Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
WordPress Post SMTP Plugin Exploited in Mass Admin Account Hijacks (2024)
In early June 2024, cybersecurity researchers identified that a critical vulnerability in the Post SMTP WordPress plugin was being actively exploited by threat actors. This vulnerability allowed attackers to hijack administrator accounts across more than 400,000 affected WordPress sites, enabling complete site control and potentially permitting installation of malicious payloads. Attackers gained initial access through the plugin's weak nonce verification, escalating privileges to compromise sites, deploy backdoors, and exfiltrate sensitive data. The incident demonstrates how widespread web application vulnerabilities can be rapidly weaponized, putting enterprises and small businesses alike at risk of data loss, defacement, or further compromise. The Post SMTP exploitation highlights a recent surge in attacks leveraging zero-day or unpatched CMS plugins on large scales, reflecting attackers’ growing focus on supply chain and SaaS-adjacent targets. As organizations increasingly depend on third-party tools and platforms, maintaining rapid patch cycles and comprehensive visibility into software components is more critical than ever.
8 months ago
Kill Chain
Akira Ransomware’s Disputed Data Breach: What Happened at Apache OpenOffice (2024)
In June 2024, the Akira ransomware group publicly claimed responsibility for a data breach affecting Apache OpenOffice, alleging the theft of 23 GB of sensitive corporate documents. Despite these assertions, the Apache Software Foundation conducted an internal investigation and officially disputed any evidence of compromise or unauthorized access, stating there were no indications of a breach in their infrastructure. This incident highlights the ongoing challenge organizations face with threat actor claims that may not always be substantiated but can cause reputational risk and user concern. Similar ransomware campaigns have surged in 2024, with groups leveraging public exposure even without confirming access to target data. The situation underscores the importance of proactive communication, transparent incident response, and technical validation as attackers increasingly use psychological pressure tactics in addition to technical intrusions.
8 months ago
Kill Chain
How Microsoft Uncovered the SesameOp OpenAI API Backdoor: 2025 Case Study
In November 2025, Microsoft’s security team identified a sophisticated backdoor campaign dubbed 'SesameOp,' wherein attackers leveraged the OpenAI Assistants API as a stealthy command-and-control (C2) channel. This unconventional tactic enabled the threat actors to instruct compromised systems via encrypted and authenticated OpenAI API communications, bypassing traditional security controls and network monitoring systems. The initial access vector is under investigation, but early signs point to phishing emails weaponized with malicious loader scripts. The use of a reputable third-party AI API provided attackers with enhanced persistence and made network traffic analysis difficult, delaying detection and remediation. This incident marks a significant escalation in attacker techniques exploiting trusted generative AI platforms for C2, illustrating the growing weaponization of legitimate SaaS services. Organizations must urgently reassess how they detect, monitor, and govern API traffic, particularly for large AI-driven platforms now woven deeply into business infrastructure.
8 months ago
Kill Chain
U.S. Cybersecurity Insiders Indicted for BlackCat Ransomware Attacks (2023)
Between May and November 2023, a trio of U.S.-based individuals—including two named suspects and an unnamed co-conspirator—compromised the networks of five American companies using BlackCat (ALPHV) ransomware. Prosecutors allege that the attackers, all cybersecurity insiders, leveraged privileged access and technical expertise to deploy ransomware on a range of targets, including a medical organization, resulting in considerable financial losses and data encryption. The conspirators used advanced methods to extort payments, disrupt operations, and evade detection. This incident highlights the growing risk posed by insider threats and the increasing sophistication of ransomware groups like BlackCat/ALPHV. Such attacks are driving regulatory calls for enhanced east-west network controls, granular segmentation, and robust anomaly detection as ransomware tactics continue to evolve.
8 months ago
Kill Chain
Google’s ‘Big Sleep’ AI Uncovers 5 Critical Safari WebKit Vulnerabilities
In October 2025, Apple publicly credited Google's AI-powered cybersecurity agent, 'Big Sleep', for identifying five critical vulnerabilities within the WebKit component of its Safari browser. These vulnerabilities, notably including CVE-2025-43429, could be exploited by attackers to trigger browser crashes or initiate memory corruption, potentially resulting in code execution or unauthorized system compromise. Google’s advanced AI techniques allowed rapid discovery and responsible disclosure, prompting Apple to issue urgent patches for all affected systems. This incident underscores a new trend where AI-driven security research exposes latent vulnerabilities faster than ever. It is increasingly relevant as cyber threats grow more sophisticated and organizations face regulatory pressure to promptly remediate critical flaws, especially in client-facing software like browsers.
8 months ago
Kill Chain
Operation SkyCloak: Tor-Enabled OpenSSH Backdoor Infiltrates Defense Networks
In November 2025, a sophisticated cyber campaign dubbed 'Operation SkyCloak' was uncovered, targeting Russian and Belarusian defense sectors. Attackers distributed weaponized attachments via phishing emails, successfully implanting a persistent OpenSSH-based backdoor on compromised hosts. To conceal its activity, the malware leverages a customized Tor hidden service with obfs4 protocol, facilitating covert command-and-control and persistent unauthorized access. This campaign demonstrates advanced threat actor operational security, targeting high-value government and defense assets to enable espionage and data exfiltration. The use of Tor-enabled backdoors in defense-related attacks is surging, marking a shift towards more covert, untraceable threat tactics. This incident exemplifies the growing adoption of anonymized infrastructure by attackers to evade detection, highlighting urgent requirements for east-west traffic inspection, advanced threat detection, and zero trust segmentation for critical sectors.
8 months ago
Kill Chain
2025 Ransomware Tsunami: Why Real-Time Data Is Now Essential for Defense
In early 2025, organizations worldwide faced a dramatic surge in ransomware attacks, as threat actors embraced data-driven approaches and leveraged AI, new exploit techniques, and ransomware-as-a-service (RaaS) business models. Attackers rapidly escalated compromise using stolen credentials, lateral movement, and encrypted communications, bypassing traditional detection tools and reducing dwell time to under an hour. With nearly half of breaches attributed to ransomware and a sharp increase in identity-driven attacks, countless organizations experienced significant operational disruptions, financial losses, and reputational damage. This incident highlights a macro-shift in the threat environment: traditional signature-based or static ransomware detection methods are now largely ineffective against modern, fast-moving adversaries. The exponential rise of hands-on, machine-speed attacks and infostealer-driven access means organizations urgently need real-time, intelligence-led detection and response capabilities.
8 months ago
Kill Chain
Inside the 2025 Cybercrime Merger: Scattered Spider, LAPSUS$, and ShinyHunters Unite
In August 2025, a powerful new cybercrime collective emerged from the merger of Scattered Spider, LAPSUS$, and ShinyHunters—three of the most notorious threat groups involved in high-profile data theft, ransomware, and extortion. This unified entity quickly established 16 Telegram channels to coordinate attacks, evade platform moderation, and amplify operations. Leveraging advanced social engineering and data exfiltration techniques, the collective launched a string of multinational breaches targeting enterprises, exposing sensitive information and causing significant financial and reputational harm to victims. Security teams observed an uptick in lateral movement, exploitation of hybrid/cloud environments, and sophisticated policy evasion tied to these actors. This incident exemplifies a growing trend where cybercriminal syndicates combine resources and expertise, accelerating the pace and scale of attacks. The merger highlights the urgent need for organizations to adapt to evolving threat actor alliances and reinforces the importance of advanced segmentation, zero trust, and robust monitoring frameworks.
8 months ago
Kill Chain
Microsoft Teams Vulnerabilities: 2025’s Wake-Up Call for Application Security
In March 2025, security researchers uncovered four critical vulnerabilities in Microsoft Teams that allowed attackers to manipulate conversations and impersonate trusted colleagues without detection. By exploiting flaws in message handling and notifications, adversaries could initiate convincing phishing and social engineering attacks, posing as legitimate users and altering message content retroactively. These flaws were exploitable until Microsoft was notified through responsible disclosure, enabling potential internal threat activity or external compromise before patches were issued. This incident highlights the growing risks of business collaboration platforms as prime targets for socially engineered attacks. With enterprise reliance on unified communications, attackers are innovating new tactics to undermine trust, emphasizing the urgent need for proactive application security and real-time threat monitoring controls.
8 months ago
Kill Chain
Critical 2025 React Native CLI Flaw Exposes Millions to Supply-Chain Attacks
In November 2025, a critical vulnerability was disclosed in the widely used "@react-native-community/cli" npm package, exposing millions of developers and organizations that rely on React Native for application development. The flaw allowed remote, unauthenticated attackers to execute arbitrary operating system commands on systems running vulnerable versions of the CLI tool. The threat stemmed from insufficient input validation, enabling exploitation via malicious npm modules or manipulated code, creating a high-risk supply-chain attack vector. The vulnerability was swiftly patched, but it highlighted significant supply-chain security gaps across the software development ecosystem. This incident is notable for reinforcing the urgent need to secure development toolchains and underscores the increasing frequency of attacks targeting open-source software dependencies. As attackers continue to exploit weak links in the software supply chain, organizations must strengthen controls, monitoring, and vulnerability management to keep pace with evolving risks.
8 months ago
Kill Chain
CISA Flags Active Exploitation of 2025 Gladinet CentreStack, Triofox, and CWP Control Web Panel Flaws
In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA) identified and announced active exploitation of two critical vulnerabilities: CVE-2025-11371 in Gladinet CentreStack and Triofox (files or directories exposed to external parties), and CVE-2025-48703 in CWP Control Web Panel (an OS command injection flaw). Threat actors are leveraging these weaknesses to gain unauthorized file access or execute malicious code within affected environments, targeting organizations across sectors. The vulnerabilities enable lateral movement, data exfiltration, and potentially full compromise, with significant risk to sensitive data, business operations, and regulatory posture for organizations running vulnerable systems. This announcement underscores a broader trend of attackers exploiting unpatched software vulnerabilities in common enterprise tools. With automatic exploitation kits and a growing focus on file-sharing and web panel infrastructure, organizations face urgent pressure to accelerate vulnerability management and adopt Zero Trust practices to contain and monitor internal threats.
8 months ago
Kill Chain
SesameOp: AI API Abused as C2 in Advanced Malware Attack (2024)
In early 2024, cybersecurity researchers uncovered a sophisticated malware campaign involving the "SesameOp" backdoor, which leveraged OpenAI's API as a covert Command and Control (C2) channel. Threat actors behind this attack established persistence within targeted organizations using a custom Linux backdoor, routing communications through encrypted API calls to OpenAI infrastructure, thus evading traditional detection methods. The malware's use of legitimate AI service channels enabled threat actors to obfuscate malicious activity, complicating incident response and extending dwell time inside compromised environments. The incident underscored the rapid innovation of attacker tactics and the challenges enterprises face as generative AI ecosystems become embedded in critical workflows. This breach exemplifies a wider, emerging risk: attackers abusing popular cloud-based and AI-driven services for lateral movement, data exfiltration, and stealthy C2 operations. With AI adoption accelerating across industries, security teams must urgently reassess control frameworks, enhance anomaly detection, and enforce visibility on legitimate platforms often overlooked in legacy monitoring.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports