Validated Containment Architectures are here. →Explore

Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

1833 threat reports
Page 113 of 153

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer Software/Engineering Threat Reports

Showing 13451356 / 1833 reports
Trust Wallet Chrome Extension Supply Chain Attack Results in $7 Million Crypto Theft
Impact· high

Trust Wallet Chrome Extension Supply Chain Attack Results in $7 Million Crypto Theft

In December 2023, Trust Wallet, a prominent cryptocurrency wallet provider, suffered a supply chain attack via its Chrome extension. Attackers compromised the extension update process on December 24, distributing malicious code to unsuspecting users. As a result, users who installed the tainted update had their crypto wallets drained, collectively losing over $7 million worth of digital assets. The attack leveraged phishing domains to trick users and highlighted gaps in software supply chain security. Trust Wallet responded swiftly with advisories and efforts to contain further compromise while warning all extension users. This breach underscores the escalating threat and sophistication of supply chain attacks targeting digital assets, echoing a sharp rise in attacks exploiting third-party software update channels. Organizations must prioritize controls around extension security, continuous monitoring, and response plans to mitigate similar high-impact incidents.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Trust Wallet Chrome Extension Breach: $7M in Crypto Lost to Supply Chain Attack
Impact· high

Trust Wallet Chrome Extension Breach: $7M in Crypto Lost to Supply Chain Attack

In December 2025, Trust Wallet suffered a major supply chain attack when a malicious version (2.68) of its Chrome browser extension was published via a compromised Chrome Web Store API key. The attacker embedded backdoored code that exfiltrated users’ decrypted mnemonic phrases to an external server, allowing theft of approximately $7 million in cryptocurrencies. Over 2,500 wallet addresses were impacted, with stolen funds laundered through centralized exchanges and cross-chain bridges. Trust Wallet responded by urging users to upgrade to a safe version, launching a reimbursement program, and enhancing release procedures. This breach highlights the growing risks of supply chain attacks targeting widely-used browser extensions, especially in the cryptocurrency sector. With attackers demonstrating sophistication by bypassing official release processes and leveraging trusted analytics tools for data exfiltration, organizations face mounting pressure to secure development and release pipelines against insider threats and credential misuse.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Typosquatted MAS Domain Delivers PowerShell Malware in 2024 Attack
Impact· low

Typosquatted MAS Domain Delivers PowerShell Malware in 2024 Attack

In early 2024, cybersecurity researchers identified a campaign leveraging a typosquatted domain mimicking the legitimate Microsoft Activation Scripts (MAS) tool to distribute the 'Cosmali Loader' malware. Unsuspecting users seeking MAS utilities were tricked into downloading malicious PowerShell scripts, which silently loaded the Cosmali Loader onto Windows machines. The loader subsequently enabled additional payload delivery, providing attackers with persistent access and the ability to deploy further malware or conduct post-infection activities. The incident demonstrates the ongoing risks of social engineering via typosquatting and open-source tool impersonation, with users and organizations inadvertently compromising their systems. This campaign is particularly relevant as it highlights the resurgence of supply chain threats and the increasing sophistication of threat actors leveraging typosquatted domains to bypass conventional defenses. The incident signals a growing trend targeting both individual users and enterprise environments through deceptive domains and script-based malware.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
MacSync Stealer 2025: Notarized macOS Malware Defeats Gatekeeper Protections
Impact· high

MacSync Stealer 2025: Notarized macOS Malware Defeats Gatekeeper Protections

In June 2025, security researchers uncovered a new campaign leveraging a variant of the MacSync information stealer, which specifically targets macOS devices. In this incident, attackers distributed malware using a digitally signed and Apple-notarized Swift-based application disguised as a messaging app installer. This approach allowed the threat to bypass Apple Gatekeeper security controls designed to prevent unauthorized software execution. Once executed, the stealer harvested sensitive user data—such as browser credentials, wallets, and system information—and exfiltrated it to remote attacker-controlled servers, posing significant operational and reputational risks to affected organizations and users. This incident highlights a growing trend wherein adversaries employ legitimate-looking, signed applications to circumvent platform defenses. With an uptick in sophisticated macOS attacks and abuse of code-signing, organizations need to bolster defenses and maintain heightened vigilance for notarized application threats in enterprise environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Webrat Infostealer Campaign: How Fake GitHub Exploits Breached the Cybersecurity Supply Chain
Impact· medium

Webrat Infostealer Campaign: How Fake GitHub Exploits Breached the Cybersecurity Supply Chain

In early 2025, security researchers identified a campaign distributing the Webrat infostealer through malicious GitHub repositories. The threat actors disguised their malware as proof-of-concept exploits for high-profile vulnerabilities, targeting not only gamers and users of cracked software, but also inexperienced cybersecurity professionals and students. Victims who downloaded these fake exploits unwittingly executed a dropper that installed Webrat, granting attackers administrator privileges, disabling security controls, and enabling data theft from wallets and communication platforms while providing backdoor access and surveillance. This incident underscores a growing attacker trend of abusing trust in open-source platforms and targeting cybersecurity researchers themselves. As the use of AI-generated content and supply chain attacks increase, professionals must exercise greater scrutiny when handling code from unverified sources, amplifying the need for security awareness and robust isolation practices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
WebRAT Infostealer Abuses GitHub: 2024 Supply Chain Attack Exposed
Impact· medium

WebRAT Infostealer Abuses GitHub: 2024 Supply Chain Attack Exposed

In June 2024, cybersecurity researchers observed a campaign distributing the WebRAT infostealer through malicious GitHub repositories. Threat actors uploaded repositories pretending to offer proof-of-concept exploits for recent vulnerabilities, luring security professionals and researchers to download and execute the malware. Once installed, WebRAT exfiltrates sensitive information, leverages encrypted channels to evade detection, and can facilitate follow-on attacks via credential or data theft. This campaign underscores the risks in sourcing security tools or code from unverified public repositories and demonstrates the sophistication of modern software supply chain attacks. The incident highlights the growing trend of cybercriminals abusing trusted platforms like GitHub to reach a wide audience. With infostealer malware evolving and developer-targeted attacks increasing, organizations must remain vigilant about supply chain security and implement controls to detect and block lateral movement or data exfiltration.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Malicious Chrome Extensions Steal Credentials in 2024 Supply-Chain Attack
Impact· medium

Malicious Chrome Extensions Steal Credentials in 2024 Supply-Chain Attack

In June 2024, security researchers discovered two malicious Chrome extensions, 'Phantom Shuttle,' available in the official Web Store, that masqueraded as proxy service plugins but instead hijacked users’ browser sessions. Once installed, these extensions intercepted sensitive user data—including login credentials—by redirecting and manipulating network traffic. By deploying the extensions within the Chrome browser ecosystem, threat actors leveraged a trusted supply-chain vector to reach a broad user base without raising immediate suspicion, resulting in widespread data theft before the plugins were reported and removed. This incident highlights the persistent risks associated with supply-chain compromise in browser extension ecosystems. Attackers increasingly exploit official platforms like Chrome’s Web Store to distribute malicious tools, circumvent traditional network defenses, and exfiltrate credentials, underscoring the need for robust extension vetting, user education, and advanced detection capabilities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Urban VPN Proxy Secretly Harvests AI Chat Data in Major 2025 Breach
Impact· high

Urban VPN Proxy Secretly Harvests AI Chat Data in Major 2025 Breach

In December 2025, security researchers revealed that Urban VPN, a widely used proxy extension, was surreptitiously intercepting conversations across multiple major AI platforms including ChatGPT, Claude, Gemini, and others. The extension embedded specialized scripts to harvest every prompt, response, and session identifier, regardless of VPN connectivity, compromising the privacy of millions of users. This covert data collection occurred without user awareness or consent, and the only available mitigation was uninstalling the extension altogether. Widespread harvesting of AI chat data raised severe concerns over data confidentiality and regulatory non-compliance. This incident underscores the increasing exploitation of browser extensions as attack vectors, especially as user reliance on generative AI tools for sensitive communications grows. The lack of transparency and opt-out mechanisms amplifies exposure to data-harvesting malware and highlights urgent needs for enhanced supply-chain vetting and detective controls in both enterprise and consumer environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
How Phantom Shuttle Chrome Extensions Undermined Enterprise Security with Man-in-the-Middle Attacks
Impact· medium

How Phantom Shuttle Chrome Extensions Undermined Enterprise Security with Man-in-the-Middle Attacks

In December 2025, cybersecurity researchers discovered two versions of a Google Chrome extension named 'Phantom Shuttle' that secretly intercepted network traffic and stole user credentials from over 170 targeted domains. Masquerading as a legitimate VPN and speed test tool, these browser add-ons leveraged proxy permissions and malicious JavaScript code to inject authentication credentials and enable man-in-the-middle attacks. Users paid for subscriptions believing they were purchasing a secure service, while in reality, their web traffic, including passwords, authentication cookies, credit card information, API keys, and browsing histories, was exfiltrated continuously to a threat actor-controlled command-and-control server. The operation leveraged a subscription model and payment integrations via Alipay and WeChat, while traffic was routed through threat actor proxies managed via PAC scripts. This incident highlights a growing trend of browser extension abuse, with attackers monetizing malicious add-ons under the guise of productivity or security tools. With enterprise users increasingly utilizing browser extensions for business workflows, unmanaged browser risk is rapidly becoming a critical threat to organizational data security and compliance.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Amazon Thwarts Massive North Korean IT Job Scam: Lessons in Zero Trust and Insider Defense
Impact· medium

Amazon Thwarts Massive North Korean IT Job Scam: Lessons in Zero Trust and Insider Defense

In 2024, Amazon confronted a surge of over 1,800 suspected North Korean state-sponsored IT job scammers who attempted to infiltrate the company’s workforce through fraudulent job applications. The attackers used sophisticated social engineering and impersonation tactics to pose as legitimate IT professionals, seeking remote work to gain internal access or sensitive data. Amazon’s security and HR teams collaborated to detect anomalies, verify identities, and block the hiring process for the fraudulent profiles, successfully preventing insider threats and potential exploitation of corporate assets. The operation underscores the increasing complexity and scale of employment-based attack vectors. This incident is particularly relevant as cybercriminals and nation-state actors are increasingly leveraging remote work trends and IT labor shortages to execute social engineering intrusions. It highlights the need for enhanced workforce vetting, robust anomaly detection, and proactive segmentation to protect organizations from evolving insider and supply chain threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Remote Code Execution Risk in Windows Imaging Component: Deep Dive into CVE-2025-50165
Impact· low

Remote Code Execution Risk in Windows Imaging Component: Deep Dive into CVE-2025-50165

In November 2025, researchers exposed a critical vulnerability (CVE-2025-50165) in the Windows Imaging Component, specifically affecting WindowsCodecs.dll. The flaw arises from the mishandling of 12-bit and 16-bit JPG image encoding, where uninitialized function pointers could lead to a remote code execution (RCE) scenario. Attackers could theoretically trigger the vulnerability when a vulnerable application (such as Microsoft Photos or other image-processing tools) attempts to (re-)encode specially crafted JPG files. However, exploitation is complex and requires precise conditions—such as address leaks and heap control—making real-world attacks unlikely. Microsoft and library maintainers released patches to address the flaw by initializing pointers and adding error checks. This case highlights persistent risks in legacy image-processing libraries and the importance of timely patching. With software supply chains increasingly relying on third-party components, vulnerabilities in popular libraries can have broad implications, especially as adversaries probe for new entry points through common file formats.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
ASUS Live Update Supply Chain Breach: Lessons from a Sophisticated APT Attack
Impact· low

ASUS Live Update Supply Chain Breach: Lessons from a Sophisticated APT Attack

In 2018, ASUS suffered a major supply chain compromise in which attackers, believed to be a state-linked APT group, infiltrated the ASUS Live Update utility and distributed a malicious software update to potentially hundreds of thousands of users. The attackers inserted a sophisticated backdoor into the official ASUS update, enabling targeted compromise of devices based on specific MAC addresses. Although the vulnerability (CVE-2025-59374) has only been formally cataloged recently, the incident itself occurred years ago, impacting trust in widely used supply chain components. This breach remains relevant due to the ongoing risk of similar supply chain tactics by advanced threat actors and the late inclusion of legacy vulnerabilities in compliance and threat feeds. Security leaders must recognize that historic supply chain compromises may resurface in compliance audits or be exploited in future campaigns through neglected, end-of-life software.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports