The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Cloud Misconfig Leaves 2,000 MCP Servers Wide Open to Attack
In June 2024, security researchers uncovered that nearly 2,000 MCP (Managed Cloud Platform) servers were left exposed to the public internet without any authentication required. Attackers could readily gain unfettered administrative access, enabling full server control, lateral movement within environments, and potential exfiltration or disruption of sensitive workloads. The breach was a direct result of critical cloud misconfigurations, specifically the omission of basic authentication on systems underpinning key business and AI operations. While no single threat actor has been publicly attributed, the sheer scale exposes businesses globally to automated attacks, data theft, and business disruption. This incident highlights the persistent danger of insecure cloud defaults, particularly as organizations accelerate adoption of agentic AI and cloud-native architectures. With threat actors increasingly scanning for misconfigured cloud assets and attacker dwell time decreasing, timely secure configuration and visibility are more essential than ever.
8 months ago
Kill Chain
Google Gemini AI AI Vulnerability Enables Stealth Phishing Across Google Products
In early 2024, a significant vulnerability was uncovered in Google’s Gemini AI assistant, exposing users across Google platforms to sophisticated prompt injection attacks. Adversaries leveraged this flaw to craft invisible, malicious prompts that disguised themselves as legitimate Google Security alerts, tricking users and facilitating vishing and phishing attacks. The flaw allowed threat actors to bypass visible UI cues, broadening attack reach across Google applications and potentially compromising internal data and account integrity. Google was notified and began remediation efforts, but the proof-of-concept highlighted how large-scale AI platforms present new attack surfaces. This incident reflects an emerging trend where AI-driven tools are being targeted through prompt injection and model manipulation, creating challenging attack vectors for even the largest technology firms. The Gemini vulnerability underscores the importance of advanced security testing for generative AI and the urgent need for zero trust controls within AI ecosystems.
8 months ago
Kill Chain
APT Group Abuses AWS with HazyBeacon Malware in Southeast Asian Government Attacks
In early 2024, an advanced persistent threat (APT) group leveraged Amazon Web Services (AWS) infrastructure to conduct an intelligence-gathering campaign targeting government entities in Southeast Asia. The attackers deployed the novel "HazyBeacon" backdoor, which communicated with command-and-control (C2) infrastructure over legitimate cloud channels to evade detection, facilitating both surveillance and data exfiltration. By abusing trusted AWS services, the group masked malicious traffic as normal cloud activity, making identification and remediation complex and exposing sensitive government operations to compromise. This incident underscores a rapidly growing trend where threat actors exploit cloud provider services as covert C2 and exfiltration channels. With attackers blending into legitimate cloud workflows, organizations face heightened urgency to enhance cloud-native visibility, enforce east-west traffic controls, and implement zero trust segmentation to mitigate advanced threats.
8 months ago
Kill Chain
2025’s Multichannel Phishing Surge: How Attackers Bypassed MFA and Hijacked Sessions
In early 2025, a wave of sophisticated phishing attacks exploited new multichannel vectors, including social media platforms, malicious search advertisements, and browser-based manipulation, to bypass multi-factor authentication and steal user sessions. Threat actors rapidly adapted to defensive advances, leveraging session hijacking and advanced social engineering to deceive users, often eclipsing legacy email-based phishing. Organizations reported credential compromise, unauthorized access to sensitive resources, and downstream data breaches as a result of these evolving techniques. The relevance of this incident is underscored by the acceleration of identity-based attacks, targeting hybrid and cloud environments and challenging traditional security controls. Regulatory focus on data privacy and authentication heightens the need for organizations to reassess their phishing defenses, user awareness, and session protection strategies.
8 months ago
Kill Chain
Salt Typhoon: Chinese APT Targets US National Guard in Stealthy 2023 Breach
Between March and December 2023, the Chinese state-sponsored threat group Salt Typhoon infiltrated the US National Guard’s networks, leveraging advanced persistent techniques to maintain undetected access for nearly a year. Attackers exploited security gaps, targeting unencrypted east-west and outbound network traffic, and exfiltrated sensitive operational and personnel data. The intrusion demonstrated advanced lateral movement, zero trust segmentation evasions, and targeted data exfiltration—all while remaining covert to standard detection and response tools initially. The resulting breach has exposed critical military data, presenting increased risks to operational integrity and individual privacy for National Guard personnel. This incident reflects a growing pattern of state-backed threat actors expanding targeting against US government and defense organizations, using stealthy persistence, multi-cloud exploitation, and sophisticated attack campaigns. It underscores urgent needs for continuous monitoring, encrypted network traffic, and zero trust strategies across hybrid and cloud infrastructure.
8 months ago
Kill Chain
Malicious Implants in AI Supply Chains: 2024’s Stealth Attack Surface
In early 2024, security researchers uncovered evidence that malicious implants are increasingly targeting AI components and applications through vulnerabilities in the supply chain. Threat actors leveraged weaknesses in popular AI frameworks and third-party dependencies to introduce stealthy backdoors and implants, enabling them to evade modern security tools. The attackers often exploited insufficient validation of AI model inputs, compromised third-party code, or leveraged misconfigurations to achieve persistent access and lateral movement within enterprise environments, resulting in sensitive data exposure and operational risk for organizations deploying AI-driven solutions. This incident underlines an emerging trend where cybercriminals and nation-state actors prioritize supply-chain vectors to subvert the rapidly expanding AI ecosystem. As AI adoption accelerates and digital trust becomes paramount, organizations face increased regulatory scrutiny and pressure to implement robust controls around software provenance and supply chain integrity.
8 months ago
Kill Chain
How Weaxor Ransomware Leveraged the React2Shell Vulnerability in 2025
In December 2025, cybercriminals exploited the critical React2Shell vulnerability (CVE-2025-55182) in React Server Components and Next.js to gain unauthorized access to a corporate endpoint. Within seconds, attackers deployed the Weaxor ransomware strain, rapidly encrypting files and appending a '.WEAX' extension, while dropping ransom notes named 'RECOVERY INFORMATION.txt' in each directory. The attack began by delivering an obfuscated PowerShell command, installing a Cobalt Strike beacon for command-and-control, disabling Windows Defender, wiping shadow copies, and clearing logs to evade detection and hinder forensic analysis. Researchers confirmed there was no lateral movement or data exfiltration prior to encryption, and the targeted machine was subsequently compromised by additional threat actors. This incident highlights the widespread exploitation of recently disclosed vulnerabilities by both ransomware gangs and nation-state actors. With opportunistic attacks increasing in speed and automation, organizations must improve patch velocity and advanced monitoring to defend against emerging, rapidly weaponized threats.
9 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports