Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

3197 threat reports
Page 256 of 267

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Information Technology/IT Threat Reports

Showing 30613072 / 3197 reports
Cloud Misconfiguration: How Exposed Docker Daemons Fueled a 2024 DDoS Botnet
Impact· high

Cloud Misconfiguration: How Exposed Docker Daemons Fueled a 2024 DDoS Botnet

In early 2024, cybersecurity researchers uncovered a widespread campaign exploiting misconfigured Docker daemons in cloud environments. Attackers leveraged openly accessible Docker APIs to deploy malicious containers and enlist compromised servers into a large-scale DDoS (Distributed Denial of Service) botnet. Using legitimate, cloud-native tools made detection and remediation more challenging for security teams. The incident resulted in increased infrastructure costs, service disruptions, and heightened risk of lateral movement and data exfiltration within affected organizations. This attack is illustrative of a growing trend where adversaries abuse cloud-native technologies and misconfigurations to orchestrate large-scale, persistent threat activity. As organizations accelerate cloud adoption, gaps in cloud security posture and lack of network segmentation are creating new attack surfaces, stressing the need for enhanced visibility, zero trust controls, and real-time anomaly detection.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
GitHub’s NPM Supply Chain Attack Shows Urgent Need for Token Security in 2024
Impact· high

GitHub’s NPM Supply Chain Attack Shows Urgent Need for Token Security in 2024

In early 2024, GitHub took action to secure the NPM supply chain following a surge of sophisticated attacks exploiting weak authentication protocols and overly permissive access tokens. Adversaries—most notably those deploying the Shai-Hulud malware—compromised developer or maintainer accounts, then published malicious NPM packages, creating a vector for large-scale supply chain infection. The breaches risked both open-source and enterprise users, potentially allowing attackers access to downstream projects, credential leakage, and further lateral movement in corporate ecosystems. This incident is a critical reminder that software supply chains are increasingly targeted by cybercriminals using stolen credentials and token abuse. It highlights how even trusted platforms can expose organizations to risk when security controls such as MFA and token lifecycles are insufficiently enforced.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
How North Korean IT Workers Exposed the Next Insider Threat: Lessons from the 2025 Breach
Impact· high

How North Korean IT Workers Exposed the Next Insider Threat: Lessons from the 2025 Breach

In 2025, organizations across multiple industries discovered they had inadvertently hired North Korean IT workers—an emerging form of insider threat tied to sophisticated fraud and sanctions evasion tactics. These workers, embedded via remote roles and often identified through HR anomalies, funneled their earnings back to the North Korean regime, potentially exposing companies and their payment processors to strict sanctions liability. Initial detections stemmed from mismatched credentials or suspicious onboarding behaviors, with security and legal teams realizing the scope only after covert employment periods. Business impact included urgent compliance, forensic device recovery, and reputational risk, with legal exposure for both inadvertent payments and regulatory reporting lapses. This incident highlights an evolving threat landscape: state-sponsored employment fraud now overlaps with insider threat and compliance failures. Increased scrutiny from regulators, combined with ongoing geopolitical and cyber risk, is driving rapid change in how companies monitor, vet, and respond to workforce-related security incidents.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Russian Disinformation Group Rybar Orchestrates REST Media Election Campaign in Moldova
Impact· high

Russian Disinformation Group Rybar Orchestrates REST Media Election Campaign in Moldova

In June 2024, researchers revealed that REST Media, an online outlet targeting Moldova’s elections, is actually a front for the Russian disinformation group Rybar. Rybar, already sanctioned by the EU and wanted by the U.S., used REST Media to amplify anti-EU narratives and undermine the Party of Action and Solidarity, leveraging platforms like TikTok, Telegram, and X to achieve millions of views. Technical forensics linked REST Media’s online infrastructure and production workflows directly to Rybar, demonstrating operational overlap and deliberate efforts at obfuscation. The campaign exploited Moldova's fragmented media regulations, using cloaked registration accounts, privacy services, and anonymized hosting, making attribution complex while rapidly expanding its influence ahead of key elections. This incident exemplifies the growing sophistication of state-sponsored information operations, exploiting both technology and weak local controls. As hybrid threats, including coordinated disinformation and cyberattacks, continue to undermine democratic processes across Eastern Europe, organizations and governments face mounting regulatory, reputational, and operational risks from similar campaigns.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Brickstorm: The Next-Level Chinese APT Breach Impacting SaaS & Legal Sectors in 2025
Impact· medium

Brickstorm: The Next-Level Chinese APT Breach Impacting SaaS & Legal Sectors in 2025

In 2025, a highly sophisticated cyberespionage campaign attributed to a suspected Chinese advanced persistent threat (APT), utilizing malware later dubbed 'Brickstorm,' successfully infiltrated multiple US legal services and tech supply chain organizations. The attackers leveraged undisclosed zero-day vulnerabilities to gain initial access, maintain exceptional stealth with average dwell times of over 400 days, and move laterally into downstream customers. Their campaign targeted proprietary source code and sensitive trade/national security intelligence, making detection challenging through advanced cleanup techniques and non-overlapping infrastructure. This incident is particularly significant as it represents a new echelon of APT supply chain intrusions, echoing a rise in strategic, multi-year campaigns focusing on SaaS and cloud intermediaries. It highlights the growing need for robust east-west visibility, zero trust segmentation, and supply chain security amid evolving TTPs that routinely outpace traditional detection and response capabilities.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
NPM Package 'Fezbox' Abused QR Codes in Sophisticated 2025 Supply Chain Attack
Impact· medium

NPM Package 'Fezbox' Abused QR Codes in Sophisticated 2025 Supply Chain Attack

In September 2025, a malicious npm package named 'fezbox' was discovered utilizing QR codes as a novel delivery mechanism for cookie-stealing malware. Masquerading as a legitimate utility library on npmjs.com, the package was downloaded at least 327 times before its removal. The attack involved the package embedding a reversed URL to evade detection, which, once decoded, retrieved a dense QR code image containing obfuscated, second-stage payload code. The malware specifically targeted credentials by harvesting cookies and sending harvested credentials to a command-and-control server via HTTPS POST, only proceeding if valid username and password data were detected. This incident highlights the increasing creativity of supply-chain attackers, leveraging steganography within QR codes to bypass traditional static security tools. As QR codes become more commonplace and attackers innovate their use beyond social engineering, organizations must strengthen package vetting, threat detection, and response for open-source dependencies within their development ecosystems.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
GitHub npm 2025: Major Supply Chain Attacks Drive Aggressive Security Overhaul
Impact· high

GitHub npm 2025: Major Supply Chain Attacks Drive Aggressive Security Overhaul

In August and September 2025, GitHub's npm ecosystem suffered a series of coordinated supply chain attacks involving high-impact campaigns such as "s1ngularity," "GhostAction," and worm-style "Shai-Hulud." Threat actors infiltrated GitHub repositories and npm packages via credential compromise and weaknesses in access controls, ultimately compromising thousands of developer accounts and private repositories. These attacks resulted in theft of sensitive code and data, disruption across open-source ecosystems, and considerable remediation costs for affected organizations. In response, GitHub has announced the rapid rollout of mandatory two-factor authentication, granular access tokens, and removal of insecure authentication methods for npm publishing, aiming to prevent recurrence and empower developers to proactively enhance their security posture. This wave of supply chain attacks underscores the growing risk of software dependency manipulation at scale. The incident highlights the urgency of hardening access controls, enforcing stronger authentication, and shifting developer communities toward zero trust principles to counteract increasingly sophisticated threats facing software ecosystems.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
SolarWinds Hit by Yet Another Web Help Desk RCE Patch Bypass in 2025
Impact· low

SolarWinds Hit by Yet Another Web Help Desk RCE Patch Bypass in 2025

In September 2025, SolarWinds disclosed a critical security vulnerability (CVE-2025-26399) in its Web Help Desk (WHD) software, affecting version 12.8.7 and prior. This flaw—stemming from unsafe deserialization in the AjaxProxy component—permits unauthenticated attackers to achieve remote code execution (RCE) on affected servers. The issue represents a patch bypass for earlier vulnerabilities (CVE-2024-28986, CVE-2024-28988), demonstrating persistent weaknesses in the remediation process. While there are no documented exploitations as of publication, previous flaws in this component were added to CISA’s Known Exploited Vulnerabilities catalog, underscoring risk to organizations reliant on WHD for ticketing and IT asset management. This incident underscores the enduring challenge of patch bypasses, where subsequent hotfixes fail to fully resolve underlying flaws, leading to repeated exposures. Weaknesses in serialization logic and high-value IT management software are a favored target for attackers seeking lateral movement, privilege escalation, or supply chain compromise.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
BadIIS Malware Spreads via SEO Poisoning in Operation Rewrite
Impact· medium

BadIIS Malware Spreads via SEO Poisoning in Operation Rewrite

In September 2025, cybersecurity analysts uncovered a targeted campaign in East and Southeast Asia, particularly Vietnam, orchestrated by a Chinese-speaking threat actor dubbed CL-UNK-1037. Using a custom malware named BadIIS, the group launched "Operation Rewrite" by employing SEO poisoning to direct unsuspecting users to compromised websites. These sites served as a launch point for deploying BadIIS, which stealthily redirected traffic, established persistent web shells, and enabled lateral movement within infected infrastructure. The attacks leveraged trusted search results to compromise both organizations and individuals, aiming to establish long-term footholds and facilitate future malicious operations. This incident highlights the increasing sophistication of adversaries leveraging advanced social engineering and technical tactics like SEO poisoning. The blending of supply chain and web application compromise with persistent malware demonstrates evolving TTPs that bypass conventional detection, emphasizing the urgent need for multilayered security and continuous vigilance for all organizations.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ShadowV2 Botnet Weaponizes AWS Docker Misconfigurations for DDoS-for-Hire Attacks
Impact· high

ShadowV2 Botnet Weaponizes AWS Docker Misconfigurations for DDoS-for-Hire Attacks

In September 2025, researchers uncovered that the ShadowV2 botnet exploited misconfigured Docker containers deployed on Amazon Web Services (AWS) instances. Attackers leveraged these open containers to install Go-based malware, transforming vulnerable cloud servers into nodes for distributed denial-of-service (DDoS) attacks available for hire. The botnet operators were able to saturate targets’ networks and disrupt organizational operations using cloud-scale resources, highlighting a sophisticated abuse of both infrastructure-as-a-service offerings and container orchestration weaknesses. The campaign predominantly impacted organizations with unmanaged or lax security practices around containerized workloads and cloud network borders. This attack underscores the growing trend of threat actors targeting cloud misconfigurations and using them as platforms for broader cybercriminal infrastructure. The incident reflects both the increasing commoditization of DDoS-as-a-service and the urgency of securing cloud-native deployments against well-known attack patterns.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
GitHub Mandates 2FA and Short-Lived Tokens After npm Supply Chain Attack
Impact· medium

GitHub Mandates 2FA and Short-Lived Tokens After npm Supply Chain Attack

In September 2025, GitHub responded to a series of sophisticated supply chain attacks targeting the npm package ecosystem, most notably the Shai-Hulud compromise. Adversaries exploited weak authentication mechanisms and abused publishing tokens to inject self-replicating malware into widely used npm libraries. These malicious packages were automatically distributed downstream to thousands of unsuspecting development workflows, putting the integrity of software supply chains at risk. The attacks prompted GitHub to mandate two-factor authentication (2FA) for all npm publishers and to introduce short-lived authentication tokens to substantially reduce exposure to token theft. This incident underscores the growing trend of attackers targeting developer ecosystems as entry points for widespread compromise. The enhanced security controls by GitHub reflect a broader industry movement to harden software supply chains amid intensifying regulatory scrutiny and increasingly sophisticated attack methods.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SolarWinds 2025 RCE Flaw: What CVE-2025-26399 Means for Enterprise Security
Impact· low

SolarWinds 2025 RCE Flaw: What CVE-2025-26399 Means for Enterprise Security

In September 2025, SolarWinds disclosed a critical vulnerability (CVE-2025-26399, CVSS 9.8) in its Web Help Desk software, allowing remote code execution via deserialization of untrusted data. Attackers could exploit this flaw to execute arbitrary commands on affected systems, potentially leading to full compromise of customer environments. SolarWinds released urgent hotfixes to address the flaw after it was identified during routine security testing, emphasizing the risk to organizations running unpatched instances exposed to the internet. This incident underscores the persistent threat posed by software supply chain vulnerabilities and insecure coding practices in widely used IT management platforms. With high-profile supply chain attacks on the rise, rapid vulnerability disclosure and patching are now critical to minimizing both direct exploitation and regulatory exposure.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports