Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Critical Authentication Bypass Vulnerabilities Target WordPress SSO Integrations
In August 2026, threat actors began actively exploiting two critical authentication bypass vulnerabilities (CVE-2026-61979 and CVE-2026-15981) in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities allow attackers to forge SAML responses and gain administrator access by manipulating signature algorithms and exploiting OpenSSL verification errors. While patches were released in July 2026, inadequate disclosure for paid plugin editions left many sites vulnerable, leading to confirmed exploitation attempts across multiple IP addresses in Europe, Africa, and the United States. This incident highlights the growing trend of authentication bypass attacks targeting enterprise SSO integrations, particularly as organizations increasingly rely on SAML-based identity federation. The delayed patching response and incomplete vendor disclosure demonstrate critical gaps in third-party plugin security management that continue to plague WordPress ecosystems.
3 weeks ago
Kill Chain
SynkLoader Malware: The Multitool Threat Preparing Networks for Ransomware
SynkLoader, a sophisticated multilingual malware family first discovered in August 2026, represents an advanced threat that combines traditional malware techniques with novel social engineering tactics. The malware uses a combination of Python scripts, malicious DLLs, and a unique screen-locking phishing module called 'PhishLocker' to steal credentials and establish persistent access to corporate networks. Initial deployment vectors include convincing phishing emails impersonating Microsoft IT services, with attackers registering legitimate Microsoft 365 tenants and hosting malicious payloads on Azure infrastructure to increase credibility. This incident highlights the evolution of ransomware precursor attacks and initial access broker tactics, particularly the resurgence of screen-locking techniques for credential theft in modern SSO-integrated environments. The malware's system profiling capabilities specifically target network size assessment, suggesting preparation for ransomware deployment or sale to ransomware operators.
3 weeks ago
Kill Chain
ToxicPanda 2.0: When Banking Trojans Become Enterprise Identity Threats
ToxicPanda 2.0, an evolved Android banking Trojan, has expanded from targeting 16 financial institutions to 349 banking, e-wallet, and cryptocurrency applications across 16 countries. The malware leverages Android's Wireless Debugging and ADB capabilities to achieve shell-level access and persistent device compromise. Beyond traditional banking fraud, the Trojan now captures lock-screen credentials and establishes enterprise-grade persistence, creating risks for corporate identity systems and authentication frameworks. This incident highlights the maturation of mobile banking Trojans from simple financial theft tools to comprehensive enterprise threats capable of compromising corporate identity anchors and multi-factor authentication systems.
3 weeks ago
Kill Chain
UAT-10147 Cybercrime Group Weaponizes AI for Massive Server Attack Campaign
In August 2026, cybersecurity researchers disclosed details of UAT-10147, a Chinese-speaking cybercrime group leveraging AI-powered tools to conduct large-scale attacks against Windows and Linux web servers globally. The threat actor deployed artificial intelligence frameworks including PentestGPT, DeepAudit, and custom AI-generated Python scripts to automate vulnerability exploitation, reconnaissance, and payload generation across approximately 170,000 target URLs. UAT-10147 exploited known vulnerabilities to establish initial access, then deployed the cross-platform SPECTRE implant featuring advanced EDR bypass capabilities and Linux rootkit functionality, primarily targeting education, media, technology, and gaming sectors in Brazil, Bolivia, China, Canada, and Vietnam for SEO fraud and data theft operations. This incident represents a significant evolution in cybercrime operations, demonstrating how threat actors are integrating AI capabilities to scale attacks and enhance operational efficiency. The emergence of AI-driven offensive frameworks marks a critical shift in the threat landscape, enabling lower-skilled actors to conduct sophisticated attacks while highlighting the urgent need for organizations to strengthen their security postures against automated exploitation campaigns.
3 weeks ago
Kill Chain
The Outsized Shadow: How 5% of AI Users Create Enterprise-Wide Security Risks
Akamai's 2026 Enterprise AI Usage Risk Report reveals that the top 5% of enterprise AI power users interact with AI models at 12 times the rate of typical employees, creating disproportionate security risks through shadow AI adoption. These super-adopters are embedding unvetted AI tools into critical business operations, with 47% of enterprise AI conversations occurring through personal identities rather than corporate-managed accounts. The research highlights emerging attack vectors including vibe hacking, cursor jacking, and comet jacking that specifically target AI-enabled workflows and bypass traditional security controls. Organizations face significant data leakage risks as employees use corporate email addresses for personal AI subscriptions, with 14.4% of conversations occurring via freemium accounts that may use sensitive data for model training. The expanding landscape of AI browser extensions poses additional vulnerabilities, with 16.31% containing known CVE exploits compared to 10.8% of standard extensions. This research underscores the urgent need for enterprises to shift from preventing AI adoption to governing AI integration, as traditional security frameworks struggle to address the unique risks posed by autonomous AI agents operating within corporate environments.
3 weeks ago
Kill Chain
Operation QUICSILVER Exploits Government Trust: How QUICAgent Backdoor Evaded Detection
Operation QUICSILVER is a cyber espionage campaign targeting Myanmar's government and IT sectors, attributed to a China-nexus threat actor with moderate confidence. First observed in April 2026, the campaign uses graduation ceremony invitation lures written in Burmese to deliver QUICAgent, a custom Go-based backdoor. The attack chain begins with malicious VHD files containing Windows shortcuts that masquerade as PDF documents, ultimately deploying the backdoor which communicates over QUIC protocol on UDP port 443 for command and control operations. This incident highlights the continued targeting of Southeast Asian governments by suspected Chinese APT groups, representing the evolving use of legitimate protocols like QUIC to evade detection. The campaign demonstrates sophisticated social engineering tactics using culturally relevant lures and reflects the ongoing geopolitical tensions in the region through cyber means.
3 weeks ago
Kill Chain
WordlistLoader and SynkLoader Campaigns Exploit ClickFix and Microsoft Teams for Credential Theft
In August 2026, cybersecurity researchers identified two new malware families - WordlistLoader and SynkLoader - being used to deliver sophisticated payloads and potentially sell access to ransomware groups. WordlistLoader delivers Amatera Stealer through ClearFake campaigns using ClickFix social engineering techniques that trick victims into executing malicious commands disguised as CAPTCHA verification. The malware uses advanced evasion techniques including EtherHiding blockchain storage and WebDAV-based delivery, while SynkLoader is distributed via Microsoft Teams phishing campaigns to capture Windows credentials through fake lock screens. This incident highlights the evolving sophistication of infostealer campaigns that increasingly abuse legitimate infrastructure like CDNs, cloud storage, and collaboration platforms. The use of blockchain-based payload storage and hardware-breakpoint ETW bypasses demonstrates how threat actors are adapting to modern security controls, making traditional signature-based detection less effective.
3 weeks ago
Kill Chain
Windows Named Pipes Under Attack: Critical Privilege Escalation Vulnerability Analysis
Windows named pipes, a critical interprocess communication mechanism, have become a significant attack vector for privilege escalation vulnerabilities in 2024. Security researchers have identified multiple instances where attackers exploit weak access controls on named pipes to gain elevated privileges and move laterally within Windows environments. These attacks leverage improperly configured pipe permissions, allowing untrusted processes to communicate with privileged services, ultimately leading to system compromise. The exploitation typically involves identifying accessible named pipes, crafting malicious requests, and leveraging inadequate input validation to execute code with elevated privileges. This attack vector has gained prominence as organizations increasingly adopt zero-trust architectures and attackers shift focus to Windows-specific interprocess communication flaws. The rise in named pipe exploitation coincides with growing ransomware campaigns targeting enterprise Windows infrastructure and sophisticated APT groups leveraging these techniques for persistent access.
4 weeks ago
Kill Chain
ChainDrop npm Worm Exposes Critical Gaps in Software Supply Chain Security
In August 2026, the ChainDrop npm worm compromised over 400 JavaScript packages including popular libraries like keyv and cacheable-request through a sophisticated three-stage attack. The malware used malicious preinstall scripts to download obfuscated payloads, directly harvested credentials from GitHub Actions runner memory and local developer environments, then self-propagated using stolen npm and GitHub tokens. The attack established persistent backdoors in developer tools like VS Code while managing command-and-control infrastructure through Ethereum blockchain transactions, demonstrating unprecedented sophistication in supply chain attacks. This incident represents a critical escalation in supply chain warfare, where attackers now target the development infrastructure itself rather than just finished applications. With modern codebases containing 80-90% open-source components and developers routinely executing code from thousands of dependencies, the attack surface has expanded exponentially beyond traditional security perimeters.
4 weeks ago
Kill Chain
SickKids Hospital Data Breach Exposes Critical Third-Party Security Gaps
In December 2024, Toronto's Hospital for Sick Children (SickKids) disclosed a cybersecurity incident that exposed personal information of current and former employees and job applicants through a vulnerability in third-party software. The breach affected human resources data including names, addresses, phone numbers, and employment details, while clinical systems and patient records remained unaffected. SickKids immediately secured the compromised system, launched an investigation with cybersecurity experts, and began notifying affected individuals while implementing additional security measures. This incident highlights the growing trend of healthcare organizations facing data breaches through third-party vendor vulnerabilities, a critical concern as healthcare becomes increasingly digitized and regulatory scrutiny intensifies under frameworks like HIPAA and emerging privacy legislation.
1 month ago
Kill Chain
Novel FTP Banner Attack Delivers E4del and PINHOLE RATs in 2026 Campaign
In July 2026, threat actors developed a novel attack technique using FTP server banners as dead-drop resolvers to deliver two previously undocumented remote access trojans: E4del and PINHOLE. The campaign begins with phishing attacks distributing ZIP archives containing malicious LNK files that connect to compromised FTP servers to retrieve PowerShell commands embedded in server greeting banners. E4del masquerades as Discord using a digitally signed Electron application, while PINHOLE uses sophisticated evasion techniques including shellcode fluctuation and retrieval of C2 configurations from Pinterest and SurveyMonkey. SOCRadar researchers found this technique remained active through August 2026 with new infrastructure continuously deployed. This incident highlights the evolution of living-off-the-land techniques where attackers abuse legitimate protocols and services to evade detection, representing a broader trend toward more sophisticated command and control methods that bypass traditional security controls.
1 month ago
Kill Chain
TrueConf Server Supply Chain Attack: How Head Mare Exploited Critical CVE-2026-72529 Vulnerability
In August 2026, CISA ordered federal agencies to patch two critical TrueConf Server vulnerabilities (CVE-2026-72529 and CVE-2026-72530) within two weeks after adding them to the Known Exploited Vulnerabilities catalog. The flaws allow unauthenticated remote code execution and sandbox escape attacks on the self-hosted communications platform. The Head Mare hacktivist group has been actively exploiting these vulnerabilities since July 2026 to replace legitimate client installers with backdoor-laden versions, targeting Russian organizations across transportation, energy, and IT sectors. This incident follows previous TrueConf compromises, including Operation True Chaos linked to Chinese threat actors in April 2026. This attack highlights the growing trend of supply chain compromises targeting enterprise communication platforms, particularly as organizations increasingly rely on self-hosted solutions for secure corporate messaging and video conferencing amid rising cybersecurity concerns about cloud-based alternatives.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports