Validated Containment Architectures are here. →Explore

Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

1833 threat reports
Page 119 of 153

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer Software/Engineering Threat Reports

Showing 14171428 / 1833 reports
Docker Hub Credential Leak: How Over 10,000 Containers Exposed the Supply Chain
Impact· low

Docker Hub Credential Leak: How Over 10,000 Containers Exposed the Supply Chain

In early June 2024, security researchers discovered that over 10,000 publicly available Docker Hub container images were leaking sensitive credentials, authentication keys, and API secrets. The exposed data included valid keys for production systems, CI/CD pipelines, cloud services, and large language models. Attackers could potentially use these secrets to compromise cloud infrastructure, move laterally within enterprise environments, exfiltrate data, or execute supply chain attacks. The incident highlights the risks associated with supply chain components and improper secrets management in application build processes. This event is highly relevant as containerized workloads and DevOps toolchains continue to proliferate, making the exposure of embedded credentials a fast-growing avenue for cyberattacks. Increased regulatory scrutiny and high-profile breaches are raising awareness of the urgent need to secure supply chain assets.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Japan’s 2024 Ransomware Surge: How Long-Tail Attacks Crippled Key Sectors
Impact· high

Japan’s 2024 Ransomware Surge: How Long-Tail Attacks Crippled Key Sectors

In early 2024, a wave of ransomware attacks swept through major Japanese organizations, targeting manufacturers, retailers, and segments of the Japanese government. Threat actors exploited vulnerable remote access points and unpatched software, using techniques such as lateral movement and data exfiltration before deploying ransomware payloads that encrypted business-critical systems. The operational disruption was immediate—many impacted organizations required months for full recovery, facing prolonged outages, loss of proprietary data, customer service challenges, and significant reputational harm. The attacks demonstrated sophisticated attacker persistence and exposed deficiencies in traffic segmentation and visibility into east-west movements within enterprise networks. This incident underscores the sophistication and persistence of modern ransomware operators in targeting essential sectors. As ransomware actors increasingly leverage stealthy, multi-stage attacks, organizations globally must reassess their east-west traffic security, incident response, and data protection programs to guard against extended, damaging outages.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
.NET SOAPwn Flaw (2025): Remote Code Execution via Rogue WSDL
Impact· medium

.NET SOAPwn Flaw (2025): Remote Code Execution via Rogue WSDL

In December 2025, security researchers at WatchTowr Labs revealed the 'SOAPwn' vulnerability (CVE-2025-34392 and CVE-2025-13659) impacting .NET Framework applications, including Barracuda Service Center RMM and Ivanti Endpoint Manager. Exploiting unsafe Web Services Description Language (WSDL) imports and HTTP client proxies, attackers could achieve remote code execution and arbitrary file writes on affected enterprise-grade systems. The flaw enabled threat actors to upload web shells, execute PowerShell scripts, or exfiltrate NTLM credentials via rogue SMB shares, potentially compromising entire application environments. Despite responsible disclosure, Microsoft stated the vulnerability is an application-level issue, leaving many unpatched systems at risk—especially those using components now at end-of-life such as Umbraco 8. This incident underscores the widespread risks associated with dynamic SOAP and WSDL usage in legacy frameworks and highlights attackers' growing focus on exploiting insecure software supply chains and overlooked application behaviors. The public disclosure has intensified scrutiny of web service integrations and spurred new urgency around secure coding practices in software built atop widely adopted frameworks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How the Shai-Hulud Worm Exposed npm’s Supply-Chain Weaknesses in 2024
Impact· medium

How the Shai-Hulud Worm Exposed npm’s Supply-Chain Weaknesses in 2024

In May 2024, the Shai-Hulud worm re-emerged in a sophisticated supply-chain attack targeting the npm ecosystem. Attackers compromised popular npm packages to inject malicious code capable of propagating to developer environments globally. Once installed via npm, the worm enabled lateral movement, credential theft, and unauthorized access, significantly elevating the risk for organizations relying on open-source JavaScript components. Detection lag and incomplete remediation allowed the campaign to impact a broad swath of organizations and developers. This incident marks a resurgence of highly automated supply-chain malware targeting open source software, mirroring broader industry concerns around software dependencies and third-party risk. Increased attacker automation and stealthy propagation tactics underscore the critical need for vigilant dependency management and advanced detection.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
North Korean Threat Actors Weaponize React2Shell to Deploy Stealthy EtherRAT in 2025 Supply Chain Campaign
Impact· medium

North Korean Threat Actors Weaponize React2Shell to Deploy Stealthy EtherRAT in 2025 Supply Chain Campaign

In late 2025, North Korea-linked threat actors exploited the critical React2Shell (CVE-2025-55182) vulnerability in React Server Components to deploy an advanced remote access trojan named EtherRAT. The campaign, tracked under 'Contagious Interview', targeted blockchain and Web3 developers through sophisticated social engineering on platforms such as LinkedIn, Upwork, and GitHub. Attackers leveraged a fake recruitment ruse, ultimately delivering EtherRAT via malicious scripts. The malware exhibits persistent mechanisms across Linux environments, utilizes Ethereum smart contracts for resilient C2, and aggressively evades detection with self-updating, obfuscated payloads. This attack demonstrates how advanced actors are increasingly adapting novel supply chain and social engineering tactics to target cloud-native developer ecosystems. The incident foreshadows a shift in the threat landscape, underlining the urgent need for robust east-west traffic controls, zero trust segmentation, and advanced anomaly detection for organizations exposed to modern DevOps and open-source risks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
React2Shell: Exploitation Surge Hits Businesses in 2025
Impact· low

React2Shell: Exploitation Surge Hits Businesses in 2025

In June 2025, attackers began widespread exploitation of CVE-2025-55182, a critical vulnerability known as React2Shell, shortly after it was publicly disclosed. Threat actors rapidly leveraged the unauthenticated remote code execution flaw to gain access to vulnerable web servers running the React2Shell component, allowing lateral movement, data exfiltration, and in some cases, ransomware deployment. The initial wave targeted a range of businesses, exploiting the window between disclosure and patch adoption, thus exposing organizations to operational disruption and compliance risks. The surge in React2Shell exploitation underscores an ongoing trend: cybercriminals are taking advantage of zero-day and recently publicized vulnerabilities with renewed speed and sophistication. Security teams must deal with shrinking patch windows, automated exploit tools, and increasing pressure from regulators to secure internet-facing applications.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Apache Tika’s Critical Patch Flaw: 2024 Supply-Chain Wake-Up Call
Impact· medium

Apache Tika’s Critical Patch Flaw: 2024 Supply-Chain Wake-Up Call

In June 2024, The Apache Software Foundation disclosed that its initial patch for a critical vulnerability (CVE-2024-29945) in Apache Tika was incomplete, leaving systems exposed to remote code execution risks. Tika, widely used for content detection and extraction, is embedded in many enterprise and cloud-native applications, amplifying the scale of exposure through the software supply chain. Attackers who exploit this flaw can execute arbitrary code on affected servers, potentially enabling data breaches or lateral movement across environments. The revised advisory and updated CVE has prompted urgent action to remediate the unresolved security gap. This incident highlights persistent challenges around open-source supply chain risks, insufficient patch validation, and the rapid exploitation of incomplete fixes. Organizations must evaluate their dependency chains, continuously monitor vendor advisories, and implement layered security controls as supply-chain vulnerabilities become increasingly frequent and business-critical.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Gemini Enterprise No-Click Vulnerability: A Wake-Up Call for AI/ML Security
Impact· medium

Gemini Enterprise No-Click Vulnerability: A Wake-Up Call for AI/ML Security

In early 2024, Google addressed a severe vulnerability in its Gemini Enterprise AI platform that allowed attackers to craft common business documents containing malicious prompt injections. These attacks did not require any user interaction; simply opening or syncing affected documents enabled adversaries to exfiltrate sensitive organizational data, bypassing usual security controls. The flaw exploited Gemini’s integration with widely used Google Workspace applications. Attackers leveraged this vulnerability to gain unintended access to confidential files, customer data, and internal communications, posing material risks to business operations and reputation. This vulnerability exemplifies emerging no-click threats in AI-integrated enterprise ecosystems, where conventional perimeter defenses and user-awareness controls are ineffective. The incident underscores the urgency for organizations to review AI/ML security posture as attackers rapidly adapt to take advantage of new AI-powered workflows.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
UK Cyber Agency Issues Stark Warning: Prompt Injection in LLMs is Here to Stay
Impact· medium

UK Cyber Agency Issues Stark Warning: Prompt Injection in LLMs is Here to Stay

In June 2024, the UK’s National Cyber Security Centre (NCSC) publicly warned that large language models (LLMs), including popular AI tools such as ChatGPT and Claude, possess a fundamental and persistent vulnerability known as prompt injection. This flaw arises because LLMs are architecturally incapable of reliably distinguishing between trusted and untrusted input within prompts. Despite repeated industry efforts to implement guardrails, researchers routinely bypass these safeguards, allowing malicious actors to manipulate LLM behavior, potentially leading to harmful outputs or the execution of unauthorized actions in real-world applications that integrate LLMs. This alert is especially significant as LLM-driven automations are rapidly proliferating in software development, browser agents, and enterprise workflows. The NCSC’s assessment signals an urgent need for organizations to shift their risk models, as AI prompt injection represents a persistent, unfixable attack vector with serious implications for data security, business integrity, and regulatory compliance.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Malicious VSCode Extensions Breach Puts Developer Supply Chains at Risk
Impact· high

Malicious VSCode Extensions Breach Puts Developer Supply Chains at Risk

In December 2025, two malicious Visual Studio Code extensions—Bitcoin Black and Codo AI—were uncovered on Microsoft’s official VSCode Marketplace, executing a supply chain attack that targeted developers. Published by an entity named 'BigBlack', these extensions installed information-stealing malware by abusing extension privileges. The malware leveraged DLL hijacking and covert batch scripts to steal credentials, browser session cookies, cryptocurrency wallet data, and system information from infected developer machines, storing exfiltrated data for later retrieval. The incident highlights how even widely trusted software platforms can host weaponized add-ons capable of compromising sensitive environments. This breach exemplifies the growing risks posed by open-source and third-party software supply chain compromises, especially targeting developer tools. The ease with which unvetted code can be distributed through official registries underscores the need for rigorous extension security and policy enforcement in enterprise environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Sneeit WordPress Plugin Hit by Critical RCE: 2025 Exploitation Wave
Impact· medium

Sneeit WordPress Plugin Hit by Critical RCE: 2025 Exploitation Wave

In August 2025, a critical remote code execution (RCE) vulnerability (CVE-2025-6389) in the widely used Sneeit Framework WordPress plugin (versions <=8.3) was discovered to be actively exploited in the wild. Attackers leveraged this flaw—scoring 9.8 on CVSS—to gain remote access to vulnerable sites, potentially executing arbitrary code, deploying malware, and further compromising user data or site integrity. The vendor responded by releasing version 8.4 with an urgent security patch, but over 1,700 active installations remain at risk. The Sneeit incident underscores a broader trend of rapid weaponization of WordPress plugin flaws by opportunistic threat actors, intensifying risk for websites lacking prompt patching and robust security controls. As attackers increasingly target web applications and supply chain components, organizations must reinforce visibility, detection, and vulnerability management strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
2025 Cyberattack Wave: USB Malware, React2Shell & AI Tool Exploits Expose Security Gaps
Impact· medium

2025 Cyberattack Wave: USB Malware, React2Shell & AI Tool Exploits Expose Security Gaps

In December 2025, organizations worldwide faced a surge of multi-vector cyberattacks exploiting recent vulnerabilities in USB devices, popular developer frameworks like React (notably the React2Shell bug), and emerging AI-powered coding environments. Attackers leveraged unpatched software, social engineering, and compromised USB devices to distribute malware and establish lateral movement within networks. The campaign capitalized on the rapid deployment of new technologies and lagging security controls, resulting in data breaches, financial theft via sophisticated WhatsApp worms, and the infiltration of development pipelines. This spate of incidents underscores the escalating convergence of traditional malware vectors and AI-driven exploits, exposing significant gaps in current security postures. As organizations accelerate digital transformation and adopt generative AI tools, adversaries are rapidly evolving, testing defenses across cloud, hybrid, and on-premises ecosystems.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports