Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
2025 Spotlight: ESET Uncovers First AI-Powered PromptLock Ransomware
In September 2025, ESET Research identified PromptLock, the first documented case of AI-powered ransomware. While not deployed in active attacks, PromptLock is a sophisticated proof-of-concept that leverages OpenAI’s gpt-oss-20b model via the Ollama API to create malicious Lua scripts in real-time. Written in Golang for both Windows and Linux, PromptLock automates enumeration, exfiltration, and encryption of target system files, with variants found on VirusTotal. Its design demonstrates the feasibility of AI-augmented malware, where dynamic scripting enables rapid adaptation to environments and highly automated attack flows. PromptLock’s discovery highlights the emergence of AI-driven tactics that could accelerate ransomware development and proliferation. As AI tools become more accessible, the risk of advanced, autonomous threats challenging enterprise security controls grows sharply, signaling a pivotal shift in the threat landscape.
8 months ago
Kill Chain
Inside the 2025 Salesloft Supply Chain Breach: Token Theft at Scale
In August 2025, Salesloft, a leading AI chatbot provider, suffered a significant supply chain compromise when attackers exfiltrated authentication tokens via its Drift integration. The breach allowed unauthorized access to hundreds of customer-connected services, including Salesforce, Slack, Google Workspace, Amazon S3, Azure, and OpenAI, impacting more than 5,000 customers. The attackers, tracked as UNC6395 and possibly linked to ShinyHunters or Scattered Spider, began siphoning sensitive corporate data from at least August 8 to August 18, 2025. The incident led to mass data theft, urgent token invalidation efforts, and subsequent blocking of Drift integrations by Salesforce. This breach highlights the surging threats posed by identity-driven attacks and the risks of over-permissive third-party integrations in the enterprise cloud ecosystem. As attackers increasingly exploit centralized authentication and SSO environments, organizations face urgent pressure to revisit access controls and strengthen detection of abuse within legitimate user sessions.
8 months ago
Kill Chain
Azure AD Credential Exposure: Public Config File Leak Spotlights Cloud Risks
In early 2024, a significant security incident was discovered involving the inadvertent exposure of Azure Active Directory credentials via a misconfigured JSON configuration file. The public accessibility of this file enabled malicious actors to directly authenticate against Microsoft’s OAuth 2.0 endpoints, bypassing traditional security controls and potentially infiltrating cloud environments. Attackers leveraged this cloud misconfiguration to escalate cloud access, risking business-critical Azure resources, data loss, and lateral movement inside affected organizations. Detection came after researchers observed unusual authentication patterns linked to public file sharing, prompting rapid investigation and remediation efforts. The incident underscores how easily overlooked misconfigurations can undermine enterprise cloud security and compliance obligations. The breach highlights ongoing challenges as organizations migrate sensitive workflows to the cloud. Public file exposure, credential leakage, and abuse of identity platforms like Azure Active Directory remain top attack vectors. This incident amplifies recent regulatory scrutiny, reinforces the need for cloud visibility and zero trust practices, and signals rising attacker sophistication in exploiting misconfigured storage and identity controls.
8 months ago
Kill Chain
Inside the Salesloft Drift Supply Chain Breach: How OAuth Token Theft Exposed SaaS Leaders
In August 2023, the threat group UNC6395 exploited a vulnerability in Salesloft’s Drift SaaS marketing platform, targeting OAuth and refresh tokens stored within its Salesforce integration. By leveraging these stolen tokens, attackers performed lateral movement into several customer Salesforce environments, extracting business contact records, support case data, and in some instances, sensitive configuration details and access credentials from high-profile clients such as Zscaler, Palo Alto Networks, Cloudflare, Proofpoint, and Tenable. Salesloft and Salesforce responded by revoking tokens and disabling integrations, while impacted organizations rushed to assess and mitigate the damage. This incident underscores the persistent risk of supply chain compromises targeting SaaS integrations and identity-based authentication mechanisms. As attackers increasingly leverage token theft for stealthy, authorized access, organizations must adopt granular permissions, token security best practices, and rapid credential rotation to safeguard against similar threats.
8 months ago
Kill Chain
FDN3’s Massive Brute-Force Attacks Target VPN & RDP Devices Globally (2025)
Between June and July 2025, Ukrainian autonomous system FDN3 (AS211736) orchestrated large-scale brute-force and password spraying attacks targeting SSL VPN and Remote Desktop Protocol (RDP) devices across multiple regions. The campaign, identified and attributed by French cybersecurity firm Intrinsec, involved distributed login attempts to compromise organizations’ remote access infrastructure using stolen or weak credentials. This led to unauthorized system access, at-risk sensitive data, and the potential for further lateral movement inside target environments. The attack underscored the critical vulnerabilities that arise when VPNs and RDP servers are exposed without adequate security controls. This incident is emblematic of the growing trend of threat actors exploiting internet-facing authentication portals with automated credential attacks. As organizations continue to rely on remote access solutions, adversaries are increasingly targeting SSL VPN and RDP endpoints to gain initial entry—a method further complicated by the prevalence of weak password policies, limited anomaly detection, and insufficient segmentation.
8 months ago
Kill Chain
Nx npm Supply Chain Breach 2025: AI Stealer Exposes Over 1,000 Developer Secrets
In late August 2025, a highly automated supply chain attack compromised the popular Nx build system on npm, enabling unidentified attackers to infect more than 1,000 JavaScript developers within just four hours. Malicious packages, leveraging artificial intelligence through CLI integrations, actively scanned victim environments for GitHub tokens, npm credentials, SSH keys, cloud secrets, and cryptocurrency wallets—exfiltrating roughly 20,000 sensitive files. Instead of using traditional command and control servers, the attackers published victims’ stolen data into public GitHub repositories, complicating detection and enabling rapid collection by threat actors. This incident marks a significant escalation in software supply chain threats by demonstrating the abuse of AI-driven reconnaissance and novel exfiltration via legitimate platforms. The swift, large-scale impact underscores rising attacker sophistication and amplified operational risk, especially as AI and developer tooling become more deeply embedded in build pipelines and cloud-native workflows.
8 months ago
Kill Chain
How a Zero-Click Exploit Unleashed AI Agent Mayhem Across Enterprises
In July 2025, researchers disclosed a critical vulnerability affecting generative AI agents deployed widely across enterprises. This exploit, requiring no user interaction (zero-click), enabled remote attackers to commandeer AI agents and gain broad, unauthorized access to sensitive business data and interdependent cloud applications. By leveraging the AI agents’ elevated privileges and extensive network reach, attackers could move laterally across organizational boundaries, exposing data in transit, triggering egress to attacker-controlled infrastructure, and bypassing traditional segmentation and policy enforcement. The incident resulted in heightened risk for data exfiltration, business interruption, and regulatory scrutiny as organizations scrambled to assess and mitigate exposure. This breach highlights the growing risks of autonomous AI behavior and the challenges of applying conventional network and application security frameworks to evolving AI-driven architectures. The attack underscores the urgent need for robust segmentation, encrypted traffic, and continuous threat monitoring in AI/ML environments, as both threat actors and defenders rapidly adapt to the rise of agentic AI.
8 months ago
Kill Chain
Federal Agency Breached via GeoServer RCE Exploit in 2024
In July 2024, a U.S. federal civilian executive branch agency suffered a significant security breach when attackers exploited a critical remote code execution (RCE) vulnerability (CVE-2024-36401) in an unpatched GeoServer instance. Threat actors gained initial access by leveraging proof-of-concept exploits that had been made public after the vulnerability's disclosure. They moved laterally across the agency’s internal network, breaching additional web and SQL servers, deploying web shells like China Chopper, escalating privileges, and maintaining persistence. The attackers remained undetected for three weeks, only triggering detection when the agency’s EDR tool flagged suspicious malware activity. This breach underscores the growing risk posed by rapid weaponization of new vulnerabilities, particularly those affecting widely used open-source platforms. The incident follows a trend of increased attacks exploiting unpatched systems and weak internal segmentation, emphasizing the urgent need for proactive vulnerability management and robust East-West traffic controls.
8 months ago
Kill Chain
Nearly 2,000 MCP Servers Left Exposed by Authentication Misconfiguration in 2024
In early 2024, security researchers discovered that nearly 2,000 MCP (Management Control Plane) servers worldwide were left completely unsecured due to disabled or unconfigured authentication settings. This cloud misconfiguration meant that anyone with internet access could gain full administrative control, potentially allowing unauthorized parties to manipulate workloads, exfiltrate sensitive data, or deploy malicious software at will. The lack of basic security controls exposed organizations leveraging agentic AI services to severe operational risks, compliance violations, and potential breaches of critical business infrastructure. This incident underscores a troubling pattern of cloud misconfiguration, particularly as organizations rapidly adopt AI and cloud-native platforms. As threat actors increasingly target exposed management interfaces and identity systems, the urgent need for robust authentication and continuous configuration monitoring has never been greater.
8 months ago
Kill Chain
Amazon ECS Privilege Escalation Flaw Exposes Critical IAM Risks in 2024
In early 2024, an independent security researcher uncovered a privilege escalation vulnerability in Amazon Elastic Container Service (ECS) that allowed attackers to abuse an undocumented protocol to gain IAM permissions well beyond their original access. By exploiting a misconfiguration in ECS’s internal handling of credentials, a malicious user could escalate from container-level privileges to full IAM role hijacking, enabling lateral movement across cloud environments and access to sensitive AWS resources. Amazon responded quickly and patched the issue after disclosure, but the flaw potentially exposed numerous customer environments to risk. This incident underscores the growing risk of cloud misconfigurations and privileged identity attacks, as well as the need for real-time monitoring of cloud service behaviors. Security teams should recognize the increasing creativity of threat actors targeting identity and access weaknesses within major cloud providers.
8 months ago
Kill Chain
Cloud Misconfig Leaves 2,000 MCP Servers Wide Open to Attack
In June 2024, security researchers uncovered that nearly 2,000 MCP (Managed Cloud Platform) servers were left exposed to the public internet without any authentication required. Attackers could readily gain unfettered administrative access, enabling full server control, lateral movement within environments, and potential exfiltration or disruption of sensitive workloads. The breach was a direct result of critical cloud misconfigurations, specifically the omission of basic authentication on systems underpinning key business and AI operations. While no single threat actor has been publicly attributed, the sheer scale exposes businesses globally to automated attacks, data theft, and business disruption. This incident highlights the persistent danger of insecure cloud defaults, particularly as organizations accelerate adoption of agentic AI and cloud-native architectures. With threat actors increasingly scanning for misconfigured cloud assets and attacker dwell time decreasing, timely secure configuration and visibility are more essential than ever.
8 months ago
Kill Chain
Google Gemini AI AI Vulnerability Enables Stealth Phishing Across Google Products
In early 2024, a significant vulnerability was uncovered in Google’s Gemini AI assistant, exposing users across Google platforms to sophisticated prompt injection attacks. Adversaries leveraged this flaw to craft invisible, malicious prompts that disguised themselves as legitimate Google Security alerts, tricking users and facilitating vishing and phishing attacks. The flaw allowed threat actors to bypass visible UI cues, broadening attack reach across Google applications and potentially compromising internal data and account integrity. Google was notified and began remediation efforts, but the proof-of-concept highlighted how large-scale AI platforms present new attack surfaces. This incident reflects an emerging trend where AI-driven tools are being targeted through prompt injection and model manipulation, creating challenging attack vectors for even the largest technology firms. The Gemini vulnerability underscores the importance of advanced security testing for generative AI and the urgent need for zero trust controls within AI ecosystems.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports