The Containment Era is here. →Explore

Industry Category

Professional Training

Breach intelligence, attack campaigns, and threat reports targeting the Professional Training sector.

73 threat reports
Page 5 of 7

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Professional Training Threat Reports

Showing 4960 / 73 reports
Ransomware Reimagined: Attackers Deploy Their Own QEMU VM for Stealth and Persistence
Impact· medium

Ransomware Reimagined: Attackers Deploy Their Own QEMU VM for Stealth and Persistence

In early 2025, a sophisticated ransomware incident was revealed by Red Canary Intelligence when an adversary launched a coordinated attack combining email bombing, social engineering, and abuse of legitimate remote access tools. Initially, victims endured email inundation designed to cause confusion and open the door to a convincing technical support ruse. Leveraging remote assistance software, attackers deployed a custom QEMU virtual machine (VM) into the compromised environment—a novel method for persistent access. Within this VM, tools such as Sliver C2, QDoor backdoor, and ScreenConnect enabled internal reconnaissance, lateral movement, and external command and control, all while evading conventional endpoint security controls. This incident is noteworthy for both its multi-layered attack chain and the adversary’s use of their own pre-configured VM for persistence, representing a shift toward virtualization-based evasion and resilience. The detection highlights a rise in blended attacks using social engineering, legitimate tools, and bespoke infrastructure, stressing the importance of defense-in-depth and advanced anomaly detection capabilities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Festo LX Appliance Security Alert: 2025 Cross-Site Scripting Vulnerability Exposes ICS Risks
Impact· low

Festo LX Appliance Security Alert: 2025 Cross-Site Scripting Vulnerability Exposes ICS Risks

In December 2025, Festo SE & Co. KG disclosed a cross-site scripting (XSS) vulnerability (CVE-2021-23414) affecting the Festo LX Appliance, impacting versions released before June 2023. Malicious actors could exploit improper input neutralization in the 'track' tag's 'src' attribute to execute arbitrary code by crafting a malicious course, potentially compromising highly privileged user accounts. Though no public exploitation has been reported, the vulnerability posed risks to organizations in critical sectors globally, with a CVSS v3.1 base score of 6.1 indicating a moderate threat profile. This incident underscores the persistent risks posed by web application vulnerabilities in ICS and OT environments. With the increased digitization of operational systems and ongoing cyberattacks targeting critical infrastructure, rapid identification, patching, and monitoring of such flaws remain crucial to protect sensitive assets and maintain compliance with evolving regulatory standards.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Gainsight Expands Customer List After Salesforce Data Breach Investigation
Impact· high

Gainsight Expands Customer List After Salesforce Data Breach Investigation

In November 2025, Gainsight disclosed an expansion of its impacted customer list following suspicious activity targeting its cloud applications within the Salesforce platform. Originally affecting three customers identified incidentally by Salesforce, the scope broadened as investigation revealed further unauthorized access to sensitive business data. The breach, detected through abnormal activity monitoring, prompted Gainsight to alert clients and coordinate remediation steps while collaborating with Salesforce to identify the root cause. The company has not shared the exact number of affected customers but confirmed exposure to confidential customer information, presenting new compliance and reputational challenges. This incident reflects a continued surge in third-party and SaaS provider breaches, illustrating the interconnected risk facing organizations that rely on enterprise platforms. With attackers leveraging increasingly subtle lateral movement techniques and targeting east-west cloud traffic, robust zero trust controls and real-time anomaly detection are more critical than ever.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Salesforce Data Breached Again: ShinyHunters Exploit Third-Party Gainsight in 2024 Attack
Impact· high

Salesforce Data Breached Again: ShinyHunters Exploit Third-Party Gainsight in 2024 Attack

In June 2024, several Salesforce customers experienced a significant data breach perpetrated by the ShinyHunters extortion group. Attackers exploited vulnerabilities in a third-party vendor, Gainsight, which had integrations with Salesforce platforms. By compromising Gainsight, ShinyHunters acquired credentials or access tokens, enabling them to exfiltrate sensitive Salesforce customer data from multiple organizations. The breach demonstrates the persistent risk of attacks originating from trusted third-party software supply chains, resulting in the exposure of business and customer information and raising concerns about the security posture of major SaaS ecosystems. This breach highlights a continued trend in which attackers bypass direct controls by targeting vendors in a SaaS environment, leveraging weak third-party access and inadequate segmentation. As businesses increase SaaS adoption and interconnectivity, these attacks demonstrate the urgent need for enhanced third-party risk management and more granular network and identity controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Salesforce Supply Chain Breach Exposes SaaS OAuth Risks in 2025
Impact· low

Salesforce Supply Chain Breach Exposes SaaS OAuth Risks in 2025

In November 2025, Salesforce detected unauthorized activity involving Gainsight-published applications integrated via OAuth tokens with the Salesforce platform. The breach potentially enabled attackers to access sensitive customer data by compromising OAuth connections between select third-party Gainsight apps and Salesforce tenant environments. Upon discovery, Salesforce revoked all active access and refresh tokens for affected integrations, initiated incident response protocols, and notified impacted customers. The unauthorized access appears limited to data accessible via the compromised tokens, but the full scope is still under investigation. This incident is significant as it demonstrates the inherent risks of third-party SaaS integrations and OAuth-based supply chain connections. As organizations increasingly leverage cloud-based ecosystems, attackers are targeting indirect trust relationships, exposing data via the weakest link. Enterprises face mounting regulatory, contractual, and operational risks from such supply chain attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(low)
Read Report
GlobalProtect VPN Portals Probed by 2.3 Million Malicious Scan Sessions
Impact· low

GlobalProtect VPN Portals Probed by 2.3 Million Malicious Scan Sessions

Beginning on November 14, 2025, cybersecurity researchers detected an unprecedented surge in malicious scanning activity targeting Palo Alto Networks GlobalProtect VPN portals worldwide. Over 2.3 million scan sessions were recorded within days, emanating from a diverse array of global IP addresses and employing automated tools to probe for vulnerabilities and gather intelligence on remote-access infrastructure. While no large-scale exploitations or breaches have yet been confirmed, the scanning phase indicates advanced reconnaissance tactics that precede exploitation, raising significant concern for organizations relying on GlobalProtect for secure remote access. This event highlights a sharp escalation in mass automated reconnaissance against widely deployed VPN systems, following recent critical vulnerabilities in VPN technologies and a growing attacker focus on initial access vectors. The trend reinforces the urgency for improved monitoring, swift patching, and modern segmentation controls in remote-access environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Global WhatsApp Hack: CTM360 Exposes HackOnChat Social Engineering Campaign
Impact· high

Global WhatsApp Hack: CTM360 Exposes HackOnChat Social Engineering Campaign

In late 2025, cybersecurity firm CTM360 revealed 'HackOnChat,' a sophisticated, large-scale social engineering campaign targeting WhatsApp users globally. Threat actors orchestrated the attack via fake authentication portals and impersonation webpages, tricking victims into divulging credentials that enabled account hijacking. The operation weaponized WhatsApp's familiar interface, leveraging psychological manipulation and deception, and resulted in thousands of compromised accounts and malicious URLs. Disruption of user communications and risk of further abuse (such as account-based impersonation or fraud) were observed. This breach underscores the accelerating use of social engineering tactics in messaging platforms, reflecting a surge in identity-based attacks that exploit user trust in familiar interfaces. Security teams are increasingly alert to evolving credential-phishing methods that bypass traditional controls, especially as regulatory scrutiny of digital identity security intensifies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Festo Didactic 2025 Incident: Siemens TIA Portal Supply Chain Vulnerability Exposes Critical Risk
Impact· medium

Festo Didactic 2025 Incident: Siemens TIA Portal Supply Chain Vulnerability Exposes Critical Risk

In November 2025, Festo SE & Co. KG disclosed a supply chain vulnerability affecting its Didactic products due to the integration of vulnerable versions of Siemens TIA Portal (V15–V18). The issue, tracked as CVE-2023-26293, stems from improper input validation, allowing attackers to leverage a path traversal flaw. This could result in the creation or overwriting of arbitrary files if a user is tricked into opening a malicious PC system configuration file, leading to potential arbitrary code execution. The exploit, which requires local access with user interaction, impacts engineering systems used globally across critical sectors, including manufacturing, energy, communications, and commercial facilities. This vulnerability is significant as it illustrates the increasing prevalence of supply chain risks in industrial and critical infrastructure software. With threat actors increasingly exploiting the software supply chain and user-driven entry vectors, maintaining rigorous update and validation processes has become a pressing challenge for organizations worldwide.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
GlobalLogic Employee Data Breach: Lessons from the 2024 Oracle EBS Compromise
Impact· high

GlobalLogic Employee Data Breach: Lessons from the 2024 Oracle EBS Compromise

In early June 2024, GlobalLogic—a Hitachi-owned provider of digital engineering services—disclosed a significant data breach involving its Oracle E-Business Suite (EBS) platform. Attackers gained unauthorized access to EBS, resulting in the theft of sensitive data for over 10,000 current and former employees. The organization responded by launching an investigation, notifying affected individuals, and collaborating with Oracle and security experts to identify the root cause and contain the intrusion. The breach's exposure meant threat actors likely accessed personally identifiable information including names, addresses, and payroll details, elevating the risk of identity theft and further compromise. This incident highlights the ongoing vulnerabilities in complex legacy applications like Oracle EBS, especially as attackers increasingly target enterprise resource systems with sophisticated intrusion techniques. With regulatory scrutiny on employee data protection intensifying, organizations must prioritize robust segmentation, encryption, and visibility controls to counter evolving attack patterns.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Triofox 2024 Breach: Remote Access Tools via Antivirus Exploit
Impact· medium

Triofox 2024 Breach: Remote Access Tools via Antivirus Exploit

In April 2024, attackers exploited a critical vulnerability in Gladinet's Triofox enterprise file-sharing platform, taking advantage of its built-in antivirus feature to deploy remote access tools (RATs) and gain SYSTEM-level privileges. By cleverly manipulating security workloads meant to protect the environment, attackers achieved remote code execution and established persistent access, potentially exposing sensitive data and internal resources to further compromise. Gladinet acknowledged the severe impact, which included the possibility of lateral movement across affected enterprises and rapid malware deployment. The campaign was identified through forensic analysis after suspicious network traffic and unusual administrative activity was detected. This incident highlights an emerging trend of adversaries abusing legitimate software features and supply chain components to bypass traditional defenses. With remote access tool deployment becoming a favored attacker tactic, organizations face increased regulatory scrutiny and must revisit least privilege, segmentation, and anomaly detection practices to address these evolving supply chain and post-exploitation threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Triofox Flaw Exploited: How CVE-2025-12480 Enabled Remote Access Tool Attacks
Impact· medium

Triofox Flaw Exploited: How CVE-2025-12480 Enabled Remote Access Tool Attacks

In June 2025, cybersecurity researchers at Google's Mandiant Threat Defense uncovered active exploitation of a critical authentication bypass vulnerability (CVE-2025-12480, CVSS 9.1) affecting Gladinet's Triofox file-sharing and remote access platform. Attackers leveraged this n-day vulnerability—now patched—to gain unauthorized access to Triofox administrative configuration panels. With authentication circumvented, they uploaded and executed malicious payloads, specifically deploying remote access tools via the platform’s integrated antivirus feature. This enabled adversaries to establish persistent footholds, move laterally, and potentially exfiltrate sensitive corporate data and credentials. The incident underscores the ongoing urgency of patch management and monitoring, as threat actors continue to weaponize critical vulnerabilities within widely used collaboration and remote access tools. Industry experts warn of increasing attacks exploiting n-day vulnerabilities before patch adoption, reflecting a broader trend toward highly targeted lateral movement and remote tool deployment campaigns.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
WordPress Sites Under Siege: Critical Post SMTP Plugin Flaw Exposes 400,000+ Websites
Impact· medium

WordPress Sites Under Siege: Critical Post SMTP Plugin Flaw Exposes 400,000+ Websites

In June 2024, a critical vulnerability was discovered in the Post SMTP mailer plugin for WordPress, widely used by over 400,000 sites. This flaw allows unauthenticated attackers to reset admin accounts and take full control of affected websites. Threat actors have already exploited the vulnerability by leveraging malicious password reset links, leading to complete site compromise, potential data theft, and abuse of compromised infrastructure for further attacks. The vulnerability prompted emergency patching and urgent advisories from both the plugin authors and security firms. This incident underscores the persistent threat posed by plugin vulnerabilities in the WordPress ecosystem, which remains a popular target for cybercriminals due to its vast user base. The surge in attacks exploiting supply chain and third-party plugin weaknesses highlights the need for rapid vulnerability management and robust security controls for web applications.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports