Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Red Hat Hit by GitLab Breach: Crimson Collective Steals Sensitive Consulting Data
In September 2025, Red Hat confirmed a security incident involving unauthorized access to a GitLab instance used by its consulting business. The threat group, Crimson Collective, claims to have exfiltrated nearly 570GB of compressed data from approximately 28,000 internal repositories, including around 800 Customer Engagement Reports (CERs) containing sensitive infrastructure details, authentication tokens, and database URIs. The attackers allegedly leveraged these credentials to potentially access downstream customer environments. Red Hat stated that no other company services or products were affected and initiated remediation steps shortly after detecting the breach. This incident highlights a growing trend of threat actors targeting source code management systems and leveraging poorly secured credentials to escalate access. It underscores the importance of robust secrets management, Zero Trust segmentation, and stringent access controls across cloud-native development environments.
8 months ago
Kill Chain
Red Hat's 2025 Consulting GitLab Breach: Crimson Collective Breaches Development Data
In October 2025, Red Hat, an IBM subsidiary, confirmed a data breach after the Crimson Collective threat group accessed and exfiltrated information from a self-managed GitLab Community Edition instance used for the company’s consulting projects. Attackers reportedly stole over 28,000 code repositories containing project specifications, code samples, internal communications, and potentially sensitive artifacts such as credentials and configuration data shared with consulting customers. The incident did not impact any other Red Hat services or products, and the company promptly launched an investigation, isolated the affected system, and notified relevant authorities and affected customers. This breach highlights growing risks associated with supply chain exposures, particularly when attackers target development and collaboration platforms where sensitive operational data may be stored. The incident is indicative of rising threats from organized cybercrime groups seeking intellectual property, credentials, and internal communications for downstream exploitation.
8 months ago
Kill Chain
Service Desk Social Engineering Attack Exposes Enterprise Vulnerabilities in 2025
In October 2025, organizations witnessed a sharp rise in successful social engineering attacks targeting enterprise service desks. Threat actors such as Scattered Spider exploited help desk processes by impersonating employees and manipulating support staff into resetting credentials or granting privileged access. These attacks bypassed traditional technical defenses by leveraging persuasive phone or chat conversations, resulting in significant business disruptions, data exposure, and potential operational outages. Notable events, such as those at MGM Resorts and Clorox, demonstrated the devastating financial and reputational impact of a single compromised support interaction, with recovery efforts spanning weeks and incurring nine-figure damages. This trend highlights the evolving threat landscape where the human element is now the primary entry vector. The urgency to adopt robust, workflow-driven identity verification, bypassing agent discretion, is underscored by regulatory scrutiny and mounting pressure to align with NIST and similar frameworks. Organizations must shift from relying on staff intuition to standardized, audited processes to mitigate these high-impact risks.
8 months ago
Kill Chain
Urgent: DrayTek Vigor Router RCE Vulnerability (CVE-2025-10547) Exposes SMB Networks
In October 2025, DrayTek disclosed a critical remote code execution vulnerability (CVE-2025-10547) impacting multiple Vigor router models, commonly used by small to medium businesses. The flaw allows unauthenticated attackers to remotely execute arbitrary code by sending specially crafted HTTP or HTTPS requests to the router's Web User Interface (WebUI). Triggered by an uninitialized stack value that facilitates arbitrary memory operations, the vulnerability could lead to full system compromise, crash, or remote takeover if exploited. DrayTek confirmed the issue following responsible disclosure and provided urgent firmware updates for affected devices. This incident exemplifies the rising risks posed by infrastructure vulnerabilities in network devices widely deployed in business environments. As attackers increasingly target edge and remote-management interfaces, proactive patch management has become paramount for organizations seeking to mitigate evolving threats and comply with stricter cybersecurity standards.
8 months ago
Kill Chain
Cl0p Ransomware Targets Oracle E-Business Suite: 2025 Executive Extortion Wave Uncovered
In October 2025, Google Mandiant and the Google Threat Intelligence Group reported a new extortion campaign targeting organizations using Oracle E-Business Suite. The campaign, believed to be orchestrated by the financially motivated Cl0p ransomware group, involved the distribution of extortion emails to C-level executives, claiming theft of sensitive business data. Attackers leveraged weaknesses in Oracle’s environment to exfiltrate confidential information, applying pressure for payment through credible threats of public disclosure and operational disruption. This incident highlights the evolving nature of ransomware tactics towards high-value enterprise applications and direct executive outreach. This case demonstrates the increasing trend of threat actors focusing on business-critical cloud and ERP platforms, not only for data theft but also to maximize ransom leverage. Sophisticated phishing, lateral movement, and exploitation of complex SaaS ecosystems make such attacks especially challenging to detect and contain.
8 months ago
Kill Chain
Multi-Vector Cyber Assault 2025: CarPlay, Cloud SQL, & iCloud Under Attack
In October 2025, coordinated threat actors launched a multi-vector attack campaign leveraging a critical CarPlay exploit, BYOVD (Bring Your Own Vulnerable Driver) tactics, SQL server compromise for covert command-and-control (C2), and targeted backdoor deployments against iCloud accounts. Attackers exploited unpatched vulnerabilities across automotive infotainment systems, enterprise firewalls, and cloud environments, enabling lateral movement and persistent access. The campaign demonstrated a sophisticated blend of supply chain targeting, abuse of trusted encryption protocols, malicious browser extension injection, and data exfiltration at scale. Impacted organizations faced substantial operational disruption, data loss, and the risk of regulatory penalties due to exposure of sensitive customer information and business-critical systems. This incident underscores the rapid evolution of attacker tradecraft, particularly in hybrid infrastructures and connected vehicles. The convergence of cloud, automotive, and critical business services in a single campaign highlights the increasing necessity for comprehensive, real-time security that spans east-west traffic, encrypted channels, and multi-cloud platforms.
8 months ago
Kill Chain
Confucius Launches Targeted Campaign Against Pakistan with WooperStealer and Anondoor Malware
In October 2025, the advanced persistent threat group Confucius launched a sophisticated phishing campaign targeting Pakistani government, defense, and critical industry sectors. Leveraging spear-phishing emails and malicious documents, the attackers deployed two custom malware strains—WooperStealer and Anondoor—to infiltrate victim environments. These tools enabled the exfiltration of sensitive information and lateral movement across internal networks, potentially exposing military secrets and compromising operational capabilities. The attack underlines the evolving TTPs used by regional espionage actors and demonstrates substantial gaps in defending east-west traffic and data exfiltration from secure environments. This incident highlights the growing prevalence of specialized information-stealing malware and the targeting of governmental infrastructure by geopolitical adversaries. It reflects broader trends in cyber-espionage and underscores heightened regulatory expectations for securing critical east-west and outbound traffic flows.
8 months ago
Kill Chain
Malicious PyPI Package 'soopsocks' Infects 2,653 Systems in Supply-Chain Breach
In October 2025, security researchers discovered a malicious Python package named "soopsocks" on the official Python Package Index (PyPI) repository, which was designed to masquerade as a legitimate SOCKS5 proxy tool while covertly delivering backdoor functionalities to affected Windows machines. Attackers used this supply-chain vector to reach unsuspecting developers and organizations, resulting in 2,653 downloads before the package was taken down by PyPI administrators. The malware enabled attackers to deploy additional payloads, potentially leading to data exfiltration and further system compromise across multiple organizations. This incident exemplifies the persistent risk of open-source ecosystem attacks, as threat actors increasingly target software supply chains and code repositories. It highlights the urgent need for organizations to harden software development pipelines and monitor third-party dependencies for tampering or malicious behavior.
8 months ago
Kill Chain
US Government 2025 Shutdown: Cyber Intel Sharing and Defense at Risk
In October 2025, a US federal government shutdown led to the temporary lapse of critically important cyber threat information sharing, coinciding with the expiration of the Cybersecurity Information Sharing Act of 2015. As Congressional inaction prevented reauthorization, legal protections for companies sharing threat data vanished, making organizations hesitant or unable to exchange intelligence. Mass furloughs affected over 65% of Cybersecurity & Infrastructure Security Agency (CISA) personnel, and many critical contractors were released, significantly slowing incident response, vulnerability patching, and cross-sector collaboration. The resulting operational gaps increased the risk of adversaries targeting federal networks and exploiting unpatched vulnerabilities. This incident highlights the risks posed by government policy disruptions and shrinking cyber workforce capacity, underscoring how national cybersecurity posture is deeply interconnected with policy stability. Its relevance is underscored by mounting state-backed cyber threats, increased phishing targeting vulnerable personnel, and heightened urgency for robust identity and incident response controls.
8 months ago
Kill Chain
ShinyHunters Target Salesforce: Social Engineering Breach Exposes SaaS Security Gaps
In early 2024, Google’s Mandiant research team identified a targeted campaign by the ShinyHunters threat group leveraging advanced social engineering techniques against Salesforce environments. The attackers—tracked as UNC6040—used convincing phishing lures and manipulation of Salesforce user credentials to gain unauthorized access to sensitive corporate data. By circumventing authentication measures and exploiting insufficient internal network segmentation and monitoring, ShinyHunters exfiltrated confidential business records, customer data, and intellectual property. The breach highlighted the group’s evolving tactics and the risks posed to organizations that rely on cloud SaaS platforms like Salesforce for critical operations. This incident underscores the increasing sophistication of social engineering attacks, with criminals exploiting both technical and human vulnerabilities in cloud platforms. As SaaS adoption accelerates, similar threats are expected to rise, placing renewed emphasis on identity security, comprehensive threat detection, and adherence to zero trust principles.
8 months ago
Kill Chain
Confucius APT Evolves: Python Backdoors Target Pakistan in 2025 Cyber-Espionage Escalation
In 2025, the Confucius advanced persistent threat (APT) group intensified its cyber-espionage operations targeting Pakistani government, military, and critical infrastructure organizations. Originally operating with infostealers like WooperStealer, Confucius shifted to deploying highly-obfuscated, Python-based surveillance backdoors such as AnonDoor. Attackers exploited spear phishing using spoofed authority emails and action-driven malicious attachments, which initiated complex infection chains via DLL sideloading, LNK files, and PowerShell loaders. This evolution improved persistence and evasiveness, resulting in increased risks to sensitive data and operational security for targeted institutions in Pakistan. The incident reflects a broader trend in state-sponsored cyberthreats: threat actors are adopting modular backdoors, diversifying attack vectors, and leveraging scripting languages to bypass security controls. Such agile TTPs (tactics, techniques, and procedures) heighten challenges for defenders, underscoring the urgent need for real-time threat detection and robust network segmentation.
8 months ago
Kill Chain
Red Hat's 2024 GitLab Breach: Supply Chain Risks and the Rise of Crimson Collective
In September 2024, Red Hat disclosed a breach of its self-managed GitLab instance used by its Consulting services, following claims by the Crimson Collective ransomware group of compromising over 28,000 private repositories. The attackers allegedly exfiltrated software source code and Customer Engagement Reports (CERs), which may contain network details, configuration data, and sensitive credentials. Red Hat initiated remediation steps and assured that its primary software supply chain and core products were not impacted. Belgian authorities warned of potential high-risk exposure for organizations with ties to Red Hat Consulting. This incident underscores a growing trend of supply chain attacks targeting private code repositories and related assets, especially in environments where critical infrastructure and third-party integrations are involved. As ransomware groups pivot to extortion and supply chain vectors, organizations must urgently review their repository and credential management, even on self-managed systems.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports