Validated Containment Architectures are here. →Explore

Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

1833 threat reports
Page 106 of 153

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer Software/Engineering Threat Reports

Showing 12611272 / 1833 reports
How an XSS Bug in StealC Malware Panel Unmasked Threat Actors in 2026
Impact· medium

How an XSS Bug in StealC Malware Panel Unmasked Threat Actors in 2026

In January 2026, cybersecurity researchers exploited a cross-site scripting (XSS) vulnerability in the StealC information stealer's web-based control panel. By leveraging this flaw, they monitored active threat actor sessions, collected system fingerprints, and obtained critical intelligence on StealC's illicit operations. The StealC malware, known for targeting credentials and sensitive data from infected endpoints, was actively managed via this compromised control panel by cybercriminal operators. As a result of this research, defenders gained unprecedented visibility into threat actor workflow and TTPs, turning a malicious tool’s own infrastructure against its controllers. This incident highlights the growing focus on attacking the infrastructure of threat actors themselves, signifying a shift in defensive strategies. Vulnerabilities within criminal tooling and panels can be weaponized by blue teams to gain actionable threat intelligence, reflecting broader trends in intrusion analysis and adversary disruption.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Google Gemini AI Prompt Injection Breach Exposes Calendar Data in 2026
Impact· high

Google Gemini AI Prompt Injection Breach Exposes Calendar Data in 2026

In early 2026, researchers uncovered a significant security flaw in Google Gemini’s AI/ML integrations that allowed attackers to exploit indirect prompt injection to circumvent authorization guardrails and access private Google Calendar events. By embedding hidden instructions in malicious calendar invites, attackers could cause Gemini to exfiltrate sensitive information from users’ calendars without their knowledge or explicit consent. The exploit, disclosed by Miggo Security, demonstrated how AI-driven features can inadvertently expand attack surfaces, resulting in unauthorized data exposure and raising serious concerns for enterprise users relying on AI-powered productivity platforms. This breach highlights an evolving trend of attackers targeting embedded AI agents within trusted cloud services. As organizations increasingly leverage AI-powered workflows, the risks of novel exploitation methods like prompt injection become more pressing, driving renewed urgency around reinforcing authorization layers and AI security best practices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Google Pixel 9 (2026): Zero-Click BigWave Driver Breach Exposes Kernel Vulnerabilities
Impact· medium

Google Pixel 9 (2026): Zero-Click BigWave Driver Breach Exposes Kernel Vulnerabilities

In January 2026, Google Pixel 9 devices were found vulnerable to a sophisticated zero-click exploit chain targeting the Android BigWave hardware driver. Attackers combined a remote code execution exploit affecting a Dolby decoder with a privilege escalation flaw in the /dev/bigwave device, accessible from the mediacodec SELinux sandbox. The chain allowed attackers to escape the sandbox, bypass SELinux protections, and achieve kernel-level arbitrary read/write, essentially gaining full device control. This exploit enabled unauthorized access to sensitive data and even allowed remote data exfiltration by attackers, severely compromising device security. This incident highlights the increasing sophistication of exploit chains leveraging hardware-specific drivers and sandbox escape techniques in mobile ecosystems. With the rise in supply chain threats, use of AI to automate exploit engineering, and growing pressure from privacy regulators, organizations face escalating risks from zero-day attacks targeting embedded devices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Researchers Hijack StealC Malware Operators: 2026's XSS-Driven Counterattack
Impact· medium

Researchers Hijack StealC Malware Operators: 2026's XSS-Driven Counterattack

In January 2026, cybersecurity researchers uncovered and exploited a cross-site scripting (XSS) vulnerability in the web administration panel of the infamous StealC infostealer malware. By leveraging this flaw, the researchers were able to hijack malware operator sessions, collect hardware and geographic fingerprints, observe live threat actor activities, and even seize control of the attackers' own administration panels. One notable instance involved tracking a StealC affiliate operating as 'YouTubeTA', who stole credentials via malicious YouTube links that resulted in over 5,000 compromised devices and the theft of nearly 390,000 passwords and 30 million cookies. The research highlights critical operational risks inherent in the malware-as-a-service (MaaS) model, particularly as platforms surge in popularity and complexity. This incident is especially relevant as the MaaS cybercrime landscape continues to expand, driving rapid adoption of infostealer toolkits like StealC. Security teams must remain vigilant to emerging attacker tradecraft and vulnerabilities, as both operators and defenders look to exploit weaknesses in rival infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Malicious Chrome Extensions Target Workday and NetSuite Users in Coordinated Attack
Impact· medium

Malicious Chrome Extensions Target Workday and NetSuite Users in Coordinated Attack

In January 2026, cybersecurity researchers uncovered a campaign involving five malicious Google Chrome extensions that impersonated enterprise platforms such as Workday, NetSuite, and SuccessFactors. These extensions worked in unison to steal authentication tokens, disrupt incident response procedures, and seize control of victim user accounts. Attackers leveraged the trust users place in HR and ERP browser tools, exploiting their position to achieve data exfiltration and persistent account takeover across corporate environments. The attack’s main impact included unauthorized access to sensitive business systems and increased potential for widespread lateral movement within organizations. This incident underscores the growing sophistication of browser-based threats as attackers increasingly mimic legitimate business tools to infiltrate organizations. With a rise in social engineering and token theft techniques targeting identity and SaaS workflows, enterprises face heightened risk to cloud and hybrid environments, necessitating additional focus on endpoint, browser, and application-layer defenses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Gootloader’s Stealth Upgrade: 1,000-Part ZIP Exploit Bypasses Detection in 2026
Impact· medium

Gootloader’s Stealth Upgrade: 1,000-Part ZIP Exploit Bypasses Detection in 2026

In January 2026, the Gootloader malware loader resurfaced with advanced evasion techniques, deploying highly obfuscated, malformed ZIP archives containing JScript payloads. By concatenating up to 1,000 archive parts and leveraging ZIP format irregularities, attackers successfully bypassed many security tools, causing them to crash or miss the threat. These ZIPs are unpackable by Windows' default utility but break common tools like 7-Zip and WinRAR. Once delivered via a decoded, XOR-encoded blob, the JScript establishes persistence through .LNK shortcuts and triggers PowerShell-based execution chains, facilitating initial access for ransomware and other malware campaigns. This incident highlights a shift toward highly customized, anti-analysis delivery methods and demonstrates how common file formats can be manipulated to evade detection. With Gootloader back in circulation, organizations face renewed threats from sophisticated malware loaders that exploit endpoint tool weaknesses and static signature limitations.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Modular DS WordPress Plugin Flaw Grants Attackers Admin Access in Widespread 2026 Breach
Impact· medium

Modular DS WordPress Plugin Flaw Grants Attackers Admin Access in Widespread 2026 Breach

In January 2026, a critical authentication bypass vulnerability (CVE-2026-23550) was discovered and exploited in the Modular DS WordPress plugin. With over 40,000 installations, the plugin allowed central management of multiple WordPress sites. The flaw enabled unauthenticated attackers to remotely access admin-level privileges by exploiting flawed logic in the plugin’s direct request mode, resulting in privileged access without cryptographic checks. Attackers were able to select or auto-enroll themselves as site administrators, exposing affected sites to full compromise and potential downstream attacks. A patch was quickly released in version 2.5.2, closing the immediate vulnerability. This incident stands out as attackers increasingly target plugin ecosystems in widely-used CMS platforms, exploiting software supply chain vectors for rapid, broad impact. The case illustrates the urgency for continuous code review and rapid patch management in response to emergent threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Chrome AI Extensions Breach: 900,000 Users’ Chat Data Stolen Through Infostealer Malware
Impact· medium

Chrome AI Extensions Breach: 900,000 Users’ Chat Data Stolen Through Infostealer Malware

In January 2026, two widely used Chrome extensions marketed as AI workflow assistants were discovered stealing ChatGPT and DeepSeek chat data from over 900,000 users. Threat actors leveraged the popularity of generative AI tools, distributing the malicious extensions through official and third-party repositories. Once installed, these extensions exfiltrated sensitive conversations and user data by intercepting traffic and bypassing standard browser security controls. The incident revealed significant vulnerabilities in the supply chain of browser add-ons and highlighted the ease with which infostealers can abuse trust in AI-powered productivity tools. Organizations and individuals relying on browser-based AI helpers were left exposed, with the compromised data raising regulatory and reputational concerns. This breach underscores a growing trend where attackers target the workflows and integrations surrounding AI, rather than the AI models themselves. The rise in infostealers embedded within productivity tools calls for urgent improvements to extension vetting, zero trust segmentation, and East-West traffic security.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical WordPress Modular DS Plugin Vulnerability Enables Site Takeover
Impact· medium

Critical WordPress Modular DS Plugin Vulnerability Enables Site Takeover

In January 2026, a critical security vulnerability (CVE-2026-23550, CVSS 10.0) surfaced in all versions of the WordPress Modular DS plugin prior to 2.5.2. The flaw allowed unauthenticated attackers to escalate privileges and take over administrator accounts by exploiting a combination of weak route authentication and permissive auto-login features, impacting over 40,000 active websites. Active exploitation began on January 13, 2026, with attackers leveraging specifically crafted HTTP GET requests through the exposed "/api/modular-connector/login/" endpoint and originating from known malicious IPs. Compromised sites faced risks of full takeover, data exfiltration, or malware delivery. This incident underscores the growing trend of supply-chain and plugin-based attacks in widely used web platforms, highlighting attackers’ shift to exploiting software design weaknesses over traditional single code bugs. The case serves as a cautionary tale for organizations reliant on third-party integrations and CMS plugins, reinforcing the importance of timely patching and continuous risk assessments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
AWS CodeBuild Misconfiguration Put GitHub Supply Chain at Risk in 2025
Impact· medium

AWS CodeBuild Misconfiguration Put GitHub Supply Chain at Risk in 2025

In September 2025, a critical misconfiguration in AWS CodeBuild was discovered by cloud security firm Wiz, potentially allowing attackers to gain full control over AWS's own public GitHub repositories, including the widely-used AWS JavaScript SDK. This vulnerability, dubbed 'CodeBreach,' arose when certain IAM roles in CodeBuild pipelines were over-privileged and could access connected GitHub repository OAuth tokens without sufficiently restrictive permissions. If exploited, an attacker could have injected malicious code into key software supply chains, jeopardizing thousands of AWS customer environments globally. AWS promptly remediated the flaw following responsible disclosure, averting a major breach. This incident highlights the persistent risks posed by cloud misconfigurations and the growing focus of attackers on software supply chains. With rapid cloud adoption, organizations must remain vigilant to configuration drift and privilege escalation risks inherent in third-party integration, especially as regulatory scrutiny and supply chain attacks continue to escalate.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Lumma Stealer 2026: Persistent Infostealer Escalates C2 Traffic Through Scheduled Tasks
Impact· medium

Lumma Stealer 2026: Persistent Infostealer Escalates C2 Traffic Through Scheduled Tasks

In January 2026, an ongoing wave of Lumma Stealer infections demonstrated a distinctive post-infection pattern on Windows hosts. After initial data exfiltration, compromised machines retrieved a malicious PowerShell payload from Pastebin, which led to repeated execution of mshta commands against a .cc command and control (C2) domain—fileless-market[.]cc. The malware automatically created dozens of scheduled tasks, each triggering outbound HTTPS connections to the C2 infrastructure over many hours, elevating the risk of persistent infiltration and extended data leakage. This approach resulted in a marked increase in C2 traffic and operational risk for affected organizations. This case is relevant now as it highlights a trend of increasingly persistent infostealer operations leveraging fileless persistence, public paste sites, and escalated task creation for resilience. Security teams must be alert to novel automation and scripting techniques that facilitate stealthy C2 traffic and recurring infections, especially as infostealers like Lumma gain popularity in the cybercriminal ecosystem.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
2026 n8n Remote Code Execution Exposes Supply-Chain Security Gaps
Impact· medium

2026 n8n Remote Code Execution Exposes Supply-Chain Security Gaps

In January 2026, a critical supply-chain vulnerability (CVE-2026-21858, CVSS 10.0) was disclosed in n8n, a widely used open-source workflow automation tool. This unauthenticated remote code execution flaw enables attackers to fully compromise vulnerable self-hosted instances, potentially taking control of exposed servers across an estimated 100,000 global installations. The vulnerability is present in n8n versions between 1.65.0 and 1.120.4. No official mitigations or workarounds exist; remediation requires upgrading to version 1.121.0 or later. Attackers exploiting this bug could gain persistent access, manipulate workflows, or use impacted servers for further lateral movement and supply-chain attacks. This incident highlights a growing trend of attackers targeting automation and orchestration platforms as initial entry points. The rapid exploitation window, lack of mitigations, and broad exposure emphasize the urgent need for organizations to prioritize patching and review their supply-chain and workflow application security.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports