Validated Containment Architectures are here. →Explore

Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

1839 threat reports
Page 133 of 154

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer Software/Engineering Threat Reports

Showing 15851596 / 1839 reports
WordPress Post SMTP Plugin Exploited in Mass Admin Account Hijacks (2024)
Impact· medium

WordPress Post SMTP Plugin Exploited in Mass Admin Account Hijacks (2024)

In early June 2024, cybersecurity researchers identified that a critical vulnerability in the Post SMTP WordPress plugin was being actively exploited by threat actors. This vulnerability allowed attackers to hijack administrator accounts across more than 400,000 affected WordPress sites, enabling complete site control and potentially permitting installation of malicious payloads. Attackers gained initial access through the plugin's weak nonce verification, escalating privileges to compromise sites, deploy backdoors, and exfiltrate sensitive data. The incident demonstrates how widespread web application vulnerabilities can be rapidly weaponized, putting enterprises and small businesses alike at risk of data loss, defacement, or further compromise. The Post SMTP exploitation highlights a recent surge in attacks leveraging zero-day or unpatched CMS plugins on large scales, reflecting attackers’ growing focus on supply chain and SaaS-adjacent targets. As organizations increasingly depend on third-party tools and platforms, maintaining rapid patch cycles and comprehensive visibility into software components is more critical than ever.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Akira Ransomware’s Disputed Data Breach: What Happened at Apache OpenOffice (2024)
Impact· high

Akira Ransomware’s Disputed Data Breach: What Happened at Apache OpenOffice (2024)

In June 2024, the Akira ransomware group publicly claimed responsibility for a data breach affecting Apache OpenOffice, alleging the theft of 23 GB of sensitive corporate documents. Despite these assertions, the Apache Software Foundation conducted an internal investigation and officially disputed any evidence of compromise or unauthorized access, stating there were no indications of a breach in their infrastructure. This incident highlights the ongoing challenge organizations face with threat actor claims that may not always be substantiated but can cause reputational risk and user concern. Similar ransomware campaigns have surged in 2024, with groups leveraging public exposure even without confirming access to target data. The situation underscores the importance of proactive communication, transparent incident response, and technical validation as attackers increasingly use psychological pressure tactics in addition to technical intrusions.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
How Microsoft Uncovered the SesameOp OpenAI API Backdoor: 2025 Case Study
Impact· low

How Microsoft Uncovered the SesameOp OpenAI API Backdoor: 2025 Case Study

In November 2025, Microsoft’s security team identified a sophisticated backdoor campaign dubbed 'SesameOp,' wherein attackers leveraged the OpenAI Assistants API as a stealthy command-and-control (C2) channel. This unconventional tactic enabled the threat actors to instruct compromised systems via encrypted and authenticated OpenAI API communications, bypassing traditional security controls and network monitoring systems. The initial access vector is under investigation, but early signs point to phishing emails weaponized with malicious loader scripts. The use of a reputable third-party AI API provided attackers with enhanced persistence and made network traffic analysis difficult, delaying detection and remediation. This incident marks a significant escalation in attacker techniques exploiting trusted generative AI platforms for C2, illustrating the growing weaponization of legitimate SaaS services. Organizations must urgently reassess how they detect, monitor, and govern API traffic, particularly for large AI-driven platforms now woven deeply into business infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Google’s ‘Big Sleep’ AI Uncovers 5 Critical Safari WebKit Vulnerabilities
Impact· medium

Google’s ‘Big Sleep’ AI Uncovers 5 Critical Safari WebKit Vulnerabilities

In October 2025, Apple publicly credited Google's AI-powered cybersecurity agent, 'Big Sleep', for identifying five critical vulnerabilities within the WebKit component of its Safari browser. These vulnerabilities, notably including CVE-2025-43429, could be exploited by attackers to trigger browser crashes or initiate memory corruption, potentially resulting in code execution or unauthorized system compromise. Google’s advanced AI techniques allowed rapid discovery and responsible disclosure, prompting Apple to issue urgent patches for all affected systems. This incident underscores a new trend where AI-driven security research exposes latent vulnerabilities faster than ever. It is increasingly relevant as cyber threats grow more sophisticated and organizations face regulatory pressure to promptly remediate critical flaws, especially in client-facing software like browsers.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical 2025 React Native CLI Flaw Exposes Millions to Supply-Chain Attacks
Impact· medium

Critical 2025 React Native CLI Flaw Exposes Millions to Supply-Chain Attacks

In November 2025, a critical vulnerability was disclosed in the widely used "@react-native-community/cli" npm package, exposing millions of developers and organizations that rely on React Native for application development. The flaw allowed remote, unauthenticated attackers to execute arbitrary operating system commands on systems running vulnerable versions of the CLI tool. The threat stemmed from insufficient input validation, enabling exploitation via malicious npm modules or manipulated code, creating a high-risk supply-chain attack vector. The vulnerability was swiftly patched, but it highlighted significant supply-chain security gaps across the software development ecosystem. This incident is notable for reinforcing the urgent need to secure development toolchains and underscores the increasing frequency of attacks targeting open-source software dependencies. As attackers continue to exploit weak links in the software supply chain, organizations must strengthen controls, monitoring, and vulnerability management to keep pace with evolving risks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Apple Patches 110 Vulnerabilities in Massive 2024 Security Update
Impact· medium

Apple Patches 110 Vulnerabilities in Massive 2024 Security Update

In early November 2024, Apple released urgently needed security updates for its operating systems, patching 110 vulnerabilities across iOS, macOS, iPadOS, watchOS, tvOS, visionOS, Safari, and Xcode. Key vulnerabilities included memory corruption flaws in ImageIO and WebKit, with previous instances of such bugs leading to remote code execution. Several vulnerabilities could allow unauthorized access to sensitive user data or privilege escalation, and most major Apple product families were impacted. No active exploitation was reported, but these vulnerabilities posed significant risks, especially if exploited in the wild. This incident underscores the importance of timely patching for organizations leveraging Apple hardware, amid escalating regulatory expectations and sophisticated exploit development targeting zero-day vulnerabilities. With Apple devices often pivotal in hybrid and remote work environments, large-scale multi-platform vulnerabilities present an attack surface of interest to both cybercriminals and nation-state actors.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Lazarus Breaches UAV Sector: 2024 Cyberespionage Attack Analysis
Impact· low

Lazarus Breaches UAV Sector: 2024 Cyberespionage Attack Analysis

In early 2024, ESET researchers uncovered a targeted cyberespionage campaign orchestrated by the North Korea-aligned Lazarus Group against a prominent company in the Unmanned Aerial Vehicle (UAV) sector. The attackers leveraged the Operation DreamJob social engineering scheme, luring victims with fake job offers and delivering custom malware through malicious attachments. Once inside, Lazarus gained remote access, exfiltrated sensitive data, and attempted to move laterally across the compromised network, emphasizing the group's advanced targeting of critical aerospace technologies. This incursion exposed operational blueprints, intellectual property, and potentially sensitive communications, raising industry-wide alarm about advanced persistent threats targeting high-value sectors. This incident is especially relevant today due to increased targeting of defense and aerospace industries by state-sponsored actors using sophisticated social engineering paired with malware. The techniques seen in Operation DreamJob reflect a broader trend of highly-customized attacks utilizing credible lures and persistent denial detection tactics.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(low)
Read Report
How OAuth Device Code Phishing Targets Azure and Google: What CISOs Need to Know in 2024
Impact· low

How OAuth Device Code Phishing Targets Azure and Google: What CISOs Need to Know in 2024

In 2024, new phishing campaigns emerged that weaponize the OAuth Device Code flow against major cloud platforms, notably Azure and Google. Attackers send users to authentic device code portals, tricking them into entering codes controlled by adversaries. Once codes are entered, threat actors receive valid OAuth tokens granting extensive access to cloud services, often bypassing multi-factor authentication. Researchers noted that Azure’s device flow presented a larger attack surface than Google’s, making it a high-value target for phishing and account compromise. The result is unauthorized access to sensitive email, data, and other cloud resources, with potential for lateral movement and persistent compromise. This breach showcases a rapidly escalating attack vector exploiting weaknesses in cloud identity flows. The rise in device code phishing reflects a broader shift by threat actors toward abusing legitimate authentication processes, especially as organizations depend more heavily on cloud services and OAuth-based SSO.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Microsoft 2024: SesameOp Backdoor Hides in OpenAI Assistants API Traffic
Impact· low

Microsoft 2024: SesameOp Backdoor Hides in OpenAI Assistants API Traffic

In early 2024, Microsoft researchers identified a sophisticated cyberattack campaign leveraging the new SesameOp backdoor malware. This threat exploits the OpenAI Assistants API as a covert command-and-control (C2) channel, enabling attackers to execute commands, exfiltrate data, and maintain persistence within compromised environments while masquerading as legitimate AI-driven traffic. The campaign targets organizations by bypassing traditional detection methods, using this unique abuse of generative AI services to hide communications and evade security controls. The operational impact is significant, posing increased risk for data loss, lateral movement, and regulatory exposure due to the highly obfuscated methodology. This incident underscores a rapid evolution in attacker tradecraft, with adversaries now weaponizing mainstream AI APIs for malicious infrastructure. As organizations accelerate adoption of AI technologies, this event highlights the urgency to address emerging risks of shadow AI and sophisticated backdoors, making robust east-west traffic inspection and AI-risk governance more important than ever.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Fake Solidity VSCode Extension Backdoors Developers in 2024 Supply Chain Attack
Impact· medium

Fake Solidity VSCode Extension Backdoors Developers in 2024 Supply Chain Attack

In early 2024, a malicious Visual Studio Code extension impersonating the popular Solidity plugin was discovered on the Open VSX Registry, a prominent open-source extension marketplace. The extension secretly installed the SleepyDuck remote access trojan. Threat actors leveraged an Ethereum smart contract to covertly communicate with infected developer environments, establishing a covert command and control channel. Dozens of unsuspecting developers who installed the fake extension were exposed to potential source code theft, workspace compromise, and broader supply chain risk for any software subsequently produced on affected systems. This incident highlights the escalating threat posed by supply chain attacks via open-source repositories and package registries, particularly those targeting development toolchains. Increasingly, attackers are exploiting trust in popular extensions, emphasizing the urgent need for organizations to bolster code integrity controls and enforce zero trust principles for their build environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SleepyDuck Supply Chain Attack: Malicious VSX Extension Exposes Developers via Ethereum C2
Impact· low

SleepyDuck Supply Chain Attack: Malicious VSX Extension Exposes Developers via Ethereum C2

In late October and early November 2025, cybersecurity researchers uncovered a malicious Visual Studio Code extension, 'juan-bianco.solidity-vlang', uploaded to the Open VSX registry. Originally benign, the extension was updated within days to include a remote access trojan called SleepyDuck, which leveraged Ethereum smart contracts to dynamically maintain connectivity with its command-and-control (C2) servers. By exploiting the trust inherent in open-source software supply chains and masquerading as a development tool, attackers enabled remote access and possible data exfiltration from developer environments, posing significant risks to organizations reliant on open-source packages. This breach highlights the persistent threat of supply chain attacks targeting developer tools and marketplaces, a rapidly growing vector as attackers seek to compromise software upstream. It also demonstrates the adoption of blockchain infrastructure for resilient, hard-to-takedown C2 mechanisms, forcing defenders to adapt to increasingly complex threat ecosystems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Remote Code Execution in XWiki: CVE-2025-24893 Exploits Hit Enterprise Wikis
Impact· low

Remote Code Execution in XWiki: CVE-2025-24893 Exploits Hit Enterprise Wikis

In November 2025, attackers began exploiting a critical remote code execution vulnerability (CVE-2025-24893) in the XWiki SolrSearch component, allowing even low-privileged users to trigger system-level commands via manipulated web requests. Although XWiki released a patch and advisory in February, broad exploitation did not emerge until the vulnerability was highlighted in the U.S. Known Exploited Vulnerabilities catalog in late October and weaponized using publicly available PoC code. The exploit chain involved attackers executing shell scripts fetched from an external server, potentially leading to data theft, malware deployment, or full system compromise in exposed enterprise wikis. This incident demonstrates the persistent risk posed by publicly disclosed vulnerabilities with lagging patch adoption; even niche, enterprise-focused applications can become attractive targets once exploitation is automated and high-profile. Organizations face mounting regulatory and business pressure to identify, patch, and harden externally exposed systems—especially as attackers increasingly weaponize proof-of-concept code for opportunistic campaigns.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports