Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
June 2026 CVE Landscape: A 49% Surge in High-Impact Vulnerabilities
In June 2026, Insikt Group identified 60 high-impact vulnerabilities, marking a 49% increase from the previous month. Notably, 23 of these vulnerabilities were included in the US Cybersecurity and Infrastructure Security Agency (CISA)'s Known Exploited Vulnerabilities (KEV) catalog. The vulnerabilities affected products from 36 vendors, with Microsoft accounting for approximately 18%. ([vulnerability-lookup.org](https://www.vulnerability-lookup.org/2026/07/02/vulnerability-report-june-2026/?utm_source=openai)) This surge underscores the escalating threat landscape, emphasizing the need for organizations to prioritize vulnerability management and remediation efforts to mitigate potential exploits.
2 months ago
Kill Chain
Unimed Cyberattack 2026: A Wake-Up Call for Healthcare Vendor Security
In April 2026, Unimed, a German medical billing provider servicing numerous university hospitals, suffered a cyberattack resulting in the theft of over 72,000 patient records. The breach exposed sensitive information, including names, addresses, and health data. Unimed promptly reported the incident to authorities and collaborated with affected hospitals to notify impacted patients. The attack did not compromise the IT systems of the client hospitals, ensuring that patient care remained unaffected. ([luxgap.com](https://luxgap.com/articles/unimed-72000-patients-voles-dlp-article-32-transferts-rgpd?lang=en&utm_source=openai)) This incident underscores the critical vulnerabilities within third-party service providers in the healthcare sector. As cybercriminals increasingly target supply chains, healthcare organizations must reassess and fortify their vendor risk management and data protection strategies to prevent similar breaches.
2 months ago
Kill Chain
Arrest of Pro-Russian Hacktivist in Spain Highlights Ongoing Cyber Threats
In July 2026, Spanish authorities, in collaboration with the FBI, arrested a suspected core member of pro-Russian hacktivist groups CyberArmy of Russia Reborn (CARR) and Z-Pentest in Palencia, Spain. The individual is accused of providing logistical support to a Ukrainian hacker affiliated with CARR and attempting to facilitate their escape to Russia. The suspect is also linked to coordinating cyber operations for the NoName057(16) group using encrypted messaging platforms. Seized items include multiple computers and frozen cryptocurrency wallets allegedly used to launder proceeds from stolen data sales. The suspect faces ongoing investigations for collaboration with a recognized terrorist organization and severe computer damage. ([es.euronews.com](https://es.euronews.com/my-europe/2026/07/06/la-policia-y-el-fbi-detienen-en-palencia-a-un-presunto-colaborador-de-hackers-prorrusos?utm_source=openai)) This arrest underscores the persistent threat posed by hacktivist groups targeting critical infrastructure across the United States and Europe. The incident highlights the importance of international cooperation in combating cybercrime and the need for organizations to bolster their cybersecurity defenses against such multifaceted threats.
2 months ago
Kill Chain
Critical ATM Software Vulnerabilities Uncovered
In July 2026, security researcher Matt Burch identified nine vulnerabilities in CryptWare's CryptoPro Secure Disk, a full-disk encryption and pre-boot authentication solution for Windows. These flaws could potentially allow attackers with physical access to ATMs to execute arbitrary code, bypass encryption, and steal cash. The vulnerabilities include integrity validation bypasses and improper storage of key materials, raising significant security concerns for organizations utilizing this software. This discovery underscores the critical need for robust physical and software security measures in ATMs, especially as 'jackpotting' attacks have been on the rise, with over 700 incidents reported in 2025, resulting in more than $20 million stolen. ([techcrunch.com](https://techcrunch.com/2026/02/19/fbi-says-atm-jackpotting-attacks-are-on-the-rise-and-netting-hackers-millions-in-stolen-cash/?utm_source=openai))
2 months ago
Kill Chain
O-UNC-066 Exploits Microsoft Entra Passkey Enrollment in Vishing Scheme
In April 2026, a threat actor identified as O-UNC-066 initiated a sophisticated vishing campaign targeting Microsoft 365 users across multiple sectors, including food and beverage, technology, healthcare, automotive, construction, and aviation. The attackers impersonated internal security personnel, contacting employees via phone and instructing them to enroll a new Microsoft Entra passkey for enhanced security. Victims were directed to phishing websites that closely mimicked Microsoft's legitimate passkey enrollment process. Unbeknownst to the users, this process allowed the attackers to register their own passkeys, thereby gaining unauthorized access to the victims' Microsoft 365 accounts. Subsequent to gaining access, the attackers engaged in data exfiltration activities, targeting sensitive information stored in SharePoint and OneDrive. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/?utm_source=openai)) This incident underscores a concerning trend in cyber threats, where attackers exploit legitimate security features to deceive users. The abuse of Microsoft's passkey enrollment process highlights the need for organizations to implement robust user education programs and to remain vigilant against evolving social engineering tactics. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/?utm_source=openai))
2 months ago
Kill Chain
Unveiling MODBEACON: Silver Fox's Latest Encrypted C2 RAT
In July 2026, the China-linked cybercrime group known as Silver Fox was identified as the operator behind a new Rust-based remote access trojan (RAT) named MODBEACON. This sophisticated malware utilizes gRPC streaming to establish encrypted command-and-control (C2) communications, effectively evading traditional network detection mechanisms. MODBEACON is distributed through counterfeit software installers, leveraging search engine optimization (SEO) poisoning techniques to lure victims into downloading the malicious payload. Once installed, the RAT enables attackers to execute commands remotely, exfiltrate sensitive data, and maintain persistent access to compromised systems. The emergence of MODBEACON underscores a growing trend among threat actors to adopt advanced encryption methods and unconventional communication protocols to obfuscate their activities. This development highlights the necessity for organizations to enhance their detection capabilities, focusing on behavioral analysis and anomaly detection to identify and mitigate such sophisticated threats.
2 months ago
Kill Chain
OpenClaw AI Assistant Vulnerabilities: A Wake-Up Call for AI Security
In early 2026, multiple critical vulnerabilities were discovered in OpenClaw, a popular open-source AI assistant. These flaws, including CVE-2026-25253, CVE-2026-24763, and CVE-2026-25157, allowed attackers to execute arbitrary code, escalate privileges, and exfiltrate sensitive data. Exploitation of these vulnerabilities led to unauthorized access to over 28,000 systems worldwide, with attackers gaining full control over affected hosts. The widespread deployment of OpenClaw in enterprise environments amplified the impact, exposing numerous organizations to significant security risks. The rapid adoption of AI agents like OpenClaw underscores the urgent need for robust security measures in AI deployments. This incident highlights the importance of comprehensive vulnerability assessments, timely patch management, and stringent access controls to mitigate the risks associated with integrating AI assistants into critical systems.
2 months ago
Kill Chain
Phishing Campaign Evades AI Detection with HTML Comment Padding
In July 2026, a sophisticated phishing campaign was identified, utilizing oversized HTML attachments filled with extensive comment padding to evade AI-based email security filters. The phishing emails masqueraded as Microsoft Teams notifications, featuring attachments named to resemble legitimate documents. These attachments, significantly larger than typical phishing payloads, contained minimal functional content surrounded by large blocks of HTML comments, effectively diluting the malicious code and bypassing detection mechanisms. This technique underscores the evolving tactics of cybercriminals in circumventing advanced security measures. The incident highlights a growing trend where attackers exploit AI and machine learning systems' limitations by manipulating content to evade detection. As AI becomes more integral to cybersecurity defenses, adversaries are developing methods to exploit its weaknesses, necessitating continuous adaptation and enhancement of security protocols to address these sophisticated evasion techniques.
2 months ago
Kill Chain
Helix Vishing Group Exploits SharePoint in Data Theft Attacks
In July 2026, a new data-extortion group named Helix emerged, employing sophisticated identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to infiltrate SharePoint environments. The attackers initiated contact by impersonating managers over the phone, convincing employees to provide device codes, thereby gaining unauthorized access to their accounts. Once inside, Helix operators registered new MFA applications to maintain persistence, systematically enumerated SharePoint content, and exfiltrated sensitive files. The stolen data was then used to extort victim organizations by threatening public disclosure or selling it to other cybercriminals. This incident underscores a significant shift towards identity-based attacks targeting cloud services, highlighting the vulnerabilities in current authentication processes. The Helix group's methods bear similarities to previous tactics employed by groups like ShinyHunters and BlackFile, indicating a possible evolution or rebranding of these threat actors. Organizations must reassess and strengthen their security protocols, particularly around identity verification and access controls, to mitigate the risks posed by such sophisticated social engineering attacks.
2 months ago
Kill Chain
Understanding the Bucket Hijacking Threat in Cloud Storage
In July 2026, a critical cloud storage attack technique known as 'bucket hijacking' was disclosed, enabling threat actors to silently redirect an organization's active cloud data streams, including audit logs and telemetry, into attacker-controlled external storage buckets across major cloud platforms. This vulnerability exploits the global uniqueness of cloud storage bucket names, allowing attackers to register a previously deleted bucket name and reroute data streams intended for the original bucket. The attack affects major cloud providers, including Google Cloud, Amazon Web Services (AWS), and Microsoft Azure, and detection is extremely challenging once deployed. ([serisec.com](https://serisec.com/index.php/2026/06/27/new-bucket-hijacking-attack-allows-hackers-to-reroute-cloud-data-streams-to-external-storage/?utm_source=openai)) This incident underscores the escalating risks associated with cloud misconfigurations and the critical need for organizations to implement robust monitoring and configuration management practices. As cloud environments become increasingly complex, the potential for such vulnerabilities to be exploited grows, emphasizing the importance of proactive security measures to safeguard sensitive data.
2 months ago
Kill Chain
Dormant GitHub Accounts: A New Vector in Supply Chain Attacks
In July 2026, Datadog Security Labs identified multiple coordinated campaigns systematically enumerating corporate GitHub organizations, repositories, and user accounts via the GitHub API. Attackers utilized automated scraping tools with custom or legitimate-sounding user agents, leveraging dormant 'ghost' accounts—created two to five years prior and left inactive—as well as compromised OAuth tokens and personal access tokens (PATs) from legitimate users. While much of the activity targeted public data, some instances involved cloning private repositories, indicating a significant escalation in threat actor capabilities. This incident underscores the evolving tactics of threat actors who exploit dormant accounts and compromised credentials to conduct reconnaissance and access sensitive information. Organizations must enhance their monitoring of API activities and implement robust access controls to mitigate such risks.
2 months ago
Kill Chain
npm 12 Enhances Security by Disabling Automatic Install Scripts
In July 2026, GitHub released npm version 12, implementing significant security enhancements by disabling install scripts by default. This change prevents automatic execution of preinstall, install, and postinstall scripts during package installation, addressing a major attack vector exploited in previous supply chain attacks. Additionally, npm v12 requires explicit approval for Git and remote URL dependencies, further strengthening the ecosystem's security posture. This update is particularly relevant as supply chain attacks have become increasingly prevalent, with attackers leveraging automatic script execution to compromise systems. By requiring explicit consent for script execution and external dependencies, npm v12 aims to mitigate these risks, promoting a more secure development environment.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports