Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Hackers Exploit Critical Everest Forms Pro Plugin Flaw
In March 2026, a critical vulnerability (CVE-2026-3300) was discovered in the Everest Forms Pro WordPress plugin, affecting versions up to 1.9.12. This flaw allowed unauthenticated attackers to execute arbitrary PHP code via the plugin's 'Complex Calculation' feature, leading to full site compromise. Despite a patch released on March 18, 2026, exploitation began on April 13, 2026, with over 29,300 attempts recorded, including the creation of rogue administrator accounts named 'diksimarina'. This incident underscores the persistent threat posed by vulnerabilities in widely-used WordPress plugins. The rapid exploitation following disclosure highlights the critical need for timely patching and robust security measures to protect web assets from emerging threats.
3 months ago
Kill Chain
Microsoft AI Red Team Enhances AI Security with Updated Failure Mode Taxonomy
In June 2026, the Microsoft AI Red Team released an updated taxonomy of failure modes in agentic AI systems, building upon their initial April 2025 publication. This revision introduces seven new failure mode categories, expands mitigation strategies, and incorporates insights from a year of red team engagements. Key developments prompting this update include the rapid mainstream adoption of open-source agentic frameworks like OpenClaw, which, upon its January 2026 launch, revealed significant vulnerabilities such as CVE-2026-25253—a critical WebSocket hijacking flaw. Additionally, the maturation of the Model Context Protocol (MCP) ecosystem has led to an increase in vulnerabilities, with 99 CVEs reported in 2025 alone. The transition of computer-use agents from research to production has further exposed novel attack surfaces, necessitating a comprehensive reevaluation of existing security frameworks. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/06/04/updating-taxonomy-failure-modes-agentic-ai-systems-year-red-teaming-taught-us/?utm_source=openai)) This update is particularly relevant as agentic AI systems become more integrated into critical domains, amplifying the potential impact of their failure modes. The introduction of new categories like Agentic Supply Chain Compromise and Goal Hijacking underscores the evolving threat landscape. Organizations must proactively adapt their security measures to address these emerging risks, ensuring the safe deployment and operation of agentic AI systems in increasingly complex environments.
3 months ago
Kill Chain
WeTransfer Phishing Campaign Delivers Multi-Stage Malware via Trusted Services
In June 2026, a sophisticated phishing campaign was identified, leveraging legitimate WeTransfer links to distribute malicious JavaScript files. The attack began with an email containing a WeTransfer link to a file named "Remittance Advice.js," which, upon execution, initiated a multi-stage infection chain. This chain involved decoding and executing PowerShell commands to download and run additional payloads, including a modified .NET DLL disguised within an MSI-branded JPEG image. The attackers utilized trusted cloud services like Cloudflare Workers and R2 to host these malicious payloads, enhancing the campaign's credibility and evading detection mechanisms. This incident underscores the increasing trend of cybercriminals exploiting legitimate platforms to deliver malware, making it imperative for organizations to scrutinize even seemingly trustworthy sources. The use of steganography to conceal malicious code within image files further complicates detection efforts, highlighting the need for advanced threat detection capabilities and continuous monitoring of network traffic to identify and mitigate such sophisticated attacks.
3 months ago
Kill Chain
OP-512: New Threat Cluster Targets Microsoft IIS Servers with Custom Web Shells
In June 2026, cybersecurity researchers identified a new threat cluster named OP-512, which targets Microsoft Internet Information Services (IIS) servers to deploy a custom web shell framework. This activity is assessed with moderate to high confidence to be linked to China and is focused on espionage. The attackers utilize a bespoke framework consisting of three web shells that provide remote access while evading detection through techniques like timestomping, which manipulates file timestamps to complicate forensic analysis. The compromised servers automatically report back to the attackers, facilitating centralized management at scale. This incident underscores a growing trend of sophisticated cyber-espionage campaigns targeting critical infrastructure. The use of custom web shells and advanced evasion techniques highlights the evolving tactics of nation-state actors, emphasizing the need for organizations to enhance their security measures to detect and mitigate such threats.
3 months ago
Kill Chain
Microsoft and Nightmare Eclipse: A 2026 Vulnerability Disclosure Controversy
In May 2026, a security researcher known as 'Nightmare Eclipse' publicly disclosed six zero-day vulnerabilities affecting Microsoft products, including Windows Defender and BitLocker. The researcher released proof-of-concept exploit code without prior coordination with Microsoft, leading to the exploitation of three vulnerabilities—BlueHammer, RedSun, and UnDefend—in active attacks before patches were issued. Microsoft responded by threatening legal action through its Digital Crimes Unit, accusing the researcher of irresponsible disclosure that endangered customers. This incident has reignited debates within the cybersecurity community regarding the ethics and protocols of vulnerability disclosure, highlighting the delicate balance between researchers and vendors. The situation underscores the ongoing challenges in establishing trust and effective communication channels between security researchers and software vendors, emphasizing the need for clear and mutually respected disclosure policies to protect end-users.
3 months ago
Kill Chain
AI Agents: The New Frontier of Insider Threats
In June 2026, DTEX researchers identified significant security vulnerabilities associated with the integration of AI agents, specifically Anthropic's Claude Cowork, into corporate environments. Their study demonstrated how these AI tools, when misused by insiders, could facilitate unauthorized access and exfiltration of sensitive data. By issuing simple prompts, users could instruct the AI to summarize and transfer confidential information from platforms like Salesforce and Outlook, effectively bypassing traditional security controls. This exploitation underscores the potential for AI agents to be leveraged in insider threats, whether through malicious intent or inadequate security measures. The rapid advancement and deployment of AI technologies in business operations have outpaced the development of corresponding security protocols. This incident highlights the urgent need for organizations to implement robust monitoring and control mechanisms for AI tools to prevent misuse and protect sensitive data. As AI becomes more embedded in critical systems, the risk of insider threats exploiting these technologies is expected to rise, necessitating immediate attention and action from cybersecurity professionals.
3 months ago
Kill Chain
IronWorm Malware Infiltrates npm: A Wake-Up Call for Supply-Chain Security
In June 2026, a sophisticated supply-chain attack introduced the IronWorm malware into 36 npm packages, compromising developer environments and CI/CD systems. IronWorm, written in Rust and concealed by an eBPF kernel rootkit, exfiltrated sensitive credentials—including those for OpenAI, AWS, and npm—via the Tor network. The malware propagated by leveraging stolen credentials to publish trojanized packages, thereby infecting additional systems. This incident underscores the escalating threat of supply-chain attacks targeting open-source ecosystems, emphasizing the need for enhanced security measures in software development pipelines.
3 months ago
Kill Chain
DentaQuest Data Breach 2026: ShinyHunters Expose 2.6 Million Records
In May 2026, DentaQuest, a leading dental benefits administrator in the United States, experienced a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers infiltrated DentaQuest's network, exfiltrating over 234 GB of sensitive data, which included personal information of approximately 2.6 million individuals. The compromised data encompassed email addresses, full names, phone numbers, government-issued IDs, health insurance details, genders, and dates of birth. Following unsuccessful ransom negotiations, ShinyHunters publicly released the stolen data, amplifying the potential for identity theft and fraud among affected individuals. This incident underscores a troubling trend of cyber extortion targeting healthcare organizations, highlighting the critical need for robust cybersecurity measures and rapid incident response protocols to protect sensitive patient information.
3 months ago
Kill Chain
Supply Chain Attack on Hola Browser Leads to Cryptominer Distribution
In June 2026, the Windows version of the Hola Browser was compromised through a supply chain attack, leading to the distribution of an unauthorized executable identified as a cryptocurrency miner. This incident was uncovered during routine certification checks by AppEsteem, revealing that the compromised software installed an undeclared file named 'me.exe' in the 'C:\Program Files\Hola\' directory. Further analysis confirmed that this file was a Monero cryptocurrency miner, which added a Windows Defender exclusion rule, copied itself as 'HolaMonitorService.exe,' created an auto-starting Windows service named 'hola_monitor_svc,' and operated when the computer was idle. Hola's CEO, Avi Raz Cohen, acknowledged the breach, stating that approximately 0.1% of users were affected, with no evidence of user data access or theft. In response, Hola rebuilt its distribution pipeline, implemented advanced code-signing verification, and introduced stricter access controls and continuous monitoring across its infrastructure. This incident underscores the persistent threat of supply chain attacks targeting widely used software applications. The compromise of Hola Browser highlights the importance of rigorous security measures in software distribution channels to prevent unauthorized code insertion. Organizations and individual users must remain vigilant, ensuring that software updates and installations come from verified sources and are subjected to thorough security assessments to mitigate the risks associated with such attacks.
3 months ago
Kill Chain
SideCopy's Xeno RAT Attack on Afghan Finance Ministry: A Case Study
In May 2025, the Pakistan-linked APT group SideCopy initiated a cyberespionage campaign targeting Afghanistan's Ministry of Finance and provincial finance offices. The attackers employed spear-phishing emails containing ZIP archives with malicious LNK files disguised as PDFs. These files, when executed, utilized mshta.exe to fetch an HTA payload from a compromised Afghan education domain, leading to the deployment of Xeno RAT 1.8.7. This malware enabled remote command execution, data exfiltration, and system monitoring, including keystroke logging and screenshot capture. The campaign demonstrated a deliberate approach to defense evasion by leveraging Pashto-language lures and hosting payloads on Afghan government infrastructure to blend malicious traffic with legitimate state communications. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/pakistan-spies-afghan-finance-ministry-xeno-rat?utm_source=openai)) This incident underscores the persistent threat posed by nation-state actors employing sophisticated social engineering tactics and leveraging local infrastructure to conduct espionage. Organizations, especially governmental entities, must enhance their cybersecurity posture by implementing robust email filtering, user education on phishing threats, and continuous monitoring for indicators of compromise to mitigate such risks.
3 months ago
Kill Chain
Prolonged Espionage: Hackers Exploit Stock Exchange Executive's Outlook Mailbox
Between October 2025 and March 2026, attackers infiltrated the Outlook mailbox of a senior executive at a major global stock exchange, maintaining undetected access for approximately 150 days. They exfiltrated sensitive data in small, incremental batches using legitimate cloud services like Dropbox and OneDrive, effectively blending malicious activity with normal network traffic. The attackers employed malware disguised as trusted software components and utilized scheduled tasks for persistence, enabling continuous monitoring and extraction of confidential communications, schedules, and potentially market-moving information. ([securityweek.com](https://www.securityweek.com/hackers-target-global-stock-exchange-in-espionage-operation/?utm_source=openai)) This incident underscores the increasing sophistication of cyber-espionage campaigns targeting high-level executives to access sensitive organizational data. The use of legitimate cloud services for data exfiltration highlights the challenges in detecting such stealthy operations, emphasizing the need for enhanced monitoring and security measures to protect executive communications. ([cyberleveling.com](https://cyberleveling.com/blog/stock-exchange-espionage-executive-email-2026?utm_source=openai))
3 months ago
Kill Chain
Beware: Fake Open-Source Tool Sites Spreading Malware via TDS
In June 2026, cybersecurity researchers identified a large-scale campaign where threat actors created counterfeit websites mimicking popular open-source and freeware tools such as Ghidra, dnSpy, and SpiderFoot. These deceptive sites, designed to appear legitimate, employed a Traffic Distribution System (TDS) to redirect users to malicious payloads, including Remus Stealer, AnimateClipper, and the SessionGate framework. The attackers utilized search engine optimization (SEO) techniques to rank these fake sites prominently on search engines like Google, increasing the likelihood of user engagement and subsequent malware infections. This incident underscores a growing trend where cybercriminals exploit SEO and TDS mechanisms to distribute malware through seemingly trustworthy channels. The sophistication of these attacks highlights the need for heightened vigilance among users and organizations, emphasizing the importance of verifying the authenticity of software download sources to mitigate the risk of malware infections.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports