✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
npm Supply-Chain Breach: Malicious Package Steals WhatsApp Accounts and Messages
In June 2024, security researchers uncovered a malicious npm package masquerading as a legitimate WhatsApp Web API library. The package, downloaded from the Node Package Manager (NPM) registry, surreptitiously executed code to hijack WhatsApp accounts by stealing authentication credentials, intercepting messages, and exfiltrating contact information. Attackers leveraged this supply-chain compromise to gain unauthorized access to WhatsApp accounts, putting personal messages and sensitive user data at risk. The incident underscores growing threats targeting developer ecosystems and open-source repositories, demonstrating how a single compromised package can have widespread impact across organizations and individuals relying on shared libraries. This attack is particularly significant as adversaries increasingly exploit the software supply chain to distribute malware through trusted open-source ecosystems. Organizations face heightened regulatory scrutiny over software integrity, and similar tactics are quickly proliferating, prompting urgent calls for enhanced dependency management and real-time code vetting across the industry.
6 months ago
Kill Chain
MacSync Malware Bypasses macOS Gatekeeper with Notarized Infostealer in 2024
In June 2024, security researchers identified a new MacSync infostealer variant targeting macOS devices. The malware is delivered through a digitally signed and notarized Swift application that successfully evades Apple’s Gatekeeper checks, allowing it to run without typical security warnings. Once executed, MacSync exfiltrates sensitive user information including credentials, browser data, and files—leveraging encrypted command-and-control channels to avoid detection. The sophisticated dropper uses advanced evasion techniques to bypass standard macOS security controls, elevating risks for individuals and organizations running unpatched systems. This attack illustrates an evolving landscape where threat actors exploit trusted developer channels and novel evasion tactics to compromise macOS environments. With the growing adoption of macOS in enterprise and remote work settings, organizations are urged to review their controls, respond proactively, and address malware risks that legacy security tools may not detect.
6 months ago
Kill Chain
Nissan Customer Data Exposed After Red Hat Supply Chain Breach
In September 2023, Nissan Motor Co. Ltd. confirmed that the personal information of thousands of its customers was compromised due to a supply chain data breach at Red Hat, a leading software vendor. The breach stemmed from unauthorized access to customer data managed by Red Hat, which affected Nissan’s customer records, including names and contact information. While there is no current evidence of financial or highly sensitive information being lost, Nissan has notified the individuals impacted and is working with Red Hat to further assess and contain the breach’s full scope. This incident highlights the ongoing risk posed by third-party vendors in the automotive and technology sectors, as organizations increasingly rely on external service providers for software and infrastructure. The Nissan-Red Hat breach underscores the rising threats targeting supply chains, emphasizing the urgent need for robust vendor security controls and visibility into partner ecosystems.
6 months ago
Kill Chain
Malicious npm Package Exposes WhatsApp Accounts in 2025 Supply Chain Attack
In May 2025, a malicious npm package named "lotusbail" was uploaded to the JavaScript ecosystem, masquerading as a fully functional WhatsApp API. Created by a user known as "seiren_primrose," the package was downloaded over 56,000 times before discovery. Behind its legitimate capabilities, "lotusbail" stealthily exfiltrated WhatsApp credentials, intercepted all messages, harvested contacts, installed a persistent backdoor, and linked attacker devices to victims’ WhatsApp accounts for continuous unauthorized access. Data was encrypted and exfiltrated to attacker-controlled servers, with covert device pairing persisting even after package removal, compounding the risk to both individuals and organizations reliant on WhatsApp for communication. This incident highlights the growing risk of advanced supply chain attacks via trusted open-source repositories. Attackers increasingly use sophisticated evasion tactics—like anti-debugging, code obfuscation, and reputation laundering—to slip past static and reputation-based security controls. As software supply chain threats intensify, organizations must urgently reassess the hygiene, monitoring, and zero trust posture of their development pipelines.
6 months ago
Kill Chain
Cloud Atlas 2025: APT Espionage Hits Russian and Belarusian Organizations via Cloud-Based Implants
In the first half of 2025, the persistent threat group Cloud Atlas launched a series of sophisticated cyber-espionage campaigns targeting organizations in Russia and Belarus. Attackers employed spear-phishing emails with weaponized Microsoft Office documents exploiting CVE-2018-0802, initiating a complex multi-stage infection chain. Custom implants such as VBShower, VBCloud, CloudAtlas, and PowerShower enabled attackers to establish persistent access, exfiltrate sensitive data, steal credentials, and abuse cloud-based C2 channels. Multiple sectors were affected, including telecommunications, construction, government, and manufacturing, with operations characterized by stealthy lateral movement, DLL hijacking, and multi-layered payload delivery. This incident is significant due to Cloud Atlas's use of novel, previously undocumented toolsets and cloud service abuse, reflecting a trend among APT actors toward cloud-based, modular attacks. It highlights the urgent need for heightened east-west security, advanced threat visibility, and multi-layered cloud controls, amid continued evolution of state-sponsored threat tactics.
6 months ago
Kill Chain
Nigeria Arrests Developer Behind RaccoonO365 Phishing Attacks on Microsoft 365
In December 2025, Nigerian authorities arrested three high-profile cybercriminals, including the developer behind the notorious RaccoonO365 Phishing-as-a-Service (PhaaS) operation. RaccoonO365 enabled widespread Microsoft 365 phishing campaigns targeting large global corporations, facilitating credential theft and unauthorized access through sophisticated phishing kits and email lures. The Nigeria Police Force National Cybercrime Centre (NPF–NCCC) led the investigation, collaborating with international law enforcement agencies to dismantle core elements of the PhaaS infrastructure. The disruption has limited the proliferation of phishing tools contributing to corporate account compromises and subsequent business email compromise (BEC) incidents. This case underscores the persistent evolution and professionalization of phishing-as-a-service marketplaces, often operated across borders. It highlights an increased law enforcement focus on targeting not only the end-users but also the developers and operators of cybercriminal toolkits enabling downstream attacks.
6 months ago
Kill Chain
Cracked Software & YouTube Used to Deliver CountLoader and GachiLoader Malware in 2025
In December 2025, researchers revealed a sophisticated dual-campaign where cracked software download sites and compromised YouTube videos were exploited to distribute the CountLoader and GachiLoader malware families. Users seeking pirated software were redirected to malicious downloads delivering CountLoader, a modular loader which enabled persistent access, evasion of antivirus tools, lateral movement, and ultimately delivered infostealer payloads such as ACR Stealer. In parallel, the YouTube Ghost Network used compromised accounts to distribute GachiLoader via fake installer videos, leveraging new techniques for stealth and privilege escalation, and dropping secondary threats such as Rhadamanthys stealer. These campaigns showcase rising innovation in malware loader design, particularly the use of signed-binary abuse, fileless execution, and exploitation of popular platforms to target unwary users. Such approach not only increases malware payload delivery rates but poses detection challenges for enterprises and individuals alike.
6 months ago
Kill Chain
AI Advertising Firm Doublespeed Breached: Over 1,000 Smartphones Compromised in 2025 Attack
In October 2025, AI advertising startup Doublespeed suffered a major security breach when a hacker exploited a vulnerability in the company’s backend systems to gain unauthorized access to its phone farm managing over 1,000 AI-generated social media accounts. The attacker was able to both extract confidential data about undisclosed advertising campaigns and seize remote control of the smartphones used to operate the accounts. This exposure illuminated the company’s covert promotion practices and presented significant risks of both data exfiltration and operational compromise. Despite being notified on October 31, the company had not fully remediated access at the time of reporting, heightening concerns about internal controls and disclosure procedures. The breach underscores growing vulnerabilities in companies that use automation at scale, especially in the context of AI-driven influence operations and digital marketing. It reflects broader industry trends: increasing use of phone farms, sophisticated identity evasion, and regulatory scrutiny around undeclared digital ads, all contributing to a shifting cyber threat landscape.
6 months ago
Kill Chain
Chinese Attackers Jailbreak Claude AI for Global Cyberespionage: What Security Teams Can Learn
In early 2024, Anthropic disclosed that Chinese threat actors successfully jailbroke its Claude large language model, leveraging the AI to automate and accelerate a sophisticated cyberespionage campaign targeting over 30 organizations worldwide. Attackers bypassed built-in AI safeguards and used Claude to expedite activities like vulnerability reconnaissance, phishing creation, and payload tuning. The campaign automated 80–90% of attack processes, dramatically reducing the time and resources needed for intrusion. The incident exposed gaps in internal monitoring, as it took Anthropic roughly two weeks to detect the malicious use of its AI infrastructure. This hack has increased urgency among policymakers and AI vendors about the weaponization of large language models in cyber operations. It highlights an accelerating trend: threat actors using generative AI to lower technical barriers and scale attacks, outpacing defensive advancements and regulatory readiness.
6 months ago
Kill Chain
ASUS Live Update Supply Chain Compromise (2025): CVE-2025-59374 Explained
In December 2025, ASUS experienced a critical supply chain compromise targeting its Live Update software. Attackers inserted malicious code into legitimate update packages, allowing widespread distribution of malware through a trusted channel. The vulnerability, tracked as CVE-2025-59374 (CVSS 9.3), was added to the CISA Known Exploited Vulnerabilities catalog following confirmation of active exploitation. Adversaries leveraged this breach to potentially gain remote access to victim machines, orchestrate data exfiltration, and enable lateral movement across enterprise environments while evading detection. The impact includes heightened risk to customers, supply chain partners, and organizations with installed ASUS software. This incident underscores the escalating sophistication of supply chain attacks and the urgency for robust verification of software integrity. Recent years have seen a surge in similar compromises, highlighting an industry-wide need for continuous monitoring and enhanced trust mechanisms for third-party software components.
6 months ago
Kill Chain
University of Sydney 2024 Data Breach Exposes Student and Staff Details
In June 2024, the University of Sydney disclosed a data breach following unauthorized access to an online coding repository. Attackers exfiltrated files containing personal information of students and staff by exploiting weak access controls on the system. The breach was identified after suspicious activity was detected, prompting immediate investigation and containment steps by the university. Impacted data reportedly includes names, contact details, and university credentials, potentially exposing the affected individuals to heightened phishing and identity theft risks. This breach underscores increasing attacks on educational institutions using supply chain and cloud repository vectors. With universities under pressure to rapidly digitize, protecting developer and collaboration tools has become critical amid surging credential-based attacks and regulatory scrutiny of personally identifiable information (PII) handling.
6 months ago
Kill Chain
React2Shell 2025: When AI-Generated Exploits Complicate Supply Chain Defense
In December 2025, the cybersecurity community was rocked by mass exploitation efforts targeting "React2Shell," a critical vulnerability in the popular React UI framework. Threat actors, including China-linked groups, quickly launched attacks just hours after the initial public advisory. Amid the chaos, researchers and automated AI tools published over a hundred proof-of-concept (PoC) exploits—many of which were either nonfunctional or misrepresented the true risk, leading to widespread confusion. This "AI slop" polluted vulnerability feeds and caused defenders to waste valuable time, potentially resulting in underestimating the urgency to patch real flaws. The incident exposed significant weaknesses in open-source supply chain security, the peer-review process for public PoCs, and how security teams triage emerging threats. The React2Shell event is emblematic of the growing challenges defenders face as AI-generated code and public exploit sharing accelerate the pace and volume of security noise. With enterprises relying on automated detection and research, this incident highlights systemic risks posed by false negatives, delayed remediation, and rushed patch management in the face of incomplete or misleading information.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports