Industry Category

Information Technology/IT

Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.

3205 threat reports
Page 81 of 268

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Information Technology/IT Threat Reports

Showing 961972 / 3205 reports
Introducing Sulla: Praetorian's Open-Source SMB Secret Scanner
Impact· MEDIUM

Introducing Sulla: Praetorian's Open-Source SMB Secret Scanner

In June 2026, Praetorian released Sulla, an open-source tool designed to scan SMB shares for exposed credentials across enterprise networks. Sulla automates the discovery of readable SMB shares, traverses their file structures, and scans contents for sensitive information using the Titus detection library. This tool addresses the challenge of manually reviewing numerous network shares, which is often tedious and inefficient. By integrating Sulla into their Continuous Threat Exposure Management platform, Guard, Praetorian ensures that SMB secrets are identified promptly as they appear in environments. The release of Sulla highlights the growing need for automated tools to detect and mitigate the risks associated with exposed credentials in network shares. As organizations increasingly rely on complex network infrastructures, tools like Sulla become essential in proactively identifying and addressing security vulnerabilities, thereby enhancing overall cybersecurity posture.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Vulnerability in SolarWinds Serv-U: CVE-2026-28318
Impact· MEDIUM

Critical Vulnerability in SolarWinds Serv-U: CVE-2026-28318

In early June 2026, a high-severity vulnerability (CVE-2026-28318) was identified in SolarWinds Serv-U, a widely used file transfer server. This flaw allows unauthenticated attackers to crash the Serv-U service by sending specially crafted POST requests with the 'Content-Encoding: deflate' header, leading to a denial-of-service (DoS) condition. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed active exploitation of this vulnerability and added it to their Known Exploited Vulnerabilities catalog on June 5, 2026. Organizations are urged to apply the available patch or implement recommended mitigations promptly to prevent service disruptions. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/06/08/cisa-patch-actively-exploited-solarwinds-serv-u-dos-vulnerability-cve-2026-28318/?utm_source=openai)) The exploitation of CVE-2026-28318 underscores the persistent targeting of file transfer services by threat actors. Given the critical role of such services in business operations, this incident highlights the necessity for organizations to maintain vigilant patch management practices and to monitor for emerging threats to ensure operational resilience.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Earth Lusca's Advanced Windows Malware Targets Government Entities
Impact· MEDIUM

Earth Lusca's Advanced Windows Malware Targets Government Entities

Between 2023 and 2024, the Chinese state-sponsored threat group Earth Lusca, also known as FishMonger, expanded its cyber espionage operations by deploying Windows variants of the previously Linux-based SprySOCKS malware. These sophisticated backdoors targeted government organizations in Taiwan, Thailand, Pakistan, and Honduras, focusing on sectors such as foreign affairs, technology, and telecommunications. The Windows versions, identified as WIN_DRV and WIN_PLUS, introduced advanced capabilities including kernel-level stealth mechanisms, enabling the malware to hide processes, network connections, and files, thereby evading detection. Both variants support over 30 command-and-control commands, facilitate communication over multiple protocols, and possess functionalities like keystroke logging and SOCKS proxy support. The emergence of these Windows variants underscores a significant evolution in Earth Lusca's tactics, highlighting the group's commitment to enhancing its toolset for broader and more effective cyber espionage campaigns. This development reflects a broader trend among nation-state actors to adapt and refine their malware to target diverse operating systems, emphasizing the need for organizations to implement comprehensive, cross-platform cybersecurity measures.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
iRhythm Data Breach 2026: A Wake-Up Call for Healthcare Cybersecurity
Impact· HIGH

iRhythm Data Breach 2026: A Wake-Up Call for Healthcare Cybersecurity

In June 2026, iRhythm Holdings, a digital healthcare company specializing in cardiac monitoring, experienced a significant data breach. On June 8, unauthorized activity was detected in third-party-hosted business applications, leading to the exfiltration of sensitive information, including proprietary data and patient protected health information (PHI). The attackers, employing social engineering tactics, contacted iRhythm on June 9, demanding a ransom to prevent public disclosure of the stolen data. The company promptly activated its cybersecurity response plan, engaged external experts, and confirmed the breach's materiality due to the volume of affected data. Importantly, iRhythm reported no impact on its products, clinical or medical device systems, patient safety, manufacturing and distribution operations, or financial reporting systems. ([streetinsider.com](https://www.streetinsider.com/Reuters/iRhythm%2Bdiscloses%2Bcyber%2Bincident%2C%2Bsays%2Bno%2Bimpact%2Bon%2Bdevice%2Bsystems%2C%2Bpatient%2Bsafety/26648941.html?utm_source=openai)) This incident underscores the escalating threat landscape targeting healthcare organizations, particularly through social engineering and ransomware attacks. The breach highlights the critical need for robust cybersecurity measures, comprehensive employee training to recognize and prevent social engineering attempts, and stringent data protection protocols to safeguard sensitive patient information.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
DragonForce Ransomware's Innovative Exploitation of Microsoft Teams in 2025
Impact· HIGH

DragonForce Ransomware's Innovative Exploitation of Microsoft Teams in 2025

In December 2025, the DragonForce ransomware group executed a sophisticated attack against a major U.S. services company. They exploited an unknown vulnerability in an SQL or MSSQL server to gain initial access. Subsequently, they deployed a custom Go-based malware named 'Backdoor.Turn,' which abused Microsoft Teams' Traversal Using Relays around NAT (TURN) protocol to conceal command-and-control (C2) communications within legitimate Teams traffic. This allowed the attackers to evade detection while exfiltrating data and deploying ransomware to encrypt the victim's systems. This incident underscores a concerning trend where threat actors leverage trusted cloud-based collaboration platforms to mask malicious activities. The abuse of Microsoft Teams' infrastructure for C2 communications highlights the need for organizations to scrutinize even legitimate traffic and implement robust monitoring mechanisms to detect anomalies within trusted services.

3 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical cPanel Plugin Vulnerability (CVE-2026-48172) Actively Exploited
Impact· CRITICAL

Critical cPanel Plugin Vulnerability (CVE-2026-48172) Actively Exploited

In May 2026, a critical privilege escalation vulnerability (CVE-2026-48172) was discovered in the LiteSpeed User-End cPanel Plugin versions prior to 2.4.5. This flaw allows authenticated cPanel users to execute arbitrary scripts with root privileges by exploiting the 'lsws.redisAble' function. The vulnerability has been actively exploited in the wild, leading to full system compromises on affected shared hosting servers. LiteSpeed released patches in May 2026, urging users to update to version 2.4.7 or later to mitigate the risk. The active exploitation of this vulnerability underscores the persistent threat posed by privilege escalation flaws in widely used web hosting platforms. Organizations must prioritize timely patching and implement robust monitoring to detect and prevent unauthorized access, especially in shared hosting environments where a single compromised account can jeopardize the entire server.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Malicious JetBrains Plugins Compromise Developer API Keys
Impact· MEDIUM

Malicious JetBrains Plugins Compromise Developer API Keys

In June 2026, Aikido Security uncovered a coordinated malware campaign involving at least 15 malicious plugins on the JetBrains Marketplace. These plugins, masquerading as AI coding assistants and Git utilities, were designed to steal AI API keys from developers. Upon users entering their API keys and clicking 'Apply,' the credentials were transmitted to a hardcoded server controlled by the attackers. The plugins, published under seven vendor accounts since October 2025, amassed nearly 70,000 installations. Notably, some plugins offered a paid tier, potentially redistributing stolen API keys to paying users. This incident underscores the escalating threat of supply chain attacks targeting developer ecosystems. As AI-powered tools become integral to software development, malicious actors are increasingly exploiting trusted platforms to distribute credential-stealing malware, highlighting the need for enhanced vigilance and security measures within developer communities.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Rokarolla Android Malware: A New Threat to Mobile Banking Security
Impact· HIGH

Rokarolla Android Malware: A New Threat to Mobile Banking Security

In June 2026, a sophisticated Android banking Trojan named Rokarolla emerged, targeting 217 banking and cryptocurrency applications. Distributed through malicious websites masquerading as legitimate Google Chrome or TikTok apps, Rokarolla gains complete administrative control over infected devices. Its capabilities include stealing lock screen credentials, contact lists, SMS data, and continuously recording user input via keyloggers. The malware employs overlays to display fake login screens, capturing sensitive financial information when users access targeted applications. Additionally, Rokarolla disables Google Play Protect, hides its icon, and maintains persistence by preventing device sleep, thereby evading detection and removal. The emergence of Rokarolla underscores a significant evolution in Android malware, combining financial data theft with extensive device surveillance and control. This trend highlights the increasing sophistication of threat actors and the urgent need for enhanced mobile security measures to protect sensitive user information and maintain device integrity.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in Google Vertex AI SDK: 'Pickle in the Middle' Attack Exposed
Impact· HIGH

Critical Vulnerability in Google Vertex AI SDK: 'Pickle in the Middle' Attack Exposed

In March 2026, a critical vulnerability was discovered in the Google Cloud Vertex AI SDK for Python, allowing attackers to hijack machine learning model uploads via a technique known as 'bucket squatting.' By preemptively creating Cloud Storage buckets with predictable names derived from a victim's project ID and region, attackers could intercept model uploads and execute arbitrary code within Google's serving infrastructure. This flaw, identified by Palo Alto Networks Unit 42 and termed 'Pickle in the Middle,' was patched by Google in April 2026 with the release of SDK version 1.148.0. Organizations using affected versions are urged to update immediately to mitigate potential risks. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/?utm_source=openai)) This incident underscores the critical importance of securing cloud-based machine learning workflows against supply chain attacks. As AI adoption accelerates, ensuring the integrity of model deployment processes becomes paramount to prevent unauthorized code execution and data breaches.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
New Malware Loaders Deployed in ClickFix Campaigns via Fake Updates
Impact· HIGH

New Malware Loaders Deployed in ClickFix Campaigns via Fake Updates

In June 2026, cybersecurity researchers identified multiple ClickFix campaigns deploying three new malware loaders: BabaDeda Loader, Lorem Ipsum Loader, and Potemkin. These campaigns utilized fake software update lures to infiltrate systems, primarily targeting the education and financial sectors. The attackers' methods included sophisticated social engineering tactics to deceive users into executing malicious payloads, leading to unauthorized access and potential data exfiltration. This incident underscores a growing trend of threat actors employing novel malware delivery mechanisms and deceptive tactics to compromise organizations. The emergence of these loaders highlights the need for enhanced vigilance and adaptive security measures to counter evolving cyber threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
SprySOCKS Windows Variant: A New Threat to Government Cybersecurity
Impact· HIGH

SprySOCKS Windows Variant: A New Threat to Government Cybersecurity

In 2023 and 2024, the China-linked cyber-espionage group FishMonger, also known as Earth Lusca and Aquatic Panda, deployed a Windows variant of the SprySOCKS backdoor against government organizations in Honduras, Taiwan, Thailand, and Pakistan. This variant utilizes malicious kernel drivers to evade detection, allowing the backdoor to conceal its processes and files by intercepting system calls and modifying outputs. The attackers likely gained initial access through exploiting vulnerabilities in public-facing servers. The emergence of this Windows variant underscores the evolving tactics of nation-state actors in enhancing malware stealth capabilities. Organizations should be vigilant about the use of kernel drivers in malware, as they pose significant challenges to detection and mitigation efforts.

3 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Rokarolla Android Trojan: A New Era of Mobile Threats
Impact· HIGH

Rokarolla Android Trojan: A New Era of Mobile Threats

In June 2026, the Rokarolla Android Trojan emerged, distributed through malicious websites masquerading as legitimate applications like Google Chrome and TikTok. This sophisticated malware not only compromised 217 banking and cryptocurrency apps to steal credentials but also executed 137 commands to gain full administrative control over infected devices. Its capabilities included harvesting lock screen credentials, exfiltrating sensitive data, deploying keyloggers, and rendering devices unusable by blocking calls, suppressing audio, and disabling security features such as Google Play Protect. ([darkreading.com](https://www.darkreading.com/endpoint-security/rokarolla-android-trojan?utm_source=openai)) The Rokarolla Trojan signifies a significant evolution in mobile malware, combining traditional banking fraud with extensive device surveillance and control. Its advanced persistence and evasion techniques highlight the increasing complexity of threats targeting Android devices, underscoring the necessity for robust mobile security measures and user vigilance against downloading apps from untrusted sources.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports