Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Massive Azure CLI Password Spray Attack Compromises 78 Microsoft Accounts
Between June 12 and June 26, 2026, a massive, automated password spray attack targeted Microsoft's Azure command-line interface (CLI), resulting in over 81 million login attempts and the compromise of at least 78 Microsoft accounts across 64 organizations. The attackers exploited a deprecated OAuth 2.0 grant type known as Resource Owner Password Credentials (ROPC) to bypass Conditional Access Policies (CAP) and multi-factor authentication (MFA) in environments where MFA was not enforced for all cloud applications. The attack originated from an IPv6 address range controlled by internet infrastructure provider LSHIY LLC (AS32167). ([thehackernews.com](https://thehackernews.com/2026/07/azure-cli-password-spray-hits-at-least.html?utm_source=openai)) This incident underscores the critical need for organizations to review and properly configure their Conditional Access Policies to enforce MFA across all applications and user groups. The exploitation of legacy authentication methods like ROPC highlights the importance of disabling deprecated protocols and ensuring that security measures are comprehensive and up-to-date. ([thehackernews.com](https://thehackernews.com/2026/07/azure-cli-password-spray-hits-at-least.html?utm_source=openai))
2 months ago
Kill Chain
Phantom Squatting: Exploiting AI-Generated Domains for Cyber Attacks
In July 2026, Palo Alto Networks' Unit 42 identified a new cyberattack technique termed 'phantom squatting,' where attackers exploit AI-generated, non-existent domains to conduct phishing and malware distribution. By prompting large language models (LLMs) with queries about official websites, attackers collect these hallucinated domains, register them, and create malicious sites that appear legitimate to users and AI tools alike. This method leverages the trust users place in AI-generated content, leading to increased risks of credential theft and malware infections. The emergence of phantom squatting underscores the evolving landscape of cyber threats, particularly as AI tools become more integrated into daily operations. Organizations must recognize the potential for AI-generated misinformation to be weaponized and implement proactive measures to monitor and secure domains that could be exploited through such techniques.
2 months ago
Kill Chain
Critical Vulnerability in Schneider Electric's EcoStruxure IT Data Center Expert: CVE-2026-8045
In June 2026, Schneider Electric disclosed a vulnerability (CVE-2026-8045) in its EcoStruxure IT Data Center Expert software, versions 9.1.1 and prior. This flaw, identified as an Improper Restriction of XML External Entity Reference (CWE-611), allows authenticated users to submit crafted XML payloads to SOAP service endpoints, potentially leading to unauthorized access and disclosure of sensitive server-side files. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-8045?utm_source=openai)) The vulnerability underscores the critical need for robust input validation and secure XML processing in software applications. Organizations utilizing affected versions should promptly apply the vendor-provided patch to mitigate potential risks associated with this security flaw.
2 months ago
Kill Chain
Protecting AI Agents from MCP Tool Poisoning Attacks
In June 2026, Microsoft Incident Response detailed a sophisticated attack pattern targeting enterprise AI agents utilizing the Model Context Protocol (MCP). The attack involved malicious modifications to MCP tool descriptions, leading AI agents to execute unauthorized actions, such as exfiltrating sensitive financial data. This exploitation underscores the vulnerabilities inherent in AI agents that transition from passive content reading to active task execution. The incident highlights the critical need for robust security measures as AI agents become more autonomous and integrated into enterprise workflows. With the projected growth of AI agents in enterprises, securing these systems against such sophisticated attacks is paramount to prevent potential data breaches and operational disruptions.
2 months ago
Kill Chain
Critical Vulnerabilities in Cursor AI Code Editor Expose Developers to Remote Code Execution
In June 2026, two critical vulnerabilities, CVE-2026-50548 and CVE-2026-50549, were discovered in Cursor, an AI-powered code editor. These flaws allowed malicious agents to bypass the application's sandbox protections, enabling unauthorized execution of commands on a developer's machine without user interaction. The vulnerabilities stemmed from improper handling of the working directory and symlink resolution, permitting attackers to write arbitrary files outside the intended workspace, leading to potential remote code execution. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-50549?utm_source=openai)) The discovery of these vulnerabilities underscores the growing risks associated with AI-integrated development tools. As AI becomes more embedded in software development, ensuring the security of such tools is paramount to prevent exploitation by threat actors.
2 months ago
Kill Chain
Urgent Alert: Ransomware Gangs Exploit Microsoft Defender 'BlueHammer' Vulnerability
In early April 2026, a security researcher known as 'Nightmare Eclipse' publicly disclosed a high-severity privilege escalation vulnerability in Microsoft Defender, dubbed 'BlueHammer' (CVE-2026-33825), along with proof-of-concept exploit code. This flaw allows local attackers to access the Security Account Manager (SAM) database, enabling them to escalate privileges to SYSTEM level and potentially take full control of the affected system. Microsoft addressed the vulnerability on April 14, 2026, as part of its Patch Tuesday updates. However, by late June 2026, the Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware gangs had begun exploiting this vulnerability in their attacks, leading to significant security concerns for organizations using unpatched systems. The exploitation of BlueHammer underscores a growing trend where threat actors rapidly weaponize newly disclosed vulnerabilities, particularly those with publicly available exploit code. This incident highlights the critical importance of timely patch management and proactive security measures to mitigate the risks associated with such vulnerabilities.
2 months ago
Kill Chain
Beware: Malicious 'Perplexity AI' Chrome Extension Intercepts User Searches
In June 2026, a malicious Chrome extension named "Search for perplexity ai" was discovered impersonating the legitimate Perplexity AI search engine. This extension altered users' default search settings, intercepting all address-bar queries and routing them through attacker-controlled infrastructure before redirecting to legitimate search services. While no credential theft was confirmed, the extension's permissions allowed for extensive data collection, posing significant privacy risks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/fake-perplexity-extension-on-chrome-web-store-tracked-searches/amp/?utm_source=openai)) This incident underscores the growing trend of cybercriminals exploiting trusted AI brands to distribute malicious software. It highlights the need for enhanced vigilance in verifying browser extensions and the importance of robust security measures to prevent unauthorized data interception.
2 months ago
Kill Chain
Malicious PyPI Packages Compromise Telegram Bot Servers in 2026
Between November 2025 and June 2026, a campaign dubbed 'Operation Navy Ghost' targeted Python developers creating Telegram bots by distributing trojanized versions of the Pyrogram library on the Python Package Index (PyPI). These malicious packages, including 'VLifeGram' and 'pyrogram-styled', contained a hidden backdoor that, upon activation, allowed attackers to execute arbitrary code and access sensitive data on compromised servers. The backdoor was designed to operate silently, suppressing errors and disabling logging, thereby granting attackers extensive control over the affected systems. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/malicious-pypi-packages-give-hackers-control-of-telegram-bot-servers/?utm_source=openai)) This incident underscores the persistent threat of supply chain attacks in open-source ecosystems. The exploitation of widely-used libraries like Pyrogram highlights the need for developers to exercise caution when integrating third-party packages. Ensuring the integrity of software dependencies is crucial to prevent unauthorized access and data breaches.
2 months ago
Kill Chain
BioShocking Attack: A New Threat to AI Browser Security
In June 2026, researchers at LayerX identified a novel prompt injection attack named 'BioShocking' targeting AI-powered browsers. The attack involves a malicious webpage presenting a BioShock-themed puzzle game that rewards incorrect answers, conditioning the browser's control agent to disregard standard safety protocols. In the final stage, the agent is directed to access a GitHub repository and extract sensitive data, such as passwords. This proof-of-concept was tested against six mainstream agentic browsers, with only OpenAI's ChatGPT Atlas implementing an effective fix after disclosure. The BioShocking attack underscores the critical need for robust security measures in AI-driven applications. As AI agents become more integrated into daily tasks, their susceptibility to manipulation poses significant risks. This incident highlights the urgency for developers to implement explicit user confirmations for sensitive actions, enhance context checks, and establish strict boundaries for agentic sessions to prevent similar exploits.
2 months ago
Kill Chain
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
In March 2026, threat actors exploited a critical vulnerability in Langflow (CVE-2026-33017), an open-source AI workflow tool, to deploy Monero cryptocurrency miners on exposed AI application endpoints. This unauthenticated remote code execution flaw allowed attackers to execute arbitrary Python code via the public flow build API endpoint, leading to unauthorized system access and resource hijacking. The attacks were observed between March 27 and April 15, 2026, with malicious scripts terminating competing miners, disabling security controls, and establishing persistence mechanisms. ([thehackernews.com](https://thehackernews.com/2026/06/langflow-rce-exploited-to-deploy-monero.html?utm_source=openai)) The rapid exploitation of this vulnerability underscores the increasing targeting of AI infrastructure by cybercriminals. Organizations utilizing Langflow versions prior to 1.9.0 are urged to upgrade immediately and review their systems for signs of compromise. ([thehackernews.com](https://thehackernews.com/2026/06/langflow-rce-exploited-to-deploy-monero.html?utm_source=openai))
2 months ago
Kill Chain
The Rise of AI-Powered Phishing Attacks in 2025
In 2025, the cybersecurity landscape witnessed a significant surge in AI-powered phishing attacks. Cybercriminals increasingly leveraged artificial intelligence to craft highly convincing phishing emails, leading to a 140% increase in browser-based phishing attacks and a 130% rise in zero-hour phishing incidents compared to the previous year. This escalation resulted in substantial financial losses, with an estimated $17 billion worth of Bitcoin stolen through AI-enhanced scams. The integration of AI into phishing tactics has not only increased the volume of attacks but also their sophistication, making detection and prevention more challenging for organizations. ([pcworld.com](https://www.pcworld.com/article/2645617/ai-driven-phishing-scams-exploded-last-year-the-trend-continues-in-2025.html?utm_source=openai)) The current relevance of this trend is underscored by the continuous evolution of AI technologies, which are being exploited by cybercriminals to automate and personalize phishing campaigns at an unprecedented scale. This development necessitates a proactive approach from organizations to enhance their cybersecurity measures and adapt to the rapidly changing threat landscape.
2 months ago
Kill Chain
Nation-State Cyberattacks on Water Systems: A Growing Threat
Between 2024 and 2026, nation-state actors from Iran, Russia, and China have increasingly targeted water and wastewater systems worldwide. These cyberattacks exploit vulnerabilities such as weak passwords, exposed programmable logic controllers (PLCs), and inadequate network segmentation, leading to unauthorized access and potential operational disruptions. Notably, in 2025, Russian-linked actors caused a municipal water tank overflow in Muleshoe, Texas, by accessing a remote industrial interface. Similarly, Iranian groups have been observed exploiting exposed PLCs in the U.S. and Israel, while China's Volt Typhoon group has compromised critical infrastructure, including water systems, aiming for strategic pre-positioning. ([darkreading.com](https://www.darkreading.com/ics-ot-security/iran-russia-china-target-water-systems-sabotage?utm_source=openai)) The current relevance of these incidents is underscored by the persistent and evolving nature of cyber threats to critical infrastructure. The exploitation of basic security oversights by sophisticated threat actors highlights the urgent need for enhanced cybersecurity measures in the water sector to prevent potential disruptions and safeguard public health and safety.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports