Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

3197 threat reports
Page 248 of 267

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Information Technology/IT Threat Reports

Showing 29652976 / 3197 reports
2025 Fortra GoAnywhere Breach: Medusa Ransomware Leverages Zero-Day and Key Compromise
Impact· high

2025 Fortra GoAnywhere Breach: Medusa Ransomware Leverages Zero-Day and Key Compromise

In early 2025, Medusa ransomware operators—tracked as Storm-1175—successfully exploited a critical vulnerability (CVE-2025-10035) in the Fortra GoAnywhere Managed File Transfer (MFT) platform. The attack required access to a private key, indicating either an advanced intrusion or insider compromise. Once inside, the threat actors moved laterally to deploy ransomware payloads, seizing sensitive business data and disrupting managed file transfers for impacted organizations. Multiple enterprises suffered data theft, business downtime, and reputational damage as a result. This incident underscores an ongoing trend of targeting supply chain platforms and MFT products with ransomware via sophisticated access methods. As ransomware groups become more resourceful in exploiting zero-days and leveraging stolen keys, organizations must prioritize proactive threat detection, timely patching, and tighter access controls to counter these evolving tactics.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Breaking: 'RediShell' RCE Vulnerability Hits 300,000+ Redis Cloud Servers
Impact· medium

Breaking: 'RediShell' RCE Vulnerability Hits 300,000+ Redis Cloud Servers

In early June 2024, security experts identified a critical remote code execution (RCE) vulnerability, dubbed 'RediShell,' impacting Redis servers worldwide. This 13-year-old flaw (CVSS 10.0) enables unauthenticated attackers to execute arbitrary commands and fully compromise exposed hosts. More than 300,000 unpatched Redis instances were found publicly accessible, largely in cloud and hybrid environments, risking complete data loss, ransomware deployment, or lateral movement within enterprise networks. Attackers rapidly weaponized the exploit to automate mass scans and attacks, prompting emergency advisories and patch releases from Redis maintainers and cloud providers. This incident underscores the ongoing risks posed by old vulnerabilities in widely deployed open-source software. The scale and speed of RediShell exploitation demonstrate attackers’ preference for high-impact, low-effort weaknesses in cloud infrastructure, forcing organizations to prioritize patching, network segmentation, and modern Zero Trust models.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
XWorm RAT Re-emerges in 2025: Ransomware & Plugins Drive Global Malware Campaigns
Impact· high

XWorm RAT Re-emerges in 2025: Ransomware & Plugins Drive Global Malware Campaigns

In mid-2025, security researchers observed the resurgence of XWorm, a modular remote access trojan (RAT) that now features extensive plugin support and an integrated ransomware module. Originally developed by XCoder and abandoned in 2024, the latest XWorm variants (v6.0–6.5) have been widely adopted by multiple threat actors and distributed via phishing campaigns using malicious scripts and document attachments. Capable of data theft, remote desktop takeover, and file encryption, XWorm leverages over 35 plugins, including modules for browser data harvesting, keystroke logging, shell access, and ransomware deployment. The malware's rapid proliferation has led to thousands of infections globally, with major activity detected in Russia, the US, India, Ukraine, and Turkey. The reappearance of XWorm, now available on dark web forums and grouped with capabilities like AI-themed lures and social engineering, demonstrates an alarming trend: readily available commodity malware is increasingly sophisticated and multifaceted. This case underscores rising risks from plug-and-play cybercrime kits and reinforces the critical need for continuous defense, layered security, and advanced threat monitoring.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Redis 2025 Critical RCE: How CVE-2025-49844 Threatens Cloud Data Security
Impact· medium

Redis 2025 Critical RCE: How CVE-2025-49844 Threatens Cloud Data Security

In October 2025, Redis disclosed a critical remote code execution vulnerability (CVE-2025-49844), stemming from a 13-year-old use-after-free bug in the Lua interpreter, impacting all major Redis releases. Exploitable via authenticated Lua scripts—enabled by default—the flaw allows attackers to escape the script sandbox, execute arbitrary code, establish persistent access via reverse shell, and ultimately gain full control of the host system. Security researchers revealed that over 330,000 Redis instances were exposed online, some requiring no authentication, enabling credential theft, data exfiltration, lateral movement, and malware deployment at scale. This incident highlights persistent risks from legacy code, cloud-exposed databases, and default insecure configurations, accelerating regulatory and industry emphasis on proactive patching, network segmentation, and least privilege controls. The vulnerability’s sheer scope and ease of exploitation underline the urgency for organizations to remediate and harden public-facing infrastructure.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Zeroday Cloud 2025: Cloud and AI Security in the Spotlight
Impact· medium

Zeroday Cloud 2025: Cloud and AI Security in the Spotlight

In December 2025, the inaugural Zeroday Cloud hacking contest was announced, offering $4.5 million in bug bounties for security researchers able to compromise open-source cloud and AI technologies. Organized by cloud security firm Wiz with major cloud providers Google Cloud, AWS, and Microsoft, the event is set to coincide with Black Hat Europe in London. Categories span AI platforms, Kubernetes, virtualization, web servers, databases, and DevOps tools, with cash rewards reaching as high as $300,000 for critical exploits that achieve remote code execution or full container escapes. The competition’s rules encourage demonstration of high-impact vulnerabilities in default configurations, drawing attention from the research and bug bounty community worldwide. This contest stands out as the largest ever focused exclusively on cloud-native and AI environments. It highlights industry-wide concerns about tooling security as organizations accelerate public cloud and AI adoption. The timing reflects both the proliferation of adversaries targeting these attack surfaces and coordinated industry efforts to crowdsource vulnerability discovery in critical platforms.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft 2025: Storm-1175 Exploits GoAnywhere Zero-Day for Devastating Ransomware Attacks
Impact· high

Microsoft 2025: Storm-1175 Exploits GoAnywhere Zero-Day for Devastating Ransomware Attacks

In September 2025, a cybercrime group tracked as Storm-1175 exploited a critical zero-day deserialization vulnerability (CVE-2025-10035) in Fortra's GoAnywhere Managed File Transfer (MFT) solution. The attackers gained initial access by remotely targeting vulnerable MFT instances and leveraged remote monitoring tools (SimpleHelp, MeshAgent) for persistence. Subsequently, they conducted network reconnaissance with Netscan, moved laterally using Microsoft RDP, exfiltrated sensitive data with Rclone, and ultimately deployed Medusa ransomware payloads to encrypt files. This campaign affected multiple organizations, exposing unpatched systems to significant operational risk and data loss. The incident highlights a continued surge in ransomware operations leveraging zero-day vulnerabilities in widely used enterprise software. Attackers are increasingly exploiting supply chain and infrastructure components to maximize impact, driving regulatory scrutiny and accelerating the need for robust patch management and segmentation practices.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Kaspersky SIEM Uncovers ToddyCat DLL Hijacking Attacks in 2024
Impact· medium

Kaspersky SIEM Uncovers ToddyCat DLL Hijacking Attacks in 2024

In early 2024, Kaspersky detected several advanced persistent threat (APT) incidents during pilot testing of their machine-learning-based DLL-hijacking detection module within their SIEM platform. Notably, the ToddyCat APT group exploited a SharePoint vulnerability (CVE-2021-27076) to gain initial access, then leveraged DLL sideloading to execute Cobalt Strike implants using masqueraded Windows system libraries. Other real-world incidents uncovered included infostealer malware posing as a policy manager, and a malicious loader activated through a USB drive, all utilizing DLL hijacking for code execution and persistence. Kaspersky’s detection tool enabled rapid identification and response, preventing further compromise and data exfiltration. This case highlights the growing sophistication of DLL hijacking techniques in APT operations and the increasing use of AI-driven security products to detect lateral movement and stealthy intrusion behaviors. The incidents underscore the need for robust behavioral analytics and real-time anomaly detection as threat actors increasingly target supply chains and trusted binaries to bypass traditional security defenses.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How a Zimbra Zero-Day Breach Exposed the Brazilian Military: Lessons for Secure Collaboration
Impact· low

How a Zimbra Zero-Day Breach Exposed the Brazilian Military: Lessons for Secure Collaboration

In early 2025, a zero-day vulnerability in Zimbra Collaboration (CVE-2025-27915), a widely used email and collaboration platform, was exploited to target the Brazilian military. Attackers used malicious ICS calendar files containing unsanitized HTML and JavaScript to trigger stored cross-site scripting (XSS) within Zimbra's Classic Web Client. This entry vector effectively bypassed standard security controls and provided attackers the ability to execute malicious code in users' browsers, potentially enabling credential theft, session hijacking, and further movement inside the organization before the vulnerability was patched. The campaign underscores how attackers are increasingly leveraging vulnerabilities in collaborative and communication tools to gain a foothold in targeted organizations and critical infrastructure. This breach is particularly relevant today given the ongoing surge in zero-day exploits against widely deployed business applications, especially in sectors such as government and defense. The rapid weaponization of collaboration-tool vulnerabilities highlights the need for timely patch management, robust segmentation, and vigilant threat detection to combat sophisticated phishing and XSS-based initial access.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Chinese Cybercrime Group Exploits IIS Servers in Global SEO & Credential Theft Scheme
Impact· medium

Chinese Cybercrime Group Exploits IIS Servers in Global SEO & Credential Theft Scheme

In October 2025, cybersecurity analysts uncovered a campaign orchestrated by a Chinese-speaking cybercrime group known as UAT-8099. The group exploited vulnerabilities in Microsoft Internet Information Services (IIS) servers, primarily targeting organizations across India and Thailand. Attackers deployed malicious scripts and leveraged the compromised servers for global search engine optimization (SEO) fraud while systematically stealing high-value credentials, configuration files, and certificate data. This sophisticated operation impacted business continuity, undermined trust, and exposed sensitive enterprise assets to further misuse. This breach exemplifies the growing threat from well-resourced cybercrime rings using server-side exploits to conduct financially motivated attacks. Similar credential theft and SEO manipulation TTPs are increasingly prevalent worldwide, highlighting an urgent need for enhanced internal server security, threat detection, and compliance with modern data protection standards.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Oracle’s 2025 Mega Breach: 0-Day, BitLocker Bypass & VMScape Trigger Industry Wake-Up
Impact· medium

Oracle’s 2025 Mega Breach: 0-Day, BitLocker Bypass & VMScape Trigger Industry Wake-Up

In October 2025, Oracle faced a significant security incident that exposed critical new 0-day vulnerabilities, impacting key platforms via exploits including a BitLocker bypass, the 'VMScape' hypervisor escape, and a fast-spreading WhatsApp worm. Threat actors leveraged multiple sophisticated attack vectors, targeting both enterprise infrastructure and end-user devices. The campaign enabled unauthorized lateral movement, data exfiltration, and disruption of cloud workloads, with global enterprises and managed service providers feeling downstream impact as security researchers identified widespread exploitation across hybrid and multicloud environments. These multi-pronged intrusions forced urgent mitigation efforts, including rapid patching, segmentation, and new traffic visibility controls to stem active attacks. The incident underscores escalating attacker sophistication in blending 0-day exploitation, social engineering, and cloud platform abuse. As threat campaigns increasingly combine lateral spread mechanisms with supply chain risks and targeted ransomware, it highlights the necessity of modern Zero Trust frameworks, advanced detection, and continuous security governance for organizations operating at cloud scale.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Self-Propagating Malware Targets WhatsApp Users in Brazil with Financial Fraud Infostealer
Impact· medium

Self-Propagating Malware Targets WhatsApp Users in Brazil with Financial Fraud Infostealer

In early June 2024, an infostealer campaign dubbed Water Saci aggressively targeted WhatsApp users in Brazil using self-propagating malware named Sorvepotel. Attackers leveraged compromised accounts to automatically distribute malicious links via WhatsApp messages, luring recipients to execute malware payloads. Once installed, Sorvepotel exfiltrates credentials and tracks browser activities, enabling threat actors to target and defraud regional financial institutions. The infection chain’s ability to rapidly spread through trusted social contacts increased both the velocity and scale of impact, compromising both individual and enterprise devices in a short time frame. The Water Saci operation highlights the evolution of credential-stealing malware adopting worm-like features to maximize reach. With messaging platforms remaining core to business and personal communications, this incident underscores the urgency of intercepting lateral movement, especially as attackers blend social engineering with advanced propagation and data theft techniques.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Salesloft Drift Supply Chain Breach: How Okta and Zscaler Responded in 2023
Impact· high

Salesloft Drift Supply Chain Breach: How Okta and Zscaler Responded in 2023

In August 2023, a sophisticated supply chain attack targeting Salesloft and Drift exposed the vulnerabilities of OAuth token management in SaaS integrations. Threat actor group UNC6395 compromised Salesloft's GitHub and later leveraged compromised OAuth tokens from the Drift platform, affecting over 700 customers—including security leaders Okta and Zscaler. While Okta’s proactive use of IP restrictions blocked malicious API requests and prevented data loss, Zscaler experienced a significant breach, exposing both customer and internal data. The campaign unfolded rapidly, relying on automated scripts for widespread data extraction via legitimate channels before defenses were activated. This incident underscores the growing pipeline threat of API- and token-driven attacks across integrated SaaS ecosystems. As organizations increasingly rely on third-party applications, traditional security mechanisms and risk due diligence are proving insufficient against lateral supply-chain intrusion tactics and the automated exploitation of tokenized access.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports