Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
VS Code Extension Access Token Leak: A 2025 Supply Chain Wake-Up Call
In October 2025, a major supply chain risk was exposed when over 100 Visual Studio Code (VS Code) extensions were found to have leaked access tokens, allowing threat actors to publish malicious updates to widely used extensions. Attackers who obtained these tokens could have distributed compromised software versions to millions of developers globally, undermining trust in open-source ecosystems and introducing the risk of code tampering, credential theft, or insertion of backdoors into organizational environments. The vulnerability lay in the mishandling and inadvertent leakage of personal access tokens (PATs) for both the VSCode Marketplace and Open VSX, giving adversaries an insidious update path into developer workstations and CI/CD pipelines. This incident highlights the increasing frequency and sophistication of supply chain attacks targeting developer tools and open-source dependencies. As the software landscape grows more interconnected, private access tokens and code-signing credentials now represent high-value targets, requiring robust security controls and zero trust validation across the development lifecycle.
8 months ago
Kill Chain
Chinese APT 'Jewelbug' Compromises Russian IT Provider in Stealthy 2025 Attack
In early 2025, the Chinese state-linked threat group known as 'Jewelbug' stealthily infiltrated a prominent Russian IT service provider over a five-month period, according to findings from Symantec. The attackers gained initial access in January, likely leveraging supply chain or credential compromise vectors, and subsequently maintained persistent, undetected presence until May. Jewelbug is known for sophisticated tactics, including advanced lateral movement, encrypted traffic, and covert exfiltration. As a result, sensitive data and core IT systems within the provider’s infrastructure were at risk, potentially impacting downstream Russian clients who relied on its managed services. This incident highlights the expanding global reach of advanced persistent threats (APTs), with Jewelbug moving beyond historical targets in Southeast Asia and South America to now conduct espionage in Russia. The breach demonstrates increasing sophistication in supply chain and east-west attack techniques, underscoring urgent need for robust lateral movement prevention, segmentation, and cloud visibility controls.
8 months ago
Kill Chain
Russian Hackers Evolve Malware via 'I am not a robot' Captchas in 2024
In early 2024, the Russian state-sponsored group Star Blizzard intensified its cyber-espionage operations, leveraging advanced malware strains (NoRobot, MaybeRobot) delivered via deceptive "I am not a robot" CAPTCHA prompts in targeted ClickFix phishing campaigns. Attackers executed multi-stage infection chains, enticing victims to enable malicious browser extensions or download trojanized payloads under the guise of legitimate productivity fixes. These campaigns enabled persistent access to sensitive organizational data, posed risks of lateral movement within networks, and facilitated exfiltration of proprietary intelligence. This incident underscores a concerning trend: the use of dynamic, highly-adaptive social engineering and malware delivery methods by state-backed actors. As similar tactics are increasingly observed across sectors, organizations must harden entry-point protections and improve internal visibility to counter evolving nation-state threats.
8 months ago
Kill Chain
Inside the LinkPro Linux Rootkit: eBPF Backdoors AWS Cloud in 2025
In October 2025, security researchers from Synacktiv revealed the discovery of LinkPro, a sophisticated GNU/Linux rootkit targeting AWS-hosted infrastructure. The attackers leveraged advanced eBPF techniques to install two modules: one for stealth, allowing the malware to evade detection, and another granting remote access via specially crafted TCP packets (magic packets). This backdoor enabled threat actors to persist undetected, hide their presence, and maintain control of compromised systems in cloud environments, posing severe risks to the underlying business operations and data confidentiality of affected organizations. This incident highlights the escalating use of kernel-level and cloud-specific attack techniques, exploiting eBPF to bypass traditional defenses. The campaign underscores a growing trend of attackers utilizing cloud-native technologies to achieve stealth and persistence, raising urgent concerns for CISOs overseeing both public cloud and Linux workloads.
8 months ago
Kill Chain
Cursor & Windsurf IDEs Hit by 94+ Chromium Vulnerabilities – Supply-Chain Exposure in 2024
In early 2024, security researchers identified that the latest releases of the Cursor and Windsurf integrated development environments (IDEs) were vulnerable to over 94 known and patched security vulnerabilities within the embedded Chromium browser and V8 JavaScript engine. These n-day vulnerabilities exist because the IDEs relied on outdated Chromium builds, exposing users to a range of critical issues, including remote code execution, privilege escalation, and data leakage. The supply-chain nature of the incident means development teams using these IDEs could inadvertently introduce risk across their entire workflow and environments. This incident underscores the persistent risk posed by vulnerable software dependencies and highlights an urgent need for improved supply-chain security. With attackers increasingly targeting development tools for initial access or lateral movement, organizations must re-evaluate their patch management, vendor risk assessments, and layered network protections.
8 months ago
Kill Chain
Critical Command Injection Flaw Found in TP-Link Omada Gateways (2024)
In June 2024, TP-Link disclosed a critical security vulnerability (CVE-2024-5035) affecting several Omada gateway models. The flaw is a pre-authentication operating system command injection that could allow remote, unauthenticated attackers to execute arbitrary commands on vulnerable devices, compromising the integrity and availability of network infrastructure. TP-Link quickly released firmware patches, urging customers to update immediately. This exposure heightened the risk of unauthorized access to internal networks, potentially leading to data breaches, lateral movement, or infrastructure disruption for organizations reliant on impacted Omada devices. The incident underscores an ongoing trend of targeting network infrastructure via supply chain or firmware vulnerabilities, which have become increasingly prevalent as attackers seek to exploit core networking hardware. This highlights the need for vigilant patch management and segmentation in defense strategies, as well as resilience against emerging firmware and gateway attacks.
8 months ago
Kill Chain
North Korean Hackers Employ EtherHiding for Unprecedented Cryptocurrency Heist
In October 2025, threat group UNC5342—attributed to North Korea—executed an advanced cryptocurrency theft operation by leveraging the novel EtherHiding technique. Attackers embedded malicious code within blockchain smart contracts to distribute malware, evading conventional detection mechanisms. Google Threat Intelligence Group (GTIG) identified this as the first known use of EtherHiding by a state-sponsored actor, resulting in the covert compromise of multiple cryptocurrency platforms and significant asset loss. The incident underscores an evolving trend: nation-state actors are adopting increasingly sophisticated blockchain-based attack methods. With rising blockchain adoption, such TTPs present serious risks for organizations involved in digital assets, regulation, and financial technology.
8 months ago
Kill Chain
Microsoft Revokes Fraudulent Certificates Exploited by Rhysida Ransomware in 2025 Campaign
In June 2025, Microsoft discovered and responded to a sophisticated campaign in which a threat actor known as Vanilla Tempest (also tracked as Storm-0785) fraudulently issued over 200 code-signing certificates. These certificates were leveraged to make malicious files appear legitimate, facilitating the distribution of a fake Microsoft Teams installer that ultimately delivered the Oyster backdoor and deployed Rhysida ransomware across targeted environments. Microsoft quickly moved to revoke all compromised certificates to mitigate the risk and prevent further exploitation by the attackers. The breach highlights the growing sophistication of ransomware groups in leveraging trusted supply chain components for malware delivery. This incident underscores the heightened threat landscape in which adversaries exploit trusted relationships and digital certificates to evade security controls. It also signals an increasing trend of ransomware utilizing living-off-the-land and supply chain abuse techniques, compounding challenges for organizations striving to maintain software integrity and regulatory compliance.
8 months ago
Kill Chain
Vidar Stealer 2.0: Infostealer Adopts Multi-threaded Data Theft & Evasion in 2024
In early 2024, the operators behind Vidar Stealer—a notorious malware-as-a-service (MaaS)—released version 2.0, introducing significant upgrades such as multi-threaded data theft and improved evasion techniques. Threat actors are leveraging this new version to accelerate theft of sensitive information, targeting both personal and enterprise environments by deploying the stealer via malicious emails, cracked software, and malvertising. The enhanced capabilities enable Vidar Stealer to exfiltrate data more efficiently and undermine traditional security controls, heightening the risks for organizations that rely on endpoint- or signature-based defenses. This evolution signals a broader trend in infostealer threats, where malware authors are quickly integrating advanced techniques for bypassing detection and maximizing operational speed. Enterprises should expect an uptick in automated, distribution-scale credential and data theft campaigns driven by increasingly sophisticated MaaS offerings like Vidar 2.0.
8 months ago
Kill Chain
Researchers Reveal Critical WatchGuard VPN Vulnerability Enabling Device Takeover
In October 2025, cybersecurity researchers disclosed a critical vulnerability (CVE-2025-9242, CVSS 9.3) in WatchGuard Fireware devices affecting OS versions 11.10.2 to 11.12.4_Update1 and 12.0. The flaw involved an out-of-bounds write in the VPN functionality, allowing unauthenticated remote attackers to execute arbitrary code. Attackers exploiting this bug could gain full control of affected appliances, potentially intercepting encrypted traffic, moving laterally within networks, or establishing persistent access. Patches were released urgently, but some organizations may remain exposed due to delayed patching or legacy hardware. This incident highlights ongoing attacker targeting of perimeter and VPN infrastructure. With rising reliance on remote access, vulnerabilities in widely deployed appliances continue to provide high-value entry vectors. Timely patching and layered network defenses are essential in light of increased regulatory scrutiny and sophisticated threat landscapes.
8 months ago
Kill Chain
North Korean APT Combines BeaverTail and OtterCookie in Major 2025 JS Malware Campaign
In October 2025, a North Korean state-sponsored hacking group with ties to the Contagious Interview campaign was observed integrating features from its BeaverTail and OtterCookie malware into a sophisticated new JavaScript-based attack. Security research from Cisco Talos revealed the group’s evolving approach: combining credential theft, evasion, and persistent access in targeted spear-phishing campaigns directed at global enterprises, which enabled stealthy lateral movement and prolonged network compromise. Analysis showed that this fusion malware increased the attackers’ efficiency and resilience, leading to significant data exposure risks and operational disruptions for affected organizations. This incident highlights a broader trend—North Korean APTs are rapidly developing multipurpose malware platforms capable of bypassing traditional defenses. The blending of well-established tools signals a new level of technical maturity, raising the urgency for organizations to shore up east-west traffic security, zero trust segmentation, and advanced threat detection controls.
8 months ago
Kill Chain
2025’s Phishing Evolution: QR-PDFs, Calendar Attacks, and MFA Relay
In early 2025, organizations faced a surge of advanced phishing attacks leveraging revitalized and sophisticated tactics. Threat actors used emails with password-protected PDF attachments containing QR codes, evading traditional email security solutions and enticing users to open links via less-protected mobile devices. Calendar invitations embedding phishing links, voice message lures with CAPTCHA-guarded landing pages, and high-fidelity credential harvesting forms that relayed real MFA challenges in real-time all contributed to more successful credential thefts. These approaches eroded user trust in standard verification mechanisms and bypassed established detection methods, leading to increased account compromise risks and potential business disruptions. This shift signals a broader trend of attackers reusing and refining both traditional and novel phishing techniques, with rising use of multi-step evasion and identity-focused targeting. Enterprise email, cloud collaboration services, and end user authentication have become critical targets, driving new regulatory scrutiny and requirements for layered, adaptive defenses.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports