Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

3202 threat reports
Page 61 of 267

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Information Technology/IT Threat Reports

Showing 721732 / 3202 reports
Lidl Data Breach: Safeguarding Customer Information in the Digital Age
Impact· MEDIUM

Lidl Data Breach: Safeguarding Customer Information in the Digital Age

In July 2026, Lidl, a leading European supermarket chain, disclosed a data breach affecting customers in Germany, Belgium, and the Netherlands. The breach occurred due to unauthorized access to a file stored by a third-party IT service provider, resulting in the exposure of personal customer information, including names, contact details, dates of birth, and customer numbers. Importantly, Lidl confirmed that passwords, billing and shipping addresses, and payment information were not compromised. The company has notified affected customers and relevant authorities, advising vigilance against potential phishing attempts. This incident underscores the critical importance of securing third-party service providers, as supply chain vulnerabilities can lead to significant data breaches. Organizations are increasingly recognizing the need to implement robust security measures and conduct thorough assessments of their external partners to mitigate such risks.

2 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CrashStealer: New macOS Malware Impersonates Apple CrashReporter
Impact· HIGH

CrashStealer: New macOS Malware Impersonates Apple CrashReporter

In early July 2026, security researchers identified 'CrashStealer,' a sophisticated macOS infostealer malware that masquerades as Apple's CrashReporter tool. Delivered through a signed and notarized installer named 'Werkbit Setup,' CrashStealer bypasses macOS's Gatekeeper protections. Once executed, it prompts users with a fake system password request to gain access to the Keychain, subsequently exfiltrating sensitive data including browser credentials, cookies, and cryptocurrency wallet information. The malware employs advanced techniques such as client-side AES-256-GCM encryption for data exfiltration and re-signing its binary to evade detection. This incident underscores a growing trend of macOS-targeted malware leveraging social engineering and legitimate-looking applications to infiltrate systems. Organizations must enhance their security posture by implementing robust endpoint protection, user education on phishing tactics, and continuous monitoring to detect and mitigate such threats.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Jscrambler npm Package Compromise: A Wake-Up Call for Supply Chain Security
Impact· HIGH

Jscrambler npm Package Compromise: A Wake-Up Call for Supply Chain Security

In July 2026, Jscrambler's npm package was compromised, leading to the publication of malicious versions (8.14, 8.16, 8.17, and 8.20) containing an infostealer malware executed during the 'preinstall' hook. This breach resulted in approximately 1,500 downloads within a two-hour window before the issue was addressed. The malware targeted sensitive data, including source code, developer credentials, cloud service keys, and cryptocurrency wallets. Jscrambler promptly deprecated the affected versions and released a secure version 8.22. This incident underscores the critical importance of securing software supply chains, as attackers increasingly exploit trusted development tools to distribute malware. Organizations must implement stringent security measures, such as code integrity checks and continuous monitoring, to prevent similar supply chain attacks.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Cyberattack on Nihon Kotsu Disrupts Taxi Services Across Japan
Impact· HIGH

Cyberattack on Nihon Kotsu Disrupts Taxi Services Across Japan

In July 2026, Nihon Kotsu, Japan's largest taxi operator, experienced a cyberattack that compromised its internal systems, leading to the shutdown of critical infrastructure, including the taxi dispatch system. The attack occurred early Saturday morning, prompting the company to implement emergency measures to prevent further damage. As a result, services such as car hire, web booking, reservation management, and telephone dispatch remain unavailable. The company has engaged external cybersecurity experts to investigate the incident and assess potential data leaks. Customers are advised to use the 'GO' taxi app or visit nearby taxi stands for services. This incident underscores the escalating threat of cyberattacks targeting critical infrastructure and essential services. Organizations must prioritize robust cybersecurity measures and incident response plans to mitigate operational disruptions and protect sensitive data.

2 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
ModHeader Extension Removed by Google and Microsoft Over Security Concerns
Impact· MEDIUM

ModHeader Extension Removed by Google and Microsoft Over Security Concerns

In July 2026, Google and Microsoft removed the ModHeader browser extension, which had approximately 1.6 million combined installs across Chrome and Edge, due to the discovery of a dormant data collection module. Security researchers found that version 7.0.18 of ModHeader contained code capable of collecting users' browsing histories and transmitting the encrypted data to an external server. Although the data collection feature was inactive, its presence raised significant privacy concerns, leading to the extension's removal from both browsers. This incident underscores the critical need for rigorous security assessments of browser extensions, especially those with extensive user bases. It highlights the potential risks associated with third-party software components and the importance of continuous monitoring to detect and mitigate hidden threats that could compromise user privacy and security.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Yellow Teams: Defining the Future of AI Security
Impact· MEDIUM

Yellow Teams: Defining the Future of AI Security

In 2026, organizations like Anthropic and OpenAI initiated projects such as Project Glasswing and Daybreak, respectively, to explore the integration of advanced AI models like Claude Mythos and GPT-5.5 into cybersecurity operations. These initiatives led to the formation of 'yellow teams'—engineering groups dedicated to developing both offensive and defensive AI tools. These teams collaborated with red (offensive) and blue (defensive) teams to harness AI capabilities for identifying vulnerabilities and enhancing security measures. The collaboration resulted in the discovery of numerous vulnerabilities, including some longstanding ones, and emphasized the necessity of integrating AI into the software development life cycle to proactively mitigate future threats. The emergence of yellow teams underscores a significant shift in cybersecurity strategies, highlighting the critical role of AI in both offensive and defensive operations. As AI technologies continue to evolve, the integration of such teams is essential for organizations aiming to stay ahead of sophisticated cyber threats and to adapt to the rapidly changing threat landscape.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
CISA's 2026 GitHub Credential Leak: Lessons in Security Oversight
Impact· HIGH

CISA's 2026 GitHub Credential Leak: Lessons in Security Oversight

In May 2026, the Cybersecurity and Infrastructure Security Agency (CISA) experienced a significant security lapse when a contractor inadvertently exposed sensitive credentials on a public GitHub repository named 'Private-CISA.' This repository, maintained by an employee of Nightwing—a contractor for CISA—contained approximately 844 MB of internal data, including administrative AWS GovCloud keys, plaintext passwords for internal systems, SSH keys, and SAML certificates. The repository was publicly accessible from November 2025 until its discovery in May 2026 by security researcher Guillaume Valadon of GitGuardian. Upon notification, CISA took steps to remove the repository and revoke the exposed credentials. ([techcrunch.com](https://techcrunch.com/2026/05/19/us-cyber-agency-cisa-exposed-reams-of-passwords-and-cloud-keys-to-the-open-web/?utm_source=openai)) This incident underscores the critical importance of stringent credential management and the need for continuous monitoring of public code repositories to prevent unauthorized data exposure. It also highlights the necessity for organizations, especially those responsible for national cybersecurity, to enforce robust security protocols and ensure that contractors adhere to the same standards to mitigate potential risks.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Misconfigured Server Exposes Sophisticated Phishing Operations Targeting Microsoft 365
Impact· HIGH

Misconfigured Server Exposes Sophisticated Phishing Operations Targeting Microsoft 365

In April 2026, a misconfigured server exposed three active Microsoft 365 phishing operations utilizing customized versions of the Evilginx adversary-in-the-middle (AiTM) proxy. The exposed server, left with directory listing enabled, revealed comprehensive toolkits, including phishing configurations, credential logs, and remote management tools. Analysis traced these operations to an Egyptian actor known as 'codemado,' who cloned and modified public Evilginx repositories to orchestrate sophisticated phishing campaigns targeting corporate mailboxes. The campaigns effectively bypassed multi-factor authentication (MFA) by proxying live login sessions and abusing legitimate Microsoft sign-in flows, allowing attackers to capture session cookies and maintain prolonged access to compromised accounts. This incident underscores the evolving sophistication of phishing-as-a-service platforms and the critical need for organizations to implement robust security measures beyond traditional MFA. The exposure of these operations highlights the importance of continuous monitoring and auditing of authentication processes to detect and mitigate unauthorized access attempts. As attackers refine their techniques to circumvent existing defenses, organizations must stay vigilant and adapt their security strategies accordingly.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Remote Code Execution Vulnerability in iCagenda Joomla Extension (CVE-2026-48939)
Impact· CRITICAL

Critical Remote Code Execution Vulnerability in iCagenda Joomla Extension (CVE-2026-48939)

In June 2026, a critical vulnerability (CVE-2026-48939) was identified in the iCagenda extension for Joomla, allowing unauthenticated attackers to upload and execute arbitrary PHP files via the file attachment feature. This flaw, present in versions prior to 3.9.15 and 4.0.8, enables remote code execution, potentially compromising the entire web server. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog on July 10, 2026, following reports of active exploitation in the wild. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-48939?utm_source=openai)) The exploitation of CVE-2026-48939 underscores a broader trend of attackers targeting vulnerabilities in widely used content management system (CMS) extensions. This incident highlights the critical need for organizations to promptly apply security patches and maintain vigilant monitoring of their web applications to prevent unauthorized access and potential data breaches.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AI-Generated PowerShell Script Used in Active Directory Attack
Impact· MEDIUM

AI-Generated PowerShell Script Used in Active Directory Attack

In early June 2026, cybersecurity researchers identified an intrusion where an unknown threat actor utilized an AI-generated PowerShell script to enumerate an Active Directory (AD) environment. The attacker gained Remote Desktop Protocol (RDP) access to a domain-joined Windows Server using pre-compromised credentials, then executed a PowerShell script titled "100% Working AD Information Gathering Script - FULLY FIXED." This script aggressively mapped users, computers, and domains, creating an AD_Report.html to summarize the enumeration. Following this, the attacker deployed legitimate tools like s5cmd.exe and SharpShares.exe to identify and exfiltrate accessible data repositories. ([itsecurityguru.org](https://www.itsecurityguru.org/2026/07/08/huntress-uncovers-vibe-coded-malware-used-to-map-active-directory-environments/?utm_source=openai)) This incident underscores the evolving threat landscape where AI-generated tools are lowering the barrier to entry for cybercriminals, enabling rapid development of custom, evasive malware. The use of AI in cyberattacks is accelerating, allowing threat actors to execute damaging campaigns more swiftly than ever before. ([infosecurity-magazine.com](https://www.infosecurity-magazine.com/news/vibe-coded-malware-ai-powershell/?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(high)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(low)
Read Report
Anubis Ransomware Exploits Citrix Bleed 2 Vulnerability in 2026
Impact· CRITICAL

Anubis Ransomware Exploits Citrix Bleed 2 Vulnerability in 2026

In early July 2026, the Anubis ransomware group exploited a critical vulnerability known as Citrix Bleed 2 (CVE-2025-5777) in Citrix NetScaler appliances to gain unauthorized access to enterprise networks. This flaw allowed attackers to bypass multi-factor authentication by stealing session tokens, leading to the compromise of 91 organizations across sectors such as healthcare, financial services, manufacturing, and technology. The attackers utilized legitimate remote management tools to maintain persistence and evade detection, culminating in the deployment of ransomware that encrypted critical data and disrupted operations. This incident underscores the persistent threat posed by unpatched vulnerabilities and the sophisticated tactics employed by ransomware groups. The exploitation of Citrix Bleed 2 highlights the importance of timely patch management and the need for comprehensive monitoring of remote access tools to detect and prevent unauthorized activities.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Urgent Alert: Widespread Scanning Targets MCP Servers and AI Assistant Credentials
Impact· HIGH

Urgent Alert: Widespread Scanning Targets MCP Servers and AI Assistant Credentials

In July 2026, security researchers identified a widespread scanning campaign targeting Model Context Protocol (MCP) servers and AI assistant credential files. Attackers systematically probed internet-facing systems for exposed MCP endpoints and configuration files associated with AI development tools, aiming to exploit misconfigurations and gain unauthorized access. This reconnaissance activity underscores the critical need for organizations to secure their AI infrastructure against emerging threats. The incident highlights a growing trend of attackers focusing on AI-related assets, exploiting the rapid adoption of AI technologies and potential security oversights. Organizations must proactively implement robust security measures to protect sensitive AI systems and data from evolving cyber threats.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports