Validated Containment Architectures are here. →Explore

Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

1839 threat reports
Page 137 of 154

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer Software/Engineering Threat Reports

Showing 16331644 / 1839 reports
North Korean APTs Breach UAV Defense Firms Using Fake Job Offers (2025)
Impact· medium

North Korean APTs Breach UAV Defense Firms Using Fake Job Offers (2025)

In October 2025, multiple European defense contractors specializing in unmanned aerial vehicles (UAVs) were targeted by a sophisticated cyber-espionage campaign attributed to North Korean threat actors, commonly known as Lazarus Group. The attackers masqueraded as recruiters and leveraged convincing fake job offers to defense engineers using social networks and spear-phishing emails, ultimately delivering malicious payloads that provided remote access to corporate networks. The primary objective was to exfiltrate proprietary drone technology and sensitive internal communications, resulting in significant intellectual property theft and exposure of confidential project details. This incident illustrates a persistent trend where state-sponsored actors target the defense sector’s engineers with social engineering tactics, reflecting a broader escalation in advanced persistent threat (APT) campaigns leveraging human-centric attack vectors. Organizations face mounting regulatory scrutiny and must enhance security controls to combat these evolving social-engineering-enabled threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
It Only Takes 250 Documents to Poison Any Large Language Model – Security Implications for 2024
Impact· high

It Only Takes 250 Documents to Poison Any Large Language Model – Security Implications for 2024

In 2024, cybersecurity researchers demonstrated that the integrity of large language models (LLMs) can be severely compromised with as few as 250 poisoned documents strategically inserted into their training data. By covertly introducing manipulated or malicious content into public data sources, attackers can alter a model’s understanding, bias its outputs, or degrade its reliability. This proof-of-concept highlights that ‘data poisoning’ attacks require minimal input yet pose substantial risk for AI reliability, potentially opening the door for misinformation, backdoors, or loss of operational trust across industries leveraging AI. Organizations relying on LLMs for critical tasks face a heightened threat of silent, hard-to-detect breaches affecting their core AI deployments. The urgency around AI/ML supply chain security has intensified, as threat actors and researchers increasingly explore the feasibility of data poisoning. Regulatory frameworks and industry best practices now emphasize the need for data provenance controls and continuous integrity monitoring of training pipelines.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
TARmageddon: Rust async-tar Supply Chain Flaw Leads to Critical RCE Risk
Impact· low

TARmageddon: Rust async-tar Supply Chain Flaw Leads to Critical RCE Risk

In June 2024, security researchers disclosed a critical vulnerability known as 'TARmageddon' in the abandoned Rust async-tar library and its forks. Attackers can exploit the flaw to achieve remote code execution (RCE) on systems using unpatched versions of the library, commonly found in developer tools and backend infrastructure. As async-tar remains unmaintained, organizations relying on affected forks or software inherit the vulnerability, potentially allowing initial compromise and lateral movement within supply chains. The flaw highlights the cascading risks of dependencies on abandoned open-source components, increasing the likelihood of stealthy supply-chain attacks bypassing traditional controls. This incident underscores a growing trend of adversaries targeting open-source software supply chains, particularly by exploiting abandoned or under-maintained libraries. The complexity and opacity of modern dependency trees, alongside escalations in software bill of materials (SBOM) scrutiny, make proactive vulnerability management and real-time supply-chain threat detection essential for reducing risk.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Pwn2Own Ireland 2025: 56 Zero-Day Vulnerabilities Exposed in One Day
Impact· medium

Pwn2Own Ireland 2025: 56 Zero-Day Vulnerabilities Exposed in One Day

In May 2025, security researchers at the Pwn2Own Ireland contest successfully exploited 56 previously unknown zero-day vulnerabilities across a broad range of consumer and enterprise devices—including the latest Samsung Galaxy S25 smartphone—over the course of a single day, earning nearly $793,000 in rewards. Participants used advanced exploitation chains targeting device software, firmware, and novel attack surfaces to gain remote code execution and bypass layered security controls. The demonstration of these critical flaws underlined the sophistication of contemporary offensive security techniques and the persistent risk posed by undiscovered vulnerabilities in modern technology stacks. Vendors were immediately notified, but the affected products are widely used globally. This incident exemplifies the accelerating pace and scale at which new vulnerabilities are uncovered, often by highly skilled researchers using techniques similar to those seen in active threat landscapes. Organizations are facing increased regulatory pressure to address zero-day risks and are urged to respond rapidly to vendor advisories and emerging disclosures.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
TARmageddon: Remote Code Execution Risk in Popular Async-Tar Rust Library Uncovered (2025)
Impact· low

TARmageddon: Remote Code Execution Risk in Popular Async-Tar Rust Library Uncovered (2025)

In late August 2025, researchers uncovered TARmageddon (CVE-2025-62518), a high-severity supply-chain vulnerability in the async-tar Rust library and its forks, including tokio-tar. This flaw could permit remote code execution (RCE) when processing maliciously-crafted tar archives, posing a significant risk to downstream applications and platforms relying on these libraries for file extraction and archive handling. Successful exploitation opens the door to system compromise, data loss, or service interruption for potentially thousands of applications leveraging async-tar in production workloads. This incident highlights the growing threat of software supply-chain vulnerabilities, especially within open-source dependencies widely adopted across cloud-native and DevSecOps environments. Organizations must closely monitor dependencies, establish strong vulnerability management pipelines, and rapidly respond to disclosures as attackers increasingly target the software supply chain.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Fake Nethereum NuGet Package Exploited Homoglyph Trick in 2025 Supply Chain Attack
Impact· medium

Fake Nethereum NuGet Package Exploited Homoglyph Trick in 2025 Supply Chain Attack

In October 2025, cybersecurity experts identified a sophisticated supply chain attack wherein a malicious NuGet package, imitating the popular Nethereum library using a homoglyph trick, was uploaded to compromise .NET developers. The attacker distributed a typosquatted package ('Netherеum.All') containing encoded command-and-control (C2) communication that secretly harvested and exfiltrated sensitive cryptocurrency wallet credentials—including private keys and mnemonic phrases—from unsuspecting developers’ systems. The campaign demonstrates a heightened level of precision in leveraging open-source repositories for credential theft, with potential widespread financial impacts for organizations developing blockchain solutions. This incident exemplifies the rapidly increasing risk posed by supply chain attacks exploiting trusted software ecosystems. It highlights both a surge in homoglyph-based typosquatting and a broader trend of targeting cryptocurrency assets via development toolchains—emphasizing the need for robust code provenance controls and package vetting.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
How a Vulnerable AI Plugin in Figma MCP Opened the Door for Remote Code Attacks
Impact· low

How a Vulnerable AI Plugin in Figma MCP Opened the Door for Remote Code Attacks

In early 2025, a critical vulnerability (CVE-2025-53967) was discovered in a third-party connector integrating agentic AI capabilities with Figma’s Multi-Cloud Platform (MCP) server. This supply-chain flaw enabled remote code execution (RCE), allowing attackers to exploit the connection to infiltrate organizational environments using the affected plugin. Threat actors leveraged the unsanctioned plugin to gain unauthorized access to internal systems, potentially exposing sensitive design data, intellectual property, and user information. The compromise highlighted risks associated with insufficient east-west security controls, lack of zero trust segmentation, and inadequate traffic visibility, ultimately impacting business continuity and trust in the collaboration platform. This incident exemplifies the growing threat of supply-chain vulnerabilities targeting enterprise SaaS applications, amid increasing adoption of AI integrations. Organizations are re-evaluating their third-party risk, agentic AI governance, and internal segmentation postures as regulatory scrutiny and attacker sophistication intensify.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Red Hat Consulting Breach 2024: Crimson Collective Launches Major Supply Chain Attack
Impact· medium

Red Hat Consulting Breach 2024: Crimson Collective Launches Major Supply Chain Attack

In April 2024, the Crimson Collective, in collaboration with elements of the Lapsus$ group, executed a supply chain attack targeting Red Hat Consulting by breaching its GitLab instance. The attackers gained unauthorized access through credential compromise and lateral movement across internal infrastructure, successfully exfiltrating sensitive source code and internal communications. The breach, which remained undetected for several days, raised concerns over east-west traffic security, lack of segmentation, and insufficient anomaly detection within Red Hat Consulting’s cloud development supply chain. This incident highlights the increasing prevalence of supply chain attacks leveraging lateral movement and sophisticated alliance between threat groups. Its relevance is underscored by renewed regulatory scrutiny, the growing risk posed by collaborative cybercriminal operations, and heightened demand for zero trust architecture and cloud-native threat mitigation strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
GitHub Copilot CamoLeak: AI Attack Demonstrates Exfiltration Risk in 2024
Impact· medium

GitHub Copilot CamoLeak: AI Attack Demonstrates Exfiltration Risk in 2024

In early 2024, cybersecurity researchers disclosed a proof-of-concept (PoC) called 'CamoLeak' demonstrating a novel attack vector exploiting GitHub Copilot’s AI code completion capability for data exfiltration. The PoC showed how sensitive code snippets and secrets could be extracted from Copilot instances by crafting malicious prompts that trick the AI into leaking previously seen proprietary content. While GitHub employs robust internal mitigations, the research exposes significant risks for organizations integrating generative AI tools into development workflows, particularly where prompt and response data may be inadequately secured. This incident underscores the rapid evolution of attack techniques targeting GenAI platforms and highlights emergent threats of data leakage through AI-driven automation. As enterprises increasingly leverage AI coding assistants, understanding and mitigating AI-enabled exfiltration vectors is key to upholding governance, compliance, and intellectual property security.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Feds Dismantle ShinyHunters' Salesforce Extortion Hub: Lessons for Cloud Security
Impact· high

Feds Dismantle ShinyHunters' Salesforce Extortion Hub: Lessons for Cloud Security

In June 2024, U.S. federal authorities dismantled an extortion portal run by the notorious ShinyHunters group, which was used to threaten Salesforce victims after a reported compromise. ShinyHunters is known for data theft and double-extortion tactics, leveraging public leaks and ransom demands to extort organizations. Despite law enforcement takedown efforts, the group's threats remain active, targeting businesses that rely on Salesforce for their customer and operational data. The attack highlights risks surrounding third-party SaaS platforms and sophisticated cybercriminal techniques that exploit sensitive, cloud-based systems for extortion. This event underscores the accelerating landscape of data extortion and the persistent threat from established ransomware and data-leak actors. As organizations increasingly depend on SaaS providers, regulators and enterprises are intensifying focus on zero trust access, east-west traffic security, and layered controls to contain lateral movement and prevent sensitive data exposure.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Harvard University Breached by Clop Ransomware: Oracle Zero-Day Attack Exposes Data
Impact· high

Harvard University Breached by Clop Ransomware: Oracle Zero-Day Attack Exposes Data

In the first half of 2024, Harvard University fell victim to a significant cyberattack orchestrated by the Clop ransomware group, exploiting a zero-day vulnerability in Oracle software. The threat actors gained unauthorized access to sensitive university data, exfiltrating large volumes as part of a broader campaign that targeted Oracle customers worldwide. The breach showcases how sophisticated ransomware groups leverage software supply chain weaknesses, often exploiting vulnerabilities before patches become available. As a result, Harvard faced disruption of operations, regulatory scrutiny, and potential exposure of sensitive academic and financial data. This incident underscores the escalating trend of ransomware operations exploiting zero-day flaws to target major institutions, particularly in the education sector. The attack highlights urgent needs for advanced segmentation, rapid patching, and proactive lateral movement prevention as ransomware groups become more aggressive and opportunistic.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Microsoft VS Code Marketplace Plugins Leak Sensitive Secrets: Supply Chain Alert
Impact· medium

Microsoft VS Code Marketplace Plugins Leak Sensitive Secrets: Supply Chain Alert

In early 2024, security researchers uncovered over 550 unique authentication secrets (such as API keys and credentials) leaking from extensions published on Microsoft's Visual Studio Code Marketplace. The exposed secrets, embedded within third-party extensions, created a major supply chain risk by potentially allowing attackers to compromise developer environments or escalate access to sensitive systems. Microsoft responded by enhancing its security review process, warning affected publishers, and initiating additional controls to prevent similar exposures in the future. This incident highlights the growing risks tied to open software ecosystems, where attackers increasingly target supply chain dependencies. With developer tools and plugin marketplaces at the core of modern workflows, secret leakage could enable widespread compromise, pushing organizations to urgently strengthen code supply chain security and compliance.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports