Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Meet ShinySp1d3r: How Affiliate Ransomware Powered by ShinyHunters Ups the Stakes
In mid-2024, cybersecurity researchers discovered an in-development version of the ShinySp1d3r ransomware-as-a-service (RaaS) platform, believed to be created by the infamous ShinyHunters threat group. The platform equips criminal affiliates with a toolkit designed to automate ransomware deployment, data encryption, and multi-extortion capabilities. Early builds circulated within cybercrime forums preview advanced features, such as dashboard controls, automated leak sites, and an affiliate earnings model, underscoring the maturity and commercialization of the threat. The potential for widespread, coordinated attacks against enterprises and public sector organizations is significantly heightened by the accessibility and ease-of-use facilitated by this service. The emergence of ShinySp1d3r represents a growing trend of professionalized cybercrime, where sophisticated threat actors develop and market turnkey attack platforms to less-skilled operators. This further accelerates ransomware proliferation and amplifies the risks for organizations reliant on digital infrastructure.
8 months ago
Kill Chain
Operation WrtHug: How Legacy ASUS Routers Became a Global Botnet in 2024
In early 2024, thousands of end-of-life ASUS WRT routers worldwide were compromised in a large-scale campaign dubbed "Operation WrtHug". Attackers exploited at least six known vulnerabilities in outdated router firmware to hijack control of the devices. These compromised routers were assimilated into a new botnet infrastructure, enabling malicious actors to facilitate unauthorized traffic routing, launch further attacks, and potentially intercept sensitive data passing through these compromised endpoints. The incident points to neglected device lifecycle management and widespread exposure due to unpatched, unsupported consumer hardware. This breach is particularly notable as it reflects a growing trend: attackers shifting focus to vulnerable, unmaintained IoT and networking hardware. With legacy devices lacking security updates, organizations face heightened risk of compromise and regulatory scrutiny, while defenders must urgently address asset visibility and enforcement across distributed infrastructure.
8 months ago
Kill Chain
Sanctions Hit Russian Bulletproof Hosting Providers Backing Global Ransomware
In June 2024, the United States, together with the United Kingdom and Australia, imposed sanctions on Russian bulletproof hosting provider Media Land and associated entities. Investigations revealed these providers had knowingly facilitated ransomware operations and other cybercriminal activities by offering infrastructure shielding malicious actors from law enforcement, particularly ransomware gangs operating out of Russia. The sanctions block their financial assets and prohibit transactions, aiming to disrupt the ecosystem supporting high-profile global ransomware attacks and cybercrime. This incident is significant amid a surge in ransomware and supply-chain attacks worldwide, with threat actors increasingly relying on bulletproof hosting to evade detection. Governments are moving quickly to cut off these enablers as part of a broader strategy against organized cybercrime.
8 months ago
Kill Chain
Phishing-as-a-Service Evolves: Sneaky2FA Adds Browser-in-the-Browser Attacks in 2024
In early June 2024, cybersecurity researchers reported that the Sneaky2FA phishing-as-a-service (PhaaS) kit has adopted the Browser-in-the-Browser (BitB) attack tactic, previously used by red teamers, to improve the effectiveness of credential phishing campaigns. This new feature enables threat actors using the Sneaky2FA service to launch highly convincing fake login pop-ups, closely mimicking legitimate authentication flows, including prompts for multifactor authentication (MFA). The update broadens the risks for both organizations and individuals, as traditional indicators of phishing are increasingly hard to spot. The deployment of BitB tactics by a turnkey phishing kit marks a concerning development in the automation and commercial accessibility of advanced cybercrime techniques. This incident underscores the escalating sophistication of phishing attacks driven by the commoditization of offensive security techniques. Organizations face renewed urgency to revisit their authentication controls, user awareness training, and phishing-resistant MFA, as adversary innovation quickly outpaces conventional defense measures.
8 months ago
Kill Chain
Critical W3 Total Cache Plugin Vulnerability Enables PHP Command Injection on WordPress Sites
In June 2024, a critical security vulnerability was disclosed in the W3 Total Cache WordPress plugin, which is widely used to optimize website performance. Attackers could exploit this flaw by submitting a specially crafted comment to a vulnerable website, enabling them to execute arbitrary PHP commands on the underlying server. This vulnerability, involving insufficient sanitization and validation within comment processing, exposes affected websites to full compromise, including unauthorized data access, web defacement, and further lateral movement inside hosting environments. Immediate patching is required as active exploitation has been observed in the wild. This incident underscores the persistent risk of supply chain attacks and plugin vulnerabilities in content management systems like WordPress. As attackers increasingly target high-profile plugins to gain initial access, maintaining up-to-date software and implementing robust security controls has never been more critical.
8 months ago
Kill Chain
Ransomware Disrupts European Airports in 2025: HardBit & SonicWall VPN Exploit
In September 2025, a coordinated HardBit ransomware attack caused significant operational disruptions across several European airports. The attack exploited a vulnerability in SonicWall SSL VPN devices (CVE-2024-40766), allowing threat actors to bypass multi-factor authentication and gain unauthorized access to critical infrastructure. Prompt law enforcement action led to the arrest of an initial suspect by the UK’s National Crime Agency, though details remain limited as investigations continue. The attack, labeled by researchers as primitive yet effective, underscores how quickly threat actors are leveraging both publicly available exploits and compromised credentials to disrupt essential services with ransomware. This event made headlines due to its impact on vital transportation infrastructure and prompted an international response highlighting the growing urgency for robust network segmentation, encrypted traffic measures, and rapid threat detection. The incident also reflects a broader trend of ransomware actors increasingly targeting critical sectors using innovative entry vectors and expanding their global footprint.
8 months ago
Kill Chain
Mobile Malware Soars in Q3 2025: Key Insights from Kaspersky's Global Report
In Q3 2025, Kaspersky reported a significant surge in mobile malware activity, with 47 million attacks prevented globally targeting Android devices with Trojans, adware, banking malware, and ransomware. Threat actors exploited new variants—including BADBOX and sophisticated Trojans like Triada and Fakemoney—utilizing methods such as pre-installed backdoors and malicious app mods. Mobile banking Trojans (especially Mamont and Coper) and region-targeted malware attacks in Turkey, India, Iran, and Germany impacted financial data security and user privacy, highlighting expanding attacker sophistication and supply chain compromise. This incident is critical as it illustrates the rising prevalence and complexity of mobile threats, coinciding with increased ransomware attacks and evolving delivery channels. The continued targeting of financial apps and global user bases signals an urgent need for organizations to strengthen mobile security, visibility, and compliance with privacy mandates.
8 months ago
Kill Chain
ServiceNow AI Agents Breached in 2025 via Second-Order Prompt Injection
In November 2025, security researchers uncovered a novel method by which ServiceNow's Now Assist generative AI platform could be manipulated through second-order prompt injection attacks. By exploiting default configurations and inherent agent-to-agent communication, attackers could coerce agentic AI features into executing unauthorized operations. This exposure allowed malicious actors to access, copy, and exfiltrate sensitive enterprise data without proper user authorization. The attack leverages prompt injection to bypass intended policy boundaries, posing significant data risk to organizations relying on ServiceNow’s AI-driven automations. This incident highlights a growing threat landscape in which AI agent-to-agent interactions are harnessed for sophisticated attacks. With increased enterprise adoption of generative AI and autonomous agents, security around configuration and prompt validation has become mission-critical. Organizations should assess agent communication safeguards and be vigilant against emerging prompt injection and shadow AI risks.
8 months ago
Kill Chain
EdgeStepper: PlushDaemon’s DNS Hijack Shakes Supply Chain Trust
In late 2025, the threat actor PlushDaemon leveraged a custom Go-based implant named EdgeStepper to facilitate a sophisticated supply chain attack targeting organizations relying on automated software updates. By hijacking DNS queries via EdgeStepper, attackers rerouted legitimate update traffic to attacker-controlled infrastructure, covertly delivering malware payloads. This adversary-in-the-middle campaign exploited a weakness in outbound traffic validation and DNS trust, leading to silent compromise of enterprise endpoints through poisoned software update mechanisms. The incident resulted in widespread concerns over supply chain integrity and exposed gaps in security monitoring of encrypted or internal network flows. This incident highlights the growing trend of adversaries exploiting DNS and software supply chains as primary attack vectors. With regulatory and industry focus tightening on secure update mechanisms and zero trust, similar AitM tactics are escalating in both frequency and sophistication, requiring renewed urgency for organizations to enhance detection at the DNS and network boundary layers.
8 months ago
Kill Chain
NHS Flags PoC Exploit for 7-Zip Symlink RCE Vulnerability (CVE-2025-11001)
In November 2025, NHS England Digital issued an advisory regarding a significant vulnerability (CVE-2025-11001) in the popular 7-Zip compression software. While no active in-the-wild exploitation was detected, a publicly available proof-of-concept (PoC) exploit for a symbolic link–based remote code execution (RCE) flaw raised concerns of imminent risk. The flaw, if exploited, could allow attackers to execute arbitrary code on systems using 7-Zip, threatening the confidentiality, integrity, and availability of healthcare data critical to NHS operations. Security teams were urged to prioritize patching and closely monitor for suspicious activity. This incident highlights a broader industry trend: attackers are rapidly weaponizing PoC exploits for newly disclosed vulnerabilities, targeting widely used utilities to enable lateral movement and privilege escalation. The urgency of patching and proactive threat detection has never been greater, especially for organizations in regulated sectors like healthcare.
8 months ago
Kill Chain
WhatsApp Hijack: Eternidade Stealer Campaign Hits Brazilian Users via Python Worm
In November 2025, cybersecurity researchers identified a sophisticated campaign targeting Brazilian users via WhatsApp, where attackers leveraged a Python-based worm combined with social engineering tactics. Victims were tricked into installing a worm that hijacked WhatsApp sessions and propagated itself to contacts, while delivering a Delphi-based banking trojan known as Eternidade Stealer. The campaign exploited IMAP to dynamically resolve command-and-control infrastructure, enabling threat actors to orchestrate info-stealing and credential harvesting at scale and with resilience to takedown attempts. The incident had significant implications for financial fraud and impacted numerous personal and business WhatsApp accounts across Brazil. This campaign is emblematic of a wider surge in malware leveraging messaging platforms for lateral movement and rapid propagation. The popularity of WhatsApp, combined with increasingly modular infostealers and TTP reuse by criminal groups, highlights the urgent need for proactive controls and visibility across both east-west and outbound communication paths.
8 months ago
Kill Chain
Cloudflare's 2024 Outage: How a Simple Misconfiguration Led to Global Disruption
In June 2024, Cloudflare, a leading cloud services provider, experienced a major global outage initially suspected to be the result of a distributed denial-of-service (DDoS) attack. Further investigation revealed that the real cause was an internal configuration error: a routine permissions update inadvertently triggered a critical software failure within network infrastructure, disrupting access to innumerable customer websites and business services for several hours worldwide. The incident underscored the fragile interplay between automated change management and resiliency of cloud-based operations. This outage is especially timely as organizations accelerate cloud adoption and automation, increasing their susceptibility to operational lapses and accidental misconfigurations. Regulatory bodies and industry frameworks are now sharpening requirements for cloud governance, real-time visibility, and robust change controls to mitigate such risks.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports