Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
ShinyHunters' Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
Between May 27 and June 9, 2026, the cyber extortion group ShinyHunters exploited a zero-day vulnerability (CVE-2026-35273) in Oracle's PeopleSoft software, specifically targeting the Environment Management Hub (EMHub). This critical flaw allowed unauthenticated remote code execution, leading to the compromise of over 100 organizations, predominantly in the higher education sector. The attackers exfiltrated sensitive data from approximately 300 PeopleSoft instances, including personal and financial information of students and staff. Oracle released a security advisory and patch on June 10, 2026, urging immediate action to mitigate the risk. ([darkreading.com](https://www.darkreading.com/vulnerabilities-threats/shinyhunters-oracle-zero-day-higher-ed?utm_source=openai)) This incident underscores the increasing targeting of educational institutions by cybercriminals exploiting unpatched vulnerabilities in widely used enterprise software. The rapid exploitation of zero-day vulnerabilities highlights the necessity for organizations to implement proactive vulnerability management and incident response strategies to protect sensitive data and maintain operational integrity.
3 months ago
Kill Chain
Anthropic Halts AI Models Fable 5 and Mythos 5 Following U.S. Government Directive
In June 2026, the U.S. government issued an export control directive requiring Anthropic to suspend access to its advanced AI models, Fable 5 and Mythos 5, for all foreign nationals, including those within the United States. This directive, citing national security concerns, led Anthropic to disable these models globally to ensure compliance. The order also affected foreign national employees of Anthropic, highlighting the broad scope of the government's action. ([tomshardware.com](https://www.tomshardware.com/tech-industry/artificial-intelligence/us-export-control-order-forces-anthropic-to-disable-claude-fable-5-and-mythos-5-worldwide?utm_source=openai)) This incident underscores the increasing regulatory scrutiny over advanced AI technologies and their potential implications for national security. Organizations developing or utilizing such technologies must stay vigilant to evolving compliance requirements and assess the impact of governmental directives on their operations and international collaborations.
3 months ago
Kill Chain
Critical Vulnerability in Splunk Enterprise: CVE-2026-20253
In June 2026, a critical vulnerability (CVE-2026-20253) was identified in Splunk Enterprise versions below 10.2.4 and 10.0.7, allowing unauthenticated users to perform arbitrary file operations via a PostgreSQL sidecar service endpoint lacking authentication controls. This flaw could lead to remote code execution, data destruction, and full system compromise. Splunk has released patches to address this issue, urging immediate updates to mitigate potential exploitation. The disclosure of CVE-2026-20253 underscores the ongoing risks associated with unauthenticated access points in enterprise software. Organizations are advised to review their security postures, apply the latest patches promptly, and implement robust access controls to prevent similar vulnerabilities from being exploited.
3 months ago
Kill Chain
ShinyHunters' Exploitation of Oracle PeopleSoft CVE-2026-35273: A Wake-Up Call for Higher Education
In late May 2026, the cybercriminal group ShinyHunters exploited a zero-day vulnerability, CVE-2026-35273, in Oracle PeopleSoft PeopleTools versions 8.61 and 8.62. This flaw allowed unauthenticated remote code execution, leading to the compromise of over 100 organizations, predominantly in the U.S. higher education sector. The University of Nottingham confirmed significant student data theft following the group's data leak. Oracle disclosed the vulnerability on June 10, 2026, and released a critical patch, urging immediate application to mitigate further risks. This incident underscores the critical importance of timely patch management and proactive vulnerability monitoring. The exploitation of unpatched systems by threat actors like ShinyHunters highlights the need for organizations to enhance their cybersecurity posture to prevent similar breaches.
3 months ago
Kill Chain
Conti Ransomware Member Pleads Guilty to Wire Fraud Conspiracy
In June 2026, Ukrainian national Oleksii Lytvynenko pleaded guilty to conspiracy to commit wire fraud for his role in the Conti ransomware group. Lytvynenko admitted to joining Conti in September 2021, developing malware used in attacks, and possessing data from 12 victims, including eight in the United States. Conti was responsible for over 1,000 ransomware attacks globally, resulting in at least $150 million in ransom payments. Lytvynenko faces up to 20 years in prison, with sentencing scheduled for September 10, 2026. This case underscores the persistent threat posed by ransomware groups and highlights the importance of international cooperation in combating cybercrime. Organizations should remain vigilant, as threat actors continue to evolve their tactics and rebrand under new identities, necessitating robust cybersecurity measures and proactive defense strategies.
3 months ago
Kill Chain
Tchap Messenger Breach: Data of 73,000 French Government Employees Exposed
In June 2026, the French government's encrypted messaging platform, Tchap, experienced a security breach when a threat actor gained access through a compromised user account. This intrusion led to the exposure of data from public chat rooms, affecting over 73,000 public sector employees. The compromised information included users' names, email addresses, avatar images, and their affiliated public sector organizations. Private conversations remained encrypted and were not accessed during the breach. This incident underscores the persistent threat posed by social engineering attacks and highlights the importance of securing even internal communication platforms. Organizations must remain vigilant and continuously enhance their security measures to protect sensitive information from unauthorized access.
3 months ago
Kill Chain
Detecting Early Warning Signs of Supply Chain Attacks on the Dark Web
In June 2026, cybersecurity researchers identified early indicators of potential supply chain attacks emerging from the dark web. Threat actors were observed advertising access to developer accounts, private repositories, and source code, which could be exploited to infiltrate organizations through trusted third-party relationships. These findings underscore the critical need for proactive monitoring of underground forums to detect and mitigate supply chain vulnerabilities before they escalate into full-scale breaches. The increasing sophistication of cybercriminals in targeting supply chains highlights the urgency for organizations to enhance their threat intelligence capabilities. By identifying and addressing these early warning signs, businesses can strengthen their defenses against complex attacks that exploit trusted connections and third-party services.
3 months ago
Kill Chain
Urgent: CISA's Directive on Patching Critical Ivanti Sentry Vulnerability
In June 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a directive mandating federal agencies to patch a critical vulnerability (CVE-2026-10520) in Ivanti Sentry devices within three days. This OS command injection flaw allows unauthenticated remote attackers to execute code with root privileges. Despite Ivanti's initial statement of no evidence of exploitation, reports emerged of attackers backdooring exposed Sentry gateways. This incident underscores the escalating threat landscape where critical vulnerabilities are rapidly exploited. Organizations must prioritize timely patching and robust vulnerability management to mitigate risks associated with such high-severity flaws.
3 months ago
Kill Chain
Arch Linux AUR Compromise 2026: A Wake-Up Call for Open-Source Security
In June 2026, over 400 packages in the Arch User Repository (AUR) were compromised to distribute a Linux rootkit and infostealer malware. Attackers spoofed trusted publishers to inject malicious preinstall scripts that downloaded and executed the 'atomic-lockfile' npm package. This malware targeted sensitive information, including credentials and access tokens, and utilized eBPF rootkit capabilities to conceal its presence. The incident underscores the vulnerabilities inherent in community-maintained repositories and the critical need for stringent package verification processes. This breach highlights the escalating threat of supply chain attacks, particularly within open-source ecosystems. Organizations must enhance their security postures by implementing robust monitoring and validation mechanisms to detect and prevent such infiltrations.
3 months ago
Kill Chain
phpBB Authentication Bypass Vulnerability Exposes User Accounts
In June 2026, a critical authentication bypass vulnerability was discovered in phpBB, a widely used open-source forum software. This flaw, present for over a decade, allowed attackers to log in as any user, including administrators, without requiring a password. The vulnerability affected phpBB versions up to 3.3.16 and 4.0.0-a2. Exploiting this issue was straightforward, requiring only a single HTTP request, and could be executed on default configurations without special knowledge. The phpBB team promptly addressed the issue by releasing version 3.3.17 on June 6, 2026, which patched the vulnerability. This incident underscores the importance of regular security audits and prompt patching in open-source software. The ease of exploitation and the widespread use of phpBB made this vulnerability particularly concerning, highlighting the need for vigilance in maintaining and updating software to protect against emerging threats.
3 months ago
Kill Chain
Massive Compromise of Arch Linux AUR Packages Leads to Deployment of Infostealer and eBPF Rootkit
In June 2026, attackers compromised over 400 packages in the Arch User Repository (AUR), modifying their build scripts to deploy a Rust-based credential stealer. This malware targeted developer secrets, including browser cookies, SSH keys, and API tokens. When executed with root privileges, it could also install an eBPF rootkit to conceal its presence. The attack exploited the trust model of the AUR by adopting orphaned packages and altering their build instructions, while the package names and histories remained unchanged. This incident underscores the vulnerabilities inherent in community-maintained repositories and highlights the need for rigorous package vetting processes. The use of eBPF rootkits represents an evolution in malware techniques, emphasizing the importance of advanced detection mechanisms to identify and mitigate such sophisticated threats.
3 months ago
Kill Chain
Critical Vulnerability in Ivanti Sentry: CVE-2026-10520
In June 2026, a critical OS command injection vulnerability, CVE-2026-10520, was identified in Ivanti Sentry versions prior to R10.5.2, R10.6.2, and R10.7.1. This flaw allows remote, unauthenticated attackers to execute arbitrary code with root privileges. Within 24 hours of disclosure, attackers exploited this vulnerability to backdoor exposed Ivanti Sentry appliances, compromising enterprise mobile gateways. ([techtimes.com](https://www.techtimes.com/articles/318221/20260611/ivanti-sentry-actively-exploited-cvss-100-flaw-backdoors-enterprise-mobile-gateways.htm?utm_source=openai)) The rapid exploitation underscores the urgency for organizations to promptly apply security patches. The availability of a public proof-of-concept exploit increases the risk of widespread attacks, emphasizing the need for immediate remediation. ([noise.getoto.net](https://noise.getoto.net/2026/06/10/cve-2026-10520-cve-2026-10523-multiple-critical-vulnerabilities-affecting-ivanti-sentry/?utm_source=openai))
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports