✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Professional Training
Breach intelligence, attack campaigns, and threat reports targeting the Professional Training sector.
Explore Other Sectors
Professional Training Threat Reports
ShinyHunters Exploit Salesforce Experience Cloud Misconfigurations in 2026 Data Breach
In March 2026, Salesforce disclosed that the ShinyHunters cybercriminal group exploited misconfigured Experience Cloud sites to access sensitive data from approximately 100 high-profile companies. The attackers utilized a modified version of the open-source tool AuraInspector to identify and exploit overly permissive guest user configurations, enabling unauthorized data extraction. Salesforce emphasized that the breach resulted from customer misconfigurations rather than inherent platform vulnerabilities. This incident underscores the critical importance of adhering to security best practices when configuring cloud services. Misconfigurations can lead to significant data breaches, as demonstrated by the ShinyHunters' exploitation of Salesforce Experience Cloud sites. Organizations must regularly review and secure their cloud configurations to prevent unauthorized access and data exposure.
4 months ago
Kill Chain
Critical Zero-Click RCE Vulnerability in FreeScout: Immediate Action Required
In March 2026, a critical zero-click remote code execution (RCE) vulnerability, identified as CVE-2026-28289, was discovered in FreeScout, an open-source help desk platform. This flaw allows unauthenticated attackers to execute arbitrary code on servers by sending a specially crafted email to a FreeScout-configured mailbox. The vulnerability arises from a Time-of-Check to Time-of-Use (TOCTOU) flaw in the filename sanitization function, enabling the upload of malicious .htaccess files with zero-width space characters to bypass security checks. Exploitation can lead to full server compromise, data breaches, and potential lateral movement within networks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/mail2shell-zero-click-attack-lets-hackers-hijack-freescout-mail-servers/?utm_source=openai)) The emergence of CVE-2026-28289 underscores the evolving sophistication of cyber threats, particularly those requiring no user interaction. Organizations utilizing FreeScout are urged to update to version 1.8.207 immediately to mitigate this risk. This incident highlights the critical need for continuous monitoring and prompt patch management to defend against rapidly developing vulnerabilities.
4 months ago
Kill Chain
Jaguar Land Rover's 2025 Ransomware Ordeal: A Wake-Up Call for the Automotive Industry
In early September 2025, Jaguar Land Rover (JLR) experienced a significant ransomware attack attributed to the cybercriminal group Scattered Lapsus$ Hunters. This attack led to a complete halt in vehicle production across JLR's global facilities, including those in the UK, Slovakia, China, India, and Brazil. Employees were instructed to stay home, and the company faced substantial operational disruptions. The attackers, a coalition of groups including Scattered Spider, LAPSUS$, and ShinyHunters, employed sophisticated social engineering tactics to infiltrate JLR's systems, resulting in the encryption of critical data and systems. The incident underscored the vulnerabilities in the automotive industry's cybersecurity defenses and highlighted the evolving threat landscape posed by organized cybercriminal alliances. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/jaguar-land-rover-shuts-down-production-due-to-ransomware-attack-scattered-lapsus-usd-hunters-takes-responsibility?utm_source=openai)) This attack is emblematic of a broader trend where cybercriminal groups are forming alliances to enhance their capabilities and impact. The collaboration between Scattered Spider, LAPSUS$, and ShinyHunters into the Scattered Lapsus$ Hunters collective signifies a shift towards more organized and aggressive cyber extortion strategies. Organizations across industries must recognize the increasing sophistication of these threats and bolster their cybersecurity measures accordingly. ([techradar.com](https://www.techradar.com/pro/security/three-of-the-biggest-cybercrime-gangs-around-appear-to-be-teaming-up-which-could-be-bad-news-for-all-of-us?utm_source=openai))
5 months ago
Kill Chain
ShinyHunters Exploit SSO Vulnerabilities in 2026 Vishing Attacks
In January 2026, the cybercriminal group ShinyHunters orchestrated a series of sophisticated voice phishing (vishing) attacks targeting single sign-on (SSO) credentials across multiple organizations. By impersonating IT support personnel, they deceived employees into providing their SSO credentials and multi-factor authentication (MFA) codes on counterfeit login portals. This enabled unauthorized access to various connected SaaS applications, including Salesforce, Microsoft 365, and Slack, leading to significant data breaches. Notable companies such as Panera Bread, Crunchbase, and Betterment confirmed unauthorized access and data exfiltration resulting from these attacks. ([zerofox.com](https://www.zerofox.com/intelligence/flash-report-shinyhunters-sso-phishing-campaign/?utm_source=openai)) This incident underscores the evolving threat landscape where attackers combine social engineering with advanced phishing techniques to bypass MFA protections. The widespread adoption of SSO systems amplifies the potential impact of such breaches, as compromising a single account can grant access to multiple platforms. Organizations must enhance their security awareness training and implement robust monitoring to detect and mitigate such sophisticated attacks.
5 months ago
Kill Chain
Vivaldi Webmail Phishing Attack Exploits Google Presentations - January 2026
In January 2026, a phishing campaign targeted Vivaldi Webmail users by exploiting Google Presentations to bypass security measures. Attackers sent emails containing links to Google Slides presentations, which, when accessed, redirected users to fraudulent login pages designed to harvest credentials. This method effectively circumvented traditional phishing detection mechanisms by leveraging trusted platforms. The incident underscores a growing trend where cybercriminals abuse legitimate services to execute phishing attacks, highlighting the need for enhanced vigilance and adaptive security strategies to counteract evolving threats.
5 months ago
Kill Chain
How Stolen Credentials Enabled Stealthy LogMeIn RMM Attacks in 2026
In January 2026, researchers reported a campaign where attackers leveraged phishing emails to steal valid user credentials, allowing them to deploy legitimate LogMeIn Remote Monitoring and Management (RMM) software for covert, persistent access to corporate systems. By utilizing IT tools typically trusted by administrators rather than custom malware, the adversaries successfully bypassed traditional security measures and gained unrestricted access to sensitive business environments. The campaign underscores the increasing sophistication of credential-based attacks and the risks posed by the misuse of legitimate remote access tools. This incident is vital in the current cybersecurity landscape as it exemplifies the growing threat of identity-driven attacks and the exploitation of trusted IT software. Organizations face mounting regulatory and operational pressure to enforce zero trust principles and segment internal traffic, as traditional perimeter defenses and malware-centric detection are increasingly ineffective against modern attacker tactics.
6 months ago
Kill Chain
Zendesk 2024 Spam Attacks Expose SaaS Security Gaps
In June 2024, multiple organizations using Zendesk experienced a widespread spam campaign that abused legitimate Zendesk instances to distribute malicious and unwanted emails. Attackers leveraged open or misconfigured support ticketing forms, submitting large volumes of spam through these systems. The CRM vendor Zendesk responded by assuring customers that the event was not tied to any software vulnerability or security breach within the platform itself. Business impact centered on increased phishing risk and operational noise in customer service channels, as well as potential reputational harm to affected brands. This incident highlights a growing trend where attackers abuse trusted SaaS communication channels to bypass traditional email security filters. As threat actors increasingly focus on exploiting third-party platforms and automation, organizations face new challenges securing digital touchpoints against social engineering and spam-based threats.
6 months ago
Kill Chain
LinkedIn Phishing Campaign Delivers RAT via DLL Sideloading—2026 Incident Analysis
In January 2026, security researchers identified a sophisticated phishing campaign exploiting LinkedIn direct messages to deliver weaponized WinRAR self-extracting archives targeting high-value individuals. Attackers used social engineering to establish trust, convincing victims to download an archive containing a legitimate open-source PDF reader, a malicious DLL, the Python interpreter, and a decoy file. Upon execution, the PDF reader sideloaded the malicious DLL, which deployed the Python interpreter, created persistence via a Registry Run key, and executed Base64-encoded shellcode in memory. This led to covert remote access, data exfiltration, and enabled attackers to move laterally across networks. The incident underscores a broader trend of attackers abusing social media platforms for initial access, bypassing traditional email-centric defenses, and leveraging open-source tools with advanced evasion techniques like DLL sideloading. As social engineering campaigns diversify across communication channels, all business sectors face amplified risks of stealthy malware delivery and long-term compromise.
6 months ago
Kill Chain
Spain’s 2026 Black Axe Bust Exposes BEC Cybercrime Risks
In January 2026, Spanish authorities arrested 34 individuals connected to the Black Axe cybercrime syndicate after dismantling a sophisticated cyber fraud ring operating across several European countries. The group, led by Nigerian nationals, specialized in Business Email Compromise (BEC) attacks and man-in-the-middle scams, intercepting legitimate corporate communications to modify payment details and siphon funds. Law enforcement seized cash, vehicles, electronics, and froze bank accounts, with total damages from the group estimated at over $6 million—$3.5 million of which is tied directly to this operation. The offenders face serious criminal charges including fraud, money laundering, and membership in a criminal organization. This case highlights both the growing scale and ongoing evolution of international BEC cybercrime, where criminal syndicates exploit business processes, global money mules, and increasingly sophisticated digital tactics. Regulatory, financial, and reputational risks remain high for organizations that fail to secure communications channels and business workflows from targeted attacks.
6 months ago
Kill Chain
Zestix Credential Heist: 2024 Cloud Infostealer Campaign Exposes MFA Weaknesses
In early 2024, a novel threat actor known as "Zestix" orchestrated a widespread credential theft campaign targeting enterprise file-sharing environments across multiple sectors. Using advanced infostealer malware, Zestix harvested cloud credentials at scale, exploiting organizations that had not enforced multi-factor authentication (MFA). The attackers subsequently gained unauthorized access to sensitive files and regulated business data from approximately 50 companies, causing both data exfiltration and operational disruptions. The breach underlines significant weaknesses in authentication and access controls within cloud ecosystems, with impacts ranging from compromised intellectual property to potential compliance violations. The incident underscores the urgent need for robust access controls and MFA as essential defenses in today’s cloud-first environments. With identity-driven breaches rising and attackers automating large-scale infostealer campaigns, organizations face increasing regulatory and reputational pressure to modernize and enforce cloud security policies.
6 months ago
Kill Chain
Ransomware at Sedgwick Government Solutions: What the 2026 TridentLocker Breach Reveals
In January 2026, Sedgwick confirmed a security incident at its subsidiary, Sedgwick Government Solutions, a contractor serving over 20 U.S. federal agencies including CISA, DHS, and the U.S. Coast Guard. The breach was perpetrated by the TridentLocker ransomware group, which claimed to have stolen 3.39 GB of sensitive documents and subsequently leaked data on its Tor site. The attackers gained access via an isolated file transfer system; however, Sedgwick asserts no evidence of compromise to core claims servers or operational disruption. External cybersecurity experts and law enforcement were immediately engaged, and affected systems were properly segmented from the wider parent company network. This incident highlights the increased targeting of government contractors by ransomware operators and underscores the importance of network segmentation, prompt incident response, and continuous monitoring. The breach reflects growing regulatory and client demands for transparent reporting and robust data protection as ransomware groups escalate their tactics.
6 months ago
Kill Chain
WhatsApp GhostPairing: How Device Linking Fueled 2024 Account Hijacks
In mid-2024, threat actors launched a sophisticated social engineering campaign dubbed 'GhostPairing' to hijack WhatsApp accounts by abusing the platform's legitimate device-linking feature. Attackers initiated account compromise by tricking victims into sharing pairing codes, which allowed unauthorized access to their WhatsApp accounts on new devices without triggering standard multi-factor authentication. Once inside, attackers could impersonate victims, access chat histories, and leverage compromised accounts for further malicious activity. The attack exploited inherent trust in WhatsApp's device linking and its secure communication channels, highlighting risks even in end-to-end encrypted environments. This incident underscores the growing trend of attackers subverting user authentication processes, exploiting legitimate features for account takeover, and using highly convincing social engineering methods. With messaging apps central to both business and personal communications, the security and user-awareness gaps demonstrated here remain acutely relevant.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports