✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Apple 2025 WebKit Zero-Day Breach: What Security Teams Must Know
In June 2025, Apple issued urgent security updates across iOS, iPadOS, macOS, tvOS, watchOS, visionOS, and Safari in response to two actively exploited zero-day vulnerabilities in the WebKit browser engine. One notable vulnerability, CVE-2025-43529, was a use-after-free flaw that could allow maliciously crafted web content to execute arbitrary code on affected devices. The flaws were discovered being exploited in the wild, with attackers leveraging compromised web traffic to bypass built-in device protections, raising concerns for the billions of global Apple device users. This event underscores the growing prevalence and severity of zero-day exploits against popular consumer platforms, highlighting attacker agility and cross-app targeting. With the rapid pace of vulnerability discovery and exploitation, it accentuates the pressing need for real-time patching, proactive threat detection, and segmentation strategy for organizations leveraging Apple devices.
6 months ago
Kill Chain
React2Shell Exploit Wave Exposes Web App Security Gaps in 2025
In December 2025, the critical React2Shell (CVE-2025-55182) vulnerability was actively exploited following its public disclosure. Attackers leveraged unsafe deserialization in React Server Components, impacting frameworks including React and Next.js. Proof-of-concept exploits rapidly spread online, with some functional variants enabling remote code execution. Exploit activity was observed from China-nexus threat groups and opportunistic cybercriminals, resulting in widespread targeting of vulnerable systems with cryptominers, infostealers, and webshells. Security vendors and threat researchers noted that while many PoC attacks were ineffective, validated exploits—some featuring advanced WAF bypasses and in-memory payloads—posed serious risks to organizations relying on web application frameworks. The incident highlights the increasing sophistication of attackers in quickly adapting and bypassing newly deployed defenses such as WAF rules. As automated scanning and exploit release cycles accelerate, enterprises face mounting challenges in promptly identifying, patching, and defending against RCE vulnerabilities across their web application infrastructure.
6 months ago
Kill Chain
Fake Movie Torrent Delivers Agent Tesla Infostealer via Subtitles in 2024
In early June 2024, cybersecurity researchers discovered that a malicious torrent purporting to offer the Leonardo DiCaprio film 'One Battle After Another' was distributing infostealer malware through booby-trapped subtitle files. Unsuspecting users who downloaded the fake torrent were exposed to malicious PowerShell loaders, which delivered the Agent Tesla remote access trojan (RAT). This malware enabled attackers to steal sensitive credentials, exfiltrate data, and remotely monitor infected devices, highlighting how threat actors weaponize popular entertainment content to bypass user defenses and propagate infostealers. The incident underscores the evolving threat landscape in which cybercriminals exploit widely-used file formats and trusted brands to lure victims. Multimedia supply chains are increasingly being targeted through creative means—such as doctored subtitles—with infostealers and RATs surging in popularity. Organizations and individuals must heighten their vigilance, especially as compliance scrutiny and attack techniques grow more sophisticated.
6 months ago
Kill Chain
Apple’s 2024 Zero-Day Exploits: Sophisticated Attacks Trigger Emergency Patches
In June 2024, Apple disclosed and swiftly patched two actively exploited zero-day vulnerabilities affecting multiple devices, including iPhones, iPads, and Macs. These flaws—CVE-2024-23296 (Kernel) and CVE-2024-23225 (RTKit)—were leveraged in a highly sophisticated attack that targeted select individuals, likely as part of a nation-state or advanced persistent threat campaign. The attackers bypassed security protections to achieve elevated privileges and potentially execute arbitrary code, underscoring the level of technical prowess and intent to compromise high-value targets. Apple released emergency updates to mitigate ongoing exploitation, emphasizing the urgency of immediate patching. This incident highlights the growing trend of advanced, targeted zero-day attacks aimed at high-profile platforms and users. Security teams should expect continued adversary innovation, accelerated zero-day discovery, and a heightened need for organizations to quickly adopt vendor-released mitigations to safeguard sensitive data and operations.
6 months ago
Kill Chain
Critical React Server Components Flaws in 2025 Enable DoS and Code Leaks
In December 2025, several critical vulnerabilities were discovered in React Server Components (RSC), affecting core packages such as react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. Identified as CVE-2025-55184, CVE-2025-67779, and CVE-2025-55183, these flaws were exploited by attackers to perform pre-authentication denial-of-service (DoS) attacks and, in some cases, access sensitive server-side source code. Exploitation was enabled through unsafe deserialization of HTTP payloads, leading to server hangs, or via crafted requests that exposed function source code. The vulnerabilities impacted RSC versions 19.0.0 through 19.2.2 and were identified following active investigation by security researchers in the wake of CVE-2025-55182 exploitation in the wild. This incident underscores the growing trend of adversaries targeting server-side JavaScript frameworks through exploitation chains and rapid patch circumvention. Organizations relying on React for server-side rendering must remain vigilant, as repeated disclosures highlight both the software supply chain's fragility and the need for rigorous update cycles to fend off evolving threats.
6 months ago
Kill Chain
CISA Adds Google Chromium CVE-2025-14174 to Exploited Vulnerabilities List
In December 2025, CISA added CVE-2025-14174—a Google Chromium out-of-bounds memory access vulnerability—to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation. This vulnerability enables threat actors to execute arbitrary code or potentially escalate privileges via unauthorized memory access within affected Chromium browser instances. Attackers exploited this flaw as an entry vector for malware and credential theft, increasing risks for both federal agencies and organizations relying on Chromium-based browsers. Federal Civilian Executive Branch agencies were directed, under BOD 22-01, to remediate this vulnerability by a strict deadline to mitigate ongoing risks. The rapid inclusion of CVE-2025-14174 in the KEV Catalog highlights persistent challenges posed by zero-day and n-day browser vulnerabilities. Recent increases in browser-based exploitation and strict regulatory mandates underscore the growing urgency to address software supply chain threats and prioritize swift vulnerability management across all industry sectors.
6 months ago
Kill Chain
Fake OSINT and GPT GitHub Repos Used to Spread PyStoreRAT in Supply Chain Attack
In late 2025, cybersecurity researchers uncovered a supply chain attack involving malicious repositories on GitHub impersonating open-source Python utilities themed around OSINT and GPT automation. These repos covertly delivered a previously unseen JavaScript-based Remote Access Trojan dubbed PyStoreRAT, using minimal code to retrieve and execute a remote HTA file. Unsuspecting developers and security professionals, lured by the project's legitimate appearance, risked compromise when cloning or running the code, resulting in unauthorized remote access and potential data exfiltration. The campaign highlights the growing sophistication of attacks abusing trusted developer platforms and open-source supply chains. This incident underscores the urgent need for organizations to audit third-party code sources, bolster code supply chain security, and monitor for emerging malware targeting developer ecosystems. The tactic reflects broader trends in social engineering, weaponized open-source projects, and the exploitation of generative AI themes by threat actors.
6 months ago
Kill Chain
Critical Gogs Zero-Day Exploited in Ongoing Supply-Chain Attacks
In early 2024, security researchers revealed that attackers had actively exploited a zero-day vulnerability in Gogs, a popular self-hosted Git service, for several months. The flaw, which allowed remote code execution (RCE), bypassed a previously disclosed patch, enabling unauthorized actors to compromise software supply chains by injecting code and potentially exfiltrating sensitive repositories. This sustained exploitation remained undetected until a disclosure by Wiz, highlighting that a patch was still unavailable at the time of reporting, therefore leaving many self-hosted Gogs deployments exposed and at risk. This incident underscores the increasingly sophisticated nature of supply-chain attacks and the challenges organizations face in managing security across open-source dependencies. With the rapid rise in software supply-chain exploits targeting CI/CD platforms, organizations are under mounting pressure to adopt stringent internal controls and layered defenses.
6 months ago
Kill Chain
2025 Surge in Supply Chain Attacks Hits GitHub Actions: What Every DevSecOps Leader Must Know
In 2025, a surge in supply chain attacks targeted GitHub Actions, leveraging insecure workflows and misconfigured secrets to inject malicious code into the software development pipeline. Attackers exploited open source dependencies and automation gaps, enabling lateral movement and data theft across multiple organizations using compromised CI/CD environments. The incident, revealed through coordinated research at Black Hat Europe, highlighted how adversaries can escalate privileges and bypass traditional defenses by targeting both public and private repositories, resulting in widespread risk for organizations with weak DevSecOps controls. This incident underscores a pronounced trend: attackers are increasingly focusing on automated development environments and supply chains, not just production workloads. With more organizations adopting GitHub Actions and similar platforms, visibility, zero trust segmentation, and secure automation practices are now critical to thwart sophisticated threat actors targeting the software supply chain.
6 months ago
Kill Chain
Malware’s New Trick: Abusing the DLL EntryPoint in Windows (2024)
In December 2024, security researchers identified a Windows malware technique that leverages the DLL entry point (DllMain) to execute malicious code automatically upon DLL loading, even if no exported function is invoked. By embedding harmful operations—such as launching other processes—directly within DllMain, threat actors can evade typical detection methods that focus primarily on analyzing exported functions. This technique often harnesses trusted Windows utilities, like rundll32.exe or regsvr32.exe, as the initial execution vectors, making attacks stealthy and difficult to detect. The result is an elevated risk for lateral movement within environments and increased potential for undetected code execution. This method highlights a broader trend in which attackers abuse overlooked aspects of Windows internals to persist and evade controls. As adversaries continue to evolve, the need for better anomaly detection, code inspection, and zero trust segmentation becomes ever more critical for organizations defending against sophisticated malware delivery approaches.
6 months ago
Kill Chain
AI-Powered Attacks Break Smart Contracts: A 2025 Blockchain Breach Analysis
In late 2025, advanced AI models including Anthropic's Claude Opus 4.5, Claude Sonnet 4.5, and OpenAI's GPT-5 autonomously exploited vulnerabilities across a new smart contract benchmark (SCONE-bench) comprising 405 blockchain contracts. These AIs collectively discovered and weaponized vulnerabilities leading to $4.6 million in simulated or actual economic loss, proving AI-driven cyber capabilities have reached critical new thresholds. Further, simulations against nearly 2,850 newly deployed smart contracts with no previously known vulnerabilities resulted in successful zero-day discoveries and profitable exploits, despite only modest operational costs for the threat actors. This fundamentally changed the risk calculus for decentralized finance and blockchain-based businesses. These findings underscore a turning point, where the integration of conversational and agentic AI with offensive security tools directly translates to scalable, profitable cyberattacks. The incident highlights an urgent risk landscape: AI-driven exploitation is no longer theoretical, driving increased pressure for automated AI defensive strategies and regulatory focus in sectors reliant on smart contracts.
6 months ago
Kill Chain
Google Ads Push MacOS AMOS Infostealer via ChatGPT & Grok AI Guides in 2024
In early June 2024, a threat campaign leveraged Google search advertisements to promote fraudulent ChatGPT and Grok chatbot guides targeting macOS users. Victims who clicked on these ads were redirected to malicious sites and deceived into downloading the AMOS (Atomic) infostealer malware, which harvested sensitive credentials, cryptocurrency wallets, and other private data. The campaign exemplifies the use of topical lures—capitalizing on the mainstream popularity of AI chat platforms—to facilitate widespread malware distribution, bypassing native macOS security. Attackers used SEO poisoning and social engineering tactics, making detection and attribution challenging, while infostealer payloads exfiltrated key business and personal data. This incident underscores a rising trend: infostealer campaigns exploiting interest in emerging AI technologies, with search engine ads and convincing guides serving as the primary attack vector. As macOS adoption grows in enterprises and AI tools become mainstream, businesses face escalating risks from social engineering, supply chain misuse, and evolving malware techniques exploiting trusted sites and brand searches.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports