The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Professional Training
Breach intelligence, attack campaigns, and threat reports targeting the Professional Training sector.
Explore Other Sectors
Professional Training Threat Reports
Anodot Data Breach 2026: A Case Study in Supply Chain Vulnerabilities
In April 2026, Anodot, a business monitoring software provider, experienced a significant data breach when attackers exploited authentication tokens to access customer cloud data. The cybercriminal group ShinyHunters claimed responsibility, leading to data theft from at least a dozen companies, including Rockstar Games. This incident underscores the vulnerabilities in third-party service providers and the cascading risks to their clients. The breach highlights a growing trend where threat actors target software vendors to gain access to multiple organizations simultaneously. Such supply chain attacks necessitate enhanced security measures and vigilance among businesses relying on external service providers.
3 months ago
Kill Chain
Critical Vulnerability in KnowledgeDeliver LMS Exploited to Deploy Malicious Payloads
In early 2026, a critical vulnerability (CVE-2026-5426) in Digital Knowledge's KnowledgeDeliver Learning Management System (LMS) was exploited by threat actors to deploy the Godzilla web shell and Cobalt Strike Beacon. The flaw, stemming from hard-coded ASP.NET machine keys, allowed unauthenticated remote code execution via malicious ViewState deserialization. This exploitation led to unauthorized access and potential data breaches in affected systems. The incident underscores the risks associated with default configurations and hard-coded cryptographic keys in software deployments. Organizations are urged to review and update their security practices to mitigate similar vulnerabilities, especially in widely used platforms like LMSs.
4 months ago
Kill Chain
Hackers Exploit SonicWall VPN MFA Bypass Vulnerability CVE-2024-12802
In early 2026, threat actors exploited a vulnerability in SonicWall Gen6 SSL-VPN appliances, identified as CVE-2024-12802, to bypass multi-factor authentication (MFA). By brute-forcing VPN credentials and leveraging incomplete patching, attackers gained unauthorized access to internal networks. Once inside, they conducted reconnaissance, tested credential reuse, and attempted to deploy tools like Cobalt Strike for command-and-control communication. The exploitation was facilitated by organizations failing to perform necessary manual reconfigurations after firmware updates, leaving systems susceptible to MFA bypass. This incident underscores the critical importance of comprehensive patch management and adherence to vendor-recommended remediation steps. The exploitation of CVE-2024-12802 highlights a broader trend of attackers targeting VPN vulnerabilities to infiltrate corporate networks, emphasizing the need for vigilant security practices and thorough system updates.
4 months ago
Kill Chain
KongTuke's Innovative Use of Microsoft Teams to Deploy ModeloRAT Malware
In April 2026, the threat actor KongTuke initiated a campaign leveraging Microsoft Teams to impersonate internal IT support staff. By contacting employees through external Teams chats, they persuaded victims to execute a malicious PowerShell command, leading to the deployment of ModeloRAT malware. This tactic enabled KongTuke to establish persistent access to corporate networks within minutes, facilitating data exfiltration and potential ransomware attacks. This incident underscores a significant shift in cybercriminal strategies, highlighting the exploitation of trusted communication platforms for social engineering. The rapid execution and effectiveness of this method emphasize the need for organizations to reassess and strengthen their security protocols, particularly concerning collaboration tools.
4 months ago
Kill Chain
Persistent OAuth Tokens: The Unseen Backdoor in Enterprise Security
In May 2026, a significant security concern emerged regarding the widespread use of OAuth tokens in enterprise environments. Employees frequently connect AI tools, workflow automations, and productivity applications to platforms like Google and Microsoft, generating persistent OAuth tokens that often lack expiration dates and are not subject to automatic cleanup. This practice creates a substantial security gap, as these tokens can grant attackers unauthorized access without the need for passwords, bypassing traditional security measures such as multi-factor authentication. The inherent design of OAuth, which does not automatically revoke tokens when employees depart or change passwords, exacerbates this vulnerability. The urgency of addressing this issue is underscored by recent incidents where threat actors exploited OAuth tokens to gain unauthorized access to sensitive data. For instance, in August 2025, attackers used compromised OAuth tokens from the Salesloft-Drift integration to access Salesforce environments of over 700 organizations, leading to significant data exfiltration. ([checkred.com](https://checkred.com/resources/blog/when-oauth-tokens-go-rogue-lessons-from-the-salesloft-drift-breach/?utm_source=openai)) These events highlight the critical need for organizations to implement robust monitoring and management of OAuth grants to prevent similar breaches.
4 months ago
Kill Chain
Breaking the Code: Multi-Stage 'Code of Conduct' Phishing Campaign Leads to AiTM Token Compromise
In April 2026, a sophisticated phishing campaign targeted over 35,000 users across 13,000 organizations, primarily in the United States. Attackers employed 'code of conduct' themed emails with polished HTML templates to create a sense of urgency. The multi-stage attack involved CAPTCHA challenges and intermediate pages, culminating in an adversary-in-the-middle (AiTM) phishing site that intercepted authentication tokens, effectively bypassing non-phishing-resistant multifactor authentication (MFA) and granting immediate account access. This incident underscores the evolving sophistication of phishing tactics, highlighting the need for organizations to implement phishing-resistant MFA methods and enhance user awareness training to mitigate such threats.
4 months ago
Kill Chain
Analyzing the UNC6040 Breach of Google's Salesforce Instance
In June 2025, Google's internal Salesforce instance was compromised by the cybercriminal group UNC6040, also known as ShinyHunters. The attackers employed a sophisticated voice phishing (vishing) campaign, impersonating IT support to deceive employees into installing a malicious version of Salesforce's Data Loader application. This granted unauthorized access to sensitive business customer data, including names and contact details. The breach was swiftly identified and contained by Google, minimizing the exposure of sensitive information. ([avertium.com](https://www.avertium.com/flash-notices/flash-notice-google-salesforce-breach-an-in-depth-analysis-of-unc6040?utm_source=openai)) This incident underscores the escalating threat posed by social engineering attacks targeting cloud-based platforms. Organizations are urged to enhance their security measures, particularly in training employees to recognize and resist such deceptive tactics, to prevent similar breaches in the future.
5 months ago
Kill Chain
Black Basta Affiliates Resurface with Targeted Social Engineering Attacks in 2026
In April 2026, a group of former Black Basta affiliates initiated a sophisticated social engineering campaign targeting over 100 employees across multiple organizations. The attackers employed mass email bombing and impersonated IT support via Microsoft Teams to gain unauthorized access to networks, aiming for data theft, ransomware deployment, and extortion. Notably, approximately 75% of the targets were senior executives, directors, and managers, indicating a strategic focus on high-privilege accounts. ([cyberscoop.com](https://cyberscoop.com/black-basta-affiliates-senior-executives-reliaquest/?utm_source=openai)) This resurgence underscores the persistent threat posed by disbanded cybercriminal groups reassembling or reusing effective tactics. The campaign's rapid execution and automation highlight the evolving sophistication of social engineering attacks, emphasizing the need for organizations to bolster their cybersecurity defenses and employee awareness programs. ([cyberscoop.com](https://cyberscoop.com/black-basta-affiliates-senior-executives-reliaquest/?utm_source=openai))
5 months ago
Kill Chain
VENOM Phishing Campaign: A Wake-Up Call for Executive Security
Between November 2025 and March 2026, a sophisticated phishing campaign utilizing the previously undocumented VENOM phishing-as-a-service (PhaaS) platform targeted C-suite executives across over 20 industries. Attackers impersonated Microsoft SharePoint notifications, embedding QR codes to lure victims into credential theft schemes. The campaign employed advanced evasion techniques, including adversary-in-the-middle (AiTM) attacks and device code abuse, effectively bypassing multi-factor authentication (MFA) and establishing persistent access to compromised accounts. ([abnormal.ai](https://abnormal.ai/resources/venom-phaas-c-suite-microsoft-credential-theft-report?utm_source=openai)) This incident underscores a growing trend of highly targeted phishing attacks against high-level executives, highlighting the need for organizations to reassess their security postures. The emergence of sophisticated PhaaS platforms like VENOM indicates an evolution in cybercriminal tactics, emphasizing the urgency for enhanced defenses against such advanced threats. ([abnormal.ai](https://abnormal.ai/resources/venom-phaas-c-suite-microsoft-credential-theft-report?utm_source=openai))
5 months ago
Kill Chain
Understanding the 2026 Surge in Device Code Phishing Attacks
In early 2026, device code phishing attacks exploiting the OAuth 2.0 Device Authorization Grant flow surged by over 37 times. Attackers initiated device authorization requests to service providers, obtained codes, and deceived victims into entering these codes on legitimate login pages, thereby granting unauthorized access to their accounts. This method, originally designed for devices lacking standard input options, was co-opted by cybercriminals to bypass traditional authentication mechanisms. The proliferation of phishing-as-a-service kits, notably EvilTokens, has significantly contributed to the widespread adoption of this technique, enabling even low-skilled attackers to execute sophisticated phishing campaigns. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/device-code-phishing-attacks-surge-37x-as-new-kits-spread-online/?utm_source=openai)) The rapid escalation of device code phishing underscores a critical shift in cyberattack strategies, emphasizing the need for organizations to reassess and fortify their authentication processes. The commoditization of such attack methods through services like EvilTokens highlights the urgency for enhanced security measures and user education to mitigate the risks associated with these evolving threats.
5 months ago
Kill Chain
WhatsApp Malware Campaign 2026: Unveiling the VBS Payloads and MSI Backdoors
In late February 2026, a sophisticated malware campaign exploited WhatsApp messages to distribute malicious Visual Basic Script (VBS) files. Upon execution, these scripts initiated a multi-stage infection chain, creating hidden directories and deploying renamed legitimate Windows utilities to retrieve additional payloads from trusted cloud services like AWS, Tencent Cloud, and Backblaze B2. The attackers employed techniques such as User Account Control (UAC) bypasses and registry modifications to escalate privileges and establish persistence, ultimately installing malicious Microsoft Installer (MSI) packages that enabled remote access to compromised systems. This campaign underscores the evolving tactics of threat actors who leverage trusted communication platforms and cloud services to evade detection and maintain control over infected devices. The incident highlights a growing trend where cybercriminals exploit widely used messaging applications and cloud infrastructures to disseminate malware, making detection and mitigation more challenging. Organizations must enhance their security measures to address these sophisticated attack vectors and protect against similar threats.
5 months ago
Kill Chain
Emerging Threat: The Underground Trade of Paid AI Accounts in 2026
In early 2026, cybersecurity researchers uncovered a burgeoning underground market where cybercriminals are actively trading access to paid AI accounts. These accounts, associated with platforms like ChatGPT, Claude, Microsoft Copilot, and Perplexity, are being sold on dark web forums and encrypted messaging channels. Threat actors obtain these accounts through various means, including credential theft, exploitation of exposed API keys, and abuse of trial programs. The illicit access enables cybercriminals to leverage advanced AI tools for malicious activities such as crafting sophisticated phishing campaigns, automating fraudulent operations, and generating convincing social engineering content. This trend underscores the evolving tactics of cybercriminals who are increasingly integrating AI capabilities into their operations to enhance the scale and effectiveness of their attacks. Organizations must recognize the critical importance of securing AI platform credentials and monitoring for unauthorized access to prevent potential misuse. ([flare.io](https://flare.io/learn/resources/webinars-events/how-the-dark-web-is-reacting-to-the-ai-revolution-2?utm_source=openai))
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports