Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
GigaWiper: Unveiling a Multifaceted Cyber Threat
In July 2026, Microsoft uncovered a sophisticated Windows backdoor named GigaWiper, which integrates three destructive functionalities: a raw disk wiper that overwrites physical drives and partition tables, a fake ransomware module that encrypts files without saving the decryption key, and a Windows drive wiper that overwrites system drives multiple times. Additionally, GigaWiper possesses espionage capabilities, including screen recording, hidden VNC sessions, and system manipulation, all while masquerading as legitimate services like OneDrive. The malware utilizes legitimate business services such as RabbitMQ, Redis, and MinIO for command and control, making detection challenging. The emergence of GigaWiper underscores a concerning trend in cyber threats, where attackers combine destructive and espionage functionalities within a single malware package. This evolution highlights the necessity for organizations to implement robust detection mechanisms, maintain offline backups, and stay vigilant against sophisticated attack vectors that blend legitimate services with malicious intent.
2 months ago
Kill Chain
AI-Powered Attack Compromises AWS Environment in Record Time
In July 2026, a lone threat actor utilized agentic AI workflows to orchestrate a sophisticated attack on a large Amazon Web Services (AWS) environment, achieving full compromise within 72 hours. The attacker exploited weaknesses across application services, AWS resources, source code repositories, CI/CD pipelines, runtime components, and data stores, leading to financial extortion of the victim. This incident underscores the evolving threat landscape where AI accelerates the speed and scale of cyberattacks, enabling even individual actors to execute complex operations rapidly. Organizations must adapt by enhancing their detection and response capabilities to counteract AI-assisted threats effectively.
2 months ago
Kill Chain
AI Gateway Compromise Exposes Critical Security Vulnerabilities
In July 2026, a threat actor compromised an Amazon EC2 server hosting an AI gateway connected to Amazon Bedrock services. The attacker utilized this access to deploy cryptomining software, exploiting the gateway's privileged position to potentially access AI models, manipulate workflows, and infiltrate the organization's cloud infrastructure. This incident underscores the critical vulnerabilities associated with AI gateways, which often serve as central points of access to sensitive data and services. The increasing deployment of AI gateways in enterprise environments highlights the urgent need for robust security measures. As these gateways aggregate access to multiple AI models and datasets, they become attractive targets for attackers seeking to exploit centralized points of control. Organizations must implement stringent access controls, continuous monitoring, and regular security assessments to mitigate the risks posed by such vulnerabilities.
2 months ago
Kill Chain
GodDamn Ransomware: Exploiting PoisonX Driver in Advanced Attacks
In May 2026, a new ransomware variant named GodDamn emerged, utilizing the PoisonX kernel driver to disable endpoint security defenses. This tactic, known as a Bring Your Own Vulnerable Driver (BYOVD) attack, allows the ransomware to neutralize security software by exploiting a signed but vulnerable driver. GodDamn is assessed to be a rebranded version of the Beast ransomware, which itself evolved from the Monster ransomware first detected in March 2022. The attackers employed tools like AnyDesk for remote access and a NirSoft-based credential harvester to extract sensitive information before deploying the ransomware payload. The use of signed drivers to disable security measures represents a significant evolution in ransomware tactics, highlighting the increasing sophistication of threat actors. Organizations must be vigilant against such advanced techniques, as they can render traditional security solutions ineffective, leading to severe operational disruptions and data loss.
2 months ago
Kill Chain
ESET Threat Report H1 2026: Unveiling PromptSpy, the First AI-Driven Android Malware
In February 2026, ESET researchers discovered PromptSpy, the first known Android malware to utilize generative AI during its execution. This malware leverages Google's Gemini AI to interpret on-screen elements dynamically, enabling it to adapt its behavior across various Android devices and maintain persistence by preventing uninstallation. PromptSpy is distributed through a malicious dropper disguised as a system update, primarily targeting Spanish-speaking users in South America, especially Argentina. Once installed, it abuses Accessibility Services to monitor and control the user interface, deploys a Virtual Network Computing (VNC) module for remote access, and captures sensitive data such as lockscreen credentials and screen activity. ([eset.com](https://www.eset.com/us/about/newsroom/research/eset-research-discovers-promptspy-first-android-threat-using-genai/%3Fsrsltid%3DAfmBOoqZ_0fHGAaMnVaEZ5B0AuPdwhhXlaecY3Klyk-8QVRG-fAAlTy6?utm_source=openai)) The emergence of PromptSpy signifies a pivotal shift in mobile cybersecurity, illustrating how threat actors are integrating generative AI to enhance malware adaptability and persistence. This development underscores the urgent need for advanced detection mechanisms and proactive security measures to counteract AI-driven threats in the evolving cyber landscape.
2 months ago
Kill Chain
CISA Urges Immediate Patching of Langflow Vulnerability CVE-2026-55255
In July 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) mandated federal agencies to patch a critical vulnerability in Langflow, a popular AI development tool. Identified as CVE-2026-55255, this Insecure Direct Object Reference (IDOR) flaw allows authenticated attackers to execute flows belonging to other users by manipulating the /api/v1/responses endpoint. Exploitation of this vulnerability can lead to unauthorized access to sensitive data and resource consumption. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-prioritize-patching-langflow-auth-bypass-flaw/?utm_source=openai)) The urgency of this directive underscores the increasing targeting of AI development platforms by cyber actors. As AI tools become integral to various sectors, ensuring their security is paramount to prevent potential data breaches and operational disruptions.
2 months ago
Kill Chain
KDDI Data Breach 2026: Zero-Day Vulnerability Exploited
In June 2026, Japanese telecommunications giant KDDI detected unauthorized access to its email platform, affecting multiple internet service providers (ISPs) including STNet, JCOM, Chubu Telecommunications, NIFTY Corporation, and BIGLOBE. The breach, initiated on May 16, exploited a zero-day vulnerability in third-party software, leading to the exposure of approximately 12.23 million email addresses and 7.61 million passwords. KDDI promptly blocked the attackers upon discovery on June 17 and implemented defensive measures to secure the compromised systems. This incident underscores the critical importance of securing third-party software components, as vulnerabilities in such software can serve as entry points for attackers. Organizations are urged to conduct thorough security assessments of third-party tools and implement robust monitoring systems to detect and respond to unauthorized access promptly.
2 months ago
Kill Chain
Entra Passkey Enrollment Vishing Targets Microsoft 365 Users
In April 2026, a threat actor identified as O-UNC-066, operating under the extortion brand 'Pink,' initiated a vishing campaign targeting Microsoft 365 users across multiple sectors, including food and beverage, technology, healthcare, automotive, construction, and aviation. The attackers impersonated IT personnel, contacting employees by phone and instructing them to enroll a new Microsoft Entra passkey for security purposes. Victims were directed to phishing websites mimicking legitimate Microsoft enrollment portals, where attackers captured credentials and multi-factor authentication (MFA) responses. Subsequently, the attackers registered passkeys under their control, gaining unauthorized access to victims' Microsoft accounts and exfiltrating data from services like SharePoint and OneDrive. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/amp/?utm_source=openai)) This incident underscores a growing trend of sophisticated social engineering attacks exploiting emerging authentication technologies. The use of real-time phishing kits capable of adapting to various MFA methods highlights the evolving tactics of cybercriminals. Organizations must remain vigilant, as such attacks can lead to significant data breaches and financial extortion. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/amp/?utm_source=openai))
2 months ago
Kill Chain
Mount Royal University 2026 Ransomware Attack: A Case Study
In June 2026, Mount Royal University (MRU) in Calgary experienced a significant cyberattack attributed to the CMD Organization ransomware group. The attackers infiltrated MRU's network, exfiltrated data from the H drive—used by students and employees—and subsequently deleted the original files to hinder recovery efforts. This breach disrupted various university services, including online platforms and internal systems, affecting current and former students and staff. The university has engaged external cybersecurity experts and reported the incident to relevant authorities. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/mount-royal-university-confirms-breach-as-hackers-claim-attack/?utm_source=openai)) This incident underscores the evolving tactics of ransomware groups like CMD Organization, which employ auction-based extortion models to maximize financial gain. Their approach not only involves data encryption but also public data leaks and auctions, amplifying pressure on victims. ([labs.beazley.security](https://labs.beazley.security/articles/cmd-organization-new-ransomware-operator-moves-to-place-public-bidding-wars-on-ransomed-data?utm_source=openai))
2 months ago
Kill Chain
Major Brands Impersonated in Phishing Scam Targeting Marketing Professionals
In July 2026, a sophisticated phishing campaign targeted marketing professionals by impersonating recruiters from renowned companies such as Netflix, Coca-Cola, and FIFA. Attackers utilized legitimate platforms like PeopleForce and Salesforce's ExactTarget to send personalized emails, leading recipients through nested redirects to a fake Google sign-in page designed to harvest credentials. This method effectively evaded traditional detection mechanisms, posing significant risks to individuals and organizations. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/big-brand-jobs-scam-marketing-pros-google-accounts?utm_source=openai)) The incident underscores a growing trend of cybercriminals exploiting trusted services and personalized lures to deceive professionals. As the job market becomes increasingly competitive and AI-generated content enhances the realism of such scams, organizations must bolster their defenses against these evolving threats. ([malwarebytes.com](https://www.malwarebytes.com/blog/scams/2026/07/fake-netflix-coca-cola-and-fifa-job-scams-target-marketers?utm_source=openai))
2 months ago
Kill Chain
GhostLock Vulnerability: A 15-Year-Old Flaw Exposing Linux Systems to Root Exploits
In July 2026, Nebula Security disclosed a critical vulnerability in the Linux kernel, known as GhostLock (CVE-2026-43499). This 15-year-old flaw allows any local user to escalate privileges to root without special permissions or network access. The vulnerability resides in the kernel's real-time mutex (rtmutex) component, where improper handling of task pointers during proxy-lock rollback leads to a use-after-free condition. Exploiting this flaw enables attackers to gain full control over affected systems and escape containerized environments. The issue affects nearly all mainstream Linux distributions since 2011, with a reported 97% exploit reliability. The disclosure of GhostLock underscores the persistent risk posed by longstanding vulnerabilities in widely used open-source software. The availability of public exploit code increases the urgency for organizations to apply patches promptly. This incident highlights the need for continuous monitoring and timely updating of systems to mitigate potential security threats.
2 months ago
Kill Chain
Critical Vulnerability in Siemens Mendix Studio Pro: CVE-2026-48192
In June 2026, Siemens disclosed a vulnerability (CVE-2026-48192) in Mendix Studio Pro versions 10.11 through 10.24 (prior to V10.24.21) and 11.0 through 11.11. The flaw arises from improper validation and sanitization of project files during the build pipeline, allowing attackers to execute arbitrary code if a user opens a specially crafted malicious project. This vulnerability could lead to unauthorized code execution within the user's context, potentially compromising developer workstations and downstream build artifacts. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-48192/?utm_source=openai)) The incident underscores the critical importance of validating and sanitizing project files in development environments. As low-code platforms like Mendix Studio Pro gain popularity, ensuring robust security measures against such vulnerabilities becomes imperative to protect development processes and prevent potential supply chain attacks.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports