<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cyberattack Case Library: Technology &amp; Supply Chain Feed</title>
    <link>https://cybercaselibrary.com/sectors/information-technology-cloud-services/</link>
    <description>Cyber incidents targeting SaaS providers, cloud infrastructure, software supply chains, and IT vendors.</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:02:15 GMT</lastBuildDate>
    <atom:link href="https://cybercaselibrary.com/feeds/technology.xml" rel="self" type="application/rss+xml"/>
    
    <item>
      <title><![CDATA[Technology & Software Incident: SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)]]></title>
      <link>https://cybercaselibrary.com/cases/solarwinds-orion-supply-chain-compromise/</link>
      <guid>https://cybercaselibrary.com/cases/solarwinds-orion-supply-chain-compromise/</guid>
      <description><![CDATA[Sophisticated software supply chain compromise by the Russian Foreign Intelligence Service (SVR), inserting the SUNBURST backdoor into updates of SolarWinds Orion software and compromising multiple federal agencies.]]></description>
      <category><![CDATA[Technology & Cloud Services]]></category>
      <pubDate>Sun, 13 Dec 2020 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Technology & Software Incident: U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-vasinskyi-kaseya-revil/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-vasinskyi-kaseya-revil/</guid>
      <description><![CDATA[Ukrainian national and REvil ransomware affiliate responsible for deploying the ransomware attack that hijacked Kaseya VSA management software, instantly encrypting up to 1,500 downstream businesses on July 4th weekend.]]></description>
      <category><![CDATA[Technology & Cloud Services]]></category>
      <pubDate>Wed, 11 Aug 2021 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Technology & Software Incident: U.S. v. Paige Thompson (Capital One Cloud Breach)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-thompson-capital-one-breach/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-thompson-capital-one-breach/</guid>
      <description><![CDATA[Former Seattle cloud engineer who identified misconfigured web application firewalls to gain unauthorized access to Capital One's Amazon Web Services storage buckets, exfiltrating 106 million customer credit card applications.]]></description>
      <category><![CDATA[Technology & Cloud Services]]></category>
      <pubDate>Mon, 29 Jul 2019 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Technology & Software Incident: U.S. v. Yevgeniy Nikulin (LinkedIn & Dropbox Breaches)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-nikulin-linkedin-dropbox/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-nikulin-linkedin-dropbox/</guid>
      <description><![CDATA[Russian national who hacked into the corporate networks of LinkedIn, Dropbox, and Formspring, stealing login credentials of over 100 million users and selling the stolen database dumps on darknet forums.]]></description>
      <category><![CDATA[Technology & Cloud Services]]></category>
      <pubDate>Wed, 05 Oct 2016 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Technology & Software Incident: Snowflake Customer Multi-Tenant Credential Stuffing Campaign]]></title>
      <link>https://cybercaselibrary.com/cases/snowflake-multi-tenant-credential-attacks/</link>
      <guid>https://cybercaselibrary.com/cases/snowflake-multi-tenant-credential-attacks/</guid>
      <description><![CDATA[Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.]]></description>
      <category><![CDATA[Technology & Cloud Services]]></category>
      <pubDate>Fri, 31 May 2024 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Technology & Software Incident: U.S. v. Paige Thompson (Capital One AWS Cloud SSRF Breach)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-thompson-capital-one/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-thompson-capital-one/</guid>
      <description><![CDATA[Former Amazon Web Services systems engineer convicted under the Computer Fraud and Abuse Act for exploiting a misconfigured open-source Web Application Firewall (WAF) using Server-Side Request Forgery (SSRF) to query AWS metadata services and steal over 100 million credit card applications from Capital One.]]></description>
      <category><![CDATA[Technology & Cloud Services]]></category>
      <pubDate>Wed, 28 Aug 2019 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Technology & Software Incident: Snowflake Enterprise Credential Stuffing & Customer Cloud Thefts]]></title>
      <link>https://cybercaselibrary.com/cases/snowflake-customer-credential-theft/</link>
      <guid>https://cybercaselibrary.com/cases/snowflake-customer-credential-theft/</guid>
      <description><![CDATA[Financially motivated threat actor collective UNC5537 systematically infiltrated over 165 corporate customer tenants hosted on Snowflake (including Ticketmaster, Santander Bank, Advance Auto Parts, and LendingTree). Attackers leveraged infostealer malware logs dating back years against enterprise user accounts that lacked multi-factor authentication and IP network allowlists, exfiltrating billions of consumer records.]]></description>
      <category><![CDATA[Technology & Cloud Services]]></category>
      <pubDate>Thu, 23 May 2024 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Technology & Software Incident: CDK Global BlackSuit Ransomware Incident]]></title>
      <link>https://cybercaselibrary.com/cases/cdk-global-blacksuit-ransomware/</link>
      <guid>https://cybercaselibrary.com/cases/cdk-global-blacksuit-ransomware/</guid>
      <description><![CDATA[Destructive ransomware incident that incapacitated CDK Global, the premier SaaS dealer management platform for approximately 15,000 car dealerships across North America. Attackers deployed BlackSuit ransomware throughout CDK cloud and on-premises data centers, forcing dealership employees into pen-and-paper workarounds for weeks until an estimated $25 million ransom was transferred.]]></description>
      <category><![CDATA[Technology & Cloud Services]]></category>
      <pubDate>Wed, 19 Jun 2024 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Technology & Software Incident: Microsoft Corporate Executive Email Intrusion (Midnight Blizzard / SVR)]]></title>
      <link>https://cybercaselibrary.com/cases/microsoft-midnight-blizzard-email-breach/</link>
      <guid>https://cybercaselibrary.com/cases/microsoft-midnight-blizzard-email-breach/</guid>
      <description><![CDATA[Russian Foreign Intelligence Service (SVR / Midnight Blizzard / APT29) compromised Microsoft corporate email systems via a password spray campaign against a legacy non-production test tenant lacking multi-factor authentication. Attackers leveraged the test account's permissions to grant full OAuth app-level access, reading executive emails and exfiltrating source code and customer cryptographic secrets.]]></description>
      <category><![CDATA[Technology & Cloud Services]]></category>
      <pubDate>Fri, 19 Jan 2024 00:00:00 GMT</pubDate>
    </item>
  
  </channel>
</rss>