Validated Containment Architectures are here. →Explore

Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

1833 threat reports
Page 107 of 153

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer Software/Engineering Threat Reports

Showing 12731284 / 1833 reports
Reprompt Attack: How Microsoft Copilot’s 2026 AI Vulnerability Enabled Silent Data Exfiltration
Impact· medium

Reprompt Attack: How Microsoft Copilot’s 2026 AI Vulnerability Enabled Silent Data Exfiltration

In January 2026, security researchers disclosed a critical vulnerability—termed the 'Reprompt' attack—in Microsoft Copilot Personal, enabling attackers to hijack user sessions and exfiltrate sensitive data through malicious prompt injection. By embedding harmful prompts in the 'q' URL parameter and leveraging Copilot's automatic execution, attackers could persistently access authenticated sessions and orchestrate stealthy data theft without user awareness. Microsoft Copilot, deeply integrated in Windows and Edge, was susceptible due to its handling of context and prompt flows; the attack chain was demonstrated by Varonis Security, who responsibly disclosed the flaw to Microsoft, leading to a patch release on January 2026's Patch Tuesday. Fortunately, there was no evidence of exploitation in the wild, and enterprise-targeted Copilot versions were unaffected due to stronger controls. This incident highlights the growing risk landscape as AI assistants and LLMs gain deeper access to personal and enterprise data. The Reprompt exploitation showcases the evolution of prompt injection from theoretical risk to practical attack, underlining the urgency for robust guardrails, user security awareness, and compliance-ready AI deployments as generative AI tools proliferate.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
How ConsentFix OAuth Phishing Redefined Microsoft Cloud Account Threats in 2024
Impact· medium

How ConsentFix OAuth Phishing Redefined Microsoft Cloud Account Threats in 2024

In early 2024, security researchers uncovered 'ConsentFix,' a sophisticated OAuth phishing campaign targeting Microsoft account holders across multiple sectors. Attackers leveraged consent phishing techniques, using malicious OAuth applications and browser-based authorization flows to trick users into granting access to their Microsoft 365 data—bypassing traditional credential-based defenses. Victims, believing they were authorizing legitimate apps, inadvertently permitted attackers to persistently access mail, files, and other sensitive resources. The campaign quickly evolved, with new variants adopting evasive tactics and leveraging cloud application trust models. Consent phishing's rise highlights a worrying trend: attackers increasingly exploit identity platforms and legitimate authorization mechanisms, rather than relying on malware or password theft. As organizations accelerate cloud adoption and remote collaboration, monitoring and mitigating application consent attacks is paramount for regulatory compliance and security posture.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Pax8’s 2026 MSP Partner Data Exposure: Lessons from a Cloud Email Mishap
Impact· medium

Pax8’s 2026 MSP Partner Data Exposure: Lessons from a Cloud Email Mishap

In January 2026, cloud marketplace giant Pax8 disclosed that it inadvertently exposed sensitive business information related to approximately 1,800 managed service provider (MSP) partners. The incident occurred when a Pax8 EMEA account manager mistakenly emailed a spreadsheet—intended for internal use—to under 40 UK-based partners. The file contained details such as partner and customer organization IDs, Microsoft product SKUs, license counts, renewal dates, booking data, and internal pricing. While the leaked data reportedly did not include personally identifiable information, it revealed confidential customer portfolios and licensing metrics, with over 56,000 entries potentially providing valuable intelligence to competitors or cybercriminals. Pax8 moved quickly to recall the emails, directly requested deletion, and launched an internal review to address the flaw. This breach highlights the persistent risks linked to accidental data disclosures, especially within cloud ecosystems and partner networks. Data leaks through misdirected emails are increasingly exploited by threat actors for social engineering, competitive maneuvering, and phased cyberattacks, driving renewed urgency for zero trust controls and robust data-handling processes.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Active Exploitation of Gogs CVE-2025-8110: Path Traversal Risks in DevOps Platforms
Impact· low

Active Exploitation of Gogs CVE-2025-8110: Path Traversal Risks in DevOps Platforms

In January 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an alert regarding the active exploitation of a critical path traversal vulnerability (CVE-2025-8110, CVSS 8.7) in Gogs, a widely used self-hosted Git service. Attackers bypassed prior security controls using symbolic links within the repository editor and abused the PutContents API to overwrite sensitive files on a server, effectively achieving code execution. Over 700 Gogs instances were reported compromised, with thousands of internet-exposed installations at risk worldwide. The exploitation allowed adversaries to gain control over affected servers, posing serious risks to intellectual property, credentials, and sensitive data. This incident is particularly significant as it highlights the continued targeting of critical DevOps infrastructure through zero-day attacks, especially when rapid patching is not possible. The Gogs event reflects wider trends of supply-chain vulnerability exploitation and underlines the urgency for defense-in-depth and active monitoring.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
China-Linked VoidLink Malware Hits Linux Cloud and Container Workloads
Impact· high

China-Linked VoidLink Malware Hits Linux Cloud and Container Workloads

In December 2025, security researchers identified a sophisticated, modular malware framework called VoidLink, engineered by a China-linked APT group to target Linux-based cloud and container environments. This threat leverages advanced rootkit features, credential harvesting, anti-forensics modules, and a modular plugin system to maintain long-term, stealthy access. The malware natively detects and adapts to Docker, Kubernetes, and major cloud service providers such as AWS, Azure, GCP, Alibaba, and Tencent, with its operators able to control it remotely via a web-based dashboard. VoidLink is believed to be used for espionage, data exfiltration, and potentially supply chain attacks affecting software developers and cloud-native infrastructure. VoidLink exemplifies a rapidly growing threat to cloud and DevOps ecosystems, where attackers increasingly favor Linux malware frameworks capable of evading modern detection. Organizations should note the malware’s cloud awareness, lateral movement abilities, and automated risk-adaptive evasions as they re-evaluate Linux and cloud security controls amidst a surge in advanced APT targeting of critical infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
How CVE-2025-6514 Unleashed AI Agents: The 2026 MCP Security Crisis
Impact· medium

How CVE-2025-6514 Unleashed AI Agents: The 2026 MCP Security Crisis

In January 2026, a critical security incident exposed systemic risks in agentic AI environments after threat actors exploited CVE-2025-6514—a vulnerability in a widely used OAuth proxy underpinning Machine Control Protocols (MCPs). By leveraging misconfigured or compromised MCP servers, attackers gained remote code execution across automation pipelines affecting over 500,000 developer environments and AI-driven workflows. The breach enabled malicious actors to execute unauthorized actions, abuse privileged APIs, and proliferate shadow API keys, resulting in substantial risks to source code integrity, business operations, and broader cloud infrastructures. This incident highlights the evolving threat landscape of autonomous AI agents and demonstrates how traditional identity models fail when automation drives execution at scale. The proliferation of agentic AI, coupled with insufficient visibility and control over MCP interactions, calls for urgent adoption of new governance frameworks, detection measures, and AI-specific access controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Node.js async_hooks Vulnerability Puts Production Apps at Risk of DoS Attacks
Impact· high

Critical Node.js async_hooks Vulnerability Puts Production Apps at Risk of DoS Attacks

In January 2026, Node.js disclosed a critical vulnerability (CVE-2025-59466) affecting all production environments using the async_hooks module, which underpins popular frameworks and monitoring tools such as React Server Components, Next.js, and major APM platforms. The flaw allowed an attacker to cause a denial-of-service (DoS) condition by forcing stack space exhaustion via unsanitized user input, leading the Node.js process to crash unexpectedly without a catchable error. All supported Node.js Long Term Support (LTS) versions were patched, while older, unsupported releases remain exposed, impacting a broad portion of the JavaScript ecosystem. This incident highlights not only the risks inherent in reliance on low-level APIs, but also the speed at which vulnerabilities impacting critical supply chain components can disrupt software availability. Organizations reliant on Node.js for cloud, SaaS, and modern web solutions face renewed pressure to update dependencies proactively and establish robust exception handling and segmentation practices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Attackers Bypass Security Using c-ares DLL Side-Loading: Commodity Malware Delivered in Active Campaign
Impact· medium

Attackers Bypass Security Using c-ares DLL Side-Loading: Commodity Malware Delivered in Active Campaign

In January 2026, security researchers reported an active malware campaign leveraging DLL side-loading via the open-source c-ares library. Attackers paired a malicious 'libcares-2.dll' with the legitimate signed 'ahost.exe' to evade security controls and deploy multiple trojans and info-stealer malwares. This method exploited trust in legitimate software to bypass endpoint defenses, leading to widespread compromise across targeted organizations and enabling the theft of sensitive data and credentials. Initial access was facilitated by distributing rogue DLLs alongside trusted binaries, primarily impacting organizations with inadequate application whitelisting and file integrity controls. This incident is particularly relevant as DLL side-loading attacks remain a favored technique for cybercriminals to circumvent detection, especially as organizations continue to migrate to cloud and hybrid environments. The campaign highlights a growing trend in software supply chain exploitation and the need for stronger endpoint and lateral movement protections.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
WhiteDate 2026 Data Breach: Privacy, Doxing, and Sensitive Data Handling
Impact· high

WhiteDate 2026 Data Breach: Privacy, Doxing, and Sensitive Data Handling

In January 2026, a sensitive data breach occurred involving WhiteDate, a controversial dating platform, exposing the personal information of its user base. The breach involved the unauthorized disclosure of email addresses and other private attributes, potentially linking individuals to a site associated with significant social stigma and white supremacist ideologies. Cybersecurity experts flagged this incident as highly sensitive due to the risk of outing individuals based solely on their presence in the dataset, which could result in reputational, professional, and even physical harm. The case reignited debates on the ethics of breach data handling and the obligations for responsible disclosure, especially where the data intersects with legally defined sensitive categories. This breach is particularly relevant as privacy frameworks and legal standards, such as GDPR and CCPA, impose stricter requirements for classifying and handling sensitive data. The rise of doxing and moral-driven disclosures increases the urgency for robust zero trust governance and nuanced incident response.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft 2026 Zero-Day: Patch Tuesday Attack Signals New Wave of Exploits
Impact· medium

Microsoft 2026 Zero-Day: Patch Tuesday Attack Signals New Wave of Exploits

On January 13, 2026, Microsoft disclosed the exploitation of a previously unknown zero-day vulnerability affecting multiple versions of Windows, as attackers leveraged the flaw ahead of the company's first Patch Tuesday of the year. The vulnerability enabled adversaries to bypass encryption and lateral movement safeguards, allowing them to access sensitive data and escalate privileges within corporate networks. The incident prompted Microsoft to release urgent security updates patching 112 CVEs, double the typical monthly total, as organizations worldwide scrambled to assess exposure and mitigate risk. Early evidence suggests sophisticated threat actors utilized tailored malware and covert tools to evade traditional defenses and achieve widespread compromise. This event is emblematic of an escalating trend in which zero-day exploits are increasingly leveraged by attackers against major vendors. With rising regulatory pressure for rapid remediation and ongoing vulnerabilities in encryption and segmentation controls, the breach reinforces the importance of proactive threat detection and multi-layered defense strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ServiceNow's AI Vulnerability Sets New Benchmark for Enterprise Risk
Impact· medium

ServiceNow's AI Vulnerability Sets New Benchmark for Enterprise Risk

In early 2024, ServiceNow integrated agentic AI capabilities into its legacy chatbot platform without adequate security controls, inadvertently exposing sensitive customer data and internal systems. Security researchers discovered that the unguarded AI layer allowed unauthorized access to confidential information by bypassing traditional authentication and authorization mechanisms. The vulnerability potentially allowed attackers to intercept unencrypted traffic and perform lateral movement within affected environments, significantly increasing the risk of data leaks and business disruption. ServiceNow has since initiated remediation efforts to close these flaws and notify impacted customers. This incident highlights the growing challenges organizations face as they rapidly adopt advanced AI technologies atop legacy infrastructures. Industry experts warn that such AI-driven vulnerabilities are increasing, drawing regulatory scrutiny and pressuring enterprises to strengthen segmentation, monitoring, and encryption for both north-south and east-west traffic flows.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
React2Shell and the December 2025 CVE Tsunami: Multi-Vector Exploitation at Scale
Impact· high

React2Shell and the December 2025 CVE Tsunami: Multi-Vector Exploitation at Scale

In December 2025, a record-setting wave of critical vulnerabilities led to a 120% surge in high-severity exploits globally, with 22 CVEs actively targeted—double the previous month. The standout event was the mass exploitation of Meta's React Server Components (CVE-2025-55182, dubbed "React2Shell"), which allowed unauthenticated remote code execution and became a magnet for a variety of threat actors, including China-linked groups Earth Lamia and Jackpot Panda plus a mix of financially motivated and state-aligned attackers. Attackers leveraged new and legacy vulnerabilities to deploy malware, pivot across internal networks, and compromise key infrastructure across vendors like Google, Fortinet, Cisco, Microsoft, and more. The incident highlights a dangerous shift: modern web frameworks are becoming high-value targets, attack toolkits are rapidly weaponizing zero-days, and threat actors now freely cycle between old and new vulnerabilities. Organizations operating React/Next.js or affected platforms face urgent patching requirements amid heightened regulatory attention and persistent adversarial activity.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports