Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
CISA Confirms Critical Lanscope Endpoint Manager Vulnerability Under Active Attack
In October 2025, a critical vulnerability (CVE-2025-61932, CVSS 9.3) in Motex Lanscope Endpoint Manager was added to CISA’s Known Exploited Vulnerabilities catalog after confirmed active exploitation in the wild. Attackers leveraged the on-premises endpoint management platform’s remote code execution flaw to obtain unauthorized access, enabling lateral movement and potential data exfiltration. Organizations relying on Lanscope Endpoint Manager may face business disruption, data integrity issues, and heightened regulatory scrutiny as a result of this exposure. The recent exploitation of this vulnerability underscores a larger trend of remote code execution exploits targeting widely deployed endpoint management products. With attackers increasingly seeking supply-chain and IT management footholds, regulatory bodies and security leaders are prioritizing rapid patch cycles and robust segmentation to limit risk.
8 months ago
Kill Chain
Jingle Thief: How Hackers Exploited Cloud to Steal Millions in Retail Gift Cards (2025)
In October 2025, a cybercriminal group known as Jingle Thief orchestrated a sophisticated financial fraud campaign targeting retail and consumer services organizations operating in cloud environments. Leveraging phishing and smishing tactics to obtain employee credentials, the attackers gained access to cloud-based systems responsible for managing digital gift card issuance. Once inside, they exploited weak east-west traffic controls and lack of adequate segmentation to move laterally and automate gift card theft at scale, resulting in losses worth millions of dollars and significant operational disruption to affected businesses. This incident highlights an ongoing escalation in targeted cloud infrastructure attacks, especially towards retail functions involving financial assets like digital gift cards. The use of cloud-native attack vectors and credential phishing underscores the urgency for enhanced zero trust practices, robust detection controls, and strict policy enforcement to protect sensitive assets in distributed environments.
8 months ago
Kill Chain
It Only Takes 250 Documents to Poison Any Large Language Model – Security Implications for 2024
In 2024, cybersecurity researchers demonstrated that the integrity of large language models (LLMs) can be severely compromised with as few as 250 poisoned documents strategically inserted into their training data. By covertly introducing manipulated or malicious content into public data sources, attackers can alter a model’s understanding, bias its outputs, or degrade its reliability. This proof-of-concept highlights that ‘data poisoning’ attacks require minimal input yet pose substantial risk for AI reliability, potentially opening the door for misinformation, backdoors, or loss of operational trust across industries leveraging AI. Organizations relying on LLMs for critical tasks face a heightened threat of silent, hard-to-detect breaches affecting their core AI deployments. The urgency around AI/ML supply chain security has intensified, as threat actors and researchers increasingly explore the feasibility of data poisoning. Regulatory frameworks and industry best practices now emphasize the need for data provenance controls and continuous integrity monitoring of training pipelines.
8 months ago
Kill Chain
FinWise Data Breach 2024: When Encryption Is the Last Line of Defense
In early 2024, FinWise, a financial services provider, suffered a significant data breach traced to an insider threat that circumvented internal security controls. The attacker exploited inadequate encryption of sensitive data in transit, extracting customer records via lateral movement across poorly segmented network segments. Because traffic was not properly encrypted, packet sniffing allowed the attacker to collect financial and personal data largely undetected for several weeks. The breach led to loss of confidential information, potential regulatory scrutiny, and reputational harm for FinWise. This incident highlights a rising wave of insider threats exploiting deficiencies in east-west traffic security and underscores the importance of robust, end-to-end encryption as regulatory bodies tighten requirements for securing data in transit and at rest across hybrid and multi-cloud environments.
8 months ago
Kill Chain
TARmageddon: Rust async-tar Supply Chain Flaw Leads to Critical RCE Risk
In June 2024, security researchers disclosed a critical vulnerability known as 'TARmageddon' in the abandoned Rust async-tar library and its forks. Attackers can exploit the flaw to achieve remote code execution (RCE) on systems using unpatched versions of the library, commonly found in developer tools and backend infrastructure. As async-tar remains unmaintained, organizations relying on affected forks or software inherit the vulnerability, potentially allowing initial compromise and lateral movement within supply chains. The flaw highlights the cascading risks of dependencies on abandoned open-source components, increasing the likelihood of stealthy supply-chain attacks bypassing traditional controls. This incident underscores a growing trend of adversaries targeting open-source software supply chains, particularly by exploiting abandoned or under-maintained libraries. The complexity and opacity of modern dependency trees, alongside escalations in software bill of materials (SBOM) scrutiny, make proactive vulnerability management and real-time supply-chain threat detection essential for reducing risk.
8 months ago
Kill Chain
Over 100 Government Agencies Breached by Iranian MuddyWater APT with Phoenix Backdoor
In early 2024, the Iranian state-sponsored threat group MuddyWater executed widespread attacks leveraging the Phoenix backdoor (version 4), successfully targeting over 100 government entities worldwide. The campaign exploited spear-phishing and malicious document attachments to deliver the backdoor, enabling persistent access, lateral movement, and data exfiltration from compromised systems. This sophisticated intrusion allowed the attackers to maintain a long-term foothold within highly sensitive government networks, posing significant operational and intelligence risks across multiple regions. This incident underscores a sharp escalation in advanced persistent threat (APT) tactics targeting public sector organizations. It highlights both the evolving sophistication and relentless nature of nation-state cyber operations, amplifying regulatory and operational pressure on government organizations to strengthen east-west traffic security, anomaly detection, and Zero Trust segmentation strategies.
8 months ago
Kill Chain
TARmageddon: Remote Code Execution Risk in Popular Async-Tar Rust Library Uncovered (2025)
In late August 2025, researchers uncovered TARmageddon (CVE-2025-62518), a high-severity supply-chain vulnerability in the async-tar Rust library and its forks, including tokio-tar. This flaw could permit remote code execution (RCE) when processing maliciously-crafted tar archives, posing a significant risk to downstream applications and platforms relying on these libraries for file extraction and archive handling. Successful exploitation opens the door to system compromise, data loss, or service interruption for potentially thousands of applications leveraging async-tar in production workloads. This incident highlights the growing threat of software supply-chain vulnerabilities, especially within open-source dependencies widely adopted across cloud-native and DevSecOps environments. Organizations must closely monitor dependencies, establish strong vulnerability management pipelines, and rapidly respond to disclosures as attackers increasingly target the software supply chain.
8 months ago
Kill Chain
MuddyWater's 2025 Global Espionage Campaign Targets 100+ Organizations
In late 2025, the Iranian nation-state threat group known as MuddyWater launched a sophisticated espionage campaign targeting over 100 organizations across the Middle East and North Africa (MENA) region. Leveraging a compromised email account as an entry point, the attackers distributed a custom backdoor named Phoenix to high-value government entities, enabling covert infiltration and sustained intelligence gathering. The operation involved methods designed to evade detection and facilitate ongoing access to sensitive data, underscoring the persistent risk posed by nation-state actors. This campaign highlights a continued escalation in advanced cyberespionage activities targeting governmental and critical infrastructure sectors. With threat actors increasingly exploiting social engineering and custom malware, organizations face intensified pressure to strengthen defenses and adhere to evolving security frameworks.
8 months ago
Kill Chain
Chinese APT Group Rapidly Exploits SharePoint Vulnerability in Major 2025 Telecom Breach
In July 2025, Chinese state-affiliated threat actors exploited the recently patched ToolShell vulnerability in Microsoft SharePoint to breach a major telecommunications company in the Middle East. This advanced persistent threat (APT) group swiftly leveraged the disclosed flaw to gain unauthorized access, rapidly launching attacks just weeks after the patch was released. Their campaign extended to government bodies in Africa and South America, as well as academic and technology institutions in the US, highlighting a rapid weaponization of public vulnerabilities. The attackers used sophisticated techniques for lateral movement, data exfiltration, and persistence within the affected networks, likely resulting in compromise of sensitive communications, operational disruption, and potential regulatory exposure for the victims. This incident demonstrates how APT actors quickly adapt to disclosed vulnerabilities and underscores the urgency for organizations to accelerate patching cycles and bolster east-west security controls. The event marks an increasing trend of state-sponsored groups targeting hybrid cloud environments and critical infrastructure via freshly disclosed exploits.
8 months ago
Kill Chain
How a Vulnerable AI Plugin in Figma MCP Opened the Door for Remote Code Attacks
In early 2025, a critical vulnerability (CVE-2025-53967) was discovered in a third-party connector integrating agentic AI capabilities with Figma’s Multi-Cloud Platform (MCP) server. This supply-chain flaw enabled remote code execution (RCE), allowing attackers to exploit the connection to infiltrate organizational environments using the affected plugin. Threat actors leveraged the unsanctioned plugin to gain unauthorized access to internal systems, potentially exposing sensitive design data, intellectual property, and user information. The compromise highlighted risks associated with insufficient east-west security controls, lack of zero trust segmentation, and inadequate traffic visibility, ultimately impacting business continuity and trust in the collaboration platform. This incident exemplifies the growing threat of supply-chain vulnerabilities targeting enterprise SaaS applications, amid increasing adoption of AI integrations. Organizations are re-evaluating their third-party risk, agentic AI governance, and internal segmentation postures as regulatory scrutiny and attacker sophistication intensify.
8 months ago
Kill Chain
China-Nexus Threat Actors Weaponize 'Nezha' RAT for Stealthy Campaigns in 2024
In early 2024, cybersecurity researchers uncovered a new campaign by China-nexus threat actors leveraging the open source "Nezha" remote access tool (RAT) to facilitate covert network access and persistence. Unlike traditional RMM (Remote Monitoring and Management) abuse, the adversaries deployed Nezha across multiple victim environments to enable encrypted traffic tunneling, conduct command-and-control operations, and bypass security controls. Targeting enterprises in various sectors, the attackers exploited weak access controls and east-west network traffic to establish lateral movement pathways, with the operation resulting in significant risks to sensitive data and business continuity. This incident highlights an accelerating trend in the use of open source, commodity tools by nation-state-aligned actors to evade detection and complicate attribution. The campaign reflects shifting threat dynamics, as attackers weaponize cloud-native techniques and legitimate tools to target organizations seeking to modernize security controls and comply with frameworks such as NIST and PCI DSS.
8 months ago
Kill Chain
LockBit, Qilin & DragonForce Forge Ransomware Cartel in 2024
In early 2024, notorious ransomware groups LockBit, Qilin, and DragonForce announced a strategic partnership, effectively forming a collaborative ransomware 'cartel.' This alliance has seen these gangs pooling resources, intelligence, and attack methods, shortly after the release of LockBit 5.0. By inviting other e-crime affiliates, they have expanded their operational reach and attack surface across multiple industries. The cartel model increases both the speed and sophistication of attacks, complicating defenders' response and extending the lifecycle of compromised environments for criminal profit. The incident is particularly relevant as it signals a new phase in ransomware operations, with threat actors adopting formal, syndicate-like coordination. It highlights escalating risks for enterprises, as collective intelligence sharing among attackers can quickly disrupt even mature security postures.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports