The Containment Era is here. →Explore

Industry Category

Professional Training

Breach intelligence, attack campaigns, and threat reports targeting the Professional Training sector.

73 threat reports
Page 3 of 7

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Professional Training Threat Reports

Showing 2536 / 73 reports
KongTuke's Innovative Use of Microsoft Teams to Deploy ModeloRAT Malware
Impact· HIGH

KongTuke's Innovative Use of Microsoft Teams to Deploy ModeloRAT Malware

In April 2026, the threat actor KongTuke initiated a campaign leveraging Microsoft Teams to impersonate internal IT support staff. By contacting employees through external Teams chats, they persuaded victims to execute a malicious PowerShell command, leading to the deployment of ModeloRAT malware. This tactic enabled KongTuke to establish persistent access to corporate networks within minutes, facilitating data exfiltration and potential ransomware attacks. This incident underscores a significant shift in cybercriminal strategies, highlighting the exploitation of trusted communication platforms for social engineering. The rapid execution and effectiveness of this method emphasize the need for organizations to reassess and strengthen their security protocols, particularly concerning collaboration tools.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Persistent OAuth Tokens: The Unseen Backdoor in Enterprise Security
Impact· HIGH

Persistent OAuth Tokens: The Unseen Backdoor in Enterprise Security

In May 2026, a significant security concern emerged regarding the widespread use of OAuth tokens in enterprise environments. Employees frequently connect AI tools, workflow automations, and productivity applications to platforms like Google and Microsoft, generating persistent OAuth tokens that often lack expiration dates and are not subject to automatic cleanup. This practice creates a substantial security gap, as these tokens can grant attackers unauthorized access without the need for passwords, bypassing traditional security measures such as multi-factor authentication. The inherent design of OAuth, which does not automatically revoke tokens when employees depart or change passwords, exacerbates this vulnerability. The urgency of addressing this issue is underscored by recent incidents where threat actors exploited OAuth tokens to gain unauthorized access to sensitive data. For instance, in August 2025, attackers used compromised OAuth tokens from the Salesloft-Drift integration to access Salesforce environments of over 700 organizations, leading to significant data exfiltration. ([checkred.com](https://checkred.com/resources/blog/when-oauth-tokens-go-rogue-lessons-from-the-salesloft-drift-breach/?utm_source=openai)) These events highlight the critical need for organizations to implement robust monitoring and management of OAuth grants to prevent similar breaches.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Breaking the Code: Multi-Stage 'Code of Conduct' Phishing Campaign Leads to AiTM Token Compromise
Impact· HIGH

Breaking the Code: Multi-Stage 'Code of Conduct' Phishing Campaign Leads to AiTM Token Compromise

In April 2026, a sophisticated phishing campaign targeted over 35,000 users across 13,000 organizations, primarily in the United States. Attackers employed 'code of conduct' themed emails with polished HTML templates to create a sense of urgency. The multi-stage attack involved CAPTCHA challenges and intermediate pages, culminating in an adversary-in-the-middle (AiTM) phishing site that intercepted authentication tokens, effectively bypassing non-phishing-resistant multifactor authentication (MFA) and granting immediate account access. This incident underscores the evolving sophistication of phishing tactics, highlighting the need for organizations to implement phishing-resistant MFA methods and enhance user awareness training to mitigate such threats.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Analyzing the UNC6040 Breach of Google's Salesforce Instance
Impact· HIGH

Analyzing the UNC6040 Breach of Google's Salesforce Instance

In June 2025, Google's internal Salesforce instance was compromised by the cybercriminal group UNC6040, also known as ShinyHunters. The attackers employed a sophisticated voice phishing (vishing) campaign, impersonating IT support to deceive employees into installing a malicious version of Salesforce's Data Loader application. This granted unauthorized access to sensitive business customer data, including names and contact details. The breach was swiftly identified and contained by Google, minimizing the exposure of sensitive information. ([avertium.com](https://www.avertium.com/flash-notices/flash-notice-google-salesforce-breach-an-in-depth-analysis-of-unc6040?utm_source=openai)) This incident underscores the escalating threat posed by social engineering attacks targeting cloud-based platforms. Organizations are urged to enhance their security measures, particularly in training employees to recognize and resist such deceptive tactics, to prevent similar breaches in the future.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Black Basta Affiliates Resurface with Targeted Social Engineering Attacks in 2026
Impact· HIGH

Black Basta Affiliates Resurface with Targeted Social Engineering Attacks in 2026

In April 2026, a group of former Black Basta affiliates initiated a sophisticated social engineering campaign targeting over 100 employees across multiple organizations. The attackers employed mass email bombing and impersonated IT support via Microsoft Teams to gain unauthorized access to networks, aiming for data theft, ransomware deployment, and extortion. Notably, approximately 75% of the targets were senior executives, directors, and managers, indicating a strategic focus on high-privilege accounts. ([cyberscoop.com](https://cyberscoop.com/black-basta-affiliates-senior-executives-reliaquest/?utm_source=openai)) This resurgence underscores the persistent threat posed by disbanded cybercriminal groups reassembling or reusing effective tactics. The campaign's rapid execution and automation highlight the evolving sophistication of social engineering attacks, emphasizing the need for organizations to bolster their cybersecurity defenses and employee awareness programs. ([cyberscoop.com](https://cyberscoop.com/black-basta-affiliates-senior-executives-reliaquest/?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
VENOM Phishing Campaign: A Wake-Up Call for Executive Security
Impact· HIGH

VENOM Phishing Campaign: A Wake-Up Call for Executive Security

Between November 2025 and March 2026, a sophisticated phishing campaign utilizing the previously undocumented VENOM phishing-as-a-service (PhaaS) platform targeted C-suite executives across over 20 industries. Attackers impersonated Microsoft SharePoint notifications, embedding QR codes to lure victims into credential theft schemes. The campaign employed advanced evasion techniques, including adversary-in-the-middle (AiTM) attacks and device code abuse, effectively bypassing multi-factor authentication (MFA) and establishing persistent access to compromised accounts. ([abnormal.ai](https://abnormal.ai/resources/venom-phaas-c-suite-microsoft-credential-theft-report?utm_source=openai)) This incident underscores a growing trend of highly targeted phishing attacks against high-level executives, highlighting the need for organizations to reassess their security postures. The emergence of sophisticated PhaaS platforms like VENOM indicates an evolution in cybercriminal tactics, emphasizing the urgency for enhanced defenses against such advanced threats. ([abnormal.ai](https://abnormal.ai/resources/venom-phaas-c-suite-microsoft-credential-theft-report?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Understanding the 2026 Surge in Device Code Phishing Attacks
Impact· HIGH

Understanding the 2026 Surge in Device Code Phishing Attacks

In early 2026, device code phishing attacks exploiting the OAuth 2.0 Device Authorization Grant flow surged by over 37 times. Attackers initiated device authorization requests to service providers, obtained codes, and deceived victims into entering these codes on legitimate login pages, thereby granting unauthorized access to their accounts. This method, originally designed for devices lacking standard input options, was co-opted by cybercriminals to bypass traditional authentication mechanisms. The proliferation of phishing-as-a-service kits, notably EvilTokens, has significantly contributed to the widespread adoption of this technique, enabling even low-skilled attackers to execute sophisticated phishing campaigns. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/device-code-phishing-attacks-surge-37x-as-new-kits-spread-online/?utm_source=openai)) The rapid escalation of device code phishing underscores a critical shift in cyberattack strategies, emphasizing the need for organizations to reassess and fortify their authentication processes. The commoditization of such attack methods through services like EvilTokens highlights the urgency for enhanced security measures and user education to mitigate the risks associated with these evolving threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
WhatsApp Malware Campaign 2026: Unveiling the VBS Payloads and MSI Backdoors
Impact· HIGH

WhatsApp Malware Campaign 2026: Unveiling the VBS Payloads and MSI Backdoors

In late February 2026, a sophisticated malware campaign exploited WhatsApp messages to distribute malicious Visual Basic Script (VBS) files. Upon execution, these scripts initiated a multi-stage infection chain, creating hidden directories and deploying renamed legitimate Windows utilities to retrieve additional payloads from trusted cloud services like AWS, Tencent Cloud, and Backblaze B2. The attackers employed techniques such as User Account Control (UAC) bypasses and registry modifications to escalate privileges and establish persistence, ultimately installing malicious Microsoft Installer (MSI) packages that enabled remote access to compromised systems. This campaign underscores the evolving tactics of threat actors who leverage trusted communication platforms and cloud services to evade detection and maintain control over infected devices. The incident highlights a growing trend where cybercriminals exploit widely used messaging applications and cloud infrastructures to disseminate malware, making detection and mitigation more challenging. Organizations must enhance their security measures to address these sophisticated attack vectors and protect against similar threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Emerging Threat: The Underground Trade of Paid AI Accounts in 2026
Impact· MEDIUM

Emerging Threat: The Underground Trade of Paid AI Accounts in 2026

In early 2026, cybersecurity researchers uncovered a burgeoning underground market where cybercriminals are actively trading access to paid AI accounts. These accounts, associated with platforms like ChatGPT, Claude, Microsoft Copilot, and Perplexity, are being sold on dark web forums and encrypted messaging channels. Threat actors obtain these accounts through various means, including credential theft, exploitation of exposed API keys, and abuse of trial programs. The illicit access enables cybercriminals to leverage advanced AI tools for malicious activities such as crafting sophisticated phishing campaigns, automating fraudulent operations, and generating convincing social engineering content. This trend underscores the evolving tactics of cybercriminals who are increasingly integrating AI capabilities into their operations to enhance the scale and effectiveness of their attacks. Organizations must recognize the critical importance of securing AI platform credentials and monitoring for unauthorized access to prevent potential misuse. ([flare.io](https://flare.io/learn/resources/webinars-events/how-the-dark-web-is-reacting-to-the-ai-revolution-2?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Cybercriminals Exploit Fake Resumes to Deploy Cryptominers in Corporate Networks
Impact· HIGH

Cybercriminals Exploit Fake Resumes to Deploy Cryptominers in Corporate Networks

In March 2026, a sophisticated phishing campaign targeted French-speaking corporate environments by distributing emails with fake resumes. These emails contained highly obfuscated VBScript files disguised as CV documents. When executed, the scripts deployed cryptocurrency miners and information-stealing malware on the victims' systems, leading to unauthorized resource utilization and potential data breaches. This incident underscores the evolving tactics of cybercriminals who exploit common business processes, such as recruitment, to infiltrate organizations. The use of obfuscated scripts and the dual payload of cryptominers and infostealers highlight the need for enhanced email security measures and user awareness training to detect and prevent such multifaceted attacks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
INC Ransomware Group's 2025 Assault on Oceania's Healthcare Sector
Impact· CRITICAL

INC Ransomware Group's 2025 Assault on Oceania's Healthcare Sector

Between July 2024 and December 2025, the INC Ransomware Group orchestrated a series of attacks targeting healthcare organizations across Australia, New Zealand, and Tonga. Utilizing tactics such as spear-phishing, exploitation of unpatched systems, and leveraging credentials from initial access brokers, the group infiltrated networks, exfiltrated sensitive data, and deployed ransomware to encrypt critical systems. Notably, in June 2025, INC disrupted Tonga's Ministry of Health, effectively shutting down core national services. ([darkreading.com](https://www.darkreading.com/threat-intelligence/inc-ransomware-healthcare-oceania?utm_source=openai)) This incident underscores the escalating threat of ransomware attacks on the healthcare sector, emphasizing the need for robust cybersecurity measures, timely patch management, and comprehensive incident response strategies to safeguard patient data and ensure the continuity of essential health services.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Salesforce Experience Cloud Guest User Misconfiguration Breach 2026
Impact· HIGH

Salesforce Experience Cloud Guest User Misconfiguration Breach 2026

In March 2026, the cybercriminal group ShinyHunters exploited misconfigured guest user profiles in Salesforce's Experience Cloud, leading to unauthorized access to sensitive customer data. By utilizing a modified version of the open-source tool AuraInspector, the attackers scanned public-facing Experience Cloud sites and extracted data without authentication. This breach impacted approximately 400 organizations, including high-profile companies such as Snowflake, Okta, LastPass, Sony, AMD, and Salesforce itself. The compromised data included names, phone numbers, and other CRM information, which were subsequently used for social engineering and voice phishing campaigns. Salesforce confirmed that the issue stemmed from customer-configured settings rather than a vulnerability in its platform. ([techradar.com](https://www.techradar.com/pro/security/shinyhunters-claims-its-behind-ongoing-salesforce-aura-data-theft-assault-warns-more-attacks-to-come?utm_source=openai)) This incident underscores the critical importance of proper configuration and regular auditing of cloud-based services. Misconfigurations, especially in widely used platforms like Salesforce, can lead to significant data breaches, emphasizing the need for organizations to adhere to security best practices and continuously monitor their systems for potential vulnerabilities.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports