Validated Containment Architectures are here. →Explore

Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

1838 threat reports
Page 122 of 154

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer Software/Engineering Threat Reports

Showing 14531464 / 1838 reports
Silver Fox Mimics Russian Tactics: Fake Teams Installer Pushes ValleyRAT in 2025 China Cyber Attack
Impact· low

Silver Fox Mimics Russian Tactics: Fake Teams Installer Pushes ValleyRAT in 2025 China Cyber Attack

In December 2025, the threat actor known as Silver Fox executed a targeted cyber campaign in China, distributing the ValleyRAT remote access trojan through a fake Microsoft Teams installer. By leveraging SEO-poisoned websites, attackers lured victims searching for legitimate collaboration apps into downloading malicious files disguised as authentic installers. Once executed, the malware provided the attackers with covert access and enabled data theft, surveillance, and potential lateral movement within targeted organizations. The campaign mimicked Russian threat actor behaviors as a false flag, complicating attribution and response. This incident highlights the increasing sophistication and frequency of social engineering attacks using trusted business tools as lures. The rise of targeted SEO poisoning, deceptive software installers, and identity obfuscation poses heightened risks for organizations handling sensitive data or operating in sensitive regions.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Authorization Bypass in SolisCloud API Exposes Global Energy Data
Impact· medium

Authorization Bypass in SolisCloud API Exposes Global Energy Data

In December 2025, the SolisCloud Monitoring Platform, widely used across the global energy sector, was found to have a critical API vulnerability that allowed authorization bypass via a user-controlled key. This flaw, tracked as CVE-2025-13932, permitted any authenticated user to manipulate API requests and access detailed plant data belonging to other customers by altering the plant_id parameter. The vulnerability, present in both API v1 and v2, exposed sensitive operational information and highlighted a significant risk of data leakage in cloud-hosted critical infrastructure platforms. No mitigation had been released by SolisCloud at the time of public disclosure. This incident underscores the heightened threat of insecure APIs in industrial control systems, coinciding with a broader increase in supply chain risks and attacks targeting energy infrastructure. Regulatory bodies are likely to intensify scrutiny, given the global deployment and criticality of such platforms in the energy sector.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical React Flaw Puts Cloud Supply Chains at Immediate Risk
Impact· low

Critical React Flaw Puts Cloud Supply Chains at Immediate Risk

In June 2024, multiple severe vulnerabilities (CVSS 10.0) were discovered in the React JavaScript library, widely used by more than a third of cloud service providers. The flaws, which have been assigned two CVEs, could enable supply-chain attacks by allowing attackers to execute unauthorized code through compromised package updates or dependencies. If exploited, these vulnerabilities may lead to credential theft, lateral movement, and unauthorized access to sensitive cloud workloads, severely impacting the confidentiality and integrity of customer data. Cloud providers were urged to apply emergency patches and audit their environments for suspicious activity. This incident exemplifies the increasing risk posed by software supply-chain vulnerabilities, particularly as critical open-source components underpin cloud and enterprise infrastructures. The speed and scale of exploitation have raised concerns with regulators and CISOs, highlighting escalating threats to core cloud services and compliance programs.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical Supply Chain React Vulnerability Puts Major Web Apps at Risk
Impact· medium

Critical Supply Chain React Vulnerability Puts Major Web Apps at Risk

In June 2025, a critical deserialization vulnerability (CVE-2025-55182) was discovered in React Server Components, an open-source project underpinning a vast ecosystem of web frameworks. The flaw, initially reported by security researcher Lachlan Davidson, allowed unauthenticated attackers to execute remote code in default configurations of major frameworks—most notably Next.js—and impacted about 39% of cloud environments using vulnerable packages. Meta, Vercel, and affected project maintainers issued emergency patches, with no exploitation observed before public disclosure, but technical details were widely circulated, causing industry-wide urgency for remediation. This incident demonstrates the growing risks associated with open-source supply chain dependencies and highlights how a single upstream vulnerability can propagate rapidly across major SaaS platforms and developer environments. The ease of exploitation and prevalence of the affected components elevate concerns about lateral movement, credential exposure, and long-tail risk in environments slow to update or lacking robust software composition analysis.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical King Addons Elementor Plugin Flaw Exploited in WordPress Sites (CVE-2025-8489)
Impact· low

Critical King Addons Elementor Plugin Flaw Exploited in WordPress Sites (CVE-2025-8489)

In early 2025, attackers began actively exploiting a critical privilege escalation flaw (CVE-2025-8489) in the King Addons for Elementor plugin on WordPress sites. By abusing an insecure registration process, threat actors were able to escalate privileges and gain administrative control over vulnerable sites without authorization. This access could be used to manipulate website content, add malicious backdoors, or exfiltrate sensitive data, impacting website owners' security and reputation. The attacks have been widespread due to the plugin's popularity and ease of exploitation, highlighting the persistent risks present in third-party WordPress extensions. This incident is particularly relevant as it exemplifies an ongoing wave of attacks targeting web application vulnerabilities in widely used CMS platforms. The proliferation of such zero-day exploits magnifies risk for organizations, especially as adversaries move quickly to weaponize flaws before patches are broadly applied.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Supply Chain Attack: Malicious Rust Crate Targets Web3 Developer Ecosystems
Impact· medium

Supply Chain Attack: Malicious Rust Crate Targets Web3 Developer Ecosystems

In April 2025, cybersecurity researchers identified a malicious Rust package named "evm-units" that was uploaded to crates.io, the central Rust package registry. Disguised as an Ethereum Virtual Machine (EVM) helper tool, the crate targeted developers working in Web3 environments across Windows, macOS, and Linux systems. Once installed, the package stealthily executed OS-specific malware to compromise developer endpoints, enabling threat actors to potentially gain access to sensitive credentials and project intellectual property. The incident underscores sophisticated, hard-to-detect supply chain tactics exploiting trusted ecosystems and automated developer workflows. This attack highlights the increasing prevalence of supply chain threats targeting open source development pipelines and blockchain ecosystems. Recent trends show attackers adapting to security controls by embedding malware into widely used software components, pressuring organizations to enhance package vetting, anomaly detection, and Zero Trust strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Marquis Data Breach: 2024 Supply Chain Attack Exposes US Banking Customers
Impact· high

Marquis Data Breach: 2024 Supply Chain Attack Exposes US Banking Customers

In early 2024, Marquis Software Solutions, a financial marketing service provider, was the victim of a significant data breach that compromised sensitive personal information across more than 74 US banks and credit unions. The attackers gained unauthorized access through a third-party vulnerability and exfiltrated data sets containing names, addresses, Social Security numbers, financial account details, and demographic information of hundreds of thousands of customers. The breach not only impacted Marquis’s direct clients but also exposed downstream institutions and their end-users, triggering regulatory notifications and potential reputational damage to affected financial entities. This incident highlights the enduring risk posed by supply chain vulnerabilities within highly regulated industries, as attackers continue targeting trusted vendors with access to sensitive data. It underscores increasing regulatory scrutiny on vendor risk management and data protection, especially within financial and healthcare sectors.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Shai Hulud 2.0: The npm Supply Chain Worm Disrupting DevOps
Impact· high

Shai Hulud 2.0: The npm Supply Chain Worm Disrupting DevOps

In September 2023, a sophisticated supply-chain attack dubbed Shai Hulud 2.0 targeted the JavaScript ecosystem by compromising over 800 Node Package Manager (npm) packages. The malware leveraged stolen npm tokens to spread and infect trusted packages with a worm-like, two-stage payload. Upon download, it harvested GitHub and cloud credentials, aggressively scanned files for secrets, and exfiltrated stolen data via malicious public GitHub repositories. If unable to gain access tokens for exfiltration, the malware triggered a destructive file-wiping payload, disrupting both individual developers and organizations. Widespread impact was observed across Russia, India, Brazil, Vietnam, and more. This incident underscores the escalating risk of deep supply-chain compromise through open-source ecosystems and highlights attackers' evolving Tactics, Techniques, and Procedures (TTPs). It demonstrates the urgent need for enhanced monitoring, credential protection, and robust controls within software supply chains.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Picklescan Bugs Expose PyTorch Supply Chain: Malicious Models Bypass Security
Impact· low

Critical Picklescan Bugs Expose PyTorch Supply Chain: Malicious Models Bypass Security

In December 2025, severe vulnerabilities were revealed in Picklescan, an open-source security tool designed to scan Python pickle files for malicious code, particularly those used with PyTorch models. Attackers were able to exploit three critical flaws, bypassing Picklescan’s intended protections to execute arbitrary code during model loading processes. This effectively enabled the distribution of malicious machine learning models that could compromise developer and production environments. The risk was amplified due to Picklescan’s popularity in data science and AI workflows, potentially impacting organizations across multiple sectors relying on PyTorch. The incident is a stark reminder of the growing risk posed by supply-chain vulnerabilities in open-source AI and machine learning tooling, especially as the adoption of MLOps and automated model deployment platforms accelerates. Organizations now face increased regulatory scrutiny and operational risks tied to software supply chain security in the era of AI-driven applications.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
2025 WordPress King Addons Breach: Unauthenticated Admin Access & Website Takeover
Impact· medium

2025 WordPress King Addons Breach: Unauthenticated Admin Access & Website Takeover

In December 2025, attackers actively exploited a critical vulnerability (CVE-2025-8489, CVSS 9.8) in the popular King Addons for Elementor WordPress plugin. The flaw allowed unauthenticated individuals to escalate privileges by specifying the 'administrator' user role at registration, instantly granting themselves administrative access. Threat actors leveraged this zero-day to seize complete control of vulnerable sites, install malicious content, and potentially exfiltrate sensitive data or deploy further attacks. Affected organizations risked significant operational disruption, data compromise, reputational harm, and potential compliance violations due to unauthorized admin creation and persistence. This incident highlights the increasing trend of exploiting supply-chain and plugin vulnerabilities in widely used CMS platforms. The rapid weaponization of unauthenticated privilege escalation flaws underscores the need for continuous patch management, threat detection, and segmentation controls to counter evolving web application and identity-focused attack techniques.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical React Server Components Flaw Enables RCE in 2025—What You Need to Know
Impact· medium

Critical React Server Components Flaw Enables RCE in 2025—What You Need to Know

In December 2025, a maximum-severity vulnerability (CVE-2025-55182), codenamed React2shell, was uncovered in React Server Components (RSC), impacting platforms like React and Next.js. The flaw enables unauthenticated remote code execution (RCE) by exploiting how React decodes certain payloads sent to its server components. If left unpatched, attackers can execute arbitrary code on vulnerable servers, leading to full system compromise and severe business disruption. The incident highlights the critical impact of supply chain vulnerabilities in widely-used open-source frameworks and the elevated risk for businesses relying on modern web development stacks. The discovery of React2shell has triggered urgent patch advisories, as similar RCE vulnerabilities in web frameworks have seen rapid weaponization by threat actors. With increasing regulatory expectations for timely patch management and growing attacker focus on open-source component supply chains, this incident reinforces the need for continuous application security monitoring and robust SDLC controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Raptor Framework: AI-Powered Exploit and Patch Creation Disrupts Vulnerability Management
Impact· low

Raptor Framework: AI-Powered Exploit and Patch Creation Disrupts Vulnerability Management

In June 2024, security researchers publicly released the Raptor Framework, an open source AI-powered toolkit capable of autonomously generating both exploit code for software vulnerabilities and their corresponding security patches. Leveraging large language models (LLMs) and novel prompting techniques, the framework orchestrates agentic AI workflows to iterate, test, and refine functional exploit and remediation code at scale. While initially intended for defensive and research use, the dual-use nature of Raptor means malicious actors could similarly employ it to accelerate exploit development or enable broader, automated vulnerability discovery across cloud and on-prem environments. The release of the Raptor Framework highlights urgent concerns around weaponized AI and the rapid democratization of advanced cyber capabilities. Security leaders must act now, as similar agentic LLM tools could fuel faster attack cycles, strain patching processes, and escalate regulatory scrutiny around software security and responsible AI use.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports