Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Unveiling 'CoSnitch': The AI Vulnerability in Microsoft Copilot
In December 2025, Varonis Threat Labs identified a vulnerability in Microsoft Copilot Personal, termed 'CoSnitch,' which allowed attackers to manipulate the AI into revealing its own architectural details. By crafting specific prompts, researchers induced Copilot to disclose information that facilitated memory poisoning, automatic prompt execution via specially crafted URLs, and data exfiltration. Microsoft addressed this issue by releasing patches on August 18, 2026, and confirmed that enterprise customers were unaffected. This incident underscores the evolving threat landscape where AI systems can be exploited to divulge sensitive information. It highlights the necessity for continuous security assessments and the implementation of robust guardrails to prevent similar vulnerabilities in AI-driven platforms.
1 month ago
Kill Chain
Critical GitLab Vulnerability CVE-2026-19478: Immediate Action Required
In August 2026, GitLab disclosed a critical vulnerability (CVE-2026-19478) in its Community and Enterprise Editions, affecting versions from 18.2 up to 19.2.3. This code injection flaw within the GraphQL API allows unauthenticated attackers to remotely modify or delete public projects and user data. The vulnerability has been assigned a CVSS score of 9.4 due to its high impact on data integrity and availability. Organizations using self-managed GitLab instances are urged to upgrade to the patched versions 18.11.11, 19.0.8, 19.1.6, or 19.2.4 immediately to mitigate this risk. The disclosure of CVE-2026-19478 underscores the critical importance of securing APIs against unauthorized access and code injection attacks. As threat actors increasingly exploit such vulnerabilities, organizations must prioritize timely patching and implement robust monitoring of API activities to detect and prevent unauthorized operations.
1 month ago
Kill Chain
Critical Vulnerabilities in macOS, SharePoint, vCenter, and IKE Under Active Exploitation
In August 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. These vulnerabilities include CVE-2026-65400 affecting Apple macOS, CVE-2026-55040 in Microsoft SharePoint, CVE-2026-59310 in VMware vCenter, and CVE-2026-33824 in Microsoft Internet Key Exchange (IKE) Service Extensions. Exploitation of these flaws has led to unauthorized access, deployment of cryptocurrency miners, backdoors, and ransomware attacks across multiple countries. The active exploitation of these vulnerabilities underscores the persistent threat posed by sophisticated cyber actors targeting widely used enterprise systems. Organizations are urged to prioritize patching and implement robust security measures to mitigate potential risks associated with these exploits.
1 month ago
Kill Chain
Microsoft Uncovers Extensive MacSync Stealer Infrastructure
In August 2026, Microsoft Defender Experts identified over 30 web domains associated with MacSync Stealer, a macOS-targeted information-stealing malware. The investigation revealed that the malware utilized social engineering tactics, such as ClickFix, to trick users into executing malicious commands in the Terminal. Once executed, MacSync Stealer collected sensitive data, including macOS Keychain contents, browser credentials, SSH keys, and AWS credentials, which were then exfiltrated to attacker-controlled servers. The malware employed various evasion techniques, including in-memory execution and the use of native macOS utilities, to minimize detection. This incident underscores the evolving sophistication of macOS-targeted malware and the increasing use of social engineering techniques to bypass traditional security measures. Organizations must remain vigilant and educate users about the risks of executing unverified commands, especially as threat actors continue to adapt their methods to exploit human factors.
1 month ago
Kill Chain
Critical Vulnerabilities Discovered in CISA's Malcolm Tool
In August 2026, multiple vulnerabilities were identified in CISA's Malcolm network traffic analysis tool, including CVE-2026-55676, CVE-2026-63133, CVE-2026-63134, CVE-2026-63177, CVE-2026-19670, and CVE-2026-19671. These flaws ranged from unbounded archive extraction leading to denial-of-service conditions to path traversal issues allowing unauthorized access. Exploitation of these vulnerabilities could enable attackers to execute arbitrary code, create unauthorized directories, or cause service disruptions. CISA promptly released patches to address these issues, urging users to update to the latest versions to mitigate potential risks. ([vulners.com](https://vulners.com/nvd/NVD%3ACVE-2026-63133?utm_source=openai)) The discovery of these vulnerabilities underscores the critical importance of timely software updates and vigilant monitoring of security advisories. As cyber threats continue to evolve, organizations must prioritize the implementation of patches and adhere to best practices to safeguard their systems against potential exploits.
1 month ago
Kill Chain
Arup's $25 Million Deepfake Scam: A Wake-Up Call for Cybersecurity
In January 2024, a finance employee at Arup's Hong Kong office received an email, purportedly from the company's UK-based CFO, requesting a confidential transaction. To verify, the employee joined a video conference with individuals appearing as the CFO and other senior colleagues. Convinced by the authenticity of the participants, the employee executed 15 wire transfers totaling approximately $25.6 million to designated bank accounts. Subsequent investigations revealed that the video call participants were AI-generated deepfakes, and the entire scenario was orchestrated by cybercriminals. This incident underscores the evolving sophistication of cyber threats, where attackers leverage advanced AI technologies to create highly convincing social engineering schemes. Organizations must recognize that traditional verification methods, such as visual and auditory confirmation, can be compromised. Implementing multi-factor authentication, establishing robust verification protocols, and educating employees about emerging threats are crucial steps in mitigating such risks.
1 month ago
Kill Chain
SilkParasite: Unveiling a Sophisticated Cyber Espionage Threat in Central Asia
In late 2025, a cyber espionage operation named SilkParasite was identified targeting Central Asian government entities. The campaign utilized seven remote access tools (RATs), including five previously undocumented variants: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. Attackers employed AI-assisted development techniques and spear-phishing emails with malicious Microsoft Office documents to infiltrate systems. The operation is linked to Chinese state-sponsored actors, evidenced by the use of backdoors like BLOODALCHEMY and SpiceRAT, both associated with Chinese hacking groups. This incident underscores the evolving sophistication of cyber threats, particularly the integration of AI in malware development. Organizations must enhance their cybersecurity measures to detect and mitigate such advanced persistent threats.
1 month ago
Kill Chain
Medusa Ransomware's Rapid Expansion: A 2026 Update
In August 2026, the Medusa ransomware-as-a-service group expanded its operations, adding over 200 new victims within a year, totaling more than 500 since its identification in 2021. The group exploits unpatched software vulnerabilities, including Fortra GoAnywhere and BeyondTrust flaws, and employs access brokers to gain initial access, paying between $100 to $1 million. Medusa actors utilize legitimate tools and 'living off the land' techniques to evade detection, leveraging remote monitoring and management software and Remote Desktop Protocol for lateral movement. Once inside a network, they use common utilities to support credential access, data exfiltration, and ransomware deployment. This incident underscores the critical need for organizations to promptly patch software vulnerabilities and implement robust access controls. The healthcare and public health sectors have been frequent targets, highlighting the importance of securing sensitive data against opportunistic ransomware attacks.
1 month ago
Kill Chain
Mabna Institute Indictment 2026: Unveiling the Massive Cyber Theft Operation
In August 2026, U.S. federal authorities unsealed an indictment against 17 Iranian nationals associated with the Mabna Institute, an Iranian Advanced Persistent Threat (APT) group active since 2013. The indictment alleges that the group conducted a coordinated cyber theft campaign targeting over 300 universities worldwide, including 144 in the United States, as well as numerous private sector companies and government agencies. The Mabna Institute is accused of stealing more than 31 terabytes of academic data and intellectual property, resulting in an estimated $3.4 billion in losses. The group's activities were reportedly conducted on behalf of the Islamic Revolutionary Guard Corps (IRGC) and other Iranian government clients. ([irancybernews.org](https://irancybernews.org/en/cyberactors/mabna-institute/?utm_source=openai)) This indictment underscores the persistent threat posed by state-sponsored cyber actors targeting academic and research institutions. The Mabna Institute's extensive phishing campaigns and data exfiltration efforts highlight the need for robust cybersecurity measures and international cooperation to protect sensitive information from nation-state adversaries.
1 month ago
Kill Chain
CISA Alerts on Ransomware Exploitation of Windows Task Host Vulnerability CVE-2025-60710
In November 2025, Microsoft patched a high-severity privilege escalation vulnerability, CVE-2025-60710, in the Windows Task Host component, which affects Windows 11 and Windows Server 2025 systems. This flaw allows local attackers with basic user permissions to gain SYSTEM-level access by exploiting improper link resolution before file access. Despite the availability of patches, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed in April 2026 that this vulnerability was being actively exploited. By August 2026, CISA reported that ransomware gangs were leveraging CVE-2025-60710 to escalate privileges and deploy ransomware on unpatched systems, posing significant risks to organizations relying on these Windows versions. This incident underscores the critical importance of timely patch management and proactive vulnerability mitigation strategies to prevent exploitation by threat actors.
1 month ago
Kill Chain
Bridging the Gap: Enhancing Cybersecurity with Behavioral Detection
In August 2026, Picus Security's Blue Report highlighted a significant gap in cybersecurity defenses: while perimeter controls effectively block known attack signatures, they often fail to detect subtle variations of the same techniques. For instance, the tool Mimikatz, when used to dump credentials via less conspicuous methods, bypassed defenses in 97% of cases. This underscores the need for security measures that focus on attacker behaviors, not just known indicators of compromise. This finding is crucial as adversaries increasingly employ stealthy tactics to evade detection. Organizations must adopt behavioral-based detection strategies to address these evolving threats and enhance their overall security posture.
1 month ago
Kill Chain
Critical Exploits Target MLflow and FUXA Vulnerabilities in August 2026
In August 2026, two critical vulnerabilities were actively exploited: CVE-2026-64849 in MLflow and CVE-2026-25895 in FUXA. The MLflow vulnerability allowed unauthenticated attackers to perform Server-Side Request Forgery (SSRF) attacks, enabling access to internal cloud metadata endpoints and extraction of sensitive data. The FUXA vulnerability permitted unauthenticated remote attackers to write arbitrary files to the server filesystem, potentially leading to remote code execution. Both vulnerabilities were promptly patched in subsequent software releases. The exploitation of these vulnerabilities underscores the persistent targeting of open-source platforms by threat actors. Organizations are urged to prioritize timely patching, conduct thorough audits for signs of compromise, and implement robust security measures to protect against similar threats.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports