lateral propagation, causing financial and reputational damage within the Brazilian financial sector. This incident marks a significant escalation in multichannel malware delivery, combining social engineering, banking trojans, and NFC payment interception. It underscores the converging risk between consumer messaging apps and new payment technologies, highlighting the urgency for layered east-west and egress network protection.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
2025 WordPress King Addons Breach: Unauthenticated Admin Access & Website Takeover
Impact· medium

2025 WordPress King Addons Breach: Unauthenticated Admin Access & Website Takeover

In December 2025, attackers actively exploited a critical vulnerability (CVE-2025-8489, CVSS 9.8) in the popular King Addons for Elementor WordPress plugin. The flaw allowed unauthenticated individuals to escalate privileges by specifying the 'administrator' user role at registration, instantly granting themselves administrative access. Threat actors leveraged this zero-day to seize complete control of vulnerable sites, install malicious content, and potentially exfiltrate sensitive data or deploy further attacks. Affected organizations risked significant operational disruption, data compromise, reputational harm, and potential compliance violations due to unauthorized admin creation and persistence. This incident highlights the increasing trend of exploiting supply-chain and plugin vulnerabilities in widely used CMS platforms. The rapid weaponization of unauthenticated privilege escalation flaws underscores the need for continuous patch management, threat detection, and segmentation controls to counter evolving web application and identity-focused attack techniques.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Exploited in the Wild: Microsoft’s Windows LNK Flaw Finally Patched After Years of Attacks
Impact· low

Exploited in the Wild: Microsoft’s Windows LNK Flaw Finally Patched After Years of Attacks

In November 2025, Microsoft silently patched CVE-2025-9491, a Windows Shortcut (LNK) file vulnerability, after years of active exploitation dating back to 2017. This flaw allowed threat actors to leverage malicious LNK files for privilege escalation and potential remote code execution through user interface misinterpretation. Attackers routinely embedded harmful LNKs in phishing emails or compromised archives, enabling them to bypass security controls and gain unauthorized access to targeted Windows systems. The issue was resolved only after mounting pressure from researchers and documented abuse by multiple attacker groups. This incident is notable as it underscores persistent risks from longstanding Windows flaws exploited in the wild. The continued abuse of LNK vulnerabilities highlights the importance for organizations to prioritize patching and segment internal networks to limit the blast radius of privilege escalation attacks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
How Iran's MuddyWater APT Used Memory-Only Malware for Stealthy Espionage in 2024
Impact· medium

How Iran's MuddyWater APT Used Memory-Only Malware for Stealthy Espionage in 2024

In early 2024, the Iranian state-backed actor MuddyWater significantly evolved its tradecraft by deploying a new memory-only loader, codenamed Fooder, and the stealthy 'MuddyViper' backdoor in espionage campaigns. The group, previously known for noisy operations, shifted to fileless malware and in-memory tactics targeting government and critical infrastructure networks in the Middle East and beyond. These attacks enabled extended persistence, facilitated lateral movement, and were effective at evading traditional endpoint detection and response solutions. As a result, targeted organizations faced serious risk of data theft and operational compromise before the campaign was exposed by security researchers. This incident marks a growing trend of threat actors adopting advanced memory-only and fileless TTPs to avoid detection. The operational upgrade by MuddyWater highlights increased sophistication among nation-state adversaries and reinforces the urgent need for advanced threat detection and stronger east-west network controls.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Clop Ransomware Hits University of Pennsylvania in Oracle EBS Supply Chain Attack
Impact· medium

Clop Ransomware Hits University of Pennsylvania in Oracle EBS Supply Chain Attack

In August 2023, the University of Pennsylvania became one of nearly 100 organizations targeted in a sweeping data theft and extortion campaign by the Clop ransomware group. Exploiting previously unknown vulnerabilities in Oracle E-Business Suite (EBS), attackers gained unauthorized access to sensitive university systems over several days. Personal data, including names, Social Security numbers, and financial information, was exposed for thousands of individuals, primarily detected when Clop issued extortion demands and Oracle disclosed the vulnerability late September. Patch deployment followed, with no public evidence of further data misuse. The mass exploitation of Oracle EBS by Clop highlights a rising trend of sophisticated ransomware groups targeting widely used enterprise applications through zero-day attacks. This incident underscores renewed urgency for robust patch management, vigilant monitoring, and segmentation in response to evolving ransomware tactics and large-scale supply chain risks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
University of Pennsylvania Data Breach Highlights ERP Security Risks in Higher Ed
Impact· high

University of Pennsylvania Data Breach Highlights ERP Security Risks in Higher Ed

In August 2024, the University of Pennsylvania confirmed that attackers infiltrated its Oracle E-Business Suite (EBS) systems, resulting in the theft of documents containing sensitive personal information. The breach, which was disclosed after internal investigations, leveraged vulnerabilities in Oracle EBS servers, a critical system for managing finances, supply chains, and human resources, enabling threat actors to compromise and exfiltrate sensitive employee and institutional data. Although the University has taken remediation steps and notified those affected, the attack underscores ongoing risks within higher education due to reliance on complex, legacy ERP platforms and the attractiveness of academic institutions as targets. This incident comes amidst a broader surge in attacks exploiting unpatched ERP systems, highlighting persistent gaps in internal segmentation and the monitoring of east-west traffic. As higher education faces increased regulatory and ransomware pressures, this breach serves as a warning of the urgent need for robust visibility, policy enforcement, and modernized security postures.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
North Korea’s 2024 IT Identity Rental Scheme: Exposing New Supply Chain Dangers
Impact· medium

North Korea’s 2024 IT Identity Rental Scheme: Exposing New Supply Chain Dangers

In 2024, cyber intelligence researchers revealed an elaborate North Korean operation targeting engineers and developers worldwide, luring them to rent out their professional identities for conducting unauthorized IT work. North Korean recruiters posed as legitimate job seekers to obtain accounts, credentials, and background checks from unsuspecting professionals, allowing the nation's sanctioned regime to surreptitiously access western technology supply chains and funnel wages into banned state coffers. This campaign created significant risks, enabling North Korea to bypass sanctions, compromise corporate infrastructure, and mask the true origins of its IT contractors within the global tech workforce. This incident highlights a sophisticated continuation of supply-chain compromise methods leveraging social engineering and identity fraud. Recent months have shown a marked increase in similar schemes, illustrating attackers' growing reliance on exploiting human trust, remote work authentication gaps, and the globalized freelance IT marketplace.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Cybercrime Goes SaaS: The Rise of Crime-as-a-Service in 2024
Impact· medium

Cybercrime Goes SaaS: The Rise of Crime-as-a-Service in 2024

In early 2024, cybersecurity researchers observed a surge in Crime-as-a-Service (CaaS) operations leveraging a subscription-based model. Attackers now rent access to advanced phishing kits, infostealer logs, Remote Access Trojans (RATs), and one-time password bots on popular chat platforms like Telegram, dramatically lowering the barrier to entry for cybercrime. These CaaS platforms enable even low-skilled actors to execute sophisticated intrusion campaigns targeting organizations across industries, often resulting in credential theft, ransomware outbreaks, and large-scale data breaches. This operational shift has enabled attackers to strike at scale and adapt quickly to new defenses, amplifying business risks and potential regulatory violations. The rise of CaaS signifies a pivotal threat evolution: democratized, on-demand cybercrime. Organizations must now address not just known threat actors, but a growing pool of opportunists leveraging plug-and-play hacking tools. This trend is accelerating, leading to urgent pressures for improved identity controls, network segmentation, and rapid anomaly detection.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Shai-Hulud 2.0: 2024 NPM Supply Chain Attack Exposes 400,000 Developer Secrets
Impact· high

Shai-Hulud 2.0: 2024 NPM Supply Chain Attack Exposes 400,000 Developer Secrets

In June 2024, the 'Shai-Hulud 2.0' campaign executed a large-scale supply chain attack against the JavaScript ecosystem by compromising over 750 packages on the NPM registry. Attackers used malicious dependencies to covertly exfiltrate environment variables and developer secrets to public GitHub repositories, exposing as many as 400,000 authentication credentials and tokens. The attack leveraged automation to rapidly disseminate malware and gather sensitive data from unwitting developers and CI systems, impacting thousands of organizations and potentially enabling downstream breaches. This incident underlines the growing risks of open-source supply chain vulnerabilities and highlights attacker innovation in automated credential harvesting. With supply chain attacks rising and developers relying on public package repositories, proactive controls and zero-trust practices have never been more essential to prevent code-integrity and data-exposure risks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Illuminate Education's 2021 Data Breach Spurs FTC-Driven Security Overhaul
Impact· high

Illuminate Education's 2021 Data Breach Spurs FTC-Driven Security Overhaul

In 2021, Illuminate Education, a major provider of educational software, suffered a significant data breach that exposed the personal information of approximately 10 million students across the United States. Attackers leveraged insufficient data security controls, including unencrypted data in transit and inadequate segmentation, to access sensitive data such as names, academic records, and demographic information. The breach led to widespread notification requirements and regulatory scrutiny from the Federal Trade Commission (FTC), highlighting critical security shortcomings and resulting in institutional reputational impact. This incident remains highly relevant as regulators continue to raise data protection standards, with the FTC mandating significant operational changes and data minimization from EdTech vendors. The breach underscores ongoing risks to student data in cloud environments and the heightened expectations for privacy safeguards, encryption, and Zero Trust policies.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports