Validated Containment Architectures are here. →Explore

Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

1838 threat reports
Page 121 of 154

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer Software/Engineering Threat Reports

Showing 14411452 / 1838 reports
How Sophisticated Attackers Exploited the 2025 React2Shell Zero-Day
Impact· medium

How Sophisticated Attackers Exploited the 2025 React2Shell Zero-Day

In June 2025, a critical remote code execution vulnerability named React2Shell (CVE-2025-55182) was exploited in the wild against organizations using React Server Components. Within hours of the public disclosure and patch release, Chinese state-linked groups such as UNC5174 (CL-STA-1015), Earth Lamia, and Jackpot Panda, alongside opportunistic cybercriminals, began mass scanning and targeting exposed systems. The threat actors successfully deployed malware (notably Snowlight and Vshell), established persistent access, conducted credential theft, and attempted to extract Amazon Web Services configuration and credential files. Over 30 organizations across industries suffered breaches, including documented impact on customer cloud environments. This campaign demonstrates the increasing speed and coordination of attackers exploiting newly public vulnerabilities, especially in widely deployed frameworks like React and Next.js. The incident underscores the necessity of rapid patching, improved east-west traffic security, and continuous threat detection, as adversaries quickly weaponize disclosures for initial access and persistent footholds.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
China-Linked Supply Chain Breach Exploits React2Shell Flaw in 2025
Impact· low

China-Linked Supply Chain Breach Exploits React2Shell Flaw in 2025

In mid-2025, multiple China-linked threat actors launched widespread exploitation of the React2Shell vulnerability (CVE-2025-55182), a critical supply-chain flaw impacting React and Next.js applications. Within hours of the flaw’s public disclosure, attackers initiated automated scanning and weaponization campaigns, targeting internet-exposed services to quickly gain unauthorized, remote code execution. Successful intrusions enabled attackers to harvest sensitive data, escalate privileges, and pivot laterally within affected cloud environments. The rapid adoption of malicious payloads and swift exploitation before most organizations could patch led to substantial business risk, data loss, and potential compliance violations across sectors. This incident underscores an escalated threat landscape where nation-state actors rapidly exploit newly-disclosed supply-chain vulnerabilities. The speed and scope of these attacks reflect a significant uptick in zero-day exploitation campaigns and highlight the urgent need for organizations to strengthen patching velocity, endpoint monitoring, and east-west segmentation controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Cloudflare’s 2024 Outage: Lessons from the React2Shell RCE Emergency
Impact· medium

Cloudflare’s 2024 Outage: Lessons from the React2Shell RCE Emergency

In June 2024, Cloudflare experienced a significant outage after emergency patching efforts to address an actively exploited remote code execution (RCE) vulnerability in the React framework, dubbed "React2Shell." The incident unfolded as threat actors began leveraging the vulnerability to attempt unauthorized code execution on internet-facing workloads, prompting Cloudflare to rush critical security mitigations. While the attack itself targeted exploitation routes via React, it was the swift application of mitigations—rather than a direct breach—which triggered widespread downtime, temporarily impacting Cloudflare's global network operations and customer accessibility. This incident underscores the increasing speed and aggression of active exploitation cycles, particularly for zero-day vulnerabilities in widely used frameworks. As attacker sophistication grows and organizations race to patch critical flaws, operational disruptions and collateral damage are becoming more frequent in the ongoing effort to balance security with business continuity.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Clop Ransomware Hits Barts Health NHS via Oracle Zero-Day
Impact· high

Clop Ransomware Hits Barts Health NHS via Oracle Zero-Day

In early 2024, Barts Health NHS Trust disclosed a data breach after Clop ransomware actors exploited a zero-day vulnerability in Oracle E-Business Suite. The attackers gained unauthorized access to internal systems, exfiltrated sensitive files from a key database, and threatened further leaks. The attack leveraged unpatched software flaws as the entry vector, allowing for rapid lateral movement and data theft before being detected. The incident disrupted operations and triggered regulatory notifications due to the sensitive nature of patient and operational information. This breach highlights the ongoing risks posed by sophisticated ransomware groups exploiting zero-day vulnerabilities in widely used enterprise software. Attacks of this kind are increasingly common, especially in the healthcare sector, which remains a high-value target for ransomware due to legacy systems and critical service mandates.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Chinese Hackers Exploit React2Shell RCE—Critical React Server Vulnerability in 2025
Impact· medium

Chinese Hackers Exploit React2Shell RCE—Critical React Server Vulnerability in 2025

In December 2025, two Chinese nation-state threat groups rapidly began exploiting CVE-2025-55182—dubbed 'React2Shell'—a critical unauthenticated remote code execution vulnerability affecting React Server Components (RSC). Within hours of public disclosure, attackers scanned for and targeted vulnerable servers globally, leveraging the flaw to gain full control over application environments, execute arbitrary commands, and establish persistent footholds for lateral movement. The wide adoption of React in enterprise and SaaS environments increased the exposure and impact of these attacks, putting sensitive business-critical data at risk and causing major security teams to issue rapid patch advisories. This incident underscores the growing speed with which advanced threat actors weaponize zero-day vulnerabilities in widely used software frameworks. It highlights the urgent need for rapid vulnerability management, enhanced east-west segmentation, and robust threat detection, as attackers increasingly exploit supply chain and development stack exposures in cloud and hybrid environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Zero-Click Agentic Browser Attack Wipes Google Drive (Perplexity Comet, 2025)
Impact· high

Zero-Click Agentic Browser Attack Wipes Google Drive (Perplexity Comet, 2025)

In December 2025, researchers from Straiker STAR Labs disclosed a zero-click browser-based attack targeting users of Perplexity's Comet browser, enabling malicious actors to erase the contents of a victim’s entire Google Drive. The attack leverages agentic browser automation capable of connecting Gmail and Google Drive accounts by abusing trusted email-based automations. Once triggered by a specially crafted email, the exploit requires no user interaction to execute the destructive action. The compromise of cloud-stored data had significant operational impact, resulting in permanent data loss for affected users and highlighting new risks for organizations relying heavily on SaaS storage platforms. This attack is significant as it demonstrates the expanding threat of zero-click vulnerabilities powered by advanced browser automation, agentic AI, and email exploits. As more organizations migrate operations and collaborative data to the cloud, the frequency and sophistication of such attacks are expected to increase, escalating the urgency for robust cloud security controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
AutoIT3 Compiled Script Malware: 2024 Infostealer Surge Targets Windows Users
Impact· high

AutoIT3 Compiled Script Malware: 2024 Infostealer Surge Targets Windows Users

In December 2024, researchers identified a fresh malware campaign abusing compiled AutoIT3 scripts to deliver infostealers and remote access trojans to Windows systems. Attackers distributed malicious executables packaged in ZIP archives, which, upon execution, leveraged AutoIT3’s FileInstall() function to embed and unpack additional payloads, including obfuscated shellcode. Once unpacked, these scripts decoded and executed shellcode in memory, deploying threats such as Quasar RAT and Phantom Stealer, thereby enabling credential theft and system compromise for victim organizations. This campaign highlights a growing trend where attackers utilize low-profile development tools, like AutoIT, to evade traditional defenses and deliver sophisticated payloads. The resurgence of compiled script-based malware demonstrates ongoing innovation in attack vectors, requiring defenders to expand their monitoring to scripting environments and unpacked resource analysis.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
React2Shell: China-Nexus Groups Target Supply Chains with Critical React Vulnerability
Impact· low

React2Shell: China-Nexus Groups Target Supply Chains with Critical React Vulnerability

In early 2024, a critical zero-day vulnerability in the widely used React JavaScript library—dubbed React2Shell—was actively exploited in the wild by sophisticated China-nexus threat actors. Attackers leveraged compromised software supply chains to infiltrate organizations during regular package updates, gaining access via vulnerable dependency injection into production environments. Once inside, adversaries orchestrated lateral movement to exfiltrate sensitive data and disrupt business operations across sectors, leveraging encrypted communication channels and advanced stealth techniques. The incident has underscored the significant risk posed by supply-chain weaknesses in core developer tools and frameworks, amplifying concerns among enterprises and regulators alike. This breach reflects a surge in supply-chain attacks targeting popular open-source components, exposing systemic vulnerabilities beyond traditional perimeter defenses. The rapid weaponization of techniques by nation-state actors highlights the urgent need for zero trust segmentation, proactive patching, and real-time threat visibility within software development ecosystems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical RCE in React Server Components Exposes Applications Worldwide (CVE-2025-55182)
Impact· low

Critical RCE in React Server Components Exposes Applications Worldwide (CVE-2025-55182)

In December 2025, a critical remote code execution (RCE) vulnerability—CVE-2025-55182—was discovered in the Flight protocol used by React Server Components. Rated CVSS 10.0, this flaw enabled unauthenticated attackers to craft malicious requests, resulting in the compromise of application servers running affected versions. Security researchers observed exploitation in the wild, with threat actors leveraging the flaw for lateral movement and potential data exfiltration. Organizations using Next.js and other frameworks integrating the vulnerable protocol faced heightened risk until urgent patches were issued. Immediate remediation efforts, threat monitoring, and network segmentation were necessary to mitigate the rapid spread. This incident underscores the increasing threat posed by supply chain vulnerabilities in widely adopted developer ecosystems. The exploitation of core component flaws in popular open-source projects amplifies business risk, as attackers accelerate adoption of frontline vulnerabilities for larger-scale impact.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Meta React Server Components 2025: Critical RCE Vulnerability Added to CISA KEV
Impact· medium

Meta React Server Components 2025: Critical RCE Vulnerability Added to CISA KEV

In December 2025, a critical remote code execution (RCE) vulnerability (CVE-2025-55182) was discovered and actively exploited in Meta's React Server Components framework. Threat actors leveraged this flaw in internet-exposed REACT instances, enabling them to execute arbitrary code remotely and potentially gain unauthorized access to internal systems. This vulnerability was significant enough to be added to CISA's Known Exploited Vulnerabilities (KEV) Catalog, prompting urgent remediation efforts across public and private organizations. Federal agencies were mandated to act by Binding Operational Directive 22-01, while industry peers were strongly advised to prioritize patching to limit exposure and prevent compromise. The exploit highlights an ongoing trend of attackers targeting widely adopted development frameworks like React, demonstrating how software supply chain and third-party vulnerabilities remain a high-risk vector. Its addition to the KEV Catalog underlines the persistent challenge organizations face in quickly identifying and mitigating critical threats across their infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical React2Shell Flaw in React & Next.js Puts Web Servers at Risk
Impact· medium

Critical React2Shell Flaw in React & Next.js Puts Web Servers at Risk

In June 2024, a critical vulnerability known as 'React2Shell' was discovered in the React Server Components (RSC) 'Flight' protocol, impacting React and Next.js applications worldwide. This flaw enables unauthenticated remote code execution (RCE), allowing attackers to execute arbitrary JavaScript code on affected web servers. Security researchers observed that threat actors could exploit the protocol by sending crafted requests, potentially leading to a full compromise of application environments and exposure of sensitive data or further lateral movement within networks. This incident underscores heightened risk in modern web application supply chains and the urgent need for timely patching within frameworks. Growing attacks on open-source packages and widespread usage of React/Next.js frameworks amplify the incident's relevance, especially as application-layer vulnerabilities facilitate high-impact breaches at scale.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How the yETH DeFi Platform Lost $9 Million in a Flash Loan Exploit (2025)
Impact· high

How the yETH DeFi Platform Lost $9 Million in a Flash Loan Exploit (2025)

In December 2025, an unknown threat actor successfully exploited a critical vulnerability in the yETH DeFi platform's smart contract infrastructure, using advanced flash loan manipulation tactics to drain approximately $9 million in funds. The attack was executed within minutes, bypassing protocol controls and effectively emptying several liquidity pools. Investigators reveal that the breach exploited flawed logic in the contract that allowed multiple reentrancies and circumvented rate checks, leading to rapid unauthorized fund transfers. Remediation steps included pausing affected smart contracts and collaborating with exchanges to freeze stolen assets. This incident highlights the rapidly evolving threat landscape targeting decentralized finance (DeFi) ecosystems, where complex protocols and smart contract bugs can be weaponized for mass financial theft. Continued increases in such exploits have intensified regulatory and investor scrutiny while prompting the DeFi sector to emphasize real-time security visibility, automated incident response, and proactive contract auditing.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports