Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Klue OAuth Breach 2026: A Wake-Up Call for Third-Party Integration Security
In June 2026, market intelligence platform Klue experienced a security breach where attackers, identified as the 'Icarus' group, exploited OAuth tokens to access and exfiltrate Salesforce CRM data from multiple organizations. The attackers infiltrated Klue's backend systems, deployed malicious code to harvest OAuth tokens, and utilized these tokens to query and extract sensitive data from connected Salesforce instances. This incident led to significant data theft and subsequent extortion attempts targeting the affected organizations. This breach underscores the critical vulnerabilities associated with third-party integrations and the exploitation of OAuth tokens. It highlights the necessity for organizations to implement stringent security measures, including regular audits of third-party applications, prompt revocation of compromised tokens, and continuous monitoring of API activities to detect and mitigate unauthorized access promptly.
3 months ago
Kill Chain
Nintendo's 2026 Data Breach: A Wake-Up Call for Third-Party Security
In June 2026, Nintendo of America experienced a data breach through TinyPulse, a third-party service used for internal employee surveys. The cybercriminal group ShadowByt3$ claimed responsibility, alleging they exfiltrated approximately 859 MB of sensitive data, including employee names, email addresses, bank statements, and W-9 forms. Nintendo confirmed the breach but stated that only internal survey content from a small subset of employees was affected, with most information dating back several years. The company's internal systems, as well as customer and financial data, remained uncompromised. This incident underscores the growing threat posed by emerging ransomware groups like ShadowByt3$, which, despite their relatively recent appearance, are capable of targeting major corporations through third-party service vulnerabilities. Organizations must reassess their third-party risk management strategies to prevent similar breaches.
3 months ago
Kill Chain
F5 Releases Patches for Critical NGINX Vulnerabilities CVE-2026-42530 and CVE-2026-42055
In June 2026, F5 disclosed two critical vulnerabilities in NGINX Open Source: CVE-2026-42530 and CVE-2026-42055, both with a CVSS v4 score of 9.2. CVE-2026-42530 is a use-after-free flaw in the ngx_http_v3_module, exploitable when NGINX is configured with the HTTP/3 QUIC module, potentially allowing remote code execution if Address Space Layout Randomization (ASLR) is disabled or bypassed. CVE-2026-42055 is a heap-based buffer overflow in the ngx_http_proxy_v2_module and ngx_http_grpc_module, triggered under specific configurations involving HTTP/2 proxying, which could also lead to remote code execution under similar conditions. F5 has released patches to address these vulnerabilities and recommends disabling HTTP/3 and adjusting configuration directives as interim mitigations. The discovery of these vulnerabilities underscores the persistent risks associated with widely used open-source software components. Organizations relying on NGINX should promptly apply the provided patches and review their configurations to mitigate potential exploitation. This incident highlights the importance of continuous monitoring and timely updates to maintain the security of critical infrastructure.
3 months ago
Kill Chain
Kali365: The Emerging Threat Bypassing MFA in Microsoft 365
In April 2026, a new Phishing-as-a-Service (PhaaS) platform named Kali365 emerged, enabling cybercriminals to hijack Microsoft 365 accounts by exploiting the OAuth device code flow. This method allows attackers to bypass multi-factor authentication (MFA) by tricking users into entering device codes on legitimate Microsoft verification pages, thereby granting unauthorized access to services like Outlook, OneDrive, and Teams. The FBI issued a public service announcement in May 2026, highlighting the widespread distribution of Kali365 via Telegram and its use in numerous attacks across various sectors, including manufacturing, education, government, financial services, and healthcare. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260521?utm_source=openai)) The significance of this incident lies in its demonstration of how attackers can circumvent traditional security measures, such as MFA, by exploiting legitimate authentication processes. The accessibility of Kali365 through subscription services lowers the barrier for less-skilled attackers to conduct sophisticated phishing campaigns, posing a substantial threat to organizations relying on Microsoft 365. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260521?utm_source=openai))
3 months ago
Kill Chain
Salesforce Data Breach via Klue App Compromise
In June 2026, threat actors exploited OAuth tokens from Klue's Battlecards app to access Salesforce instances, leading to unauthorized data exfiltration. This incident mirrors previous breaches involving third-party integrations like Salesloft's Drift and Gainsight, highlighting the persistent risks associated with SaaS application connections. The attackers authenticated through a compromised Klue integration service account, generating OAuth tokens that granted access to customers' integrated Salesforce environments. The exfiltration process involved automated scripts querying the Salesforce REST API over a 24-hour period, with some instances experiencing concentrated bursts of nearly a thousand queries in 15 minutes. This breach underscores the critical need for organizations to scrutinize third-party integrations and enforce stringent security measures to protect sensitive data. The recurrence of such attacks emphasizes the importance of continuous monitoring and the implementation of robust security protocols to mitigate risks associated with third-party applications.
3 months ago
Kill Chain
Unveiling the Popa Botnet: A Threat Hidden in Plain Sight
In June 2026, cybersecurity researchers uncovered that the 'Popa' botnet, active for four years, had compromised millions of Android-based TV boxes, turning them into nodes for a residential proxy network. This network facilitated activities such as advertising fraud, account takeovers, and mass data scraping. Investigations linked the botnet to NetNut, a residential proxy provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd. The compromised devices, often marketed as offering free access to subscription services, were found to have pre-installed software that enrolled users' home internet connections into the proxy network without explicit consent. This incident highlights the growing threat posed by malicious software embedded in consumer devices, particularly those offering 'free' services. The use of residential proxy networks for illicit activities underscores the need for consumers to exercise caution when purchasing and installing such devices. It also emphasizes the importance of regulatory scrutiny over companies providing proxy services to ensure they are not facilitating cybercriminal activities.
3 months ago
Kill Chain
INC Ransomware: A Rising Threat with Over 830 Victims Since 2023
Since August 2023, the INC ransomware group has rapidly evolved into a significant ransomware-as-a-service (RaaS) operation, claiming over 830 victims by June 2026. The group's attacks are characterized by the use of Rust-based encryptors for cross-platform compatibility and resistance to reverse engineering. They employ a diverse range of tools and techniques, including exploiting vulnerabilities in public-facing applications, credential dumping from Veeam backup servers, and utilizing living-off-the-land binaries (LOLBins) for lateral movement. Notably, INC has targeted unpatched edge devices for initial access and used commercial remote monitoring and management (RMM) tools for command-and-control operations. The rise of INC ransomware underscores the adaptability of cybercriminals in leveraging existing vulnerabilities and tools to execute widespread attacks. Their success highlights the critical need for organizations to maintain up-to-date security measures, conduct regular vulnerability assessments, and implement robust incident response plans to mitigate the risks posed by such sophisticated ransomware operations.
3 months ago
Kill Chain
DragonForce Ransomware's Stealthy Exploitation of Microsoft Teams
In December 2025, the DragonForce ransomware group infiltrated a major U.S. services firm by exploiting an SQL-related vulnerability. They deployed a custom Go-based remote access trojan (RAT) named Backdoor.Turn, which concealed command-and-control (C2) traffic within Microsoft Teams' TURN relay infrastructure. This method allowed the attackers to remain undetected for one to two months, as the malicious traffic appeared as legitimate Teams communication. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/06/16/dragonforce-microsoft-teams-malware-backdoor-turn/?utm_source=openai)) This incident underscores a significant evolution in cyberattack methodologies, highlighting the increasing sophistication of threat actors in leveraging trusted communication platforms to evade detection. Organizations must reassess their security postures to address such advanced persistent threats.
3 months ago
Kill Chain
Microsoft Uncovers Sophisticated Windows Clipper Malware Campaign
In June 2026, Microsoft disclosed a sophisticated malware campaign targeting Windows users through USB drives containing malicious LNK files. Once executed, these shortcuts leveraged Windows Script Host and ActiveX to initiate a Tor proxy, establishing a connection to a hidden command-and-control (C2) server. The primary objective of this campaign was to deploy a cryptocurrency clipper, designed to intercept and alter clipboard contents, thereby redirecting cryptocurrency transactions to attacker-controlled wallets. This incident underscores the persistent threat posed by USB-based malware and the evolving tactics of cybercriminals who exploit legitimate Windows functionalities to evade detection. The use of Tor for C2 communication highlights the increasing adoption of anonymization techniques by threat actors, complicating traditional network defense strategies.
3 months ago
Kill Chain
Red Hat npm Supply Chain Attack: A Wake-Up Call for Software Security
In June 2026, Red Hat's npm packages were compromised in a significant supply chain attack. Threat actors infiltrated the @redhat-cloud-services namespace, injecting a credential-stealing worm into 32 packages, affecting 96 versions. These malicious packages, downloaded over 116,000 times weekly, exploited GitHub Actions' OpenID Connect to publish the compromised code, indicating a breach in the CI/CD pipeline. The attack led to unauthorized access to sensitive credentials, posing substantial risks to downstream users. ([aikido.dev](https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting trusted software ecosystems. Organizations must enhance their security measures, particularly in CI/CD pipelines, to prevent similar breaches. The event highlights the necessity for continuous monitoring and rapid response strategies to mitigate the impact of such sophisticated attacks.
3 months ago
Kill Chain
Surge in SSH Brute Force Attacks Correlates with Global Events in 2026
Between February and May 2026, a DShield honeypot recorded over 20 million SSH brute-force attempts, revealing a significant correlation between attack volumes and external events such as geopolitical tensions and cybersecurity advisories. Notably, a 2100% surge in attacks coincided with CISA's Emergency Directive 26-03 addressing Cisco SD-WAN vulnerabilities, and peaks in activity aligned with escalating conflicts involving Iran, Israel, and the United States. These findings underscore the adaptability of threat actors who exploit global events to intensify their malicious activities. The study highlights the persistent threat posed by coordinated SSH brute-force attacks and the necessity for organizations to implement robust security measures. As attackers continue to leverage global events to orchestrate large-scale attacks, it is imperative for entities to enhance their defenses, monitor for unusual activity, and stay informed about emerging threats to mitigate potential breaches.
3 months ago
Kill Chain
Crypto Clipper Malware: A New Threat Leveraging Tor and Worm-Like Propagation
In February 2026, Microsoft identified a Windows-based cryptocurrency clipper malware that propagates via malicious shortcut (.lnk) files. This malware comprises a worm component for self-propagation and a stealer component that harvests and exfiltrates cryptocurrency wallet information. Notably, it utilizes Windows Script Host and ActiveX to launch a bundled Tor proxy, enabling communication with a hidden-service command-and-control (C2) server. The malware performs high-frequency clipboard monitoring, screenshot exfiltration, and wallet-address substitution, effectively turning a financially motivated stealer into a lightweight backdoor. The incident underscores the evolving sophistication of malware leveraging anonymized communication channels like Tor and worm-like propagation methods. Organizations should be vigilant about script-based threats and implement behavioral detection mechanisms to identify suspicious activities such as script interpreters spawning unexpected child processes, localhost proxy usage, and clipboard inspection behaviors.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports