Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

3197 threat reports
Page 33 of 267

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Information Technology/IT Threat Reports

Showing 385396 / 3197 reports
Securing the Software Supply Chain in the Age of AI-Generated Code
Impact· HIGH

Securing the Software Supply Chain in the Age of AI-Generated Code

In August 2026, a significant security concern emerged regarding AI-generated code and its impact on the software supply chain. AI coding assistants, while enhancing developer productivity, have been found to introduce unvetted or hallucinated dependencies into codebases. This phenomenon, known as 'slopsquatting,' occurs when AI models suggest non-existent package names, which attackers can then register and populate with malicious code. Such vulnerabilities have led to compromised builds and increased security risks across numerous repositories. The urgency of this issue is underscored by the rapid adoption of AI coding tools and the corresponding rise in supply chain attacks. Organizations are now facing the challenge of implementing robust governance mechanisms to vet AI-generated code and prevent the ingestion of malicious dependencies, highlighting the critical need for proactive security measures in the era of AI-assisted development.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical VMware vCenter RCE Flaw Exploited for Reverse SSH Access
Impact· CRITICAL

Critical VMware vCenter RCE Flaw Exploited for Reverse SSH Access

In August 2026, a critical vulnerability (CVE-2026-59310) in VMware vCenter's Syslog Server was actively exploited, allowing unauthenticated attackers to execute arbitrary code remotely. This flaw enabled the deployment of reverse SSH tools, granting persistent remote access to compromised systems. The attack campaign rapidly expanded, affecting 361 IP addresses across 47 countries, with significant concentrations in Germany, the U.S., Turkey, Iran, and France. The swift exploitation of this vulnerability underscores the increasing agility of threat actors in leveraging newly disclosed flaws. Organizations must prioritize timely patching and enhance monitoring to detect and mitigate such sophisticated attacks promptly.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(low)
Read Report
Understanding the LegacyHive Windows Zero-Day Vulnerability
Impact· HIGH

Understanding the LegacyHive Windows Zero-Day Vulnerability

In July 2026, a security researcher known as Nightmare Eclipse disclosed a zero-day vulnerability named 'LegacyHive' affecting the Windows User Profile Service. This flaw allows local non-administrator users to load and modify registry hives of other users, including administrators, potentially leading to privilege escalation. The proof-of-concept exploit was released shortly after Microsoft's July Patch Tuesday, impacting fully updated Windows systems. Microsoft has since released patches to address this vulnerability. The disclosure of LegacyHive underscores ongoing challenges in timely vulnerability management and the risks posed by unpatched systems. It highlights the importance of prompt patch application and the need for robust security practices to mitigate potential exploitation.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Armored Likho's 2026 Cyber-Espionage Campaign: A Deep Dive into BusySnake Infostealer
Impact· HIGH

Armored Likho's 2026 Cyber-Espionage Campaign: A Deep Dive into BusySnake Infostealer

In July 2026, the previously undocumented APT group 'Armored Likho' launched sophisticated cyber-espionage campaigns targeting government agencies and electric power entities in Russia, Brazil, and Kazakhstan. Utilizing spear-phishing emails disguised as official communications, they deployed the Python-based 'BusySnake' infostealer to exfiltrate sensitive data, including credentials and cryptographic keys. The malware's advanced obfuscation techniques and modular architecture enabled persistent access and evasion of detection mechanisms. This incident underscores the escalating threat posed by APT groups leveraging AI-generated malware to target critical infrastructure. Organizations must enhance their cybersecurity posture to defend against such evolving tactics.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Akira Ransomware Exploits Safe Mode to Disable EDR and Exfiltrate Data
Impact· CRITICAL

Akira Ransomware Exploits Safe Mode to Disable EDR and Exfiltrate Data

In August 2026, an Akira ransomware affiliate exploited an exposed SonicWall VPN device lacking multi-factor authentication to gain initial access to a target network. Within two hours, the attacker connected to the domain controller via RDP, enumerated Active Directory users and computers, and moved laterally to an application server. Utilizing WinRAR, they archived mapped file shares and employed the s5cmd tool to upload the stolen data to an attacker-controlled S3 bucket. Subsequently, AnyDesk was installed for persistent remote access. The attacker then rebooted the compromised host into Safe Mode with Networking, effectively disabling endpoint detection and response (EDR) solutions and Microsoft Defender’s real-time protection. Despite these efforts, the ransomware payload failed to execute due to system resource constraints, preventing file encryption. However, the attacker successfully exfiltrated sensitive data and credentials within a five-hour window. This incident underscores the evolving tactics of ransomware operators, particularly the use of Safe Mode to bypass security defenses. Organizations are advised to implement multi-factor authentication on all VPN accounts, monitor for Safe Mode boot configuration changes, and detect unauthorized remote access tools to mitigate such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Exploitation of SharePoint Authentication Bypass Vulnerability CVE-2026-55040
Impact· CRITICAL

Exploitation of SharePoint Authentication Bypass Vulnerability CVE-2026-55040

In July 2026, Microsoft disclosed a critical vulnerability in SharePoint Server, identified as CVE-2026-55040, which allows unauthenticated attackers to bypass authentication mechanisms via weaknesses in the JWT token validation process. This flaw enables adversaries to impersonate legitimate users, including administrators, potentially leading to unauthorized data access and modification. Following the release of a proof-of-concept (PoC) exploit by Rapid7, threat actors began actively exploiting this vulnerability, with multiple incidents reported globally, including a significant breach affecting the Swiss government's IT network. The rapid exploitation of CVE-2026-55040 underscores the critical importance of timely patch management and proactive security measures. Organizations utilizing SharePoint are urged to apply the latest security updates promptly and to implement robust monitoring and access controls to mitigate the risk of unauthorized access and data breaches.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Bleeding Llama: Critical Memory Leak in Ollama (CVE-2026-7482)
Impact· MEDIUM

Bleeding Llama: Critical Memory Leak in Ollama (CVE-2026-7482)

In May 2026, a critical vulnerability known as 'Bleeding Llama' (CVE-2026-7482) was disclosed in Ollama, a widely used framework for running large language models locally. This unauthenticated heap out-of-bounds read flaw allows remote attackers to exfiltrate sensitive data—including API keys, user conversations, and system prompts—from any internet-exposed Ollama server with minimal effort. The vulnerability affects versions up to 0.17.0, with an estimated 300,000 servers exposed at the time of disclosure. Ollama addressed the issue in version 0.17.1, but many instances remain unpatched, leaving organizations vulnerable to data breaches and unauthorized access. ([lyrie.ai](https://lyrie.ai/research/research/2026-05-08-bleeding-llama-ollama-cve-2026-7482?utm_source=openai)) The 'Bleeding Llama' incident underscores the critical importance of timely patch management and robust security practices in AI infrastructure. As AI models become integral to business operations, ensuring their security is paramount to prevent data leaks and maintain trust in AI-driven systems.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Near-Autonomous AI Cyberattack on Taiwanese Government in 2026
Impact· CRITICAL

Near-Autonomous AI Cyberattack on Taiwanese Government in 2026

In August 2026, a sophisticated cyberattack targeted the Taiwanese government, marking the first publicly known instance of a near-autonomous AI-driven breach against a state entity. Suspected Chinese hackers employed open-source AI frameworks, Hermes and OpenClaw, to orchestrate the attack, which led to the exfiltration of over 2,500 personnel records. The AI system autonomously adapted during the operation, conducting 'Learning Cycles' to identify vulnerabilities and expanding its reach to government IT supply chain vendors, a nuclear safety agency, and multiple energy sector companies. This incident underscores the escalating use of AI in cyber warfare, highlighting the need for enhanced defensive measures against autonomous threats. The attack's ability to self-correct and adapt without human intervention signifies a paradigm shift in cyberattack methodologies, necessitating a reevaluation of current cybersecurity strategies to address AI-driven threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Unmasking the Threat: North Korean IT Worker Impersonation in 2026
Impact· HIGH

Unmasking the Threat: North Korean IT Worker Impersonation in 2026

In July 2026, the U.S. Department of State issued an alert regarding North Korean IT workers impersonating foreign nationals to secure remote employment with U.S. companies. These operatives utilized falsified identities, AI-generated profiles, and deepfake technologies to bypass standard hiring processes. Once employed, they exfiltrated sensitive data, including source code and proprietary information, and funneled salaries back to North Korea, thereby circumventing international sanctions and funding the regime's activities. This incident underscores the evolving sophistication of social engineering tactics in cyber threats. The integration of AI and deepfake technologies into these schemes highlights the urgent need for organizations to enhance their identity verification and remote hiring protocols to prevent similar infiltrations.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Adobe Commerce Vulnerability CVE-2026-71362: Immediate Action Required
Impact· CRITICAL

Critical Adobe Commerce Vulnerability CVE-2026-71362: Immediate Action Required

In August 2026, a critical vulnerability (CVE-2026-71362) was identified in Adobe's Commerce and Magento platforms, allowing unauthenticated attackers to hijack customer accounts. The flaw, stemming from improper handling of customer identity in session management, enabled unauthorized access to sensitive customer data. Security firm Sansec reported active exploitation attempts, emphasizing the urgency for immediate patching. This incident underscores the persistent threat posed by web application vulnerabilities, highlighting the necessity for robust session management and prompt application of security updates to protect customer information and maintain trust.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Hundreds of Fake Chrome VPN Extensions Compromise User Security
Impact· MEDIUM

Hundreds of Fake Chrome VPN Extensions Compromise User Security

In August 2026, researchers uncovered a campaign involving over 737 malicious Chrome browser extensions that impersonated reputable VPN services such as Proton VPN, NordVPN, and ExpressVPN. These extensions, downloaded nearly 75,000 times primarily by Russian users, rerouted all browser traffic through SOCKS5 proxies controlled by a single operator. This setup allowed the threat actor to monitor users' browsing activities, including destination URLs and any unencrypted data transmitted over HTTP. The extensions employed deceptive tactics, including advertising non-existent premium server locations and using misleading disclosures to evade detection. Despite Google's removal of over 200 of these extensions, more than 500 remained available in the Chrome Web Store at the time of discovery. This incident underscores the persistent threat posed by malicious browser extensions and highlights the need for vigilant scrutiny of browser add-ons. Users are advised to verify the authenticity of extensions before installation and to regularly review and manage their browser's proxy settings to prevent unauthorized data interception.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Understanding the 'Plug and Pwn' Attack: A New Threat to Windows Systems
Impact· HIGH

Understanding the 'Plug and Pwn' Attack: A New Threat to Windows Systems

In August 2026, security researchers unveiled the 'Plug and Pwn' attack, exploiting Windows' Plug and Play feature to gain SYSTEM privileges by emulating USB devices. By presenting fake USB hardware, attackers could trigger Windows to install vulnerable vendor software automatically, leading to unauthorized access. Notably, some attack vectors required no user interaction or physical device connection, utilizing Remote Desktop Protocol (RDP) to achieve the same outcome. This method underscores significant vulnerabilities in Windows' device installation processes, potentially allowing attackers to execute arbitrary code with elevated privileges. The 'Plug and Pwn' attack highlights the evolving sophistication of hardware-based exploits and the critical need for organizations to reassess endpoint security measures. As attackers increasingly leverage legitimate system functionalities for malicious purposes, it becomes imperative to implement stringent device installation policies and monitor for anomalous hardware behaviors to mitigate such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports