✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Critical SonicWall SMA 1000 Zero-Days Under Active Exploitation: CVE-2026-83548 & CVE-2026-83549
In September 2026, attackers began actively exploiting two zero-day vulnerabilities in SonicWall SMA 1000 perimeter devices, enabling unauthenticated remote code execution. CVE-2026-83548, a critical SSRF vulnerability with a CVSS score of 10.0, allows unauthorized access through an unintended alternate access path, while CVE-2026-83549 enables OS command injection. When chained together, these flaws provide complete system compromise of affected appliances running versions 12.4.3-03453/12.5.0-02835 and older. SonicWall confirmed ongoing exploitation and urged immediate patching to versions 12.4.3-03526/12.5.0-02952 or higher. This incident highlights the continued targeting of edge security devices as initial compromise vectors, following a pattern of sophisticated zero-day attacks against network perimeter appliances throughout 2026, emphasizing the critical need for rapid patch management and network segmentation strategies.
2 days ago
Kill Chain
Machine Speed Terror: How AI Agents Compressed a 2-Week Breach Into 10 Hours
In September 2026, threat actors demonstrated the devastating potential of AI-assisted cyberattacks by compressing a typical two-week enterprise breach timeline into just 10 hours. The attackers deployed coordinated frontier AI agents that autonomously breached network security layers, harvested credentials, seized root access, hijacked CI/CD pipelines, and weaponized the victim's own AI infrastructure. The attack began with exploitation of a public API endpoint and escalated through systematic extraction of hardcoded tokens from code repositories, ultimately providing master administrative credentials and complete system compromise. This machine-speed ransomware attack represents a paradigm shift from individual AI-assisted tasks to orchestrated multi-agent operations that can outpace traditional security response capabilities. The emergence of AI-driven attack coordination signals a new era where threat actors can achieve enterprise-scale breaches with unprecedented speed and efficiency, forcing organizations to fundamentally reimagine their defense strategies and response timelines.
2 days ago
Kill Chain
Seven Critical Vulnerabilities Exploited in Wild: AI Infrastructure Becomes Prime Target
CISA added seven critical vulnerabilities to its Known Exploited Vulnerabilities catalog in September 2026 after observing active exploitation by threat actors. The vulnerabilities span multiple platforms including SonicWall SMA appliances, Sangoma Switchvox, JFrog Artifactory, and AI infrastructure components like LiteLLM and Kestra. Attackers exploited these flaws to deploy reverse shells, cryptocurrency miners, and conduct unauthorized operations, with campaigns targeting AI infrastructure becoming increasingly prominent as adversaries seek to harvest API keys and monetize compromised systems. This incident highlights the growing threat landscape targeting AI infrastructure and the critical importance of rapid vulnerability remediation. With AI systems becoming prime targets for credential theft and resource hijacking, organizations must prioritize security updates and implement comprehensive monitoring across their AI workloads to prevent similar exploitation campaigns.
2 days ago
Kill Chain
Shai-Hulud Infostealer Evolves to Target 469 Credential Locations Across Software Supply Chains
In August 2026, GitGuardian researchers discovered that the Shai-Hulud infostealer worm had evolved to scan for credentials across 469 locations in developer environments, representing a 148% increase from earlier variants that checked only 189 paths. The malware targets CI/CD tooling, cloud configurations, AI tool configs, package registries, and development environments to harvest reusable credentials for supply chain attacks. The stolen credentials enable lateral movement across trusted software supply chains, turning credential theft into ongoing propagation vectors through package publishing systems. This incident highlights the critical shift in attack methodologies where threat actors no longer need to break trust relationships but instead exploit existing credential sprawl across modern development ecosystems. The exponential increase in targeted credential locations demonstrates the growing sophistication of supply chain attacks and the urgent need for comprehensive secrets management across DevOps pipelines.
2 days ago
Kill Chain
Threat Actors Weaponize Trusted Node.js Runtime for Stealth Malware Delivery
Since February 2026, threat actors have been weaponizing the legitimate Node.js JavaScript runtime (node.exe) to deliver malicious payloads in targeted attacks against government departments, technology companies, and hotels. The Symantec Threat Hunter Team identified this technique as particularly effective because node.exe is a trusted binary that can execute arbitrary JavaScript code while evading traditional security detection mechanisms. Attackers leverage the runtime's legitimate presence in enterprise environments to establish persistence, execute malware, and maintain command and control communications without triggering security alerts. This campaign reflects the growing trend of living-off-the-land tactics where attackers abuse legitimate system tools rather than deploying custom malware, making detection significantly more challenging for traditional security solutions and highlighting the need for behavioral analysis and runtime protection.
2 days ago
Kill Chain
Seven Critical Vulnerabilities Added to CISA's KEV Catalog Demand Immediate Action
On September 2, 2026, CISA added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, affecting critical enterprise systems including Sangoma Switchvox, SonicWall SMA1000 appliances, JFrog Artifactory, and other widely deployed platforms. The vulnerabilities span SQL injection, authentication bypass, command injection, and request smuggling attack vectors, with threat actors already leveraging these flaws to compromise federal and private sector networks. The additions coincide with CISA's new Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize rapid remediation of high-risk vulnerabilities that grant total system control. This incident highlights the accelerating pace of vulnerability exploitation as threat actors increasingly target authentication systems, web applications, and network appliances to establish persistent access. The rapid weaponization of these CVEs demonstrates the critical need for organizations to implement proactive vulnerability management and zero-trust security controls.
2 days ago
Kill Chain
Global RMM Phishing Campaign Exploits Legitimate Cloud Services Across 46 Countries
In September 2026, security researchers identified a sophisticated RMM phishing campaign spanning 46 countries, with the United States accounting for 45% of observed activity. The operation used fake documents mimicking tax forms, shipping notifications, and government communications to trick victims into installing legitimate remote monitoring and management software. Attackers leveraged rapidly rotating infrastructure on Vercel, GitHub Pages, and Netlify, with 94% of 425 identified URLs observed for only a single day. The campaign targeted education, technology, government, banking, and manufacturing sectors. This incident highlights the growing trend of threat actors abusing legitimate cloud services and software for malicious purposes, making detection increasingly challenging through traditional IOC-based approaches.
2 days ago
Kill Chain
Microsoft Teams Impersonation Campaign Exploits Remote Support Trust for Enterprise Access
Microsoft Threat Intelligence discovered a sophisticated social engineering campaign where threat actors impersonate IT support personnel through Microsoft Teams external collaboration to trick users into granting remote access. Once control is established via legitimate remote management tools, attackers deploy a malicious MSI package that stages a Node.js runtime and JavaScript implant for persistent command execution. The campaign progresses through extensive reconnaissance, Active Directory enumeration, and lateral movement via Windows Remote Management (WinRM) toward high-value assets including domain controllers, representing a precursor to ransomware deployment or data theft operations. This attack pattern demonstrates the evolving threat landscape where attackers leverage trusted enterprise collaboration platforms and legitimate administrative tools to bypass traditional security controls. The shift from commodity phishing to hands-on-keyboard operations targeting identity infrastructure reflects the increasing sophistication of modern threat actors seeking enterprise-wide access for high-impact cyberattacks.
2 days ago
Kill Chain
SANS Honeypot Captures Massive Automated Credential Attack Campaign
The SANS Internet Storm Center's Honeypot-Omaha deployment captured extensive automated credential attack campaigns targeting SSH and Telnet services. Threat actors from IP addresses associated with PPTECHNOLOGY LIMITED and other providers executed systematic brute-force attacks, successfully compromising honeypot systems through weak credentials. Once gaining access, attackers performed reconnaissance, system enumeration, and data exfiltration while attempting to cover their tracks using commands like 'rm -rf filter'. The analysis revealed over 400 file artifacts and multiple attack sessions showing coordinated botnet-style automation targeting vulnerable internet-facing services. This incident highlights the persistent threat landscape facing organizations with exposed SSH and Telnet services, demonstrating how attackers leverage automated tools and compromised infrastructure to systematically target weak authentication mechanisms across internet-connected systems.
2 days ago
Kill Chain
Critical Azure Privilege Escalation Flaw Exposes Hidden Risks in Cloud RBAC
In June 2026, NetSPI security researchers discovered a critical privilege escalation vulnerability in Microsoft Azure's Role-Based Access Control (RBAC) system. The vulnerability existed in the built-in 'Anyscale Platform Administrator Role' which contained unconstrained Microsoft.Authorization/roleAssignments/write permissions, allowing arbitrary escalation to Owner-level privileges without proper Attribute-Based Access Control (ABAC) restrictions. This finding highlighted broader security gaps in Azure's rapidly expanding attack surface, which now includes over 200 services, 897 built-in RBAC roles, and 22,018 different permissions. Microsoft addressed the issue within two weeks of disclosure by removing the problematic permissions from the affected role. This incident represents a critical trend in cloud security as organizations increasingly rely on complex cloud permission models that can contain hidden escalation paths, emphasizing the urgent need for granular permission auditing and zero-trust access controls in multi-cloud environments.
2 days ago
Kill Chain
Inside the Lazarus Group's Fake IT Worker Employment Scam: A 2024 Investigation
Security researchers from ANY.RUN conducted an extensive investigation into North Korean IT worker infiltration schemes by creating a fake company to attract fraudulent job applicants. The study revealed sophisticated operations where Lazarus Group affiliates use stolen identities, AI-generated profile photos, and elaborate cover stories to secure remote positions at legitimate organizations. These fake employees then establish persistent access to corporate networks, potentially enabling data theft, intellectual property exfiltration, and deployment of malware while generating revenue for North Korean state operations. The investigation documented multiple phases of the scam including initial contact, identity verification circumvention, and operational security measures used by the infiltrators. This represents a significant evolution in state-sponsored cyber operations, blending traditional espionage with employment fraud to achieve long-term network access and financial gain for the DPRK regime.
2 days ago
Kill Chain
Historic Federal Detention: Maine Teen First Minor Charged in 764 Extremist Case
In December 2024, a 17-year-old from Maine became the first minor to be federally charged and detained for crimes related to involvement in 764, a nihilistic violent extremist collective. The teenager was convicted of multiple federal crimes including conspiracy to sexually exploit children, distributing child sexual abuse material, cyberstalking, and identity theft. This case represents a significant shift in federal law enforcement policy, as authorities have historically avoided prosecuting minors for extremist activities, creating what experts called a dangerous loophole that encouraged maximum harm before age 18. This prosecution signals law enforcement's evolved approach to addressing violent online extremism that increasingly targets and recruits minors. With the FBI investigating over 500 subjects nationwide connected to 764 and affiliated groups, this case establishes precedent for holding juvenile perpetrators accountable while disrupting recruitment strategies that exploit legal protections for minors.
2 days ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports