The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Outsourcing/Offshoring
Breach intelligence, attack campaigns, and threat reports targeting the Outsourcing/Offshoring sector.
Explore Other Sectors
Outsourcing/Offshoring Threat Reports
Jade Sleet's Supply Chain Attack: How North Korean Hackers Weaponized Terraform to Breach IT Providers
In March 2026, North Korean threat actor Jade Sleet compromised an Indian IT services provider through a sophisticated supply chain attack targeting a DevOps engineer's Apple Silicon MacBook. The attack employed social engineering via fake job interviews and weaponized Terraform dependency files hosted on malicious infrastructure mimicking HashiCorp's registry. The compromise deployed two advanced Rust-based backdoors - FLATROOF and ROOFDECK - enabling extensive system reconnaissance, data theft, and persistent access. The same tactics and tools were used in the high-profile KelpDAO LayerZero bridge attack that occurred in April 2026, highlighting the interconnected nature of supply chain compromises. This incident exemplifies the evolving threat landscape where nation-state actors increasingly target third-party vendors and developer environments to gain access to larger organizational networks. The attack demonstrates how modern threat actors exploit trusted development tools and processes, making detection significantly more challenging and expanding the potential impact across multiple downstream organizations.
3 days ago
Kill Chain
N-able N-central CVE-2026-86218: When RMM Platforms Become Attack Vectors
N-able released an emergency hotfix for CVE-2026-86218, a maximum-severity remote code execution vulnerability in its N-central remote monitoring and management platform used by IT departments and MSPs. The flaw allows unprivileged attackers to execute malicious code on exposed N-central instances through low-complexity attacks. With nearly 1,500 N-central servers exposed online and evidence of active exploitation flagged by Huntress cybersecurity, the company urged immediate patching to N-central 2026.3 Hotfix 4. This incident highlights the persistent targeting of remote management platforms that provide privileged access to client networks and infrastructure. RMM platforms continue to be attractive targets as they offer attackers potential access to multiple downstream organizations through a single compromise, making them critical components in supply chain attack scenarios.
2 weeks ago
Kill Chain
Brightly Software's 2023 Insider Threat: A Cautionary Tale
In December 2023, Cameron Curry, a data analyst contractor at Brightly Software, exploited his access to sensitive corporate data, including employee compensation information, to orchestrate an extortion scheme. After his contract ended, Curry sent over 60 threatening emails to Brightly's employees and executives, demanding approximately $2.5 million to prevent the release of the stolen data. The company reported the incident to the FBI on December 14, 2023, and ultimately paid $7,540.92 in ransom. Curry was arrested and, in March 2026, convicted on six counts of extortion, leading to a two-year prison sentence. This case underscores the significant risks associated with insider threats, particularly when contractors or employees have access to confidential information. Organizations must implement stringent access controls, continuous monitoring, and robust incident response plans to mitigate such risks. The incident also highlights the importance of promptly reporting breaches to authorities to facilitate swift legal action.
1 month ago
Kill Chain
Critical N-able N-central Vulnerability Exploited: Immediate Action Required
In August 2026, N-able's N-central platform, widely used by Managed Service Providers (MSPs) for remote IT management, was found to have a critical vulnerability (CVE-2026-18577) that allowed unauthenticated attackers to gain full administrative access. Exploiting this flaw, attackers could run scripts, deploy tools, and open remote sessions across all managed endpoints. The vulnerability stemmed from an incomplete fix of a previous issue (CVE-2026-18556). N-able released Hotfix 2 to address this, urging all on-premise users to apply the patch immediately. Hosted instances received automatic updates. Organizations were also advised to monitor their environments closely for signs of compromise. ([itpro.com](https://www.itpro.com/security/cyber-attacks/msps-urged-to-patch-immediately-after-n-able-issues-hotfix-for-n-central-god-mode-flaw?utm_source=openai)) This incident underscores the critical importance of timely patch management and vigilant monitoring in IT environments. The rapid exploitation of such vulnerabilities highlights the evolving tactics of threat actors and the necessity for organizations to stay ahead with proactive security measures.
1 month ago
Kill Chain
N-able RMM Vulnerability Exploited in Supply-Chain Attack
In August 2026, N-able disclosed that attackers exploited a patch bypass vulnerability (CVE-2026-18577) in its N-central remote monitoring and management (RMM) platform. This flaw allowed unauthorized administrative access to customer environments. The attackers utilized the 'Take Control' feature to connect to systems within the managed environment and established persistence by registering a new service for a CloudFlare tunnel. N-able promptly developed and released a fix, urging customers to upgrade to version 2026.3.1.7. The incident underscores the critical importance of timely patch management and vigilance in monitoring RMM tools, as they can serve as potent vectors for supply-chain attacks. Organizations must ensure that such platforms are regularly updated and monitored to prevent unauthorized access and potential data breaches.
1 month ago
Kill Chain
Critical Authentication Bypass in N-able N-central: CVE-2026-18577
In August 2026, N-able disclosed an authentication bypass vulnerability (CVE-2026-18577) in its N-central Remote Monitoring and Management (RMM) platform, affecting both hosted and on-premises servers. This flaw allowed unauthenticated attackers to gain administrative access, potentially compromising managed endpoints and sensitive data. The company released hotfix 2026.3.1.7 to address the issue and urged immediate updates. Indicators of compromise included specific IP addresses and unauthorized services like 'Cloudflared'. This incident underscores the critical importance of promptly addressing vulnerabilities in RMM platforms, which are attractive targets due to their extensive access to client systems. Organizations must remain vigilant, ensuring timely application of patches and continuous monitoring to mitigate risks associated with such exploits.
1 month ago
Kill Chain
Lidl Data Breach: Safeguarding Customer Information in the Digital Age
In July 2026, Lidl, a leading European supermarket chain, disclosed a data breach affecting customers in Germany, Belgium, and the Netherlands. The breach occurred due to unauthorized access to a file stored by a third-party IT service provider, resulting in the exposure of personal customer information, including names, contact details, dates of birth, and customer numbers. Importantly, Lidl confirmed that passwords, billing and shipping addresses, and payment information were not compromised. The company has notified affected customers and relevant authorities, advising vigilance against potential phishing attempts. This incident underscores the critical importance of securing third-party service providers, as supply chain vulnerabilities can lead to significant data breaches. Organizations are increasingly recognizing the need to implement robust security measures and conduct thorough assessments of their external partners to mitigate such risks.
2 months ago
Kill Chain
Hims & Hers Data Breach: Lessons in Third-Party Security
In early February 2026, telehealth company Hims & Hers Health experienced a data breach when unauthorized individuals accessed support tickets through their third-party customer service platform, Zendesk. The breach, occurring between February 4 and February 7, exposed personal information such as names and contact details of customers. Importantly, no medical records or doctor communications were compromised. The company promptly secured the platform and initiated an investigation upon discovering the suspicious activity on February 5. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hims-and-hers-warns-of-data-breach-after-zendesk-support-ticket-breach/?utm_source=openai)) This incident underscores the vulnerabilities associated with third-party service providers and the critical need for robust security measures. As cyber threats targeting support systems increase, organizations must enhance their security protocols to protect sensitive customer data and maintain trust.
5 months ago
Kill Chain
Crunchyroll's 2026 Data Breach Raises User Privacy Concerns
In March 2026, Crunchyroll, a leading anime streaming platform, faced a class-action lawsuit alleging violations of the Video Privacy Protection Act (VPPA). The lawsuit claims that Crunchyroll shared users' personal data, including email addresses, device IDs, and viewing histories, with the marketing company Braze without obtaining proper consent. This alleged data sharing has raised significant privacy concerns among users and industry observers. ([animecorner.me](https://animecorner.me/crunchyroll-hit-with-class-action-lawsuit-over-allegedly-disclosing-anime-viewing-habits-to-third-party/?utm_source=openai)) This incident underscores the critical importance of adhering to data privacy regulations and obtaining explicit user consent before sharing personal information. It also highlights the potential legal and reputational risks companies face when failing to protect user data adequately.
6 months ago
Kill Chain
Telus Digital's 2026 Data Breach: A Wake-Up Call for Cloud Security
In March 2026, Telus Digital, the business process outsourcing arm of Canadian telecommunications provider Telus, confirmed a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers exploited Google Cloud Platform credentials obtained from a previous breach, enabling them to access Telus Digital's systems over several months. This intrusion led to the exfiltration of nearly 1 petabyte of sensitive data, including customer support records, call logs, and internal corporate information. The breach not only compromised Telus Digital's data but also affected numerous client companies relying on their services. ShinyHunters attempted to extort Telus Digital for $65 million, threatening to release the stolen data publicly. Telus Digital has since engaged cybersecurity experts and law enforcement to investigate and mitigate the breach's impact. This incident underscores the escalating threat posed by sophisticated cybercriminal groups like ShinyHunters, who have been linked to multiple high-profile data thefts and extortion campaigns targeting major organizations worldwide. Their tactics often involve exploiting misconfigured cloud services and leveraging stolen credentials to infiltrate systems, highlighting the critical need for robust security configurations and vigilant monitoring of cloud environments.
6 months ago
Kill Chain
China’s Brickstorm Malware Campaign: The New Face of State-Level US Espionage in 2024
In 2024, U.S. and Canadian cybersecurity authorities, together with threat analysts from Google and CrowdStrike, disclosed an extensive, ongoing cyber-espionage campaign attributed to China-linked state actors known as Warp Panda and UNC5221. Utilizing the advanced Brickstorm malware, attackers achieved undetected persistence within critical infrastructure and government agency networks for an average of over a year, beginning as early as 2022. Brickstorm, targeting VMware vSphere and Windows environments, enabled stealthy lateral movement, automated reinfection, and the theft of sensitive identity and configuration data. The campaign exploited cloud misconfigurations, edge device vulnerabilities, and under-monitored zones, impacting dozens of U.S. organizations and associated downstream victims. This incident reflects the continued evolution of state-sponsored Chinese cyber-operations. Its strategic targeting, tradecraft sophistication, and stealth tactics represent persistent threats for both government and private sector organizations managing hybrid or multi-cloud environments.
8 months ago
Kill Chain
Hacker Exposes 2.3TB in FS Italiane / Almaviva Supply Chain Breach (2024)
In June 2024, a hacker reportedly breached the systems of Almaviva, an Italian IT provider serving FS Italiane Group, the nation’s railway operator. The attacker claimed to have exfiltrated 2.3TB of sensitive corporate data—including documents, contracts, financial information, and communications—garnered by exploiting weaknesses in the supplier’s defenses. Although FS Italiane’s operational technology was not directly compromised, the breach of Almaviva’s infrastructure exposed highly confidential client and business data, raising concerns about third-party risks and data privacy for an array of Italian public sector organizations. This incident highlights a worrying trend of attackers targeting IT services providers as a conduit for large-scale data breaches against critical infrastructure operators. With supply chain vulnerabilities on the rise, organizations must urgently reassess their vendor risk management and network segmentation strategies to prevent similar cascading impacts.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports