✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
WinRAR Patch Delays Enable Nation-State Attackers in 2024
In early 2024, nation-state threat actors from Russia and China exploited a critical WinRAR vulnerability (CVE-2023-38831) well after a public patch became available in July 2023. Attackers leveraged the flaw via malicious archive files to gain initial access, with phishing lures targeting small- and medium-sized businesses (SMBs) and government targets. Despite availability of security updates and widespread coverage, a significant number of organizations remained unpatched, enabling cyber-espionage operations, data theft, and operational disruptions. This incident highlights the persistent risk posed by software supply chain vulnerabilities, especially when patch adoption is slow. The continued exploitation of a months-old flaw underscores how threat actors weaponize common utilities and rely on lagging defenses, driving urgency for improved vulnerability management and zero trust controls.
6 months ago
Kill Chain
xAI Grok Deepfakes Spark 2024 Class Action: Legal and Security Wake-Up Call for AI
In January 2024, a class action lawsuit was filed against xAI—parent company of Grok—alleging that the generative AI chatbot enabled the creation and public dissemination of millions of non-consensual, sexualized deepfake images of women, men, and children. Victims claim that xAI executives failed to implement safeguards, allowed features that facilitated image manipulation simply by tagging users, and promoted options encouraging explicit content generation. Investigations are now being pursued internationally, and at least 100 plaintiffs are seeking justice for significant reputational, psychological, and legal harm stemming from Grok’s misuse. This major incident is emblematic of the growing risks in AI/ML security, as emerging generative tools become vehicles for large-scale privacy violations and abuse. The resulting public and regulatory scrutiny highlights urgent compliance and ethical gaps, especially as new legislation around synthetic sexual content and child abuse material accelerates worldwide.
6 months ago
Kill Chain
Enterprise AI at Risk: Hackers Hijack Exposed LLM Endpoints in Bizarre Bazaar Operation
In early June 2024, security researchers revealed an active campaign—dubbed the Bizarre Bazaar operation—where threat actors systematically scanned for and exploited publicly exposed Large Language Model (LLM) service endpoints. Attackers hijacked these AI/ML endpoints by bypassing inadequate API controls and leveraging unsecured cloud configurations, enabling unauthorized access to advanced AI resources. Compromised infrastructure became part of an underground market offering illicit AI compute power, leading to business risks ranging from intellectual property leakage to tool misuse and service disruption for impacted organizations. This incident spotlights the growing exploitation of AI infrastructure, with attackers rapidly adopting novel tactics as organizations rush to deploy LLMs. Weak segmentation, lack of egress controls, and poor visibility have left many organizations vulnerable to sophisticated abuse, elevating urgency for robust enterprise AI security and compliance measures.
6 months ago
Kill Chain
SolarWinds Web Help Desk Flaws: Critical RCE and Authentication Bypass in 2024
In June 2024, SolarWinds disclosed and patched multiple critical vulnerabilities in its Web Help Desk software, including an authentication bypass (CVE-2024-28995) and a remote command execution (RCE) flaw. These security issues, if left unpatched, allow attackers to compromise systems with minimal or no authentication, granting them access to execute arbitrary commands and potentially control affected servers. SolarWinds urged its customers to update immediately and disclosed that no in-the-wild exploitation had been confirmed at the time of announcement, but the severity of the flaws warranted immediate action across enterprise environments. This incident is particularly relevant due to a surge in software supply chain and IT management platform attacks, where adversaries exploit widely used admin tools to gain privileged access. Critical RCE and authentication vulnerabilities present potent risks to organizations, intensifying regulatory scrutiny and heightening the importance of timely patch management and proactive security measures.
6 months ago
Kill Chain
New Sandbox Escape Flaws in n8n Expose Instances to Remote Code Execution
In January 2026, security researchers uncovered two critical sandbox escape vulnerabilities in the popular n8n workflow automation platform, identified as CVE-2026-1470 and CVE-2026-0863. The flaws allowed authenticated users to exploit weaknesses in JavaScript and Python sandboxing mechanisms, enabling remote code execution on affected self-hosted instances. Attackers with valid user credentials could abuse these vulnerabilities to gain control of underlying systems, access sensitive data, and potentially compromise integrated services. Despite requiring authentication, the ease of privilege escalation and potential for lateral movement made these vulnerabilities highly impactful. This incident is highly significant given the large number of exposed n8n instances and the growing reliance on workflow automation by organizations worldwide. The vulnerabilities underline persistent challenges in securely sandboxing dynamic scripting languages, a common risk in platforms that allow code-based automation or AI integrations. The slow patching pace also highlights the pressing need for improved vulnerability management across self-hosted cloud infrastructure.
6 months ago
Kill Chain
Fake PyPI Spellchecker Packages Delivered RAT in Supply Chain Attack (2026)
In early 2026, security researchers uncovered a supply chain attack involving two malicious packages—spellcheckerpy and spellcheckpy—distributed on the popular Python Package Index (PyPI). Masquerading as legitimate spellchecking tools, these packages were downloaded over 1,000 times before removal, each covertly containing a remote access trojan (RAT). When unsuspecting developers installed the packages, attackers could gain persistent access to compromised systems, enabling data exfiltration, lateral movement, and remote command execution. No specific organizational victims were named, but the risk extended globally to Python developers and projects that leveraged these components. This incident is emblematic of the growing trend of supply chain attacks targeting open source repositories, exploiting trust in widely used ecosystems like PyPI. As software supply chains become common attack vectors, organizations face heightened pressure to vet dependencies and implement controls to prevent compromise via upstream components.
6 months ago
Kill Chain
Exposed Interfaces & Supply Chain Risks: The 2026 Moltbot AI Assistant Breach
In January 2026, researchers uncovered widespread security vulnerabilities in Moltbot (formerly Clawdbot), an open-source AI assistant that achieved viral adoption among both consumers and employees in the enterprise sector. Due to prevalent misconfigurations—specifically, exposed admin interfaces and reverse proxy errors—hundreds of Moltbot instances were accessible online, allowing unauthenticated attackers to steal API keys, OAuth tokens, credentials, message histories, and even execute commands remotely with system-level permissions. Additional risks arose as malicious skills (modules) could be planted in the official registry, rapidly propagating supply-chain threats to unsuspecting enterprise and developer systems, further compounded by the assistant lacking sandboxing or privilege separation by default. This incident highlights a growing trend where AI/GenAI tools, easily adopted outside corporate IT control, create new vectors for credential theft, data leakage, and lateral movement. As attackers focus on AI-driven endpoints and shadow IT, failure to enforce zero trust, segmentation, and robust monitoring introduces significant business risk and regulatory exposure.
6 months ago
Kill Chain
Google Flags Ongoing Exploitation of WinRAR CVE-2025-8088 by Elite Threat Actors
In July 2025, a critical vulnerability (CVE-2025-8088) in RARLAB WinRAR was identified and subsequently patched, but not before multiple threat actors, including government-backed groups from Russia and China as well as financially motivated cybercriminals, actively exploited it. Attackers leveraged the flaw as an initial access vector, distributing diverse malicious payloads to compromise targeted systems. The exploitation campaign enabled unauthorized access to sensitive environments and facilitated follow-on activities such as lateral movement and data exfiltration, raising serious concerns for organizations and individuals relying on WinRAR for file management. This incident is significant as it highlights the speed and sophistication with which both nation-state and financially driven attackers weaponize zero-day vulnerabilities. The continued exploitation of unpatched systems following disclosure underscores the persistent risks organizations face from lagging patch cycles and evolving adversary tactics.
6 months ago
Kill Chain
Critical vm2 Node.js Flaw Enables Sandbox Escape and Supply-Chain Exploit
In January 2026, a critical vulnerability (CVE-2026-22709, CVSS 9.8) was disclosed in the popular Node.js library vm2, enabling attackers to escape its JavaScript sandbox and execute arbitrary code on affected systems. The flaw, present in version 3.10.0, allowed exploitation via manipulation of Promise.prototype.then and Promise.prototype.catch, providing a direct path to remote code execution. Organizations relying on vm2 for untrusted code execution and sandboxing were at significant risk, with the vulnerability exposing underlying infrastructure to privilege escalation, data exfiltration, or supply-chain compromise. This incident highlights increased supply-chain risk in NPM ecosystems, where critical open-source dependencies like vm2 are often trusted by default. There is growing urgency as attackers increasingly target widely-used libraries to compromise downstream applications at scale, underscoring the need for stronger package vetting, runtime segmentation, and elastic incident response.
6 months ago
Kill Chain
Critical n8n Vulnerabilities Allow Authenticated Remote Code Execution (2026)
In January 2026, cybersecurity researchers uncovered two critical vulnerabilities in the n8n workflow automation platform, including a CVE-2026-1470 flaw (CVSS 9.9) which enables authenticated users to achieve remote code execution via eval injection. Discovered by the JFrog Security Research team, attackers exploiting these weaknesses could bypass the Expression system and execute arbitrary commands on affected servers. Successful exploitation could allow lateral movement and data exfiltration by leveraging internal automation integrations, putting sensitive business processes and connected services at significant risk. This incident underscores a rising trend of attackers targeting automation and orchestration platforms as high-value footholds in enterprise environments. With the increased adoption of low-code automation, vulnerabilities in such platforms can propagate risk across multiple systems, driving urgent need for software vendors and organizations to prioritize security reviews, patch management, and robust segmentation controls.
6 months ago
Kill Chain
Fake AI Coding Assistant Delivers Malware via VS Code Marketplace in 2026 Supply-Chain Attack
In January 2026, cybersecurity researchers discovered a malicious Visual Studio Code extension masquerading as "ClawdBot Agent - AI Coding Assistant" in the official VS Code Marketplace. The extension claimed to offer AI-assisted coding functionality but instead delivered a concealed malware payload to users who installed it. The attack leveraged the supply chain vector—abusing trust in a popular development marketplace—and could compromise the local development environment, providing the threat actor with unauthorized access and control over the affected system. This incident highlights the expanding risk of supply-chain attacks in developer ecosystems and raises concerns about the integrity of widely used software distribution platforms. This case underscores a rising trend of threat actors exploiting trusted software repositories to launch targeted malware campaigns. As AI coding assistants and marketplace extensions surge in popularity, organizations face mounting pressure to implement rigorous vetting and monitoring to protect software supply chains from increasingly sophisticated threats.
6 months ago
Kill Chain
Stanley Malware: Chrome Web Store Defense Bypassed for Phishing – 2026 Breach Analysis
In January 2026, security researchers uncovered 'Stanley', a Malware-as-a-Service (MaaS) operation specializing in the distribution of phishing Chrome extensions designed to bypass Google’s official Chrome Web Store review process. Marketed on underground forums, Stanley provides subscribers with malicious browser extensions capable of injecting full-page phishing iframes, silently installing on Chrome, Edge, and Brave, and maintaining persistent command-and-control communication. The malware enables attackers to manipulate users’ browsing sessions while masking the true origin, collect sensitive credentials, and target victims based on IP and geography. This poses a significant risk of data theft and compromise within organizations that rely on browser-based workflows. This incident underscores the growing trend of abusing trusted extension platforms to deliver targeted phishing and credential theft at scale. The ability for criminal actors to bypass established security vetting processes presents urgent challenges for enterprise security teams and highlights the broader concern over supply chain weakness in browser ecosystems.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports