Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Scattered Spider's 2024 Cyberattack on Transport for London: A Case Study
In late August 2024, the cybercriminal group Scattered Spider infiltrated Transport for London's (TfL) systems, compromising the Oyster refunds system and causing significant operational disruptions. The attack led to the theft of customer data and forced all 28,000 TfL employees to reset their passwords, resulting in financial damages estimated at £29 million ($38.3 million). This incident underscores the escalating threat posed by cybercriminal groups targeting critical infrastructure. Organizations must enhance their cybersecurity measures to prevent similar breaches and mitigate potential operational and financial impacts.
3 months ago
Kill Chain
New macOS ClickFix Attack Silently Mounts DMGs to Deploy Infostealer
In June 2026, a new macOS ClickFix campaign emerged, utilizing Terminal commands to silently download, mount, and execute info-stealing malware from malicious disk image (DMG) files. This attack infects Mac devices with the Atomic macOS Stealer (AMOS), which exfiltrates browser credentials, cryptocurrency wallet data, Keychain information, messaging app data, and user documents. The campaign begins with a fake CAPTCHA page instructing users to open Terminal and paste a malicious command, leading to the automatic execution of the malware. This method represents an evolution in ClickFix attacks, combining social engineering with automated malware deployment to enhance stealth and effectiveness. The significance of this incident lies in the increasing sophistication of social engineering attacks targeting macOS users. By leveraging trusted system utilities and deceptive prompts, attackers can bypass traditional security measures and user vigilance. This trend underscores the need for enhanced user education, robust endpoint protection, and continuous monitoring to detect and mitigate such evolving threats.
3 months ago
Kill Chain
Xsolis Data Breach 2026: A Wake-Up Call for Healthcare Cybersecurity
In January 2026, healthcare technology company Xsolis experienced a data breach affecting nearly 1.4 million individuals. The breach resulted from a targeted phishing attack on January 20, 2026, which allowed unauthorized access to Xsolis's network. The attackers accessed files containing sensitive personal and health information, including names, addresses, dates of birth, Social Security numbers, health insurance details, and medical treatment information. Xsolis detected the unauthorized activity on January 22, 2026, promptly contained the breach, and initiated an investigation with external cybersecurity experts. The company has since notified affected individuals and implemented additional security measures to prevent future incidents. This incident underscores the persistent threat of phishing attacks in the healthcare sector, highlighting the critical need for robust cybersecurity measures and employee training to protect sensitive patient data. The breach also raises concerns about potential identity theft and fraud for the affected individuals, emphasizing the importance of vigilance and proactive monitoring of personal information.
3 months ago
Kill Chain
WhatsApp Phishing Campaign Installs ManageEngine RMM Tool via VBScript
In June 2026, a sophisticated phishing campaign was identified targeting users of WhatsApp Desktop and WhatsApp Web across multiple countries, including Malaysia, Brazil, India, Mexico, Singapore, the U.K., Spain, Taiwan, and Australia. Attackers utilized compromised WhatsApp accounts to distribute malicious Visual Basic Script (VBScript) files disguised as legitimate business documents, such as invoices and billing statements. Upon execution, these scripts installed ManageEngine Endpoint Central, a legitimate Remote Monitoring and Management (RMM) tool, granting attackers full remote control over the victim's system. This unauthorized access enabled the exfiltration of sensitive data, installation of additional malware, and potential lateral movement within corporate networks. This incident underscores a concerning trend in cyber threats where attackers leverage legitimate software tools to evade detection and maintain persistent access within compromised systems. The use of social engineering tactics, such as distributing malware through trusted communication platforms like WhatsApp, highlights the evolving nature of phishing campaigns and the necessity for organizations to enhance their security awareness training and implement robust endpoint protection measures.
3 months ago
Kill Chain
Malicious npm Packages Masquerade as PostCSS Tools to Deploy Windows RAT
In June 2026, cybersecurity researchers identified a series of malicious npm packages masquerading as legitimate PostCSS tools. These packages, including 'aes-decode-runner-pro', 'postcss-minify-selector', and 'postcss-minify-selector-parser', were designed to deliver a Windows-based Remote Access Trojan (RAT) upon installation. The packages were published over the past month by an npm user named 'abdrizak'. The malicious code was heavily obfuscated, leveraging techniques like Base64 and XOR encoding, as well as minification, to resist analysis and detection efforts. Upon installation, the packages retrieved a malicious script from a remote server, executing it silently to deploy the RAT on Windows systems. ([research.jfrog.com](https://research.jfrog.com/post/from-postcss-typosquat-to-windows-rat/?utm_source=openai)) This incident underscores the persistent threat of supply chain attacks within the npm ecosystem. Attackers continue to exploit the trust in widely used open-source packages to distribute malware, highlighting the need for enhanced vigilance and security measures among developers and organizations.
3 months ago
Kill Chain
AIR's Experiment Unveils Critical Security Gaps in AI Agent Skill Marketplaces
In June 2026, security firm AIR conducted an experiment to highlight vulnerabilities in AI agent skill marketplaces. They created a fake AI agent skill named 'brand-landingpage,' which purported to assist users in building landing pages using Google's Stitch design tool. This skill was submitted to a popular skill marketplace and promoted via an Instagram ad, ultimately reaching approximately 26,000 agents, including those on corporate accounts. Notably, all security scanners tested by AIR marked the skill as safe. The payload was intentionally benign, merely collecting users' email addresses to demonstrate the ease with which malicious skills could bypass existing security measures. This incident underscores the pressing need for enhanced security protocols in AI agent skill ecosystems, as traditional trust signals such as GitHub stars and scanner verdicts proved insufficient in detecting potential threats. The reliance on external links within skills, which can be altered post-review, presents a significant risk, emphasizing the necessity for continuous monitoring and comprehensive vetting processes to safeguard against supply chain attacks in AI environments.
3 months ago
Kill Chain
FortiBleed: Unprecedented Credential Harvesting Targets FortiGate Firewalls
In June 2026, a Russian-speaking initial access broker initiated 'FortiBleed,' a large-scale credential-harvesting operation targeting over 430,000 FortiGate firewalls globally. The campaign involved deploying custom sniffers on compromised devices to capture cleartext and hashed credentials, which were then used to infiltrate Active Directory domains and other services. This incident underscores the critical need for organizations to secure their network devices, as attackers increasingly exploit firewall vulnerabilities to gain unauthorized access. The widespread impact of FortiBleed highlights the importance of regular security assessments and prompt patch management.
3 months ago
Kill Chain
DifyTap Vulnerabilities: A Wake-Up Call for AI Platform Security
In June 2026, security researchers identified four critical vulnerabilities, collectively termed 'DifyTap,' in the Dify AI platform. These flaws—CVE-2026-41947, CVE-2026-41948, CVE-2026-41949, and CVE-2026-41950—allowed unauthorized access to sensitive data, including private AI chat histories and documents across tenants. Exploitation could lead to significant data breaches and compromise of AI applications. The DifyTap vulnerabilities underscore the escalating risks associated with AI platforms, emphasizing the need for robust security measures and prompt patch management to protect sensitive information and maintain trust in AI-driven services.
3 months ago
Kill Chain
FortiBleed: Massive Credential Exposure in Fortinet Firewalls
In June 2026, the 'FortiBleed' campaign emerged as a significant cybersecurity threat, compromising over 86,000 Fortinet FortiGate firewalls across 194 countries. Attackers utilized a Golang-based tool, FortigateSniffer, to exploit default credentials and weak password practices, turning these devices into passive credential collectors across 24 authentication protocols. This led to the exposure of approximately 110 million credentials, affecting major corporations and government agencies worldwide. The incident underscores the critical importance of robust password policies and the implementation of multi-factor authentication (MFA). Organizations are urged to review and enhance their security measures to prevent similar breaches, as reliance on default credentials and inadequate password management continue to be exploited by threat actors.
3 months ago
Kill Chain
GitHub Actions Enhances Security with 'actions/checkout' v7 Update
In June 2026, GitHub enhanced the security of its software supply chain by updating the 'actions/checkout' action to block common 'pwn request' attack patterns. These attacks exploit the 'pull_request_target' workflow trigger to execute malicious code with full workflow privileges. Effective June 18, 2026, 'actions/checkout' version 7 and later versions refuse to fetch fork pull request code in 'pull_request_target' and 'workflow_run' workflows by default, unless explicitly configured otherwise. This change aims to prevent unauthorized code execution and protect repositories from potential compromises. This update is particularly relevant now due to the increasing prevalence of supply chain attacks targeting CI/CD pipelines. By enforcing stricter defaults, GitHub addresses a critical vulnerability that has been exploited in recent incidents, thereby strengthening the overall security posture of the developer community.
3 months ago
Kill Chain
Unveiling the Complexity: Dual Threat Actors Exploit SharePoint Vulnerabilities in 2026
In June 2026, Microsoft's Detection and Response Team (DART) investigated a complex cyber intrusion involving two unrelated threat actors operating simultaneously within the same environment. The initial access was achieved through exploitation of known vulnerabilities in on-premises SharePoint servers, notably CVE-2025-49706 and CVE-2025-49704. One actor, identified as Storm-2603, utilized legitimate tools like Velociraptor to map the environment and established multiple remote access channels via Cloudflare tunneling, Zoho Assist, and SSH connections configured through Visual Studio Code. Concurrently, a second, unidentified actor employed techniques such as malicious DLL sideloading and custom backdoors, complicating detection and attribution. This dual-actor presence enabled sustained access and obfuscated the full scope of the intrusion. This incident underscores the evolving complexity of cyber threats, where multiple actors may exploit the same vulnerabilities simultaneously, blending tactics to evade detection. It highlights the critical need for organizations to implement comprehensive patch management, enhance identity security, and maintain continuous visibility across their environments to detect and respond to such sophisticated attacks effectively.
3 months ago
Kill Chain
OpenAI's 'Patch the Planet' Initiative: A New Era in Open-Source Security
In June 2026, OpenAI, in collaboration with Trail of Bits, launched 'Patch the Planet,' an initiative aimed at enhancing the security of critical open-source software. This program pairs OpenAI's advanced AI models, such as GPT-5.5-Cyber, with human security engineers to identify vulnerabilities, develop patches, and assist maintainers in integrating these fixes. Early participants include projects like cURL, Go, Python, Sigstore, and pyca/cryptography. The initiative has already led to the discovery of hundreds of security issues and the merging of numerous patches, significantly improving the security posture of these foundational software components. ([techcrunch.com](https://techcrunch.com/2026/06/22/openai-launches-new-initiative-to-help-find-and-patch-open-source-bugs/?utm_source=openai)) The relevance of this initiative is underscored by the increasing reliance on open-source software in critical infrastructure and the persistent challenges in maintaining its security. By combining AI-driven analysis with expert human intervention, 'Patch the Planet' addresses the pressing need for scalable and efficient vulnerability remediation in the open-source ecosystem.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports