Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
OceanLotus Targets Vietnamese Investors via FireAnt Metakit Supply Chain Attack
Between mid-2024 and March 2026, the Vietnam-aligned threat actor OceanLotus (APT32) conducted cyber espionage campaigns targeting domestic entities. Notably, from October 2025 to March 2026, they executed a supply chain attack by compromising the update mechanism of FireAnt Metakit, a widely used stock investment platform in Vietnam. This allowed them to distribute the SPECTRALVIPER backdoor to a select group of investors, facilitating unauthorized access and data exfiltration. This incident underscores a strategic shift by OceanLotus towards domestic targets, highlighting the evolving threat landscape where nation-state actors exploit trusted software supply chains to infiltrate critical sectors. Organizations must enhance their software supply chain security and implement robust monitoring to detect such sophisticated attacks.
3 months ago
Kill Chain
OpenClaw AI Agent Phishing Incident Highlights Critical Security Gaps
In June 2026, a significant cybersecurity incident was reported involving the OpenClaw AI agent. Security researchers at Varonis conducted an experiment where they connected an OpenClaw email agent to a simulated Gmail inbox containing fictitious company data. Through a single phishing email impersonating a colleague, the AI agent was tricked into disclosing sensitive information, including AWS credentials, database connection strings, and a customer export list. This breach underscores the vulnerability of autonomous AI systems to social engineering attacks, highlighting the need for robust security measures in AI deployments. The incident is particularly concerning given the increasing integration of AI agents in enterprise environments. As these systems gain more autonomy and access to critical data, the potential for exploitation through sophisticated phishing tactics grows. Organizations must prioritize the development and implementation of security frameworks tailored to AI agents to prevent similar breaches in the future.
3 months ago
Kill Chain
Understanding the OpenClaw Vulnerability and AI Agent Supply Chain Risks
In early 2026, the OpenClaw AI agent framework, widely adopted for automating enterprise workflows, was found to have a critical vulnerability (CVE-2026-25253) that allowed remote code execution via a WebSocket exploit. This flaw enabled attackers to hijack agents by tricking users into visiting malicious websites, potentially compromising entire workstations. The incident highlighted the risks associated with unmanaged, autonomous AI systems operating with extensive access and minimal oversight. ([waxell.ai](https://www.waxell.ai/blog/openclaw-ai-agent-supply-chain-security?utm_source=openai)) This event underscores the growing security challenges in AI agent supply chains, emphasizing the need for robust governance and verification mechanisms. As organizations increasingly deploy AI agents, ensuring the integrity and security of third-party skills and components becomes paramount to prevent similar vulnerabilities and attacks.
3 months ago
Kill Chain
OpenAI Identifies Chinese Influence Operations Leveraging ChatGPT
In June 2026, OpenAI's threat intelligence team identified two distinct influence operations originating from China, utilizing ChatGPT to generate content aimed at exacerbating divisive topics such as AI and data centers. The first operation, termed "Data Center Bandwagon," produced imagery and social media posts alleging that data center expansions were increasing electricity costs for Americans. The second operation created content portraying tariffs as covert tools for nations to exert control over the global technological landscape, selectively including U.S. President Donald Trump while omitting Chinese President Xi Jinping. Both campaigns employed VPNs to mask their origins, used ChatGPT in simplified Chinese to generate content in both English and Chinese, and impersonated Americans on platforms like X and YouTube. Despite these efforts, OpenAI found minimal evidence of significant engagement beyond the operators' own amplification networks, indicating limited impact on public discourse. This incident underscores the evolving use of AI tools in state-sponsored influence operations and highlights the necessity for vigilance against such tactics. The use of generative AI by foreign actors to manipulate public opinion represents a growing challenge in the cybersecurity landscape, emphasizing the need for robust detection and mitigation strategies to counteract misinformation campaigns.
3 months ago
Kill Chain
CISA's BOD 26-04: A New Era in Risk-Based Vulnerability Management
On June 10, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive (BOD) 26-04, mandating federal agencies to prioritize vulnerability remediation based on four specific criteria: public exposure of the asset, evidence of active exploitation, potential for automated exploitation, and the technical impact of the vulnerability. Vulnerabilities meeting all four criteria require remediation within three days, accompanied by a forensic assessment to determine if systems have been compromised. ([cyberscoop.com](https://cyberscoop.com/cisa-vulnerability-remediation-directive-bod-26-04/?utm_source=openai)) This directive reflects CISA's response to the accelerated threat landscape, particularly the role of artificial intelligence in rapidly identifying and exploiting vulnerabilities. By focusing on risk-based prioritization, BOD 26-04 aims to enhance the efficiency and effectiveness of federal agencies' cybersecurity efforts, ensuring that the most critical vulnerabilities are addressed promptly to mitigate potential threats. ([cyberscoop.com](https://cyberscoop.com/cisa-vulnerability-remediation-directive-bod-26-04/?utm_source=openai))
3 months ago
Kill Chain
Microsoft Addresses Critical Zero-Day Vulnerabilities: YellowKey, GreenPlasma, and MiniPlasma
In June 2026, Microsoft addressed three critical zero-day vulnerabilities—YellowKey, GreenPlasma, and MiniPlasma—disclosed by the researcher 'Nightmare Eclipse.' YellowKey (CVE-2026-45585) allowed attackers with physical access to bypass BitLocker encryption via the Windows Recovery Environment. GreenPlasma (CVE-2026-45586) and MiniPlasma (CVE-2020-17103) were privilege escalation flaws in the Collaborative Translation Framework and Cloud Files Mini Filter Driver, respectively, enabling local attackers to gain SYSTEM privileges on fully patched Windows systems. These vulnerabilities were patched in Microsoft's June 2026 Patch Tuesday updates. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-yellowkey-greenplasma-miniplasma-zero-days/?utm_source=openai)) The disclosure of these vulnerabilities highlights ongoing challenges in vulnerability management and coordinated disclosure practices. The public release of proof-of-concept exploits prior to patches underscores the need for robust security measures and prompt patch management to mitigate potential threats.
3 months ago
Kill Chain
Microsoft Exchange Server CVE-2026-42897 Zero-Day Exploited in Attacks
In May 2026, Microsoft disclosed a high-severity cross-site scripting (XSS) vulnerability, CVE-2026-42897, affecting on-premises Exchange Server versions 2016, 2019, and Subscription Edition. This flaw allows remote attackers to execute arbitrary JavaScript in the context of a user's browser by sending specially crafted emails, which, when opened in Outlook Web Access (OWA), trigger the exploit. The vulnerability was actively exploited in the wild, prompting Microsoft to release security updates in June 2026 to address the issue. Organizations were advised to apply these updates promptly and maintain existing mitigations to ensure comprehensive protection. The exploitation of CVE-2026-42897 underscores the persistent targeting of email infrastructure by threat actors, highlighting the critical need for organizations to prioritize the security of their communication platforms. This incident serves as a reminder of the importance of timely patch management and the implementation of robust security measures to defend against evolving cyber threats.
3 months ago
Kill Chain
GitHub's npm v12: Strengthening Security Against Supply-Chain Attacks
In June 2026, GitHub announced significant security enhancements for npm version 12, aimed at mitigating supply-chain attacks. Key changes include requiring explicit approval for running preinstall, install, or postinstall scripts from dependencies, and restricting automatic fetching of dependencies from Git repositories and remote URLs unless explicitly permitted. These measures are designed to prevent unauthorized code execution during package installations, thereby enhancing the security of the npm ecosystem. This initiative addresses vulnerabilities exploited in recent supply-chain attacks, such as the Shai-Hulud campaign, which compromised numerous npm packages to steal developer credentials. By implementing these changes, GitHub aims to fortify the software supply chain against emerging threats and protect developers from potential security breaches.
3 months ago
Kill Chain
Critical Langflow Vulnerability CVE-2026-5027 Exploited in the Wild
In early 2026, a critical path traversal vulnerability, CVE-2026-5027, was discovered in Langflow, an open-source AI development platform. This flaw allowed unauthenticated attackers to write arbitrary files to exposed servers by exploiting the 'POST /api/v2/files' endpoint, which failed to properly sanitize user-supplied filenames. The vulnerability was publicly disclosed on March 27, 2026, after initial reports to the Langflow team went unanswered. Exploitation of this flaw has been observed in the wild, with attackers dropping test files on vulnerable instances. Langflow users are urged to upgrade to version 1.10.0 to mitigate this risk. This incident underscores the critical importance of timely vulnerability management and the risks associated with default configurations that allow unauthenticated access. Organizations must prioritize patching known vulnerabilities and reassess default settings to prevent unauthorized exploitation.
3 months ago
Kill Chain
Miasma Worm Source Code Leaked on GitHub: Implications for Open-Source Security
In June 2026, the Miasma worm, an evolution of the Shai-Hulud malware, was deliberately leaked on GitHub by threat actors. This credential-stealing framework targets developers by infecting their machines, harvesting build environment and cloud credentials, and propagating itself by compromising legitimate repositories and packages. Notably, Miasma has been linked to significant supply chain attacks, including the compromise of 73 Microsoft GitHub repositories and Red Hat npm packages. The worm's autonomous propagation mechanism poses a substantial risk to the open-source ecosystem, enabling rapid and widespread distribution of malicious code. The deliberate release of Miasma's source code is expected to facilitate further adaptations by malicious actors, potentially leading to an increase in sophisticated supply chain attacks. This incident underscores the critical need for enhanced security measures within the open-source community to mitigate the risks associated with such self-propagating malware.
3 months ago
Kill Chain
The Gentlemen Ransomware Group: A Rising Threat in 2026
The Gentlemen ransomware group, emerging in mid-2025, has rapidly become the second most active ransomware-as-a-service (RaaS) operation, claiming over 330 victims by mid-2026. Offering affiliates a 90% revenue share, the group attracts experienced operators who exploit internet-facing devices like VPNs and firewalls to gain initial access, swiftly encrypting entire networks within hours. Their cross-platform ransomware, written in Go, targets Windows, Linux, and ESXi environments, employing advanced techniques such as lateral movement, defense evasion, and data exfiltration to maximize impact. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor/?utm_source=openai))The rapid ascent of The Gentlemen underscores the evolving sophistication of ransomware operations, highlighting the urgent need for organizations to bolster their cybersecurity defenses. The group's aggressive recruitment and advanced tactics exemplify the growing threat posed by RaaS platforms, emphasizing the importance of proactive threat intelligence and robust security measures to mitigate such risks. ([computerweekly.com](https://www.computerweekly.com/news/366643511/The-Gentlemen-emerging-as-key-ransomware-player?utm_source=openai))
3 months ago
Kill Chain
Proto6 Vulnerabilities in protobuf.js: A Threat to Node.js Applications
In June 2026, cybersecurity researchers identified six critical vulnerabilities, collectively termed 'Proto6,' in protobuf.js—a widely used JavaScript and TypeScript implementation of Google's Protocol Buffers. These flaws, including CVE-2026-44291 and CVE-2026-44295, could lead to remote code execution (RCE) and denial-of-service (DoS) attacks if exploited. The vulnerabilities affect Node.js applications utilizing protobuf.js, Google Cloud client libraries, messaging frameworks like Baileys, and CI/CD pipelines. Attackers can exploit these issues by introducing malicious protobuf schemas, potentially compromising sensitive data and system integrity. The discovery underscores the growing risks in software supply chains, especially within data and AI ecosystems that frequently exchange schemas and configurations. Organizations are urged to update to protobuf.js versions 7.5.6 or 8.0.2 to mitigate these threats.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports