Newest first. These kill chains run from the July 2026 Hugging Face intrusion back to 1990s social engineering, and reading them in either direction makes the same point: the tooling changed, the root causes did not. Fast-moving incidents are tracked first in the news feed, with the recurring root causes distilled in breach lessons - which walks the same set in chronological order - and the 2025 year in review. The most instructive incidents graduate into full kill chains here.
-
Hugging Face / OpenAI Agent - Sandbox Escape via a Package-Proxy Zero-Day → Malicious Dataset RCE → Node-Level Access → Cloud and Cluster Credentials
The first chain here where no human chose the target. An OpenAI model under evaluation escaped its sandbox through a zero-day in the package proxy meant to contain it, reasoned that Hugging Face probably hosted the benchmark's answers, and attacked production infrastructure to get them. It was cheating on a test…
Read kill chain → -
Suspected AI-Assisted AWS Compromise - App Weakness → Machine-Speed Secrets Sweep → Multi-Account Persistence → CI/CD Abuse → Infrastructure Extortion in 72 Hours
One actor went from an internet-facing application weakness to broad control of a large AWS estate in roughly 72 hours, with no custom malware and no zero-day, then extorted the victim by controlling the infrastructure rather than encrypting it. Four accounts' keys were used in a single observed second. The AI angle is Sygnia's inference, not proven fact…
Read kill chain → -
Storm-2949 - SSPR Reset + Fake IT Call → MFA Method Takeover → Azure RBAC Abuse → Key Vault, SQL and Storage Theft
Microsoft assesses with high confidence that this actor triggered an Entra ID self-service password reset on a target's behalf, then phoned the target as IT support to get the MFA prompt approved, with no malware at initial access. From one identity it rode existing privileged RBAC across subscriptions into Key Vault, SQL, storage, and VMs…
Read kill chain → -
Megalodon - Infostealer-Harvested GitHub Credentials → 5,718 Automated Commits → Injected Actions Workflows → CI Secret and OIDC Theft Across 5,561 Repos
5,718 commits into 5,561 repositories in six hours on a single afternoon, authored as build-bot and auto-ci with commit messages that read like routine CI maintenance. No exploit anywhere in the chain: over a third of the affected repo owners were on machines already infected by infostealers, and the credentials were simply bought…
Read kill chain → -
Mini Shai-Hulud / TanStack - Pwn Request → Actions Cache Poisoning → OIDC Theft from Runner Memory → npm Publish with Valid SLSA Provenance
A self-spreading worm published 84 malicious versions across 42 @tanstack npm packages in six minutes, then wormed on to 150+ more. No maintainer token was stolen: a fork PR poisoned the GitHub Actions cache, a later release run restored it, and OIDC tokens scraped from runner memory published tarballs carrying valid SLSA provenance…
Read kill chain → -
Vimeo / Anodot - Stolen Analytics Vendor Tokens → Direct Snowflake and BigQuery Access → 119,000 Records Exfiltrated → Extortion
ShinyHunters never touched Vimeo's perimeter. They stole the tokens an analytics vendor held on Vimeo's behalf and queried its Snowflake and BigQuery instances directly, staying inside the integration's own permissions the entire time, which is exactly why no escalation alert could fire…
Read kill chain → -
Vercel / Context.ai - Infostealer at a Vendor → OAuth App Compromise → Google Workspace Takeover → Plaintext Environment Variables
A commodity infostealer on one AI vendor employee's machine ended inside a major hosting platform. No Vercel vulnerability was exploited and no Vercel credential was stolen: every hop rode an authorization somebody had legitimately granted, and the exposed customer secrets were the ones nobody had flagged "sensitive"…
Read kill chain → -
LiteLLM / TeamPCP - Poisoned Security Scanner → Stolen PyPI Token → .pth Autorun → Cloud Credential Sweep → Kubernetes Lateral Movement
The compromise started in a security tool: TeamPCP poisoned Trivy, which ran as a step inside LiteLLM's own CI and handed over the project's PyPI publishing token. Two malicious releases went up 13 minutes apart with no matching git tag, planting a .pth file that ran on every Python interpreter start, before any application code…
Read kill chain → -
GTG-1002 - Jailbreak by Task Decomposition → Claude Code as the Operator → ~30 Targets Attacked Autonomously → Human Approval at 4-6 Gates
The jailbreak was not a clever prompt: operators told Claude it worked for a security firm doing authorized testing, then decomposed the campaign into tasks each innocuous alone. Anthropic assesses the AI did 80-90% of the work. Two caveats stated plainly on the page: single-source attribution, and the agent hallucinated results…
Read kill chain → -
Oracle E-Business Suite / Cl0p (CVE-2025-61882) - Unauthenticated XSLT Injection → Server-Side RCE → Two Months of Silent Zero-Day → Executive Email Extortion
The counterweight to every identity chain on this page: no credential stolen, no employee tricked, no token forged. For roughly two months organizations running fully patched, vendor-supported ERP were being emptied with no advisory to act on, and the first many heard of it was an extortion email to their executives…
Read kill chain → -
Shai-Hulud - npm Phishing → TruffleHog Sweep of the Developer's Machine → Self-Replication Across 500+ Packages → Secrets Committed to Public Repos
The first true worm in the npm ecosystem. It downloaded TruffleHog, a defender's tool, and pointed it at the developer, then authenticated as that maintainer and republished itself into up to twenty of their packages automatically. Reaching 500+ packages did not take 500 attacker decisions. It took one…
Read kill chain → -
npm debug / chalk - Fake 2FA-Reset Email → Live TOTP Relayed → Maintainer Account Taken Over → 18 Packages at 2.6 Billion Weekly Downloads Trojanized
MFA was enabled and did not help: a lookalike npmjs.help page relayed a live TOTP code in real time. One volunteer maintainer's inbox sat upstream of 2.6 billion weekly downloads. Contained in hours - then the same phishing pattern launched the Shai-Hulud worm exactly one week later…
Read kill chain → -
Nx / s1ngularity - PR Title Injection in pull_request_target → Stolen npm Token → AI CLIs Weaponized to Hunt Secrets → Credentials Published to Public Repos
Shell commands in a pull request title ran with repository permissions and walked out with the npm publishing token. The payload then found the developer's own Claude, Gemini and Q CLIs and drove them with --dangerously-skip-permissions to hunt for secrets: the first supply-chain attack to weaponize installed AI agents…
Read kill chain → -
Salesloft Drift / UNC6395 - GitHub Compromise → Stolen Drift OAuth Tokens → Bulk SOQL Exfil → Secret-Mining → 700+ Orgs Hit
UNC6395 (GRUB1) stole OAuth tokens from the Salesloft Drift integration and used them to run bulk SOQL queries against 700+ Salesforce tenants, then mined the exports for embedded AWS keys, Snowflake tokens, and passwords to enable downstream cloud compromise…
Read kill chain → -
Entra ID Actor Token (CVE-2025-55241) - Undocumented S2S Token → Unsigned Impersonation JWT → Legacy Graph Skips the Tenant Check → Global Admin in Any Tenant
The one entry here that is not a breach. Responsibly disclosed and fixed globally in three days, with no evidence anyone exploited it. It earns its place because every control this site recommends sat outside the path: no MFA, no Conditional Access, no tenant hardening at any price tier would have mitigated impersonating Global Admin in any tenant on Earth…
Read kill chain → -
UNC6040 - Vishing the Help Desk → Victim Authorizes a Fake Data Loader → OAuth Connected App → Bulk Salesforce Exfiltration → Extortion Months Later
No Salesforce vulnerability was exploited at any point. Operators phoned employees as IT support and walked them through Salesforce's own consent page to authorize a fake Data Loader. Everything the victim saw was genuine except who was asking. Google's own corporate instance was among the victims; extortion arrived months later…
Read kill chain → -
tj-actions/changed-files - Stolen PAT → Retag to Malicious Commit → Runner Memory Dump → Secrets in Public Logs → 23,000+ Repos Exposed
A chained GitHub Actions supply-chain compromise (CVE-2025-30066): a stolen bot PAT let attackers retag every version of tj-actions/changed-files to a malicious commit that scraped CI runner memory and printed AWS keys, PATs, and npm tokens into publicly readable build logs…
Read kill chain → -
Codefinger / S3 Ransomware - Stolen AWS Keys → Valid Access → Bucket Enum → SSE-C Encryption → 7-Day Delete + BTC Ransom
The Codefinger crew used compromised AWS access keys to encrypt victims' S3 buckets with AWS's own SSE-C, keeping the AES-256 key so data cannot be recovered, then set 7-day lifecycle deletion timers and demanded Bitcoin. No AWS vulnerability was exploited…
Read kill chain → -
Ultralytics - Fork Branch Name as Shell Injection → Actions Cache Poisoned → Malicious Build Published Through Trusted Publishing → XMRig
A fork's branch name was the injection vector. It poisoned the Actions cache, which the release build then restored - so the malicious versions were published by the project's real workflow and carried entirely correct provenance. Trusted Publishing worked as designed and did not help. The direct ancestor of Mini Shai-Hulud…
Read kill chain → -
UNC5537 / Snowflake - Infostealer Creds → No MFA → SHOW TABLES → Bulk Exfil → 165+ Orgs Extorted
A financially motivated threat actor tracked as UNC5537 spent months harvesting Snowflake credentials from infostealer malware logs, then systematically logged into victim Snowflake tenants - none of which required MFA - and exfiltrated…
Read kill chain → -
Polyfill.io - The Domain Was Sold → Every Site Still Loading the Script Handed Over Its Users → Conditional Mobile Redirects to Scam Sites
Nothing was hacked. Someone bought the domain, and every site still carrying the script tag began serving malicious code to its own visitors. The payload fired for mobile users only, so developers checking on desktop saw a clean script. Reported as 100,000 sites; the real figure was above 490,000…
Read kill chain → -
XZ Utils (CVE-2024-3094) - A Two-Year Campaign to Become the Maintainer → Backdoor Only in Release Tarballs → IFUNC Hook Into sshd → Pre-Auth RCE
This one starts with work, not theft. Two years of legitimate contributions and a sock-puppet pressure campaign against a burned-out volunteer maintainer. The backdoor was never in git - only in the release tarballs. Caught by accident, because someone noticed sshd logins were half a second slow…
Read kill chain → -
Change Healthcare / ALPHV - Stolen Credentials on a Citrix Portal With No MFA → Nine Days of Lateral Movement → Ransomware → A Third of US Patients Affected
One account, one internet-facing portal, one missing control. Nine days of quiet exfiltration before anything was encrypted. Then pharmacies could not verify coverage and providers could not get paid, for weeks. ~190 million people - the largest US healthcare breach recorded…
Read kill chain → -
Midnight Blizzard / Microsoft - Password Spray on a Forgotten Test Tenant → A Legacy OAuth App With Production Rights → Executive Email → Secrets in That Email → Source Code
The way in was an account nobody owned, in an environment nobody considered production. Then a legacy OAuth app that still held corporate permissions. Then executive, legal and security mailboxes - and the secrets people had emailed each other, which reached source code repositories…
Read kill chain → -
Promptware - Indirect Prompt Injection → Context Poisoning → Persistence → C2 → Covert Camera Livestream
Researchers demonstrated a complete seven-stage kill chain targeting cloud-connected AI assistants - from a malicious Google Calendar invite to covert Zoom video streaming, all triggered by the victim typing "thanks." Documented across 36…
Read kill chain → -
Okta Support System - Credential Saved to a Personal Google Profile → HAR Files Full of Session Tokens → Customer Sessions Hijacked
Chrome synced a service account password into an employee's personal Google account, and the support case system it unlocked was full of customer HAR files containing live session tokens. Three customers found this before Okta did, while a logging gap blinded its own investigation for 14 days…
Read kill chain → -
Scattered Spider / MGM Resorts - LinkedIn OSINT → Vishing Help Desk → Okta Super Admin → Azure AD → 100 ESXi Servers Encrypted
Scattered Spider (UNC3944) compromised MGM Resorts International in September 2023 using a single 10-minute phone call to the IT help desk. Attackers researched an MGM employee on LinkedIn, impersonated them to a help desk agent, obtained…
Read kill chain → -
Microsoft AI Research SAS Token - Over-Permissioned Token → Public GitHub → 38TB Internal Data Exposed for 3 Years
A Microsoft AI researcher shared a URL to open-source training data on a public GitHub repository. The URL contained an Azure Shared Access Signature token - but instead of being scoped to a specific file or container, it was an Account…
Read kill chain → -
Storm-0558 - Compromised Engineer → Crash Dump → Stolen MSA Signing Key → Forged Tokens → Government Email Espionage
Chinese nation-state actor Storm-0558 compromised a Microsoft engineer's corporate account, discovered a consumer MSA signing key that had accidentally been included in a crash dump in a debugging environment, and used it to forge…
Read kill chain → -
MOVEit Transfer / Cl0p - SQL Injection Zero-Day → LEMURLOOT Web Shell → Mass Data Theft in Days → 2,600+ Organizations Extorted
One unauthenticated SQL injection flaw in software whose whole purpose is holding other people's sensitive files. Cl0p harvested ~2,600 organizations in a campaign measured in days, then extorted them all at once. Most victims had never heard of MOVEit - their payroll provider ran it…
Read kill chain → -
3CX / X_TRADER - Trojanized Trading App on a Personal PC → Stolen 3CX Credentials → Both Build Environments Compromised → Signed Softphone Shipped to Customers
The first documented cascading software supply chain compromise: one supply chain attack used as the delivery mechanism for another. An end-of-life trading app on an employee's personal computer ended with 3CX signing and shipping a backdoored softphone to its own customers…
Read kill chain → -
CircleCI - Malware on an Engineer's Laptop → A Live 2FA-Backed SSO Session Stolen → Production Access → Every Customer Secret Assumed Compromised
Not a password - a live session cookie, already backed by 2FA. No login, no MFA prompt, no failed authentication to alert on. The advisory that followed is the memorable part: assume everything you have given us is compromised, and rotate it today…
Read kill chain → -
LastPass - Dev Env Breach → Source Code Recon → DevOps Home PC (Plex Exploit) → Keylogger → AWS S3 Vault Backup Exfil
A two-stage attack first compromised LastPass's development environment, then used the stolen technical knowledge to target a specific DevOps engineer - one of only four people with access to production decryption keys. The attacker…
Read kill chain → -
Uber - Dark Web Creds → MFA Push Fatigue → Hardcoded PAM Secret → Full AWS/GCP Admin
An 18-year-old attacker purchased an Uber contractor's VPN credentials from a dark web infostealer marketplace, then used MFA push-bombing combined with WhatsApp social engineering to bypass two-factor auth. Once inside the corporate…
Read kill chain → -
0ktapus / Twilio - SMS Phishing at Scale → Credentials and Live OTPs Relayed → 130+ Organizations Breached → And the One That Held
The only chain here that ends in a control working. Cloudflare staff received the same SMS, and at least three typed their credentials and one-time codes into the attacker's page. It failed anyway, because a FIDO2 key will not authenticate to a domain it was not registered to. 130+ other organizations were not so equipped…
Read kill chain → -
Okta / LAPSUS$ - A Subcontractor's Support Engineer → Five Days Inside → 366 Customers Exposed → And Two Months Before Anyone Was Told
The intrusion was ordinary; the disclosure was not. Okta correlated the LAPSUS$ screenshots to the January incident in about ninety minutes once they were public - after two months in which the customers who might have checked their own logs were never asked to…
Read kill chain → -
Log4Shell - A Logging Library Interpreting Its Own Input → JNDI Lookup to an Attacker Server → Unauthenticated RCE Almost Everywhere → And Nobody Could Say Where
Not a breach, and that is the point. The defining experience of December 2021 was not exploitation - it was that when leadership asked whether they were affected, the honest answer was that nobody knew, and finding out took weeks. The moment SBOM stopped being a compliance idea…
Read kill chain → -
ChaosDB - A Notebook Feature in a Managed Database → Local Privilege Escalation → Firewall Rules Rewritten → Full Admin on Other Tenants' Databases
The Entra Actor token flaw broke authentication. This one broke tenant isolation - the property every multi-tenant cloud service rests on, and the one boundary a customer cannot audit, test or compensate for. Several thousand Azure customers, and no configuration would have helped…
Read kill chain → -
Kaseya VSA / REvil - Authentication Bypass in an RMM Server → Ransomware Pushed as a Software Update → ~1,500 Businesses Encrypted
Launched into the July 4 weekend. One compromised management server reaches every client an MSP administers, so ~50-60 MSPs produced ~1,500 encrypted businesses. Coop Sweden closed 800 stores it could not run - a company with no relationship to Kaseya at all. The flaws had already been reported…
Read kill chain → -
Codecov Bash Uploader - Credential Leaked by a Docker Build → One Line Added to a Script Everyone Curls → Two Months of CI Environment Variables Exfiltrated
A credential recoverable from a Docker image layer bought write access to a script tens of thousands of pipelines curl and execute on every build. The payload was one added line. It ran for two months and ended not because of monitoring, but because one customer compared a SHA-256 against the published value…
Read kill chain → -
SolarWinds - Build System Compromise → SUNBURST Backdoor → On-Prem to Cloud Pivot → Golden SAML → US Government Espionage
Russian SVR (APT29 / Cozy Bear) breached SolarWinds' build pipeline and injected the SUNBURST backdoor into signed Orion software updates sent to 18,000+ customers. At high-value government targets, they used SUNBURST to achieve domain…
Read kill chain → -
Capital One - SSRF → IMDSv1 → Over-Privileged IAM Role → 106M Record S3 Exfiltration
A former AWS engineer exploited a misconfigured WAF via server-side request forgery to reach the EC2 instance metadata service, stealing temporary IAM role credentials. An over-privileged role then granted access to 700+ S3 buckets…
Read kill chain → -
event-stream - Publish Rights Handed Over on Request → Encrypted Payload in a New Dependency → Targeted Theft From One Bitcoin Wallet App
The oldest supply-chain chain here and the template for the newest. A maintainer who had not used the package since 2012 handed publish rights to a volunteer who asked. Two million weekly downloads, to steal from exactly one Bitcoin wallet app. The argument it started about unpaid maintenance is still unanswered…
Read kill chain → -
Kevin Mitnick / Novell - War Dialing → Pretexting → The Voicemail Trap That Named the Hacker → The Watched Honeypot
Mitnick war-dialed Novell's campus while a fugitive - and tipped the defenders off. A network admin recognized his pretext, taped the voicemail that named him, and then Novell granted him honeypot dial-up access and watched every keystroke…
Read kill chain →
Real cloud breaches chain three to six tactics together. Detection content should target the chains, not isolated techniques. - the lesson under every kill chain on this page