Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation
In May 2026, a critical vulnerability (CVE-2026-54420) was identified in the LiteSpeed cPanel Plugin versions prior to 2.4.8, allowing users with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux or CageFS. This flaw, resulting from improper handling of symbolic links, was actively exploited in the wild, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities catalog on June 15, 2026. Administrators were urged to upgrade to LiteSpeed WHM Plugin v5.3.2.1 or later to mitigate the risk. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-54420?utm_source=openai)) The incident underscores the persistent threat posed by privilege escalation vulnerabilities in widely used web hosting environments. It highlights the importance of timely patch management and vigilant monitoring to prevent unauthorized access and potential system compromise.
3 months ago
Kill Chain
CISA Highlights Active Exploitation of Two Critical Vulnerabilities
On June 15, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-20262 and CVE-2026-54420. CVE-2026-20262 affects Cisco Catalyst SD-WAN Manager, allowing authenticated remote attackers to create or overwrite files on the system, potentially leading to root access. CVE-2026-54420 impacts the LiteSpeed cPanel Plugin, where improper handling of symbolic links enables users with FTP or web shell access to exploit shared hosting servers running CloudLinux/CageFS. Both vulnerabilities have been actively exploited in the wild, posing significant risks to affected systems. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-sdwan-arbfw-c2rZvQ.html?utm_source=openai)) The inclusion of these vulnerabilities in the KEV Catalog underscores the critical need for organizations to prioritize patching and mitigation efforts. The active exploitation of these flaws highlights the evolving threat landscape and the importance of maintaining up-to-date security measures to protect against potential breaches.
3 months ago
Kill Chain
Critical Vulnerability in Splunk Enterprise: CVE-2026-20253
In June 2026, a critical vulnerability (CVE-2026-20253) was disclosed in Splunk Enterprise versions 10.0.x and 10.2.x, stemming from an unauthenticated PostgreSQL sidecar service endpoint. This flaw allows remote attackers to perform arbitrary file creation or truncation without credentials, potentially leading to remote code execution by exploiting PostgreSQL's lo_export function. While no active exploitation has been reported, a public proof-of-concept is available, increasing the risk for unpatched or exposed systems. The incident underscores the importance of promptly addressing vulnerabilities in widely used enterprise tools. Organizations must ensure timely patching and robust network segmentation to mitigate such risks, especially given the rapid dissemination of exploit proofs in the cybersecurity community.
3 months ago
Kill Chain
Inside the Modern SOC: Navigating 2026's Identity-Based Cyber Threats
In 2025, Unit 42 responded to over 750 major cyber incidents across various industries and countries. A significant trend observed was the rapid acceleration of attack timelines, with some adversaries moving from initial access to data exfiltration in just 72 minutes—a fourfold increase from the previous year. This surge is largely attributed to the integration of AI by threat actors, enhancing their speed and efficiency. Additionally, identity-based attacks have become predominant, with 65% of initial accesses driven by techniques such as social engineering and credential misuse. ([paloaltonetworks.com](https://www.paloaltonetworks.com/blog/2026/02/unit-42-global-ir-report/?utm_source=openai)) The current cybersecurity landscape underscores the urgency for organizations to adapt to these evolving threats. The rise in AI-driven attacks and the exploitation of identity vulnerabilities necessitate a reevaluation of security strategies. Implementing robust identity and access management, enhancing monitoring capabilities, and adopting AI-driven defense mechanisms are crucial steps to mitigate these accelerated and sophisticated threats.
3 months ago
Kill Chain
ShinyHunters Breach Infinite Campus: 137,000 School Staff Accounts Exposed
In March 2026, the ShinyHunters extortion group infiltrated Infinite Campus's Salesforce instance, compromising personal information of over 137,000 school staff members. The stolen data included names, email addresses, phone numbers, physical addresses, and support tickets. Infinite Campus, a leading EdTech provider serving over 3,200 school districts across the United States, confirmed the breach but stated that the majority of the exposed information was publicly available directory data. This incident underscores the escalating trend of cybercriminals targeting educational institutions and their service providers. The breach highlights the critical need for robust security measures and vigilant monitoring of third-party platforms to safeguard sensitive information in the education sector.
3 months ago
Kill Chain
North Korean Hackers Exploit Developer Tools in Sophisticated Phishing Campaign
In early 2026, a North Korean state-sponsored threat actor, identified as UNK_DeadDrop, launched a sophisticated phishing campaign targeting software developers across nearly 100 organizations, primarily in the United States. The attackers sent over 250 emails between April and May, masquerading as recruitment offers or code review requests. These emails directed recipients to clone malicious GitHub or GitLab repositories, which, when opened in code editors like Visual Studio Code, executed embedded malware. This approach enabled the attackers to steal cryptocurrency wallets and sensitive developer credentials. ([theregister.com](https://www.theregister.com/security/2026/06/08/suspected-norks-send-250-fake-dev-job-pitches-to-steal-crypto/5252526?utm_source=openai)) This incident underscores a significant evolution in cyberattack methodologies, where adversaries exploit trusted developer tools and workflows to deliver malware. The campaign's scale and sophistication highlight the increasing targeting of the tech industry by state-sponsored actors, emphasizing the need for heightened vigilance and robust security measures within development environments. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/?utm_source=openai))
3 months ago
Kill Chain
Critical Authentication Bypass in SimpleHelp: CVE-2026-48558
In June 2026, a critical vulnerability (CVE-2026-48558) was discovered in SimpleHelp remote management software versions 5.5.15 and earlier, as well as 6.0 pre-release versions. This flaw allows unauthenticated attackers to create privileged technician accounts by exploiting improper validation of identity tokens in the OpenID Connect (OIDC) authentication flow. Consequently, attackers can gain unauthorized access to managed endpoints, execute scripts, and perform administrative actions without user interaction. SimpleHelp addressed this issue by releasing patched versions 5.5.16 and 6.0 RC2 on June 9, 2026. Organizations are urged to update their systems promptly to mitigate potential exploitation risks. This incident underscores the critical importance of robust authentication mechanisms and thorough validation processes in remote management tools. The exploitation of OIDC vulnerabilities highlights a growing trend where attackers target identity and access management systems to gain unauthorized access, emphasizing the need for continuous vigilance and timely patch management.
3 months ago
Kill Chain
Critical LiteLLM Vulnerabilities Expose AI Gateways to Unauthenticated RCE
In May 2026, a critical vulnerability chain was discovered in LiteLLM, an open-source AI gateway widely used to interface with over 100 large language model providers. The primary flaw, CVE-2026-42271, is a command injection vulnerability affecting versions 1.74.2 through 1.83.6. This vulnerability allows authenticated users, including those with low-privilege internal-user keys, to execute arbitrary commands on the host system by exploiting two Model Context Protocol (MCP) test endpoints. When combined with CVE-2026-48710, an authentication bypass in the Starlette web framework, attackers can achieve unauthenticated remote code execution, granting them full control over the server. This chain of vulnerabilities exposes sensitive API keys and secrets stored by the proxy, potentially compromising connected AI systems and enabling lateral movement within enterprise networks. The active exploitation of these vulnerabilities underscores the increasing targeting of AI gateway infrastructures by threat actors. Organizations relying on LiteLLM are urged to upgrade to version 1.83.7 or later, which addresses these issues by implementing stricter authorization controls and updating dependencies. Additionally, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-42271 to its Known Exploited Vulnerabilities catalog, emphasizing the urgency for immediate remediation to prevent potential breaches and data exfiltration.
3 months ago
Kill Chain
Palo Alto Networks PAN-OS GlobalProtect VPN Authentication Bypass Vulnerability (CVE-2026-0257)
In May 2026, Palo Alto Networks disclosed CVE-2026-0257, a high-severity authentication bypass vulnerability in the GlobalProtect portal and gateway components of PAN-OS software. This flaw allows unauthenticated remote attackers to forge valid session cookies, enabling unauthorized VPN connections into corporate networks. Active exploitation of this vulnerability was observed starting May 17, 2026, with attackers attempting to access GlobalProtect portals. While no post-access behavior or lateral movement has been identified, the potential for unauthorized access to sensitive internal resources poses a significant risk. The inclusion of CVE-2026-0257 in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog underscores the urgency for organizations to address this issue. The active exploitation highlights a broader trend of attackers targeting VPN infrastructures to gain unauthorized access, emphasizing the need for robust authentication mechanisms and timely patch management to mitigate such threats.
3 months ago
Kill Chain
Unveiling the Threat: 152 Malicious Chrome Extensions Compromise User Security
In June 2026, cybersecurity researchers uncovered a network of 152 Google Chrome extensions, primarily offering live wallpaper functionalities, that were distributing potentially unwanted programs (PUPs). These extensions, spanning 38 separate Chrome Web Store publisher accounts and three brand backends—tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com—had collectively amassed 105,000 installations. Despite claiming not to collect user data, the extensions' privacy policies revealed the logging of IP addresses, ISPs, click counts, and referrers, with data shared with Google AdSense, DoubleClick, and third-party ad partners. Additionally, some extensions manipulated browser behavior to simulate organic search traffic, thereby fabricating the origin of their own traffic. This incident underscores the persistent threat posed by malicious browser extensions, which can compromise user privacy and security. The deceptive practices employed highlight the need for vigilant monitoring of browser add-ons and the importance of scrutinizing privacy policies, even for seemingly benign applications.
3 months ago
Kill Chain
Google Patches Actively Exploited Chrome Zero-Day Vulnerability CVE-2026-11645
In June 2026, Google addressed a high-severity zero-day vulnerability, CVE-2026-11645, in its Chrome browser. This flaw, an out-of-bounds read and write issue in the V8 JavaScript engine, allowed remote attackers to execute arbitrary code via crafted HTML pages. The vulnerability was actively exploited in the wild, prompting Google to release an emergency update to mitigate the risk. Users were urged to update to version 149.0.7827.103 to secure their systems. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/06/09/google-chrome-zero-day-cve-2026-11645/?utm_source=openai)) This incident underscores the persistent targeting of widely used software by threat actors and highlights the critical importance of timely software updates. The exploitation of such vulnerabilities can lead to significant data breaches and system compromises, emphasizing the need for robust cybersecurity practices.
3 months ago
Kill Chain
Former IT Employee Sentenced for Prolonged Cyberattacks on School District
In June 2026, Ezekiel Dean Potter, a former senior IT support specialist at Saydel Community School District in Des Moines, Iowa, was sentenced to 21 months in prison for conducting a series of unauthorized cyberattacks against his former employer. After his termination in April 2023, Potter retained access credentials and over the next 21 months, he deleted the district's Facebook page, disrupted access to educational platforms, and reset employee usernames and passwords, causing significant operational disruptions and financial losses estimated at tens of thousands of dollars. This incident underscores the critical importance of promptly revoking access credentials of departing employees and implementing robust monitoring systems to detect unauthorized access. The case highlights the potential risks posed by insider threats and the necessity for organizations to enforce strict access control policies to safeguard their digital assets.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports