Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Russian Hackers Exploit WebEx and Zoom Installers to Deploy Starland RAT
In June 2025, the Russian threat actor UAT-11795 initiated a campaign targeting users primarily in the United States, with additional victims in Germany, Romania, and Venezuela. The attackers distributed trojanized installers of legitimate software, including WebEx and Zoom, to deploy the Starland RAT malware. This backdoor enabled the exfiltration of browser data, cryptocurrency wallet assets, system details, and Active Directory information. The malware also facilitated remote command execution, screenshot capture, and the deployment of additional payloads such as CastleStealer and Remcos RAT. This incident underscores the increasing sophistication of supply chain attacks, where trusted software is weaponized to infiltrate systems. The use of trojanized installers highlights the critical need for organizations to enforce strict software sourcing policies and to educate users on the risks of downloading software from unofficial sources.
2 months ago
Kill Chain
23andMe Data Breach: A Wake-Up Call for Credential Security
In October 2023, genetic testing company 23andMe disclosed a significant data breach resulting from credential-stuffing attacks that went undetected for five months, from April to September 2023. Attackers exploited reused passwords to access approximately 14,000 user accounts, subsequently exposing sensitive genetic and personal information of 6.9 million customers. This data was later found for sale on the dark web, raising serious privacy concerns. The incident underscores the critical importance of robust cybersecurity measures, including the implementation of multi-factor authentication and proactive monitoring systems. Organizations handling sensitive data must prioritize these defenses to prevent similar breaches and protect consumer trust.
2 months ago
Kill Chain
ClickLock: The New macOS Malware Exploiting User Trust
In July 2026, cybersecurity researchers identified a new macOS malware named ClickLock, which employs social engineering tactics to deceive users into revealing their system login passwords. The malware initiates by presenting a fake Cloudflare 'human verification' prompt, leading users to execute a command in the Terminal. This action triggers the download of malicious modules that disable keyboard interrupts and suppress system notifications. Subsequently, ClickLock displays a counterfeit macOS password dialog, coercing users into entering their credentials. Upon obtaining the password, the malware exfiltrates sensitive data, including login credentials, cryptocurrency assets, and browser information, to the attackers via Telegram. Additionally, it installs a persistent backdoor, granting ongoing remote access to the compromised systems. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-clicklock-macos-malware-traps-users-into-revealing-login-password/?utm_source=openai)) The emergence of ClickLock underscores a growing trend in macOS-targeted malware leveraging sophisticated social engineering techniques. This incident highlights the necessity for heightened user awareness and the implementation of robust security measures to counteract such deceptive attacks.
2 months ago
Kill Chain
GoSerpent Backdoor: A Persistent Threat to Southeast Asian Governments
The GoSerpent campaign is a sophisticated, multi-stage attack targeting government and diplomatic entities in Southeast Asia since at least 2021, with evolved variants deployed through 2026. The Go-based GoSerpent backdoor establishes persistent access and deploys ThumbcacheService for document collection, Mimikatz and QuarksDumpLocalHash for credential dumping, and later stages use Stowaway RAT and TmcLoader/TmcPayload to exfiltrate collected data via network shares using stolen credentials. The tight integration between collection, credential theft, and exfiltration components demonstrates advanced operational planning and long-term intelligence gathering objectives.
2 months ago
Kill Chain
Scattered Spider Hackers Sentenced for 2024 TfL Cyberattack
Between August 31 and September 3, 2024, Transport for London (TfL) experienced a significant cyberattack orchestrated by the Scattered Spider hacking group. The attackers, Thalha Jubair and Owen Flowers, exploited social engineering techniques to infiltrate TfL's network, leading to the compromise of personal data belonging to approximately 10 million customers. The breach resulted in substantial operational disruptions, including the inoperability of 148 systems and the necessity for all 27,000 employees to reset their passwords in person. The financial impact was severe, with losses and recovery costs totaling £29 million. ([nationalcrimeagency.gov.uk](https://www.nationalcrimeagency.gov.uk/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted?utm_source=openai)) This incident underscores the escalating threat posed by sophisticated cybercriminal groups employing advanced social engineering tactics. Organizations must prioritize robust cybersecurity measures, including comprehensive employee training and the implementation of phishing-resistant multi-factor authentication, to mitigate the risks associated with such attacks.
2 months ago
Kill Chain
Identity Attacks Surpass Exploits as Leading Ransomware Cause in 2026
In 2026, identity-based attacks emerged as the leading cause of ransomware incidents, surpassing traditional vulnerability exploits. According to Sophos' State of Ransomware 2026 report, malicious emails (26%) and phishing (24%) accounted for half of all ransomware attack vectors, while exploited vulnerabilities declined to 18%. Notably, 67% of victims identified the ransomware attack as their most significant identity-related breach of the year. Despite the deployment of multifactor authentication (MFA) in 97% of credential-based attacks, these measures failed to prevent compromises, highlighting gaps in implementation and the evolving sophistication of attackers. This shift underscores the critical need for organizations to enhance their identity security frameworks. The prevalence of identity-driven attacks necessitates a reevaluation of current security protocols, emphasizing advanced email filtering, comprehensive MFA deployment, and regular phishing awareness training to mitigate the rising threat landscape.
2 months ago
Kill Chain
Critical Unpatched Flaw in Shark Vacuums Highlights IoT Security Risks
In July 2026, a critical security vulnerability was discovered in Shark RV2320EDUS robot vacuums, allowing attackers to remotely execute commands on other Shark vacuums within the same AWS region. By extracting the device certificate from the vacuum's flash storage, an attacker could gain root access to other devices, enabling actions such as controlling the vacuum's movements, accessing onboard cameras, retrieving home maps, and obtaining Wi-Fi credentials in plaintext. The flaw was reported to SharkNinja in March 2026 but remained unpatched as of the disclosure. This incident underscores the escalating risks associated with IoT devices, particularly those with inadequate security configurations. The ability to exploit a single device to compromise an entire network of similar devices highlights the urgent need for robust security measures in IoT device design and deployment.
2 months ago
Kill Chain
PhantomEnigma: Cyberattack Compromises Brazilian Government Websites
In July 2026, cybersecurity analysts uncovered a campaign named PhantomEnigma, which exploited over 20 Brazilian government websites to distribute malware targeting banking and public-sector organizations. Attackers compromised legitimate .gov.br domains and email accounts, enabling them to bypass security protocols and deliver malicious payloads through trusted channels. This operation utilized modular malware and frequently rotated infrastructure, complicating detection and mitigation efforts. The campaign's sophistication underscores the critical need for robust cybersecurity measures to protect sensitive government and financial data. The PhantomEnigma incident highlights a growing trend of cybercriminals leveraging trusted government infrastructure to conduct attacks, increasing the difficulty of detection and response. This case serves as a stark reminder for organizations to enhance their security postures, particularly in monitoring and securing official digital platforms against such sophisticated threats.
2 months ago
Kill Chain
TELEPUZ Malware Exploits ClickFix to Compromise Systems
In late April 2026, a new modular malware named TELEPUZ began spreading through websites compromised with ClickFix lures. This malware, written in C, is lightweight and modular, indicating active development by a small team or solo developer. The infection chain starts with a ClickFix social engineering lure that downloads and executes a second-stage VIDAR Go variant, leading to the deployment of TELEPUZ. The malware employs various obfuscation techniques, including garbage instructions, import name hashing, string encryption, and indirect system calls, to evade detection. It also performs anti-VM and geolocation checks to avoid execution in sandboxed environments or unauthorized geographic locations. Once active, TELEPUZ disables security monitoring by unhooking NTDLL, turning off Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW), and removing third-party DllNotification callbacks. The malware's modular design allows it to download additional components, such as keyloggers, stealers, and web injectors, enhancing its capabilities to steal sensitive data and execute arbitrary commands on infected systems. The rapid pace of updates and the steady volume of daily builds uploaded to VirusTotal suggest that TELEPUZ is likely offered under a malware-as-a-service (MaaS) model, posing a significant threat to organizations and individuals alike. The emergence of TELEPUZ highlights the evolving sophistication of malware campaigns leveraging social engineering techniques like ClickFix. The use of modular malware-as-a-service models enables rapid development and deployment of new threats, making it imperative for organizations to stay vigilant and implement robust security measures to detect and prevent such infections.
2 months ago
Kill Chain
ThreatsDay: July 2026 Cybersecurity Incidents Unveiled
In July 2026, multiple cybersecurity incidents emerged, including malicious NuGet packages masquerading as game cheats to deploy spyware, trojanized installers delivering remote access tools, and cyberstalkers exploiting Chrome Sync to monitor victims' browsing activities. These attacks leveraged familiar tools and settings to infiltrate systems, leading to unauthorized data access and potential financial losses. The incidents underscore a trend where attackers repurpose legitimate tools and features for malicious purposes, highlighting the need for heightened vigilance and robust security measures to protect against evolving threats.
2 months ago
Kill Chain
Critical n8n Token Exchange Flaw (CVE-2026-59208) Exposes User Accounts
In June 2026, a critical vulnerability (CVE-2026-59208) was identified in n8n's Enterprise instances, specifically affecting configurations that trust multiple external token issuers. The flaw allowed attackers to authenticate as users from different issuers by exploiting the platform's reliance on the 'sub' claim in JSON Web Tokens (JWTs) while ignoring the 'iss' claim. This oversight enabled unauthorized access to user accounts without requiring their passwords. n8n addressed the issue with a patch released on June 24, 2026. This incident underscores the importance of robust identity verification mechanisms in multi-issuer environments. As organizations increasingly integrate third-party authentication systems, ensuring comprehensive validation of token claims becomes crucial to prevent unauthorized access and potential data breaches.
2 months ago
Kill Chain
Cato Networks' 2026 Research Highlights the Importance of AI Harnesses in Cybersecurity
In July 2026, Cato Networks conducted research demonstrating the significant impact of integrating Large Language Models (LLMs) with bespoke cybersecurity harnesses. By pairing OpenAI's ChatGPT 5.5 and GPT 5.5-Cyber models with their proprietary tool, Cato Networks achieved complete end-to-end attack chains, including domain administrator privileges and Active Directory access, in as little as 40 minutes. This research underscores the critical role of technical harnesses in guiding LLMs to perform complex cybersecurity tasks autonomously. The findings highlight the necessity for organizations to develop and implement tailored AI harnesses to effectively manage and direct LLMs in cybersecurity operations. As AI-enabled hacking becomes more prevalent, the ability to control and optimize these models through specialized harnesses is essential for maintaining robust security postures.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports