Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

3197 threat reports
Page 34 of 267

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Information Technology/IT Threat Reports

Showing 397408 / 3197 reports
Microsoft's August 2026 Patch Tuesday: Addressing 398 Security Vulnerabilities
Impact· HIGH

Microsoft's August 2026 Patch Tuesday: Addressing 398 Security Vulnerabilities

In August 2026, Microsoft released patches for 398 security vulnerabilities across its Windows operating systems and supported software. Among these, CVE-2026-68820, a privilege escalation flaw in the afd.sys component, was actively exploited. This vulnerability allows attackers to elevate privileges by exploiting race conditions in the Windows socket driver. Additionally, two other vulnerabilities, CVE-2026-62832 and CVE-2026-72971, were publicly disclosed prior to the patch release, highlighting the critical need for timely updates. The increasing volume of vulnerabilities, attributed to AI-driven discovery methods, underscores the necessity for organizations to enhance their patch management processes. The active exploitation of CVE-2026-68820 emphasizes the urgency of applying these patches promptly to mitigate potential security breaches.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
LiteLLM Supply Chain Attack: A Wake-Up Call for Open-Source Security
Impact· HIGH

LiteLLM Supply Chain Attack: A Wake-Up Call for Open-Source Security

In March 2026, versions 1.82.7 and 1.82.8 of LiteLLM, an open-source AI gateway, were compromised and published on PyPI. These versions contained credential-stealing code capable of harvesting sensitive information such as cloud keys, SSH keys, Kubernetes tokens, and database passwords. The malicious packages were available for approximately 40 minutes before being quarantined. Subsequent analysis by CloudSEK revealed that the attackers had exfiltrated data from approximately 2,500 organizations, including major corporations like NVIDIA, Cisco, Deloitte, Volkswagen, FedEx, Siemens, and X Corp. This incident underscores the escalating threat of supply chain attacks targeting widely used open-source components. Organizations are urged to implement stringent security measures, including regular audits of third-party dependencies, to mitigate the risk of similar breaches.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Global Exploitation of VMware vCenter Vulnerability CVE-2026-59310
Impact· CRITICAL

Global Exploitation of VMware vCenter Vulnerability CVE-2026-59310

In early August 2026, threat actors began exploiting CVE-2026-59310, a critical directory-traversal vulnerability in VMware vCenter Server, allowing unauthenticated remote code execution. Despite Broadcom's release of patches in late July, attackers leveraged this flaw to deploy persistent access mechanisms, notably using reverse_ssh to maintain control over compromised systems. The campaign affected 361 unique IP addresses across 47 countries, with significant concentrations in Germany, the U.S., Turkey, Iran, and France. This incident underscores the rapid weaponization of disclosed vulnerabilities by advanced persistent threat actors, emphasizing the necessity for organizations to promptly apply security patches and monitor for unauthorized outbound connections indicative of compromise.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Enterprise Defenses: Strong Perimeter, Weak Interior
Impact· MEDIUM

Enterprise Defenses: Strong Perimeter, Weak Interior

In the first half of 2026, Picus Labs conducted over 338 million attack simulations across client production environments, revealing a significant disparity in defense effectiveness. While perimeter defenses showed improvement, blocking approximately 69% of attacks, internal defenses were notably weaker, with a post-compromise prevention rate of only 37%. This indicates that once attackers breach the perimeter, they face minimal resistance, especially during reconnaissance and credential theft phases. This trend underscores the urgent need for organizations to bolster internal security measures. As attackers increasingly employ stealthy techniques to evade detection, focusing solely on perimeter defenses is insufficient. Enhancing internal monitoring and response capabilities is crucial to mitigate the risks associated with these evolving threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Adds Three Known Exploited Vulnerabilities to Catalog
Impact· CRITICAL

CISA Adds Three Known Exploited Vulnerabilities to Catalog

On August 11, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. The vulnerabilities are: CVE-2026-20349 affecting Cisco Secure Firewall ASA and FTD, CVE-2026-68820 in Microsoft Windows Ancillary Function Driver for WinSock, and CVE-2026-72898 in Metabase. These vulnerabilities are frequently targeted by malicious actors and pose significant risks to federal enterprises. CISA's Binding Operational Directive (BOD) 26-04 mandates federal agencies to prioritize remediation of high-risk vulnerabilities listed in the KEV Catalog. While BOD 26-04 applies to federal agencies, CISA encourages all organizations to adopt risk-based vulnerability management practices and address these vulnerabilities promptly.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Massive Discovery: 737 Malicious Chrome VPN Extensions Compromising User Security
Impact· MEDIUM

Massive Discovery: 737 Malicious Chrome VPN Extensions Compromising User Security

In August 2026, security researchers uncovered 737 malicious Chrome VPN and proxy extensions primarily targeting Russian-speaking users. These extensions, published across at least 40 developer accounts, amassed over 75,000 installs. They impersonated 66 established VPN brands, including Proton VPN, NordVPN, and ExpressVPN, to lure users. Once installed, the extensions routed users' entire browser sessions through SOCKS5 proxies controlled by the threat actors, enabling them to intercept and monitor all browser traffic. This adversary-in-the-middle (AitM) position allowed the attackers to observe browser destinations, source IP addresses, TLS SNI values, and any unencrypted HTTP request bodies. This incident underscores the growing sophistication of cyber threats targeting browser extensions. The attackers' ability to impersonate reputable VPN services highlights the need for users to exercise caution when installing browser add-ons. It also emphasizes the importance of robust vetting processes within browser extension marketplaces to prevent the distribution of malicious software.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical API Flaw in Leading AI Models Exposes Sensitive Data
Impact· MEDIUM

Critical API Flaw in Leading AI Models Exposes Sensitive Data

In August 2026, researchers identified a vulnerability in the API implementations of OpenAI, Anthropic, and Google, allowing weaker AI models to decode encrypted reasoning traces from stronger models. This flaw enabled the extraction of sensitive information, including API keys and passwords, from session logs. The issue stemmed from the portability of encrypted reasoning objects across sessions and models, which could be exploited to reveal hidden content. The affected companies have since implemented mitigations to address this vulnerability. This incident underscores the critical importance of securing AI model APIs and the potential risks associated with encrypted reasoning objects. It highlights the need for developers to sanitize shared traces and avoid exposing raw API transcripts, even when visible text appears safe.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Metabase CVE-2026-72898: Critical SQL Injection Vulnerability Exposed
Impact· CRITICAL

Metabase CVE-2026-72898: Critical SQL Injection Vulnerability Exposed

In August 2026, a critical unauthenticated SQL injection vulnerability (CVE-2026-72898) was discovered in Metabase's password reset functionality. This flaw allows remote attackers to execute arbitrary SQL commands against the Metabase application database without authentication, potentially leading to full administrative access and data exfiltration. Metabase has confirmed active exploitation of this vulnerability in the wild, emphasizing the urgency for immediate remediation. The rapid exploitation of CVE-2026-72898 underscores a growing trend of attackers swiftly leveraging newly disclosed vulnerabilities. Organizations must prioritize timely patching and adopt proactive security measures to mitigate risks associated with such critical flaws.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Gunra Ransomware's Escalating Threat to Government Agencies in 2026
Impact· CRITICAL

Gunra Ransomware's Escalating Threat to Government Agencies in 2026

In August 2026, U.S. federal agencies and South Korea's National Policy Agency issued a joint advisory warning government and critical infrastructure organizations worldwide about the Gunra ransomware group's activities. Emerging in April 2025, Gunra utilizes a double-extortion model, encrypting data and threatening public disclosure to coerce ransom payments. The group exploits vulnerabilities in Fortinet firewalls (CVE-2024-55591 and CVE-2025-24472) and SSH access controls in VPN gateways to gain initial access. Initially targeting Windows systems, Gunra expanded to cross-platform attacks with a Linux variant introduced in mid-2025. In January 2026, they launched a ransomware-as-a-service (RaaS) platform, recruiting affiliates and initial access brokers to broaden their reach. This advisory underscores the escalating threat posed by Gunra, especially to government and critical infrastructure sectors. The group's rapid evolution, from leveraging leaked Conti ransomware code to establishing a RaaS platform, highlights the increasing sophistication and commercialization of ransomware operations. Organizations are urged to patch known vulnerabilities, implement network segmentation, and maintain offline backups to mitigate potential attacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Cisco ASA and FTD VPN Vulnerability CVE-2026-20349: Immediate Action Required
Impact· HIGH

Critical Cisco ASA and FTD VPN Vulnerability CVE-2026-20349: Immediate Action Required

In August 2026, Cisco disclosed a high-severity denial-of-service (DoS) vulnerability, identified as CVE-2026-20349, affecting Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software. This flaw allows unauthenticated, remote attackers to crash affected devices by sending crafted HTTP requests to the Remote Access SSL VPN service. Exploitation results in device reloads, causing significant operational disruptions. The active exploitation of CVE-2026-20349 underscores the critical need for organizations to promptly apply security patches. This incident highlights the persistent threat landscape targeting network infrastructure and the importance of maintaining up-to-date defenses to mitigate potential attacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Sandworm's Sophisticated Attack: Trojanized WireGuard VPN Client Targets IT Professionals
Impact· HIGH

Sandworm's Sophisticated Attack: Trojanized WireGuard VPN Client Targets IT Professionals

In May 2026, the Russian state-sponsored hacking group Sandworm, specifically its sub-cluster UAC-0145, initiated a sophisticated social engineering campaign targeting IT professionals. Posing as recruiters from reputable IT firms, they engaged victims through fake job offers, leading to interviews conducted over Zoom. During these sessions, candidates were instructed to download a trojanized WireGuard VPN client named 'SopraVPN' from a deceptive SourceForge page. This malicious software, once installed, executed embedded PowerShell code, enabling the attackers to establish persistent access to the victims' systems. The campaign's primary objective was to infiltrate and compromise critical infrastructure and government entities, leveraging the trust and technical expertise of IT professionals to gain unauthorized access to sensitive networks. This incident underscores the evolving tactics of nation-state actors, who are increasingly employing advanced social engineering techniques to bypass traditional security measures. Organizations must remain vigilant, ensuring that their recruitment processes are secure and that employees are educated about potential cyber threats. The use of trojanized software in targeted attacks highlights the necessity for robust endpoint detection and response solutions to detect and mitigate such sophisticated threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Project CAV3RN's Evolving Tactics: Leveraging Google Apps Script and DNS for Stealthy C2
Impact· LOW

Project CAV3RN's Evolving Tactics: Leveraging Google Apps Script and DNS for Stealthy C2

In August 2026, Kaspersky researchers identified an evolution in the Project CAV3RN cyberespionage framework, which has been targeting Israeli organizations since December 2025. The latest development involves a sophisticated command-and-control (C2) module that utilizes Google Apps Script as a relay and employs DNS-based mechanisms for C2 channel selection. This approach allows the malware to blend its communication with legitimate network traffic, thereby evading traditional detection methods. The framework's modular design and rapid development indicate a persistent and adaptable threat. The significance of this incident lies in the increasing trend of threat actors leveraging legitimate cloud services to obfuscate malicious activities. By integrating Google Apps Script and DNS-based techniques, Project CAV3RN exemplifies the challenges in distinguishing between normal and malicious network behavior, underscoring the need for advanced detection strategies.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports