✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
How Law Enforcement Finally Defeated the 23-Year Sality Botnet Empire
The Sality botnet, a Russia-based peer-to-peer malware operation that infected over 11 million devices during its 23-year lifespan, was successfully dismantled in January 2025 through a coordinated effort by CrowdStrike, law enforcement agencies, and the Shadowserver Foundation. The botnet's decentralized architecture, which historically made it resilient against takedown attempts, was ultimately exploited by researchers who manipulated its peer-to-peer communication system to permanently sever operator control. The operation involved domain seizures coordinated by the FBI, Justice Department, and European authorities, marking the end of one of the longest-running criminal botnets in cybersecurity history. This takedown demonstrates the evolving capabilities of law enforcement and private security firms to dismantle sophisticated peer-to-peer botnets, signaling a shift in the cybercrime landscape where even decentralized criminal infrastructure is no longer immune to coordinated disruption efforts.
2 days ago
Kill Chain
Global Law Enforcement Dismantles 20-Year Sality Botnet in Coordinated Takedown
In September 2026, international law enforcement agencies including the FBI, DOJ, and European authorities successfully dismantled the Sality botnet infrastructure in a coordinated global operation. The peer-to-peer botnet, active for over two decades and controlled by the Russian cybercriminal group SALTY SPIDER, had infected more than 15,000 devices since 2003. The takedown involved seizing command and control domains across the US and Europe, while CrowdStrike's Counter Adversary Operations team executed a sinkhole operation to isolate infected machines and disrupt the botnet's communication backbone. This takedown reflects the growing effectiveness of international cybercrime cooperation and highlights the persistent threat of long-running botnets that adapt their payloads over time, most recently focusing on cryptocurrency clipjacking attacks through EggJagger malware.
2 days ago
Kill Chain
Russian Cybercriminal Charged in Massive Freelancer Phishing Campaign
Between June 2016 and November 2017, Russian national Searzhudin Tamirlanovich Aktulaev conducted a large-scale phishing campaign targeting freelance workers through a California-based employment platform. Using 255 fake accounts, Aktulaev sent malicious Excel attachments to 80,000 freelancers, deploying TVRAT and DarkVNC malware to gain remote access to victim systems. The malware enabled theft of e-commerce credentials and personally identifiable information, with half of all victims located in the United States. Aktulaev was arrested in Cyprus in May 2025 and extradited to face federal charges. This case demonstrates the persistent threat of credential theft operations targeting gig economy workers and the growing sophistication of Russian cybercriminals exploiting legitimate platforms for large-scale data harvesting campaigns.
2 days ago
Kill Chain
Critical JFrog Artifactory Flaw Enables Supply Chain Attacks Through Forged Admin Tokens
In September 2026, security researchers at watchTowr observed active exploitation of CVE-2026-82329, a critical authentication bypass vulnerability in JFrog Artifactory's default configuration. Attackers exploited this flaw to forge administrative access tokens without authentication, gaining full control over Artifactory instances used by organizations to manage software packages and artifacts. The vulnerability affected self-managed Artifactory deployments and allowed attackers to potentially poison trusted software packages, enumerate users and configurations, and compromise downstream systems that automatically pull artifacts from compromised repositories. This incident highlights the growing threat to software supply chains and the critical importance of securing development infrastructure components. As organizations increasingly rely on automated CI/CD pipelines and artifact repositories, attacks targeting these foundational systems can have cascading effects across entire development ecosystems.
2 days ago
Kill Chain
Active Exploitation of Sangoma Switchvox Flaw Enables Reverse Shell Attacks
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox VoIP platforms that enables remote code execution. Horizon3 researchers discovered this critical flaw among 12 vulnerabilities reported in April 2026, with Sangoma releasing patches in July. Since August 2026, threat actors have systematically targeted the approximately 4,000 internet-exposed Switchvox systems, deploying reverse shells to establish persistent access and exfiltrate system information to remote command-and-control servers. This incident exemplifies the growing threat landscape targeting enterprise communication infrastructure, where VoIP systems have become prime targets for attackers seeking to establish footholds in corporate networks and potentially intercept sensitive communications.
2 days ago
Kill Chain
Critical WordPress Plugin Vulnerability Exposes 5 Million Sites to Complete Takeover
A critical SQL injection vulnerability (CVE-2026-19949) in the All-in-One WP Migration and Backup WordPress plugin exposed over 5 million websites to complete takeover attacks. Security researcher Jack Taylor discovered the second-order SQL injection flaw that allows unauthenticated attackers to plant malicious code through WordPress trackbacks, which executes when administrators perform routine backup operations. The vulnerability enables attackers to expose the plugin's secret import key and upload malicious archives containing executable code, potentially leading to full website compromise. While ServMask patched the issue in version 7.110 on August 20, 2026, approximately 3.25 million sites remain vulnerable as only 35% of users have updated. This incident highlights the growing trend of supply chain attacks targeting widely-used WordPress plugins, emphasizing the critical need for organizations to maintain rigorous plugin update procedures and implement comprehensive application security controls.
2 days ago
Kill Chain
Spring Ring Campaign: How Vishing Attacks Weaponized Microsoft Teams in 2026
Between January and April 2026, the "Spring Ring" threat operation targeted over 150 Microsoft Teams users across 10+ organizations using sophisticated voice phishing (vishing) attacks. Attackers impersonated internal IT support staff through Teams chats, then conducted voice calls to trick employees into installing remote access tools or executing malware. The most advanced variant employed NTLM relay attacks targeting domain controllers for full infrastructure compromise, demonstrating a significant evolution from traditional email phishing to real-time social engineering through trusted collaboration platforms. This incident reflects the accelerating shift toward platform-native attacks as threat actors exploit the inherent trust users place in enterprise collaboration tools. With vishing attacks doubling in the first half of 2026 according to CrowdStrike data, organizations face an urgent need to reassess security controls around identity verification and SaaS platform governance as traditional perimeter defenses prove inadequate against socially-engineered compromise vectors.
2 days ago
Kill Chain
METR AI Security Incident: How $600K in Credentials Were Stolen Through Basic Cloud Hygiene Failures
In March 2026, AI model evaluation nonprofit METR suffered a significant credential theft incident when attackers exploited a fail-open authentication vulnerability in a researcher's AWS instance containing API keys for public AI models. The attackers maintained persistence for three weeks, consuming approximately $600,000 in AI model credits. A separate May incident involved sustained reconnaissance and probing of METR's infrastructure, including attempts to access internal evaluation data through an inadvertently exposed SQL endpoint. Both incidents highlight critical security gaps in AI research organizations handling sensitive frontier model evaluations for major vendors including OpenAI, Anthropic, Google, and Meta. The attacks demonstrate how conventional cloud security failures can lead to substantial financial impact and potential intellectual property exposure in the rapidly evolving AI evaluation ecosystem.
2 days ago
Kill Chain
Critical Langflow CVE-2026-0768 Exploitation Highlights AI Platform Security Risks
CVE-2026-0768, a critical remote code execution vulnerability in Langflow AI development platform, is being actively exploited by threat actors conducting reconnaissance and credential harvesting. The vulnerability, with a 9.8 CVSS score, was disclosed in January 2026 by Trend Micro's ZDI and has since seen sustained exploitation from over 20 IP addresses across multiple countries. Attackers are targeting internet-exposed Langflow installations to extract credentials, conduct lateral movement, and establish persistence mechanisms, with some campaigns showing evidence of hunting for already-backdoored installations. This incident highlights the accelerating threat landscape targeting AI platforms, with Langflow seeing 11 vulnerabilities exploited in 2026 alone compared to just one in previous years. The rapid adoption of AI technologies without security-first principles, combined with Langflow's typical internet-accessible deployment model, creates attractive targets for adversaries seeking access to enterprise networks and sensitive AI infrastructure.
2 days ago
Kill Chain
The Insider Recruitment Crisis: How Ransomware Groups Are Bypassing Zero Trust
Organizations are experiencing a significant surge in insider-assisted ransomware attacks as threat actors increasingly recruit employees to bypass strengthened perimeter defenses. Reports from 2026 indicate a 42% increase in malicious insider incidents, with ransomware groups like Medusa and LockBit 2.0 actively soliciting employees through Dark Web forums, offering up to $15,000 or percentage-based ransom payments for network access. Research by Flashpoint revealed that over 75% of threat actor recruitment posts originated from insiders advertising corporate access to malicious third parties, representing a fundamental shift in attack methodology. This trend reflects the cybersecurity industry's paradoxical success - as organizations implement stronger technical controls and zero-trust architectures, attackers are pivoting to exploit human vulnerabilities through financial incentives and targeting disgruntled employees during layoffs and organizational changes.
2 days ago
Kill Chain
Critical Sangoma Switchvox Vulnerability Exploited for Unauthenticated Remote Access
Threat actors are actively exploiting CVE-2026-9586, a critical SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 with a CVSS score of 9.3. The flaw allows unauthenticated attackers to execute arbitrary code as PostgreSQL superuser without credentials through the /pa endpoint. Despite patches being released in July 2026, exploitation attempts began on August 30, 2026, targeting approximately 4,000 internet-exposed instances primarily in the U.S. Attackers are deploying reverse shells and extracting sensitive data including authentication materials. This incident highlights the growing trend of rapid exploitation of VoIP and communication infrastructure vulnerabilities, as threat actors increasingly target enterprise communication systems that became critical during remote work adoption and often remain inadequately secured.
3 days ago
Kill Chain
Critical GeoNetwork Vulnerabilities Threaten 121 Government Geoportals Worldwide
In July 2026, GeoNetwork, an open-source geospatial metadata catalog used by government agencies worldwide, patched two critical vulnerabilities that could be chained together for unauthenticated remote code execution. CVE-2026-63219 (CVSS 8.6) allows anonymous file uploads to the formatter directory, while CVE-2026-58400 (CVSS 9.1) enables malicious XSLT stylesheets to execute operating system commands through the Saxon transformation engine. Security researcher Rafael Castilho identified 121 exposed instances across 39 countries, with 89% belonging to government, military, or national agencies running the vulnerable software behind critical geoportal infrastructure. This incident highlights the growing targeting of geospatial infrastructure, following recent exploitation of GeoServer vulnerabilities for cryptocurrency mining and backdoor deployment. As governments increasingly digitize spatial data services and critical infrastructure mapping, these specialized systems present attractive targets for nation-state actors and cybercriminals seeking to compromise sensitive geographic intelligence.
3 days ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports