Validated Containment Architectures are here. →Explore

Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

3036 threat reports
Page 5 of 253

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Information Technology/IT Threat Reports

Showing 4960 / 3036 reports
Russian Cybercriminal Extradited for Massive Excel Malware Campaign
Impact· MEDIUM

Russian Cybercriminal Extradited for Massive Excel Malware Campaign

Russian national Searzhudin Tamirlanovich Aktulaev, 40, has been charged by the U.S. Department of Justice for orchestrating a sophisticated malware campaign between 2016 and 2017. Aktulaev created approximately 255 fake accounts on a freelance platform and distributed malware-laced Excel attachments to roughly 80,000 users. The attack leveraged social engineering tactics within trusted business communications to deliver malicious payloads, potentially compromising thousands of victims' systems and data. Aktulaev was arrested in Cyprus in May 2025 and extradited to the United States on August 28, 2026. This case highlights the persistent threat of nation-state actors exploiting trusted platforms and file formats for malware distribution, particularly as cybercriminals increasingly target business communication channels and use legitimate services as attack vectors in 2026's evolving threat landscape.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SonicWall SMA 1000 Zero-Day Attack Chain: CVE-2026-83548 & CVE-2026-83549 Analysis
Impact· CRITICAL

SonicWall SMA 1000 Zero-Day Attack Chain: CVE-2026-83548 & CVE-2026-83549 Analysis

In September 2026, SonicWall disclosed two zero-day vulnerabilities (CVE-2026-83548 and CVE-2026-83549) in its Secure Mobile Access 1000 series VPN appliances that were actively exploited by attackers. The vulnerabilities allow threat actors to chain a pre-authentication server-side request forgery (SSRF) flaw with a post-authentication command injection vulnerability to achieve remote code execution on affected devices. SonicWall confirmed active exploitation and recommended immediate patching, system reimaging if compromised, and password resets for all affected appliances. This incident highlights the continued targeting of enterprise VPN infrastructure by sophisticated threat actors, reflecting a broader trend of attacks against network perimeter devices that became critical during remote work adoption and remain attractive targets for initial access operations.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
BGP Hijacking Enables Virtualizor Supply Chain Compromise
Impact· HIGH

BGP Hijacking Enables Virtualizor Supply Chain Compromise

In late August 2026, attackers executed a sophisticated supply chain attack against Virtualizor, a popular virtualization management platform, by hijacking Border Gateway Protocol (BGP) routes to redirect software update traffic. The attack occurred between August 28-30, 2026, when threat actors diverted Softaculous traffic to attacker-controlled servers and delivered malicious Virtualizor updates that established persistent root access on affected systems. At least 5 of 34 hypervisors at one hosting provider were compromised, with attackers installing backdoors, creating unauthorized accounts, and maintaining persistence through systemd services. This incident highlights the growing sophistication of supply chain attacks targeting critical infrastructure management software. As organizations increasingly rely on automated software updates and third-party platforms for cloud operations, attackers are exploiting trust relationships and network-level vulnerabilities to achieve widespread compromise with minimal detection.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
GitSpawn Attacks Target AI Coding Agents: CVE-2026-19592 Analysis
Impact· HIGH

GitSpawn Attacks Target AI Coding Agents: CVE-2026-19592 Analysis

In September 2026, Manifold Security disclosed eight critical vulnerabilities across seven AI coding agents including Claude Code, Codex, and Cursor, where malicious Git configurations could execute attacker code without user approval. The flaws exploit the core.fsmonitor Git setting, allowing repository-supplied commands to run with full user privileges outside sandbox environments. Four vulnerabilities remained unpatched at publication, affecting popular development tools used by millions of developers worldwide. This incident highlights the growing security risks in AI-powered development environments as organizations increasingly adopt autonomous coding agents. With the rapid expansion of AI tooling in software development workflows, similar supply-chain attacks targeting developer infrastructure represent a critical emerging threat vector requiring immediate attention.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
First Major AI-Assisted Ransomware Attack: How Frontier AI Agents Executed 50+ Attack Techniques in 10 Hours
Impact· HIGH

First Major AI-Assisted Ransomware Attack: How Frontier AI Agents Executed 50+ Attack Techniques in 10 Hours

In September 2026, Unit 42 investigators responded to a groundbreaking ransomware attack where threat actors deployed frontier AI agents to autonomously breach an enterprise network in under 10 hours. The attackers used multiple AI agents working in parallel to compress traditional multi-week intrusion operations, executing over 50 MITRE ATT&CK techniques including network reconnaissance, secrets harvesting, privilege escalation, CI/CD pipeline exploitation, and cloud infrastructure hijacking. The AI-driven attack achieved the operational impact of multiple coordinated red teams while leaving behind an 80-page technical security audit documenting exploited vulnerabilities. This incident represents a critical inflection point in cybersecurity, demonstrating how threat actors are weaponizing frontier AI and agentic frameworks to dramatically accelerate attack timelines and operational efficiency, marking the emergence of machine-speed cyber operations as a mainstream threat vector.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Silver Fox Supply Chain Attack: How Counterfeit Software Sites Compromise Enterprise Networks
Impact· HIGH

Silver Fox Supply Chain Attack: How Counterfeit Software Sites Compromise Enterprise Networks

Microsoft Defender Experts has identified an active malware campaign using counterfeit software download websites to distribute malicious installers targeting organizations across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The campaign primarily affects China-based operations and Chinese-speaking users through high-fidelity clones of legitimate vendor sites offering popular software downloads. Once executed, the malicious installers deploy persistent malware that weakens security protections, establishes command and control connections, and enables potential data exfiltration through encrypted channels. This incident highlights the growing sophistication of supply chain attacks targeting software distribution channels, coinciding with increased regulatory focus on software supply chain security and the rise of AI-powered security evasion techniques.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Langflow Vulnerability CVE-2026-0768 Exploited to Steal AI and Cloud Credentials
Impact· MEDIUM

Critical Langflow Vulnerability CVE-2026-0768 Exploited to Steal AI and Cloud Credentials

Threat actors are actively exploiting CVE-2026-0768, a critical unauthenticated remote code execution vulnerability in Langflow, an open-source AI application development framework. The flaw allows attackers to execute arbitrary Python code with root privileges without authentication, enabling them to steal sensitive credentials including OpenAI API keys, AWS secrets, and administrative authentication tokens. VulnCheck detected over 360 exploitation attempts originating primarily from Russia, with attackers conducting reconnaissance and harvesting environment variables from compromised instances. This incident highlights the growing trend of AI infrastructure targeting as organizations rapidly adopt AI development platforms without adequate security controls, making them prime targets for credential theft and supply chain attacks.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Faronics Deploy Platform Exploited in Sophisticated ScreenConnect RAT Campaign
Impact· MEDIUM

Faronics Deploy Platform Exploited in Sophisticated ScreenConnect RAT Campaign

Between July and August 2026, cybercriminals exploited the legitimate Faronics Deploy endpoint management platform to gain unauthorized administrative control over victim computers. The attackers used phishing emails disguised as invoices and tax documents to trick users into downloading a legitimate but malicious Faronics Deploy installer. Once installed, the threat actors remotely executed PowerShell scripts to deploy ConnectWise ScreenConnect remote access software, establishing persistent backdoor access to over 457 endpoints across multiple organizations. This incident highlights the growing trend of Living-off-the-Land (LotL) attacks where cybercriminals abuse legitimate administrative tools to bypass traditional security controls and establish covert command-and-control channels.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Breeze Comet's Sophisticated Attack on Brazilian Payment Systems Exposes Critical Infrastructure Vulnerabilities
Impact· HIGH

Breeze Comet's Sophisticated Attack on Brazilian Payment Systems Exposes Critical Infrastructure Vulnerabilities

Since 2024, the financially motivated threat actor Breeze Comet (formerly UNC5669) has targeted Brazilian financial services, retail, and e-commerce organizations through sophisticated payment system manipulation attacks. The group gains initial access via password spraying and social engineering calls impersonating IT support to install remote access tools like AnyDesk, then deploys custom malware including COBALTSPIN, LIGHTPAINT, and MILDFROST to maintain persistence and lateral movement. Successfully executing hundreds of fraudulent transactions worth tens of thousands of dollars, the group specifically targets entities with access to Brazil's National Financial System Network and payment platforms like Pix, STR, and Boleto. This campaign represents a significant evolution in Latin American cybercrime from opportunistic retail fraud to direct targeting of core financial infrastructure. The threat actor's use of AI-assisted malware development and expansion into other Latin American and African countries signals a new model for financially motivated attacks that defenders must prepare for as interconnected payment ecosystems become increasingly vulnerable.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
How Mirage Kitten's NodeRabbit Malware Exploited Developer Trust in 2024
Impact· HIGH

How Mirage Kitten's NodeRabbit Malware Exploited Developer Trust in 2024

In 2024, Iranian APT group Mirage Kitten launched sophisticated social engineering campaigns targeting aviation and fintech sectors across the Middle East and Africa using two new cross-platform malware families: NodeRabbit and PollCat. The threat actors posed as recruiters on LinkedIn, delivering trojanized coding challenges that contained Node.js-based remote access trojans capable of running on Windows, Linux, and macOS. The malware established persistence through multiple mechanisms and communicated with command-and-control infrastructure hosted on Azure and Cloudflare, affecting organizations in Egypt, Ethiopia, and Afghanistan. This campaign represents a significant evolution in nation-state tactics, showcasing how APT groups are adapting to target developer communities through increasingly sophisticated supply chain attacks and social engineering techniques that exploit trust in professional recruitment processes.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical JFrog Artifactory Vulnerability Exploited Days After Disclosure
Impact· CRITICAL

Critical JFrog Artifactory Vulnerability Exploited Days After Disclosure

On August 28, 2026, JFrog patched CVE-2026-82329, a critical authentication bypass vulnerability in Artifactory with a CVSS score of 9.8. Within days of disclosure, threat actors began actively exploiting the flaw to mint administrative tokens and gain unauthorized access to software repositories. The vulnerability affects default configurations across multiple Artifactory versions and requires no authentication or user interaction. Attackers can forge access credentials through a phantom join key mechanism in JFrog Access, enabling them to enumerate users, compromise build pipelines, and potentially poison the entire software supply chain. This incident represents another example of the accelerating timeline from vulnerability disclosure to active exploitation, particularly targeting critical infrastructure components. The rapid weaponization of supply chain vulnerabilities highlights the growing sophistication of threat actors and their focus on high-impact targets that can compromise multiple downstream organizations.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
TerminalFix Campaign Exposes Enterprise Vulnerability to PowerShell Social Engineering
Impact· HIGH

TerminalFix Campaign Exposes Enterprise Vulnerability to PowerShell Social Engineering

The TerminalFix campaign represents a sophisticated evolution of ClickFix social engineering attacks, targeting enterprise networks through fake Cloudflare CAPTCHA overlays that trick users into executing malicious PowerShell commands. First documented by Microsoft researchers in August 2026, this multistage attack establishes persistent access through DLL sideloading, steganographic payloads hidden in PNG images, and Python-based reverse tunnels that provide direct access to internal networks. The campaign has successfully compromised organizations across multiple industries, with attackers leveraging this access for privilege escalation, security control bypass, data exfiltration, and ransomware deployment. This incident highlights the growing sophistication of social engineering attacks that bypass traditional security controls by manipulating user trust and exploiting legitimate system tools like PowerShell for malicious purposes.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports