Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
SAP's July 2026 Security Updates: Addressing Critical Vulnerabilities in NetWeaver and Commerce Cloud
In July 2026, SAP released security updates addressing 16 vulnerabilities across multiple products, including three critical flaws in NetWeaver, Commerce Cloud, and Approuter. The most severe, CVE-2026-44747, is a memory corruption issue in NetWeaver Application Server ABAP, potentially leading to unauthorized data access and system unavailability. CVE-2026-27690, an HTTP request smuggling vulnerability in SAP Approuter, could allow unauthenticated attackers to access user responses and trigger denial-of-service attacks. CVE-2026-44761 in SAP Commerce Cloud involves default credentials that enable attackers to obtain valid access tokens and manipulate data via certain APIs. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/sap-warns-of-critical-flaws-in-netweaver-and-commerce-cloud/?utm_source=openai)) These vulnerabilities underscore the critical need for organizations to promptly apply security patches to prevent potential exploitation. The increasing complexity and integration of enterprise software systems make timely updates essential to maintain system integrity and protect sensitive data.
2 months ago
Kill Chain
Phishing Alert: LastPass and Bitwarden Users Targeted in July 2026
In July 2026, a sophisticated phishing campaign targeted users of LastPass and Bitwarden, two prominent password management services. Attackers sent emails from addresses like 'hello@lastpassnewsletter.com' and 'hello@bitwardennewsletter.com', falsely notifying recipients of updated security policies. These emails directed users to fraudulent websites impersonating DocuSign, prompting them to download malicious files purportedly compatible with both Windows and macOS systems. The domains used, such as 'lastpasscompliance[.]com' and 'bitwardencompliance[.]com', were flagged as malicious by security services. LastPass confirmed that its systems remained uncompromised and that the phishing emails did not originate from its infrastructure. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/lastpass-bitwarden-users-targeted-with-fake-security-alerts/?utm_source=openai)) This incident underscores a growing trend of cybercriminals targeting password manager users through sophisticated phishing tactics. The use of legitimate-looking emails and websites to deceive users highlights the need for heightened vigilance and robust security measures. Organizations and individuals must remain alert to such evolving threats to safeguard sensitive information.
2 months ago
Kill Chain
Windows 11 July 2026 Patch Tuesday: Critical Updates and New Features
On July 14, 2026, Microsoft released cumulative updates KB5101650 and KB5099414 for Windows 11 versions 25H2/24H2 and 23H2, respectively. These mandatory updates addressed 571 security vulnerabilities, including three zero-day exploits, and introduced new features such as improved Bluetooth reliability, enhanced Widgets experience, and Point-in-Time restore functionality. The updates also included various performance and reliability improvements across system components, including File Explorer, networking, printing, and accessibility. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5101650-and-kb5099414-cumulative-updates-released/amp/?utm_source=openai)) The release of these updates underscores the ongoing need for organizations to prioritize timely patch management. With the increasing complexity and volume of vulnerabilities, staying current with security updates is essential to protect systems against potential exploits and maintain operational integrity.
2 months ago
Kill Chain
SonicWall SMA1000 Zero-Day Vulnerabilities: Immediate Action Required
In July 2026, SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances: CVE-2026-15409, a server-side request forgery flaw, and CVE-2026-15410, a post-authentication code injection vulnerability. These flaws allowed unauthenticated attackers to make unauthorized requests and authenticated administrators to execute arbitrary OS commands, respectively. Both vulnerabilities were actively exploited in zero-day attacks, prompting SonicWall to release urgent security patches. Organizations utilizing affected SMA1000 models were advised to upgrade to the latest firmware versions immediately and to inspect their systems for indicators of compromise. This incident underscores the persistent targeting of remote access solutions by threat actors, highlighting the necessity for continuous monitoring, timely patching, and comprehensive security measures to protect against evolving cyber threats.
2 months ago
Kill Chain
Microsoft's Unprecedented Patch Tuesday: 622 Vulnerabilities Addressed
On July 14, 2026, Microsoft released patches for a record-breaking 622 vulnerabilities across its product suite, including Windows, Office, Azure, Defender, and SQL Server. Notably, two zero-day vulnerabilities were actively exploited: CVE-2026-56155 in Active Directory Federation Services, allowing local privilege escalation to administrator, and CVE-2026-56164 in SharePoint Server, enabling network-based privilege escalation without authentication. Additionally, a BitLocker security feature bypass (CVE-2026-50661) was publicly disclosed prior to the patch release. ([securityweek.com](https://www.securityweek.com/microsoft-patches-record-622-vulnerabilities-including-two-exploited-zero-days/?utm_source=openai)) This unprecedented volume of patches underscores the increasing complexity of Microsoft's ecosystem and the growing sophistication of threat actors. Organizations are urged to prioritize applying these updates promptly to mitigate potential risks associated with these vulnerabilities.
2 months ago
Kill Chain
Critical Vulnerability in Cursor IDE: Automatic Execution of Malicious Code in Compromised Repositories
In July 2026, a critical vulnerability was discovered in Cursor IDE, an AI-powered coding platform. This flaw allows attackers to embed a malicious 'git.exe' file within a repository. When a developer opens such a compromised project, Cursor automatically executes the malicious binary without any warnings or prompts, leading to potential unauthorized code execution on the developer's machine. Despite being reported to Cursor in December 2025, the vulnerability remains unpatched, posing significant risks to developers using the platform. This incident underscores the growing security challenges associated with AI-assisted development tools. As these platforms become more integrated into software development workflows, they present new attack vectors that can be exploited by threat actors. The lack of prompt remediation highlights the need for developers and organizations to remain vigilant, implement robust security measures, and advocate for timely patches from software vendors to mitigate emerging threats.
2 months ago
Kill Chain
ClickFix Malware Campaign: A 2026 Cybersecurity Wake-Up Call
In early 2026, a significant malware campaign known as 'ClickFix' exploited a critical vulnerability in the Ghost Content Management System (CVE-2026-26980) to compromise over 700 websites, including those of prominent educational institutions and tech companies. Attackers injected malicious JavaScript into these sites, presenting users with fake Cloudflare verification prompts that instructed them to execute commands leading to malware installation. This social engineering tactic effectively bypassed traditional security defenses, resulting in widespread data breaches and operational disruptions. The ClickFix campaign underscores a growing trend in cyber threats where attackers leverage trusted platforms and social engineering to deploy malware. The rapid evolution of such tactics highlights the need for organizations to adopt advanced detection methods, such as YARA-based structural analysis, and to enhance user awareness training to mitigate the risks associated with these sophisticated attacks.
2 months ago
Kill Chain
Lucide Proxy Campaign: A New Wave of Supply Chain Attacks
In May 2026, a campaign involving 148 malicious npm packages, disguised as student web proxies, covertly transformed users' browsers into nodes of a distributed denial-of-service (DDoS) botnet. These packages, branded as 'Lucide' and presented as tutoring services like 'Riverbend Tutoring' and 'Northstar Tutoring,' lured students seeking to bypass school web filters. Upon visiting these proxy sites, users' browsers loaded remote JavaScript payloads that executed DDoS attacks and injected aggressive popunder advertisements. The campaign exploited the npm ecosystem to distribute these packages, leveraging the browsers of end-users for malicious activities without their knowledge. ([research.jfrog.com](https://research.jfrog.com/post/lucide-proxy-npm-malware-campaign/?utm_source=openai)) This incident underscores a significant evolution in supply chain threats, highlighting the vulnerability of end-user systems to malicious code distributed through trusted platforms. The attackers' use of mutable remote loaders and rapid iteration of package versions indicates a low operational security posture, focusing on maximizing short-term impact. Organizations must remain vigilant against such deceptive tactics, emphasizing the importance of scrutinizing third-party packages and educating users about the risks associated with untrusted proxy tools.
2 months ago
Kill Chain
U.S. Sanctions 1VPNS and Cryptor Seller for Enabling Ransomware Attacks
On July 13, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) sanctioned First VPN Service (1VPNS), its Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for facilitating ransomware attacks against American entities. 1VPNS provided anonymizing infrastructure that enabled ransomware groups to obscure their operations, while Silayev sold cryptors that disguised malware to evade detection. These services were instrumental in attacks targeting U.S. businesses, financial services, hospitals, and municipal governments, resulting in billions of dollars in losses. ([publicnow.com](https://www.publicnow.com/view/0E2E8ABF10AF6840E4588F09B8C6B2408783C702?utm_source=openai)) This action underscores the U.S. government's commitment to disrupting the cybercriminal ecosystem by targeting not only the perpetrators but also the enablers of ransomware operations. The sanctions highlight the critical role that infrastructure providers and tool developers play in the proliferation of ransomware, emphasizing the need for comprehensive cybersecurity measures and international cooperation to combat these threats.
2 months ago
Kill Chain
Grok Build CLI's Unauthorized Git Repository Uploads Raise Privacy Concerns
In July 2026, security researcher cereblab discovered that xAI's Grok Build CLI (version 0.2.93) was uploading entire Git repositories, including full commit histories and files not accessed during coding tasks, to a Google Cloud Storage bucket managed by xAI. This behavior occurred even when users disabled the 'Improve the model' setting, which was presumed to prevent such data transmissions. The uploads included sensitive information, such as credentials stored in `.env` files, raising significant privacy and security concerns. xAI addressed the issue by implementing a server-side configuration change to halt these unauthorized uploads. ([breachnews.com](https://breachnews.com/research/grok-build-uploaded-entire-git-repositories-to-xai-storage-by-default/?utm_source=openai)) This incident underscores the critical importance of transparency and user consent in AI tools handling sensitive data. It highlights the need for developers to scrutinize the data practices of AI coding assistants and for organizations to implement robust data governance policies to protect proprietary information.
2 months ago
Kill Chain
Understanding OAuth Client ID Spoofing in Microsoft Entra ID
In early 2026, attackers began exploiting a technique known as OAuth client ID spoofing to stealthily enumerate user accounts and validate credentials within Microsoft Entra ID environments. By submitting authentication requests with spoofed client IDs—identifiers that do not correspond to registered applications—attackers could infer valid usernames and passwords without generating successful sign-in events, thereby evading traditional detection mechanisms. This method allowed unauthorized access to cloud services without alerting defenders. ([proofpoint.com](https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy?utm_source=openai)) The adoption of OAuth client ID spoofing signifies a shift in attacker tactics towards more covert credential validation methods. Organizations must enhance their monitoring strategies to detect such evasive techniques and implement robust authentication policies to mitigate the risk of unauthorized access.
2 months ago
Kill Chain
EU and UK Sanction Russian Entities Over Cyberespionage Campaign
In July 2026, the European Union and the United Kingdom imposed coordinated sanctions on Russian military intelligence officers, hackers, and private companies in response to a prolonged cyberespionage campaign attributed to Russian actors. The EU targeted nine individuals and four entities, while the UK sanctioned 24 individuals and organizations. These sanctions, including asset freezes and travel bans, were directed at actors linked to Russia's FSB and GRU intelligence agencies, accused of conducting cyber operations targeting governments and critical infrastructure since 2010. Key affected countries include France, Germany, Poland, the Netherlands, and Finland, with specific incidents such as the sabotage of Polish railway infrastructure highlighted. ([apnews.com](https://apnews.com/article/1d3c542e1409b54a10856eacad18b7ca?utm_source=openai)) This incident underscores the escalating threat of state-sponsored cyberattacks on critical infrastructure and governmental networks. The coordinated response by the EU and UK reflects a growing recognition of the need for unified action against cyber threats, emphasizing the importance of robust cybersecurity measures and international cooperation to safeguard national security and public services.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports