Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Kerberoasting in 2025: Service Account Risks and Zero Trust Imperatives
In early 2025, a significant cyber incident occurred in which attackers leveraged Kerberoasting techniques to compromise Active Directory (AD) environments. Threat actors exploited weakly protected service accounts to request service tickets, subsequently brute-forcing their encrypted credentials offline. This attack method enabled them to escalate privileges and potentially gain domain administrator access, often without triggering security alerts. The intrusion highlighted shortcomings in credential hygiene, detection capabilities, and adherence to modern encryption standards within corporate IT infrastructures. Operational impacts included increased risk of lateral movement, data exfiltration, and potential business disruption had the attackers established persistent access. Kerberoasting attacks have become more prevalent due to their stealthy nature and the widespread reliance on legacy authentication protocols. As organizations accelerate digital transformation and adopt zero trust models, identity-based threats like these place added emphasis on proactive credential management, monitoring, and compliance with encryption regulations.
8 months ago
Kill Chain
The Washington Post Oracle Supply Chain Breach: Lessons on Third-Party Risk in 2024
In June 2024, The Washington Post began notifying nearly 10,000 employees and contractors that their personal and financial information had been exposed following a breach involving Oracle-managed systems. The incident stemmed from an attack on a third-party vendor, believed to be tied to the widespread theft of cloud-stored data, which granted unauthorized access to sensitive HR and payroll details. The compromise was discovered post-incident, and affected individuals include current and former staff spanning back several years. Although there is no evidence of active misuse, the breach has prompted heightened security reviews. This breach exemplifies escalating risks inherent in supply-chain and third-party systems, with attackers increasingly targeting service providers to access large pools of critical enterprise data. Organizations across all sectors are now under pressure to strengthen controls around third-party integrations to reduce exposure.
8 months ago
Kill Chain
Akira Ransomware Targets Nutanix AHV Linux VMs: 2024 Attack Analysis
In early 2024, threat actors associated with the Akira ransomware group expanded their operations to target Nutanix AHV virtual machines (VMs) running on Linux, according to alerts from CISA and other cybersecurity agencies. By leveraging compromised credentials or exploiting vulnerabilities, attackers gained access to enterprise infrastructure and deployed a Linux-based Akira encryptor capable of encrypting entire Nutanix VM environments. This strategy disrupted critical workloads and led to significant operational downtime, as well as potential data loss and extortion threats for affected organizations. This incident underscores a trend of ransomware groups shifting focus toward virtualization platforms and cloud infrastructure, extending risks beyond traditional endpoints. The Akira campaign highlights the growing sophistication of ransomware TTPs and the urgent need for robust segmentation and lateral movement controls within virtualized environments.
8 months ago
Kill Chain
ImunifyAV RCE Flaw Puts Millions of Linux Websites at Immediate Risk in 2024
In June 2024, a critical remote code execution (RCE) vulnerability was discovered in ImunifyAV, a malware scanner widely deployed on Linux web servers hosting millions of websites globally. Attackers could exploit this unauthenticated flaw to execute arbitrary code on vulnerable servers, potentially gaining full control over hosting environments and compromising customer websites at scale. The flaw threatened the security of hosting providers and their clients, enabling advanced threat actors to launch further attacks, steal data, or deploy additional malware. Immediate patching was required to prevent exploitation in the wild. This incident underscores the increasing risks posed by third-party security tool vulnerabilities, especially in shared and cloud-hosted web environments. Rapid exploitation of newly disclosed software flaws and supply chain attacks continues to rise, highlighting the critical importance of timely patch management and zero trust controls.
8 months ago
Kill Chain
IndonesianFoods npm Worm Floods Registry with 100,000 Packages in Major Supply Chain Incident
In June 2024, the npm package ecosystem was targeted by a self-propagating malware dubbed the 'IndonesianFoods' worm. The worm exploited npm’s open publishing model, rapidly flooding the registry with nearly 100,000 malicious, junk packages at a rate of one every seven seconds. Working autonomously, the malware replicated itself using pre-programmed scripts, creating an unprecedented scale of package spam, which overwhelmed the registry, threatened package discovery, and disrupted normal operations for developers worldwide. No evidence so far points to direct compromise of sensitive data or targeted attacks on organizations, but the overwhelming volume affected the trust and stability of the npm supply chain platform. This event spotlights the vulnerability of open-source ecosystems to automated spam and self-replicating threats, underscoring the growing risk in software supply chains from both criminal and experimental actors. The surge in npm-focused attacks amplifies calls for stronger package validation, improved security automation, and supply-chain controls industry-wide.
8 months ago
Kill Chain
Flood of Fake npm Packages Reveals Growing Supply Chain Attack Risk
In early 2024, a financially-motivated threat actor orchestrated a large-scale spam campaign that flooded the npm package registry with over 67,000 fake packages. By systematically publishing malicious and junk modules, the actor exploited npm’s open nature, allowing the fake packages to persist on the platform for nearly two years. These packages, often uploaded with auto-generated names and code, increased risks for developers by inflating dependency confusion attack surfaces and potentially delivering malware through the software supply chain. The incident underscored ongoing challenges in detecting and mitigating large-scale abuse within open-source ecosystems, disrupting trust and reliability for countless organizations relying on npm. This attack is emblematic of a wider trend in software supply-chain targeting, with threat actors increasingly exploiting public repositories to propagate malicious code or disrupt developer workflows. As software supply chains remain a critical risk focal point, organizations face mounting regulatory scrutiny and require robust governance and anomaly detection controls to safeguard development environments.
8 months ago
Kill Chain
Inside the Cisco 2025 Multi-Vector Breach: 0-Days, State Actors, and Encrypted Threats
In November 2025, Cisco experienced a sophisticated multi-vector cyberattack that leveraged previously unknown zero-day vulnerabilities across its networking equipment. Attackers combined techniques such as encrypted traffic evasion, lateral movement, and zero-trust segmentation bypasses, using advanced tools to avoid detection and compromise both east-west and north-south flows. The intrusion enabled threat actors—suspected of state affiliation—to exfiltrate internal data, disrupt encrypted hybrid connections, and potentially impact customer networks on a global scale before the breach was identified and contained. This incident highlights an emerging trend: attackers are orchestrating multiple, layered techniques to exploit evolving environments, such as hybrid and multi-cloud infrastructure. As organizations rely on AI-driven security and expand east-west traffic, defenders face increased complexity, raising the urgency for integrated, visibility-rich, and compliance-driven zero trust architectures.
8 months ago
Kill Chain
CISA Flags Critical WatchGuard Fireware Flaw: 54,000 Fireboxes at Risk from Unauthenticated Attacks
In November 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-9242, a critical out-of-bounds write vulnerability in WatchGuard Fireware OS, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. Attackers leveraged this flaw—rated CVSS 9.3—to gain unauthenticated remote access to over 54,000 exposed WatchGuard Firebox appliances worldwide, enabling potential system compromise and lateral network movement. The vulnerability affects Fireware OS versions 11.10.2 through recent releases, putting a significant number of network security devices at risk. This incident highlights the urgent need for aggressive patching and improved visibility into network infrastructure exposures. With attackers increasingly targeting edge devices and exploiting unpatched vulnerabilities, organizations must prioritize vulnerability management and zero trust network segmentation to contain emerging threats.
8 months ago
Kill Chain
Operation Endgame 2025: Law Enforcement Disrupts Rhadamanthys, Venom RAT, and Elysium Botnet
Between November 10 and 13, 2025, international law enforcement agencies led by Europol and Eurojust conducted Operation Endgame, a sweeping crackdown targeting malicious cyber infrastructures. The operation succeeded in dismantling key components of the Rhadamanthys Stealer, Venom RAT, and Elysium botnet, disrupting networks that facilitated global credential theft, remote access, and command-and-control activities. The coordinated seizures involved simultaneous server takedowns across multiple countries and the arrest of key individuals behind these malware operations, significantly diminishing the power and reach of these cybercriminal networks. This incident highlights an increasing trend of robust international cooperation in targeting advanced malware and botnet ecosystems. The disruption of these criminal infrastructures sends a strong message to threat actors, demonstrating both the technical capabilities and resolve of law enforcement to combat cybercrime at scale.
8 months ago
Kill Chain
2024 Salesloft-Drift Supply Chain Breach: AWS Credential Exposure and Cloud Security Lessons
In early 2024, a sophisticated supply chain attack targeted the Salesloft and Drift integration, leading to the compromise of AWS credentials and unauthorized access to cloud environments. Threat actors exploited weaknesses in the integration pipeline, leveraging exposed secrets to move laterally and access sensitive customer data before the breach became public. Red Canary detected anomalous cloud activity tied to this attack, providing early detection prior to broad public awareness and response, thereby helping to mitigate further impact. This incident is significant as it demonstrates the growing frequency and sophistication of supply chain attacks within SaaS and cloud services, especially those exploiting secret leaks and third-party application integrations. The breach highlights the need for heightened vigilance, identity and credential protection, and advanced threat detection capabilities in the cloud ecosystem.
8 months ago
Kill Chain
Akira Ransomware 2025: How Edge Device Vulnerabilities Fueled Infrastructure Attacks
In November 2025, the Akira ransomware group and affiliates such as Storm-1567 and Howling Scorpius intensified attacks on critical infrastructure sectors by exploiting edge device and backup server vulnerabilities. Threat actors leveraged techniques including authentication bypass, brute-force credential attacks, and the deployment of new Akira_v2 malware for rapid encryption. Their sophisticated methods involved lateral movement through RDP/SSH, defense evasion with remote tools (Anydesk, LogMeIn), disabling security controls, and stealthy data exfiltration via FTP/SFTP/cloud channels. Impacted sectors ranged from Manufacturing and Education to Healthcare and Finance, resulting in encrypted systems, data theft, and serious operational disruption. This incident underscores the persistent evolution of ransomware tactics and the growing threat to organizations of all sizes. The prevalence of supply chain risks, rapid malware adaptation, and exploitation of misconfigured or outdated security perimeters demand continuous vigilance and investment in advanced detection, rapid patching, and segmentation strategies.
8 months ago
Kill Chain
CitrixBleed 2: New Zero-Day Storm Hits Identity and Network Gateways
In early 2025, security teams discovered active exploitation of two newly identified zero-day vulnerabilities: CVE-2025-5777 in Citrix NetScaler and CVE-2025-20337 in Cisco Identity Service Engine (ISE). An advanced persistent threat (APT) group rapidly targeted both flaws, focusing on critical infrastructure where identity and access management systems form the backbone of secure connectivity. Attackers leveraged these zero-days to bypass authentication and elevate privileges, enabling lateral movement across east-west network segments and exfiltrating sensitive data. The incident underscores the risks posed by unpatched identity infrastructure in enterprise environments, leading to operational disruptions and an urgent patch response from affected vendors. This breach highlights a surge in sophisticated campaigns targeting the convergence of networking and identity technologies. The focus on identity-driven systems, rapid weaponization of zero-day exploits, and threat actors’ ability to pivot between vendors reinforce the growing challenge organizations face in defending mission-critical services amid a shifting risk landscape.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports