Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Prinz Eugen Ransomware: A New Threat Targeting Recent Files
In June 2026, the Prinz Eugen ransomware group launched attacks targeting organizations in the United Kingdom, France, and South Africa. The group gained initial access through stolen RDP credentials, utilizing legitimate remote monitoring and management tools to establish persistence. Their Go-based malware prioritized encrypting recently modified files, aiming to disrupt critical business operations. Notably, the ransomware did not leave a ransom note, complicating detection and response efforts. This incident underscores the evolving tactics of ransomware groups, emphasizing the need for organizations to enhance their cybersecurity measures. The use of legitimate tools for malicious purposes highlights the importance of monitoring for anomalous behavior and implementing robust access controls to mitigate such threats.
3 months ago
Kill Chain
CISA Confirms Active Exploitation of Splunk Enterprise Vulnerability CVE-2026-20253
In June 2026, a critical vulnerability (CVE-2026-20253) was identified in Splunk Enterprise versions 10.2.0 to 10.2.3 and 10.0.0 to 10.0.6, allowing unauthenticated remote attackers to create or truncate arbitrary files via a PostgreSQL sidecar service endpoint lacking authentication controls. This flaw enables potential remote code execution, posing significant risks to affected systems. ([advisory.splunk.com](https://advisory.splunk.com/advisories/SVD-2026-0603?utm_source=openai)) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation of this vulnerability and has mandated federal agencies to patch their systems by June 22, 2026.
3 months ago
Kill Chain
Understanding Device Code Phishing: The New Frontier in MFA Bypass
In early 2026, cybersecurity researchers identified a surge in phishing campaigns exploiting the OAuth 2.0 Device Authorization Grant flow to bypass multi-factor authentication (MFA). Attackers trick users into entering device codes on legitimate Microsoft authentication pages, granting unauthorized access to services like Outlook, OneDrive, and Teams without stealing credentials. This method allows persistent access, even after password resets, posing significant risks to organizations relying on traditional MFA for security. The proliferation of Phishing-as-a-Service platforms, such as Kali365, has lowered the technical barrier for cybercriminals, enabling large-scale exploitation of this technique. The FBI and Microsoft have issued warnings, emphasizing the need for organizations to implement conditional access policies, disable device code authentication where unnecessary, and adopt phishing-resistant MFA solutions to mitigate these evolving threats.
3 months ago
Kill Chain
Texas Parks and Wildlife Department Data Breach Exposes Over 3 Million Records
In June 2026, the Texas Parks and Wildlife Department (TPWD) disclosed a significant data breach involving its license system vendor, exposing personal information of over 3 million individuals. The compromised data includes driver's license information, passport numbers, email addresses, phone numbers, and residential addresses. Notably, Social Security numbers, dates of birth, and financial information were not affected. The breach was detected by the Texas Cyber Command, prompting an immediate investigation and the implementation of enhanced security measures. ([tpwd.texas.gov](https://tpwd.texas.gov/about/notification-of-data-security-incident/?utm_source=openai)) This incident underscores the escalating risks associated with third-party vendors in data security. Organizations are increasingly vulnerable to breaches through external partners, highlighting the necessity for stringent vendor management and comprehensive security protocols to safeguard sensitive information.
3 months ago
Kill Chain
AutoJack Attack: A Wake-Up Call for AI Agent Security
In June 2026, Microsoft researchers disclosed a critical vulnerability named 'AutoJack' that allows a single web page to hijack AI browsing agents, leading to remote code execution on the host machine. By directing an AI agent to load a malicious web page, attackers can exploit JavaScript to interact with privileged local services, spawning unauthorized processes without requiring user credentials or further interaction. This exploit underscores the significant risks associated with AI agents' integration with web content and their elevated system privileges. The AutoJack attack highlights the growing trend of adversaries targeting AI development tools and agents. Similar incidents, such as the 'Agentjacking' attack, have demonstrated how AI coding agents can be manipulated into executing malicious code through crafted error reports. These developments emphasize the urgent need for robust security measures in AI agent design and deployment to prevent exploitation through prompt injections and other novel attack vectors.
3 months ago
Kill Chain
The Gentlemen RaaS Unleashes GentleKiller: A New EDR Evasion Framework
In June 2026, The Gentlemen ransomware-as-a-service (RaaS) operation was identified as actively developing and distributing a suite of endpoint detection and response (EDR) termination tools, collectively known as the GentleKiller framework. This framework targets approximately 400 processes associated with 48 distinct security programs, effectively disabling system defenses prior to deploying ransomware payloads. The Gentlemen group has demonstrated rapid operationalization of newly disclosed proof-of-concept exploits, often integrating them within days of public release. The Gentlemen's ability to swiftly adapt and enhance their EDR evasion techniques underscores a significant evolution in ransomware tactics, emphasizing the need for organizations to implement robust, multi-layered security measures. The group's extensive use of the bring your own vulnerable driver (BYOVD) technique highlights the importance of monitoring and controlling driver installations to prevent such attacks.
3 months ago
Kill Chain
Critical Vulnerabilities in Apollo Pharmacy's Blood Glucose Monitoring System APG-01 BT
In June 2026, vulnerabilities were identified in the Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT, specifically affecting version 0x0110_v1.1.0. These vulnerabilities, CVE-2026-50034 and CVE-2026-52866, allow attackers within Bluetooth Low Energy (BLE) range to intercept sensitive health data and disrupt device connectivity. The first vulnerability enables unauthorized access to glucose measurement values, while the second allows an attacker to monopolize the device's BLE connection, preventing legitimate use. These issues highlight the critical need for robust security measures in medical devices, especially those utilizing wireless communication protocols. As healthcare increasingly relies on connected devices, ensuring the confidentiality and availability of patient data is paramount to maintaining trust and compliance with regulatory standards.
3 months ago
Kill Chain
Fortinet Credential Exposure 2026: Massive 'FortiBleed' Campaign
In June 2026, a significant cybersecurity incident known as 'FortiBleed' exposed credentials associated with approximately 74,000 Fortinet devices, including firewalls and VPN gateways. Security researchers discovered a massive archive containing FortiGate firewall URLs, usernames, emails, and plaintext passwords from major corporations such as Chevron, Samsung, Foxconn, and Toyota. The attackers, reportedly Russian-speaking, executed over 1.1 billion credential attempts against 320,000 FortiGate VPN instances, leading to the compromise of Active Directory environments and, in some cases, the exfiltration of classified documents. Fortinet responded by emphasizing best practices like regular credential updates and enabling multi-factor authentication (MFA) to mitigate risks. This incident underscores the critical importance of robust credential management and the implementation of MFA, especially for internet-facing systems. The scale and sophistication of the 'FortiBleed' campaign highlight the evolving tactics of cyber adversaries and the necessity for organizations to proactively secure their network infrastructures.
3 months ago
Kill Chain
Belgian Bank Customers Targeted in Sophisticated Phishing Attack Using IPv4-Mapped IPv6 Addresses
In June 2026, a phishing campaign targeted customers of a major Belgian bank by exploiting IPv4-mapped IPv6 addresses to obfuscate malicious URLs. The attackers sent emails containing links formatted as IPv6 literals, such as 'hxxp://[::ffff:5511:74be]/kWC5PHA1', which, when decoded, resolved to an IPv4 address hosting the phishing content. This technique aimed to bypass security controls that rely on detecting suspicious domain names or IP addresses. Upon clicking the link, victims were redirected to a fraudulent website designed to harvest sensitive banking credentials. The campaign underscores the evolving tactics of cybercriminals in leveraging less commonly monitored aspects of internet protocols to evade detection. ([isc.sans.edu](https://isc.sans.edu/diary/32804?utm_source=openai)) The use of IPv4-mapped IPv6 addresses in phishing attacks highlights a growing trend where attackers exploit the complexities of IPv6 to conceal malicious activities. As IPv6 adoption increases, security systems must adapt to recognize and mitigate threats that utilize these advanced obfuscation methods. Organizations are urged to enhance their monitoring capabilities to detect such techniques and educate users about the risks associated with unfamiliar URL formats.
3 months ago
Kill Chain
Operation Endgame: A Major Blow to SocGholish Malware Infrastructure
In June 2026, an international law enforcement coalition comprising agencies from the Netherlands, Canada, the United States, and Germany executed Operation Endgame, targeting the SocGholish malware infrastructure. This coordinated effort led to the takedown of 106 servers and the remediation of 14,971 WordPress websites infected with SocGholish, a JavaScript-based downloader malware. SocGholish, active since 2017, masquerades as browser updates to distribute additional malicious payloads, often leading to ransomware attacks orchestrated by groups like Evil Corp. The operation significantly disrupted the malware's distribution channels, mitigating further risks to global digital systems. ([politie.nl](https://www.politie.nl/en/news/2026/june/18/international-law-enforcement-initiate-hunt-on-malware-group-socgholish.html?utm_source=openai)) The success of Operation Endgame underscores the effectiveness of international collaboration in combating cyber threats. However, the persistent evolution of malware tactics necessitates continuous vigilance and adaptive cybersecurity measures. Organizations are urged to regularly update their systems, monitor for unauthorized access, and educate users about the dangers of deceptive software updates to prevent future infections.
3 months ago
Kill Chain
TeamPCP's Supply Chain Attacks: A Wake-Up Call for Open-Source Security
Between February and June 2026, the cybercriminal group TeamPCP executed a series of supply chain attacks, compromising over 1,000 open-source software packages. By infiltrating widely used tools such as Trivy, Checkmarx KICS, LiteLLM, and the Telnyx Python SDK, TeamPCP exploited vulnerabilities in CI/CD pipelines and AI development tools to inject malicious code, leading to the exfiltration of sensitive data and credentials. This campaign underscored the critical weaknesses in the software supply chain, particularly the reliance on unverified code dependencies and the lack of rigorous security checks in automated deployment systems. The incident highlights the urgent need for organizations to reassess their software development practices, emphasizing the importance of verifying the integrity of open-source components and implementing robust security measures within CI/CD pipelines. As supply chain attacks become more prevalent, the industry must prioritize security to prevent similar large-scale compromises in the future.
3 months ago
Kill Chain
USB Worm Targets Cryptocurrency Wallets via Windows Shortcut Files
In June 2026, a sophisticated USB worm emerged, targeting cryptocurrency wallets by distributing clipboard-stealing malware through Windows shortcut (LNK) files on USB drives. Upon execution, the malware scans the system for document files, hides the originals, and replaces them with malicious shortcuts. It monitors clipboard activity to detect and replace cryptocurrency wallet addresses with those controlled by the attacker, captures screenshots, and exfiltrates data via the Tor network. The worm also propagates by copying itself to newly connected USB devices, facilitating further spread. This incident underscores the evolving tactics of threat actors leveraging removable media to infiltrate systems, emphasizing the need for heightened vigilance and robust security measures to protect sensitive financial information.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports