Validated Containment Architectures are here. →Explore

Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

1838 threat reports
Page 126 of 154

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer Software/Engineering Threat Reports

Showing 15011512 / 1838 reports
Fortinet & Chrome 2025: Anatomy of a Multi-Vector SaaS and 0-Day Breach
Impact· medium

Fortinet & Chrome 2025: Anatomy of a Multi-Vector SaaS and 0-Day Breach

In November 2025, a coordinated wave of cyberattacks exploited zero-day vulnerabilities targeting Fortinet security appliances and Google Chrome, while also abusing software supply chains and SaaS platforms. Attackers employed advanced techniques including lateral movement within trusted environments, the deployment of custom malware like BadIIS, and supply-chain infiltration, allowing them to bypass perimeter defenses and remain undetected across enterprise networks. Major cloud and SaaS providers such as Microsoft, Salesforce, and Google rapidly initiated emergency incident response, mitigating exploit attempts, DDoS attacks, and malicious update channels affecting a wide range of organizations. This incident marks a sharp escalation in multi-vector threats—combining zero-day exploitation, supply-chain compromise, and SaaS risk. The campaign aligns with the latest tactics of threat actors leveraging trusted software channels and abusing cloud-native tools, underscoring rising regulatory scrutiny and the urgent need for robust zero trust security measures across multi-cloud and SaaS environments.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fluent Bit 2025: Supply Chain Vulnerabilities Endanger Cloud Infrastructures
Impact· medium

Fluent Bit 2025: Supply Chain Vulnerabilities Endanger Cloud Infrastructures

In October 2025, researchers unveiled a set of five critical vulnerabilities in Fluent Bit, a widely-adopted open-source cloud telemetry agent. These vulnerabilities allowed threat actors to bypass authentication and carry out path traversal attacks, achieving remote code execution and potential full infrastructure compromise. Exploiting these flaws, attackers could gain lateral movement inside cloud environments, disrupt operations via denial-of-service, and manipulate data tags, threatening confidentiality and availability across cloud deployments. The compromise highlights significant risks inherent in modern cloud supply chains, as compromised upstream dependencies can quickly propagate and affect numerous downstream organizations. This incident is particularly significant as supply-chain vulnerabilities targeting cloud-native tools are rising sharply, mirroring an industry-wide shift toward “living off the land” attacks. As organizations adopt more open-source agents and components, attackers increasingly exploit integration points, elevating the risk profile for even mature cloud infrastructures.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Sha1-Hulud Strikes npm: Credential Theft Campaign Hits Over 25,000 Open-Source Repositories
Impact· medium

Sha1-Hulud Strikes npm: Credential Theft Campaign Hits Over 25,000 Open-Source Repositories

In November 2025, security researchers uncovered a widespread supply chain attack dubbed the "Sha1-Hulud" wave targeting the npm registry. Threat actors compromised over 25,000 repositories by trojanizing hundreds of widely used npm packages, injecting malicious code into the preinstall scripts. This code siphoned developer credentials and environmental secrets during package installations, potentially giving attackers unauthorized access to private projects and infrastructure. The campaign relied on malicious npm uploads, affecting downstream open-source users and organizations across the software supply chain. This incident highlights the persistent risk of supply chain attacks via popular package ecosystems, underscoring the need for robust code vetting, audit logging, and least privilege principles. With growing reliance on open-source software, attackers continue to exploit trusted platforms to achieve broad compromise.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Rondo Botnet Exploits Pentaho URL Mapping Flaws: Lessons from the 2022 Breach
Impact· low

Rondo Botnet Exploits Pentaho URL Mapping Flaws: Lessons from the 2022 Breach

In late 2022, the Hitachi Vantara Pentaho Business Analytics Server was targeted by attackers exploiting CVE-2022-43939 and CVE-2022-43769, leveraging flaws in URL mapping and URL-based access control. Threat actors, including the 'Rondo' botnet group, exploited a template injection vulnerability that allowed unauthenticated command execution by bypassing authentication controls via specific URL paths. This enabled attackers to remotely execute arbitrary code, potentially gaining control over affected systems, exfiltrate data, and laterally move within enterprise networks. The automation and scale of these attacks highlighted application misconfigurations, lapses in secure access control design, and the ongoing risk of vulnerable web application endpoints. This incident underscores a broader trend of threat actors exploiting subtle misconfigurations in URL handling and web server rules. Organizations are now under increased regulatory and operational pressure to audit legacy web applications and APIs, implement zero trust segmentation, and rigorously validate access control rules as attackers aggressively pursue these weaknesses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Salesloft Drift SaaS Breach: How Excessive Trust Unlocked CRM Data
Impact· medium

Salesloft Drift SaaS Breach: How Excessive Trust Unlocked CRM Data

In early 2024, the Salesloft Drift SaaS integration breach unfolded when attackers exploited security weaknesses in the Drift chatbot’s OAuth implementation. Malicious actors obtained chatbot OAuth tokens—intended for secure system integrations—and leveraged these for legitimate API calls against customer CRM environments, such as Salesforce. Because the tokens remained valid and were often granted excessive standing privileges, attackers could exfiltrate sensitive business records, contact information, support data, and even embedded credentials across over 700 organizations, all without immediate detection. This breach underscored a powerful new threat vector involving identity and permissions sprawl in SaaS and AI-driven environments. As organizations increasingly rely on deeply integrated third-party systems with broad and persistent access, similar attacks targeting privileged automation and identity-based authorizations are expected to surge without robust governance and continuous monitoring.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Salesforce Data Breached Again: ShinyHunters Exploit Third-Party Gainsight in 2024 Attack
Impact· high

Salesforce Data Breached Again: ShinyHunters Exploit Third-Party Gainsight in 2024 Attack

In June 2024, several Salesforce customers experienced a significant data breach perpetrated by the ShinyHunters extortion group. Attackers exploited vulnerabilities in a third-party vendor, Gainsight, which had integrations with Salesforce platforms. By compromising Gainsight, ShinyHunters acquired credentials or access tokens, enabling them to exfiltrate sensitive Salesforce customer data from multiple organizations. The breach demonstrates the persistent risk of attacks originating from trusted third-party software supply chains, resulting in the exposure of business and customer information and raising concerns about the security posture of major SaaS ecosystems. This breach highlights a continued trend in which attackers bypass direct controls by targeting vendors in a SaaS environment, leveraging weak third-party access and inadequate segmentation. As businesses increase SaaS adoption and interconnectivity, these attacks demonstrate the urgent need for enhanced third-party risk management and more granular network and identity controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
APT31 Orchestrates Stealthy Cloud-Based Attack on Russian IT Firms (2024–2025)
Impact· medium

APT31 Orchestrates Stealthy Cloud-Based Attack on Russian IT Firms (2024–2025)

Between 2024 and 2025, the advanced persistent threat group APT31, linked to China, conducted a series of covert cyberattacks against Russia’s IT sector, specifically targeting firms involved in government contracting. Leveraging cloud services and encrypted traffic, the attackers infiltrated networks while remaining undetected for long periods. APT31 employed sophisticated lateral movement, abuse of multicloud visibility gaps, and zero trust segmentation bypasses, resulting in the exfiltration of sensitive data and potential compromise of government-integrator communication flows. This incident reflects growing tensions and evolving threat tactics in state-sponsored cyberespionage, where cloud infrastructure, stealthy east-west movements, and advanced evasion are exploited. The attack underscores the critical need for enforced segmentation, robust cloud-native security, and proactive anomaly detection to defend against advanced persistent threats targeting the IT supply chain.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
LINE Messaging Bugs Expose Millions to Asian Cyber Espionage in 2024
Impact· high

LINE Messaging Bugs Expose Millions to Asian Cyber Espionage in 2024

In June 2024, security researchers disclosed several critical vulnerabilities in the LINE messaging app, widely used across Asia, arising from its use of a proprietary and flawed cryptographic protocol. The bugs enable attackers to intercept and replay message traffic, impersonate users, and siphon sensitive chat data, despite the app's claims of end-to-end encryption. No specific threat actor has been confirmed, but the flaws create opportunities for state-sponsored espionage and criminal data compromise. The weaknesses persist in both in-app and network-level communication, putting millions of users’ private conversations at risk. This incident highlights the dangers of custom security implementations and is of urgent concern given LINE’s importance in business and personal use across Asia. With attackers increasingly targeting messaging platforms and governments ramping up regulatory scrutiny around privacy and secure communications, organizations must prioritize rigorous security architecture and compliance.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
SolarWinds 2020: Unpacking the Supply Chain Breach and SEC Fallout
Impact· low

SolarWinds 2020: Unpacking the Supply Chain Breach and SEC Fallout

In late 2020, SolarWinds experienced a massive supply chain attack when advanced threat actors compromised the company's Orion software update mechanism. Attackers, attributed to Russia’s APT29 (Cozy Bear), injected malicious code into official software updates, giving them covert backdoor access to the systems of approximately 18,000 SolarWinds customers, including U.S. government agencies and Fortune 500 firms. The attack vectors enabled months of undetected lateral movement, extensive data exfiltration, and widespread compromise of critical infrastructure and networks. The breach also triggered broad regulatory and legal scrutiny, including an SEC lawsuit alleging inadequate disclosures and misrepresentation of cybersecurity practices by SolarWinds and top executives. The SolarWinds attack remains highly relevant as it catalyzed global focus on supply chain security, regulatory enforcement, and the rise of sophisticated software supply chain threats. Its legacy informs today’s cyber hygiene mandates and the zero trust adoption trending across both public and private sectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Salesforce Supply Chain Breach Exposes SaaS OAuth Risks in 2025
Impact· low

Salesforce Supply Chain Breach Exposes SaaS OAuth Risks in 2025

In November 2025, Salesforce detected unauthorized activity involving Gainsight-published applications integrated via OAuth tokens with the Salesforce platform. The breach potentially enabled attackers to access sensitive customer data by compromising OAuth connections between select third-party Gainsight apps and Salesforce tenant environments. Upon discovery, Salesforce revoked all active access and refresh tokens for affected integrations, initiated incident response protocols, and notified impacted customers. The unauthorized access appears limited to data accessible via the compromised tokens, but the full scope is still under investigation. This incident is significant as it demonstrates the inherent risks of third-party SaaS integrations and OAuth-based supply chain connections. As organizations increasingly leverage cloud-based ecosystems, attackers are targeting indirect trust relationships, exposing data via the weakest link. Enterprises face mounting regulatory, contractual, and operational risks from such supply chain attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(low)
Read Report
PlushDaemon Leverages Router Update Supply Chain in 2024 Chinese APT Attack
Impact· low

PlushDaemon Leverages Router Update Supply Chain in 2024 Chinese APT Attack

In 2024, a sophisticated Chinese state-sponsored group, tracked as PlushDaemon, exploited a unique supply chain tactic by compromising router firmware to hijack software update processes. These attackers covertly inserted malicious code into router updates, allowing them to intercept and manipulate network communications and deploy persistent malware within organizational networks—most notably targeting Chinese entities. Their approach leveraged trusted update channels, evading traditional detection methods and enabling infiltration with minimal immediate disruption, causing operational risk and potential data exposure on a wide scale. This technique underscores a growing trend of software supply chain attacks, where trusted network or infrastructure elements become the entry point for espionage or cyber sabotage. Organizations face mounting pressure to secure update mechanisms as attackers increasingly target foundational controls rather than endpoint devices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Phishing Attack Uses CSS Stuffing on Firebase to Evade Detection in 2024
Impact· low

Phishing Attack Uses CSS Stuffing on Firebase to Evade Detection in 2024

In November 2024, a phishing campaign leveraged Google Firebase Storage to host a credential-harvesting site that appeared as a convincing login overlay targeting recipients of a personalized email link. The HTML file was intentionally bloated—containing only a small amount of functional code alongside hundreds of kilobytes of unused or benign-looking CSS, including modified Bootstrap styles. This technique, referred to as "CSS stuffing," was likely used to manipulate heuristic or ML-based security scanners by altering the statistical fingerprint of the malicious file. Although most security scanners employ size thresholds well above the file size, the approach reflects increasing sophistication in phishing obfuscation tactics. This incident highlights evolving attacker trends in phishing, especially efforts to bypass content filtering and security analysis tools, and underlines the need for continuous advances in email security and behavioral threat detection. Organizations must remain vigilant against obfuscated phishing threats that exploit widely trusted cloud services.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports