Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Panama Ministry of Economy Breach: INC Ransomware’s 2025 Attack Explained
In September 2025, Panama's Ministry of Economy and Finance (MEF) announced a cyber incident after the INC Ransomware gang claimed liability for a breach. The ministry reported detecting malicious software on one workstation, activating security protocols, and asserting no core systems or sensitive data were affected. However, INC Ransom posted evidence and claimed to have exfiltrated over 1.5 TB of emails, financial, and budgeting documents from MEF. The threat actor listed MEF on its leak site and began releasing data samples, raising concerns about the extent of exposure. This incident underscores the continued evolution and impact of ransomware-as-a-service (RaaS) operations targeting government and finance sectors. With INC Ransom’s repeated high-profile attacks, the breach reflects the growing risk of sophisticated data theft and extortion campaigns confronting public sector organizations globally.
8 months ago
Kill Chain
2025 Cursor AI Code Editor Vulnerability: Supply-Chain Risk via Malicious Repositories
In September 2025, a security flaw was disclosed affecting Cursor, an AI-powered code editor, that allowed silent code execution when users opened repositories embedded with malicious payloads. The vulnerability stemmed from a default-disabled security setting, letting attackers execute arbitrary code on victim machines under their own user privileges. Security researchers highlighted the risk of potential supply-chain attacks, as any developer opening a tampered repository could unwittingly trigger the exploit, potentially leading to credential theft, system compromise, or further lateral movement within organizational networks. The impact was amplified by Cursor's AI-driven capabilities and its popularity in modern development environments. This incident spotlights the growing risks at the intersection of AI-driven tools and software supply chains. With more organizations relying on smart code editors and automated workflows, attackers are increasing their focus on weaknesses in tool defaults and developer behaviors, driving regulatory concern and heightening the urgency for robust code execution safeguards.
8 months ago
Kill Chain
Cryptojacking Surge: TOR-Based Attack Exploits Docker API Misconfigurations in 2025
In July 2025, cybersecurity researchers identified a new wave of cryptojacking attacks leveraging the TOR network to hide command-and-control infrastructure. Attackers targeted internet-exposed and misconfigured Docker APIs, deploying malicious containers that mined cryptocurrency on compromised infrastructures. This campaign, tracked by Akamai and initially reported by Trend Micro in June 2025, showed sophisticated behaviors including blocking rival threat actors and securing persistence, which increased the impact on affected organizations by silently draining cloud computing resources and escalating operational costs. This incident highlights the growing convergence of container security risks and anonymizing networks like TOR, reflecting a broader trend of attackers shifting toward stealthy, infrastructure-focused exploits. With cloud-native workloads and container orchestration becoming standard, organizations face urgent regulatory and operational pressure to harden APIs and improve cloud security hygiene.
8 months ago
Kill Chain
How Salt Typhoon & Volt Typhoon Forced a U.S. Critical Infrastructure Cybersecurity Rethink
Between 2021 and 2023, advanced Chinese threat actors known as Salt Typhoon and Volt Typhoon conducted highly covert cyber intrusions targeting U.S. telecommunications networks and critical infrastructure sectors. These groups utilized advanced tactics such as "living off the land," abusing legitimate administrative tools, and blending into east-west network traffic, making detection and remediation extremely challenging for defenders. Their primary objectives ranged from long-term espionage and persistent access to prepositioning for potential disruptive attacks in the event of geopolitical conflict. The hacks led federal agencies like the FBI and CISA to revise investigative methods, shifting to assume attackers may already be inside the network and forcing collaboration to uncover subtle anomalies rather than clear indicators. This incident is indicative of a broader industry trend: state-backed actors increasingly focus on stealth, cloud environments, and edge devices, targeting managed service providers and exploiting blind spots in monitoring. Their evolving tactics closely align with growing regulatory and CISO concern for stronger east-west visibility, zero trust controls, and continuous threat hunting across hybrid cloud infrastructure.
8 months ago
Kill Chain
npm Supply-Chain Attack Exposes Open-Source Dependencies: 2024 Incident Analysis
In June 2024, a supply-chain attack struck the widely used npm ecosystem when a threat actor compromised developer Josh Junon's account via a phishing-enabled two-factor reset. The attacker injected malicious code into 18 high-download open-source JavaScript packages, including 'ansi-styles', 'chalk', and 'debug', targeting cryptocurrency transactions. Although the incident caused significant alarm due to the downloads’ reach (>2 billion/week), rapid detection by the open-source community and immediate takedown by npm limited the impact. The injected packages were removed within hours, and the attacker ultimately stole just over $1,000 in cryptocurrency. This incident highlights the growing sophistication of supply-chain and social engineering attacks on open-source platforms. As attackers target developer credentials and critical project maintainers, organizations face renewed urgency to reassess their software supply chain controls and dependency management.
8 months ago
Kill Chain
KazMunayGas Penetration Test Mistaken for Russian Cyberattack: Lessons From a Simulated Incident
In early 2024, Kazakhstan's largest oil company, KazMunayGas, was mistakenly believed to have suffered a cyberattack attributed to a Russian Advanced Persistent Threat (APT) group using a compromised employee email account. Initial reports claimed that attackers breached internal systems, raising alarm over possible business disruption and data compromise. However, after internal review, the company clarified the activity was actually part of an authorized penetration testing exercise, not a malicious breach, and no operational impact or data loss occurred. This incident comes amid heightened concern about cyberthreats targeting energy companies, particularly in regions where geopolitical tensions and state-sponsored actors are active. It demonstrates the confusion that can arise when security drills mimic genuine adversary tactics, highlighting the necessity for robust communication around cybersecurity validation activities.
8 months ago
Kill Chain
Microsoft Patch Tuesday 2025: Patch Critical Privilege Escalation Flaws Now
In September 2025, Microsoft released patches addressing 81 vulnerabilities across enterprise products and core Windows systems. No vulnerabilities were detected as actively exploited, but experts cautioned that several critical and high-severity flaws could become prime targets. Notably, CVE-2025-55232 (CVSS 9.8) enables unauthenticated code execution on Microsoft High Performance Compute Pack installations. Critical elevation of privilege issues, such as CVE-2025-54918 (Windows NTLM) and CVE-2025-55234 (Windows SMB), expose organizations to potential lateral movement, ransomware, and large-scale data exfiltration risks if not remediated. This incident underscores the growing urgency of rapid patch cycles as attacker interest in privilege escalation and lateral movement techniques surges. With threat actors leveraging unpatched vulnerabilities for ransomware and data theft, organizations must bolster detection and enforcement around privilege-oriented exploits.
8 months ago
Kill Chain
How Outdated Encryption in Microsoft Defaults Enabled the 2024 Ascension Ransomware Attack
In February 2024, Ascension, one of the largest healthcare organizations in the United States, suffered a massive ransomware attack linked to longstanding encryption flaws in Microsoft’s default configurations. Attackers infiltrated Ascension’s network via a phishing email opened by a contractor on a company laptop using default Microsoft Edge and Bing settings. Exploiting weak encryption (RC4) and leveraging the Kerberoasting technique on Microsoft Active Directory, the ransomware group rapidly gained administrative privileges and deployed malware across the organization’s systems. This breach compromised sensitive data belonging to over 5.6 million patients, including personal, medical, payment, insurance, and government identification records, and severely disrupted business operations.
8 months ago
Kill Chain
Global NPM Phishing Breach Exposes Billions to Supply Chain Malware
In September 2023, threat actors compromised the NPM account of Qix, a well-known developer, through a phishing attack and used the access to publish malicious updates to 18 highly popular open-source packages. These tainted packages, which collectively garnered over 2 billion weekly downloads, included 'ansi-styles', 'debug', 'chalk', and 'supports-color'. The inserted malware aimed to steal cryptocurrency by tampering with API calls and redirecting wallet transactions. The attack window was brief—about two hours—before the breach was discovered, the malicious versions withdrawn, and further spread prevented. While technical fallout was limited and the attackers profited minimally, the incident exposed significant vulnerabilities in the open-source software ecosystem and generated substantial remediation efforts globally. This episode highlights urgent risks inherent in software supply chains and the dependency of modern development on a small number of package maintainers. Public attention to supply chain defense, rapid incident response, and robust dependency vetting is rising as organizations face the reality of widespread reliance on community-maintained resources.
8 months ago
Kill Chain
Microsoft September 2025 Patch Tuesday: Spotlight on Network Privilege Escalation Flaws
On September 2025, Microsoft released security patches addressing over 80 vulnerabilities across Windows products, including 13 rated as 'critical.' Notably, CVE-2025-54918, a vulnerability in Windows NTLM authentication, allows attackers with network access and credential knowledge to elevate privileges to SYSTEM level remotely. Another disclosed vulnerability, CVE-2025-55234 in the SMB client, is also remotely exploitable and could result in code execution through replay attacks. Alongside these, the update addressed an NTFS remote code execution flaw (CVE-2025-54916) that, although not network-exploitable, poses significant risk via social engineering vectors. This Patch Tuesday illustrates a continued shift in attacker focus towards privilege escalation and lateral network movement within enterprise environments. Escalating regulatory scrutiny and rising advanced persistent threats reinforce the urgency of timely patching and integrated security controls for both external and east-west traffic.
8 months ago
Kill Chain
U.S. Indicts Ukrainian Ransomware Operator Behind Hundreds of Global Attacks
In June 2024, the U.S. Department of Justice indicted Volodymyr Tymoshchuk, a Ukrainian national linked to the development and deployment of the Nefilim, LockerGoga, and MegaCortex ransomware variants. Operating under aliases such as 'deadforz' and 'farnetwork,' Tymoshchuk and his co-conspirators targeted organizations—including healthcare, industrial, and blue-chip companies—across the U.S., Europe, and Australia from at least 2018 onward. Over 250 U.S. and hundreds of global victims experienced encrypted systems, data theft, and significant operational disruption, resulting in tens of millions of dollars in damages attributed to ransom payments, mitigation, and recovery costs. This indictment underscores increasing law enforcement cooperation and heightened government focus on disrupting ransomware-as-a-service ecosystems. The ongoing campaign and associated public rewards for information highlight how ransomware actors continue evolving tactics, targeting high-revenue organizations and leveraging affiliate networks to scale global extortion operations.
8 months ago
Kill Chain
Hackers Deploy Advanced Botnet Over Exposed Docker APIs via Tor (2025)
In September 2025, a sophisticated threat campaign was uncovered targeting exposed Docker APIs, where attackers leveraged the Tor network to obfuscate their activities and deploy a new, evolving botnet. The attackers used automated scanning to discover open Docker API endpoints (commonly on port 2375), then executed a multi-stage infection chain utilizing malicious containers. These payloads established persistent SSH access, blocked further exploitation by others, and launched additional tools for internal scanning, lateral movement, and covert communication. While earlier versions dropped cryptominers, the updated tooling focused on botnet expansion, user monitoring, and groundwork for additional attacks such as credential theft or DDoS. This incident exemplifies the rapid shift toward automation and stealth in cloud-native threats. Its relevance is underscored by the proliferation of misconfigured APIs and cloud workloads, combined with attackers’ increasing use of anonymizing networks (like Tor) and multi-vector attacks. Organizations with exposed or poorly secured container environments are urgently at risk.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports