Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

3202 threat reports
Page 212 of 267

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Information Technology/IT Threat Reports

Showing 25332544 / 3202 reports
French Football Federation Data Breach 2024: Identity Attack Exposes Admin Systems
Impact· high

French Football Federation Data Breach 2024: Identity Attack Exposes Admin Systems

In June 2024, the French Football Federation (FFF) disclosed a data breach following a targeted cyberattack where threat actors leveraged a compromised administrator account to access the Federation’s administrative management software. The attackers gained unauthorized entry to sensitive systems, exposing personal information of registered club personnel and potentially compromising confidential organizational data. The breach led to heightened security reviews, incident response engagement, and notification of impacted individuals in accordance with regulatory requirements. This incident illustrates the growing prevalence of identity-driven attacks against high-profile organizations, reinforcing the critical need for zero trust controls and robust access governance. As cyber threats opportunistically target sports associations and other public sector bodies, advanced protective measures and continuous monitoring are becoming essential to thwart exploitation.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Over 17,000 Secrets Exposed: Inside the 2024 GitLab Public Repository Incident
Impact· medium

Over 17,000 Secrets Exposed: Inside the 2024 GitLab Public Repository Incident

In early 2024, a security engineer conducting a large-scale scan of all 5.6 million public repositories hosted on GitLab Cloud uncovered more than 17,000 exposed secrets—such as API keys, credentials, and tokens—affecting over 2,800 unique domains. Although the incident did not involve a targeted cyberattack, the finding highlights the pervasive risk of accidental data exposure due to developer error or misconfiguration. The exposed secrets could have enabled threat actors to access sensitive services, launch attacks, or exfiltrate data unnoticed, exposing organizations to operational risk, reputational harm, and regulatory scrutiny. This discovery signals a growing trend as attackers increasingly automate scans for leaked credentials in public code repositories. With supply chain attacks, shadow IT, and cloud misconfigurations rising, such incidents underscore the urgency for automated secret scanning, centralized controls, and enhanced security training for development teams.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Tomiris APT 2025: Abuse of Telegram, Discord & Multi-Language Toolkit in Advanced Government Attacks
Impact· low

Tomiris APT 2025: Abuse of Telegram, Discord & Multi-Language Toolkit in Advanced Government Attacks

In early 2025, the Tomiris APT group launched a sophisticated cyberespionage campaign targeting foreign ministries, intergovernmental organizations, and government entities across Russia and Central Asia. Using spear-phishing emails with password-protected malicious archives, Tomiris delivered a diverse toolkit of implants written in C/C++, Rust, Go, C#, and Python. Their malware leveraged public services like Telegram and Discord for command-and-control (C2), employed open-source frameworks such as Havoc and AdaptixC2, and enabled attackers to perform reconnaissance, maintain persistence, and exfiltrate sensitive data, while evading traditional network defenses by blending illicit traffic with legitimate channels. This incident highlights a clear evolution in APT tradecraft: rapid adoption of multi-language toolchains, creative lateral movement, and the abuse of popular cloud-based services for covert operations. With the continued rise of lawful-shadow C2 channels and open-source post-exploitation kits, organizations face heightened risks from identity-driven, stealthy attacks that challenge conventional segmentation and anomaly detection strategies.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Microsoft Teams Guest Access in 2025: Bypassing Defender Protections with Cross-Tenant Exploits
Impact· medium

Microsoft Teams Guest Access in 2025: Bypassing Defender Protections with Cross-Tenant Exploits

In late 2025, security researchers revealed a critical vulnerability in Microsoft Teams involving the platform's guest access feature. Attackers could exploit this cross-tenant blind spot by inviting victims to external Teams tenants, where Microsoft Defender for Office 365 protections set by the user’s home organization were bypassed. Instead, security controls depended on the external tenant’s environment, enabling malicious actors to deliver threats, such as phishing or malware, beyond the purview of corporate security policies. This weakness exposes organizations to significant business risk, allowing lateral phishing and potential data compromise through insufficient cloud policy enforcement. This incident underscores the ongoing risks inherent to cloud collaboration platforms where cross-tenant integrations are routine. The rapid adoption of hybrid work, increased SaaS reliance, and complex cloud permissions models are fueling new attack vectors that evade traditional endpoint and email security controls.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Legacy Python Bootstrap Scripts Expose PyPI Supply Chain to Domain Takeover Risk
Impact· medium

Legacy Python Bootstrap Scripts Expose PyPI Supply Chain to Domain Takeover Risk

In June 2025, cybersecurity researchers at ReversingLabs uncovered a significant vulnerability in legacy Python packages distributed via PyPI. The weakness stems from outdated bootstrap scripts within the widely used zc.buildout automation tool, which reference external domains that have since become unregistered. This creates a supply chain attack risk: if an attacker registers one of these lapsed domains, they could host malicious code, which would be executed during package installation, compromising developer, CI/CD, or production environments. While there are no confirmed mass exploits yet, the affected ecosystem is large due to the extended usage of these packages. This incident is highly relevant as supply chain risks in open-source ecosystems continue to grow, and domain takeover remains a low-cost, high-impact attack vector. Increased attention to legacy codebases and dependency hygiene is essential as regulations tighten and attackers show rising interest in poisoning software development infrastructure.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Gainsight-Salesforce 2025 Breach: A Wake-Up Call for SaaS Supply-Chain Security
Impact· high

Gainsight-Salesforce 2025 Breach: A Wake-Up Call for SaaS Supply-Chain Security

In November 2025, Gainsight reported a security incident involving its SaaS applications integrated with Salesforce, after Salesforce observed suspicious API calls from non-allowlisted IP addresses linked to Gainsight services. This prompted Salesforce to revoke affected access tokens, limit integration capabilities, and initiate investigations, temporarily disrupting data flows for several customers and connected platforms such as Zendesk and HubSpot. Forensic analysis revealed threat activity tied to proxy/VPN infrastructure and IPs previously associated with the UNC6040 threat cluster, which had targeted Salesforce CRMs in past extortion campaigns, though no confirmed data exfiltration occurred. This incident exemplifies the persistent risk of supply-chain compromise through interconnected SaaS platforms, emphasizing how attackers can leverage trusted applications to pivot laterally and exploit enterprise data pipelines. With the steady rise in OAuth-based integrations and API dependency, businesses face mounting urgency to reevaluate third-party access, enforce zero-trust principles, and proactively monitor for anomalous behaviors within their SaaS ecosystems.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
North Korean Hackers Target Developers with Massive npm Supply-Chain Attack
Impact· low

North Korean Hackers Target Developers with Massive npm Supply-Chain Attack

In November 2025, North Korean threat actors associated with the "Contagious Interview" campaign launched an extensive supply-chain attack by publishing 197 malicious npm packages. According to threat intelligence from Socket, these packages—downloaded over 31,000 times—were engineered to distribute a new OtterCookie malware variant, combining features from BeaverTail and earlier OtterCookie strains. The attackers leveraged the npm ecosystem to infiltrate development pipelines, enabling remote code execution and persistent access across compromised environments, potentially exposing confidential data and intellectual property. This incident underscores the escalating risks of supply chain attacks targeting software registries. With developers increasingly relying on open-source dependencies, threat actors are focusing on abusing trusted platforms like npm to propagate sophisticated malware at scale. Organizations must strengthen software supply chain security and closely monitor package repositories to mitigate these emerging threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
OpenAI Mixpanel Breach: 2024 Supply-Chain Exposure of API Customer Data
Impact· high

OpenAI Mixpanel Breach: 2024 Supply-Chain Exposure of API Customer Data

In June 2024, OpenAI disclosed that a breach at its third-party analytics provider Mixpanel exposed limited identifying information of certain ChatGPT API customers. According to the company's notification, attackers compromised Mixpanel's systems and accessed data such as organization names and email addresses transmitted through Mixpanel's embedded analytics scripts. OpenAI clarified that payment or sensitive API data was not affected, and the incident did not impact all users. Prompt investigation and mitigation steps were initiated, including collaboration with Mixpanel and additional security controls around third-party integrations. This incident underscores the persistent risks associated with the digital supply chain. As organizations increasingly rely on external vendors for analytics and infrastructure, threat actors continue to exploit third-party weaknesses to obtain customer data—driving heightened attention from regulators and boards.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
2025 Multi-Vector Attack: AI Malware, Voice Bots, Crypto Laundering & IoT Breach
Impact· medium

2025 Multi-Vector Attack: AI Malware, Voice Bots, Crypto Laundering & IoT Breach

In November 2025, threat analysts observed a coordinated, multi-vector cyberattack campaign targeting enterprises across finance, healthcare, and IoT-heavy sectors. Attackers leveraged AI-powered malware, compromised voice bots, and elaborate cryptocurrency laundering techniques to infiltrate organizations, bypass security controls, and exfiltrate sensitive data. Initial access was achieved via sophisticated phishing augmented by AI voice impersonation, while lateral movement and data theft exploited weaknesses in internal segmentation and unencrypted east-west traffic. The campaign’s complexity resulted in service downtime, financial losses, and data exposure for several multinational organizations. This incident is notable for blending diverse threat techniques—AI-driven social engineering, voice-based exploits, and infrastructure abuses—reflecting the current trend towards multifaceted attacks capable of outmaneuvering traditional defenses. The scale and automation highlight increased attacker innovation and challenge existing compliance and zero trust frameworks.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Bloody Wolf's NetSupport RAT Campaign Breaches Kyrgyzstan and Uzbekistan: 2025 Analysis
Impact· medium

Bloody Wolf's NetSupport RAT Campaign Breaches Kyrgyzstan and Uzbekistan: 2025 Analysis

In mid-2025, the threat actor known as Bloody Wolf launched a targeted cyber campaign against government and enterprise entities in Kyrgyzstan, later expanding its operations to Uzbekistan by October 2025. Utilizing sophisticated phishing lures, attackers delivered Java-based loaders that deployed the NetSupport Remote Access Trojan (RAT), allowing persistent access and potential data exfiltration. The campaign featured advanced evasion tactics, encrypted command-and-control traffic, and was attributed by Group-IB and local cybersecurity agencies. Affected organizations faced risks of unauthorized network access and potential compromise of sensitive information. This incident highlights ongoing regional cybercrime escalation, especially the trend of weaponizing legitimate tools like NetSupport RAT through creative malware loaders. With cross-border expansion and zero-day techniques, the event exemplifies how remote access trojans are reshaping threat landscapes and driving demand for advanced network and east-west traffic controls.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Anthropic AI Breach: Chinese State-Sponsored Espionage Campaign Shakes Cybersecurity Landscape
Impact· low

Anthropic AI Breach: Chinese State-Sponsored Espionage Campaign Shakes Cybersecurity Landscape

In late 2024, Anthropic disclosed a sophisticated espionage campaign linked to Chinese state-sponsored actors who leveraged the Claude AI platform to automate and scale cyber-operations targeting at least 30 global organizations. Attackers reportedly used Claude to streamline reconnaissance and intrusion tasks, combining AI capabilities with human expertise to enhance operational stealth and impact. The U.S. House Homeland Security Committee responded by summoning Anthropic’s CEO and other tech leaders to testify about the security implications of AI-augmented tradecraft and the risks posed by pairing AI with emerging technologies like quantum computing. This incident underscores how state-sponsored groups are rapidly evolving, using commercially available AI to bypass defenses and accelerate cyber operations. The attack has triggered urgent calls for stronger safeguards, regulatory clarity on AI security, and cross-sector strategies to counter AI-enabled cyber threats.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Crisis24 Shuts Down CodeRED Emergency System Following Ransomware Breach
Impact· high

Crisis24 Shuts Down CodeRED Emergency System Following Ransomware Breach

In early June 2024, Crisis24 permanently shut down its OnSolve CodeRED emergency notification system after a ransomware attack severely damaged the platform's environment. The incident, attributed to the INC ransomware group, involved unauthorized access to and exfiltration of user data, including names, addresses, email addresses, phone numbers, and passwords. Forensic analysis indicated the attack was contained within the legacy CodeRED environment. The shutdown left dozens of municipalities and law enforcement agencies temporarily without emergency notification services, though the U.S. government's Emergency Alert System was unaffected. Crisis24 accelerated rollout of its new platform, conducted a security audit, and notified law enforcement. This breach underscores the increasing risk posed by ransomware groups targeting public safety infrastructure. With attackers leaking sensitive personal data and causing operational disruptions, organizations face mounting pressure to modernize legacy systems and enhance both incident response and segmentation controls in light of sophisticated, persistent threats.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports