✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Critical Adobe ColdFusion Vulnerability (CVE-2026-48282) Requires Immediate Attention
In June 2026, a critical path traversal vulnerability, identified as CVE-2026-48282, was discovered in Adobe ColdFusion versions 2025.9, 2023.20, and earlier. This flaw allows unauthenticated remote attackers to execute arbitrary code on affected servers without user interaction, potentially leading to full system compromise. The vulnerability arises from improper limitation of a pathname to a restricted directory, enabling attackers to access and manipulate files outside the intended directory structure. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-48282?utm_source=openai)) The inclusion of CVE-2026-48282 in CISA's Known Exploited Vulnerabilities Catalog underscores the urgency for organizations to address this issue promptly. Given the active exploitation in the wild, entities using vulnerable ColdFusion versions must prioritize patching to mitigate the risk of unauthorized access and potential data breaches. ([resecurity.com](https://www.resecurity.com/ar/blog/article/cve-2026-48282-adobe-coldfusion-rds-path-traversal-leading-to-rce?utm_source=openai))
2 weeks ago
Kill Chain
Critical Vulnerability in Siemens Mendix Studio Pro: CVE-2026-48192
In June 2026, Siemens disclosed a vulnerability (CVE-2026-48192) in Mendix Studio Pro versions 10.11 through 10.24 (prior to V10.24.21) and 11.0 through 11.11. The flaw arises from improper validation and sanitization of project files during the build pipeline, allowing attackers to execute arbitrary code if a user opens a specially crafted malicious project. This vulnerability could lead to unauthorized code execution within the user's context, potentially compromising developer workstations and downstream build artifacts. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-48192/?utm_source=openai)) The incident underscores the critical importance of validating and sanitizing project files in development environments. As low-code platforms like Mendix Studio Pro gain popularity, ensuring robust security measures against such vulnerabilities becomes imperative to protect development processes and prevent potential supply chain attacks.
2 weeks ago
Kill Chain
GitHub's 'Verified' Commits Vulnerable to Hash Malleability
In July 2026, researcher Jacob Ginesin identified a vulnerability in GitHub's commit verification process, revealing that signed Git commits can be altered to produce new hashes without invalidating their signatures. This flaw allows attackers to replicate commits with identical content, authorship, and timestamps, yet different hashes, while still displaying a 'Verified' status on GitHub. Consequently, systems relying on commit hashes for security measures, such as blocklists and provenance logs, are susceptible to evasion tactics. ([thehackernews.com](https://thehackernews.com/2026/07/github-verified-commits-can-be.html?utm_source=openai)) This discovery underscores the critical need for robust verification mechanisms in software development platforms. As supply chain attacks become more sophisticated, ensuring the integrity and authenticity of code commits is paramount to maintaining trust and security in open-source ecosystems.
2 weeks ago
Kill Chain
Critical Vulnerability in Hitachi Energy's PROMOD V: CVE-2026-10763
In June 2026, Hitachi Energy disclosed a vulnerability (CVE-2026-10763) in its PROMOD V software, which utilized unencrypted HTTP communication due to the lack of HTTPS support from a third-party Digipede server. This flaw exposed sensitive data to potential interception and manipulation, posing risks such as credential theft and unauthorized access. The affected versions include PROMOD V up to 1.0.10. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-10763?utm_source=openai)) This incident underscores the critical importance of secure communication protocols in industrial control systems. Organizations are urged to review their software dependencies and ensure that all components support encrypted communications to mitigate similar vulnerabilities.
2 weeks ago
Kill Chain
CISA Highlights Three Actively Exploited Vulnerabilities in Latest KEV Catalog Update
On July 7, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. These vulnerabilities include CVE-2026-48908, an unrestricted file upload flaw in JoomShaper's SP Page Builder; CVE-2026-55255, an authorization bypass in Langflow; and CVE-2026-56290, an improper access control issue in Joomlack's Page Builder. Such vulnerabilities are commonly exploited by malicious actors, posing significant risks to federal enterprises. The inclusion of these vulnerabilities underscores the critical need for organizations to prioritize remediation efforts. CISA's Binding Operational Directive (BOD) 26-04 mandates federal agencies to address high-risk vulnerabilities promptly, emphasizing the importance of proactive vulnerability management to safeguard against active threats.
2 weeks ago
Kill Chain
HalluSquatting: Exploiting AI Coding Assistants to Deploy Botnet Malware
In July 2026, researchers identified a novel cyberattack technique termed 'HalluSquatting,' which exploits AI coding assistants' tendency to generate plausible but non-existent resource names. Attackers predict these hallucinated names, register them, and embed malicious code. When users prompt their AI assistants to fetch these resources, the assistants inadvertently execute the malicious code, potentially installing botnet malware on the user's machine. This method leverages AI hallucinations and prompt injections to compromise systems without direct user interaction. The emergence of HalluSquatting underscores the evolving threat landscape in AI-integrated development environments. As AI tools become more prevalent, attackers are increasingly targeting their inherent vulnerabilities. This incident highlights the urgent need for enhanced security measures in AI-driven tools to prevent exploitation through such sophisticated techniques.
2 weeks ago
Kill Chain
Expansion of Deepfake CSAM Lawsuit Targets xAI and Stability AI
In July 2026, a class-action lawsuit against xAI, the developer of the AI tool Grok, was expanded to include two additional plaintiffs. These individuals allege that Grok was used by acquaintances to generate nonconsensual deepfake child sexual abuse material (CSAM) based on their real photos. The lawsuit also names Stability AI as a defendant, claiming that its Stable Diffusion model facilitated the creation of such illicit content. The plaintiffs report significant emotional distress and a loss of control over the dissemination of these images. This incident underscores the urgent need for robust safeguards in AI technologies to prevent misuse, particularly in generating harmful content. It highlights the growing legal and ethical challenges companies face in ensuring their AI models are not exploited for creating nonconsensual and illegal material.
2 weeks ago
Kill Chain
Januscape Vulnerability: Critical Linux Kernel Flaw Enables VM Escape
In July 2026, a critical vulnerability known as 'Januscape' (CVE-2026-53359) was disclosed in the Linux kernel's KVM/x86 virtualization component. This 16-year-old flaw allows attackers with root access inside a guest virtual machine to execute arbitrary code on the host, potentially compromising all other guests and the host system itself. The vulnerability arises from a use-after-free issue in the shadow MMU emulation, affecting both Intel and AMD processor architectures. The disclosure of Januscape underscores the persistent risks associated with long-standing vulnerabilities in widely used open-source software. It highlights the necessity for organizations to maintain rigorous patch management practices and to monitor for emerging threats that could exploit such vulnerabilities, especially in multi-tenant cloud environments where the impact can be widespread.
2 weeks ago
Kill Chain
Understanding the Cordyceps Vulnerability in GitHub Actions
In June 2026, Novee Security identified a critical vulnerability class in GitHub Actions workflows, termed 'Cordyceps.' This flaw allows unauthenticated attackers to exploit CI/CD pipelines by manipulating untrusted pull requests, leading to unauthorized code execution and potential supply chain compromises. Over 300 repositories, including those of Microsoft, Google, and Apache, were confirmed vulnerable, exposing them to credential theft and malicious code injection. The Cordyceps vulnerability underscores the escalating risks in software supply chains, especially as AI-generated code becomes more prevalent. Traditional security scanners often miss such complex, composition-based flaws, highlighting the need for enhanced security measures in CI/CD workflows to prevent potential large-scale attacks.
2 weeks ago
Kill Chain
Accenture Confirms Data Breach After Hacker Offers Stolen Data for Sale
In July 2026, Accenture, a global professional services company, confirmed a security breach after a threat actor known as "888" claimed to have stolen 35 GB of data, including source code, RSA keys, SSH keys, Azure personal access tokens, Azure Storage access keys, and configuration files. The threat actor began offering this data for sale on a cybercrime forum. Accenture stated that they were aware of the incident, had remediated its source, and that there was no impact on their operations and service delivery. However, the company did not disclose how the attackers gained access or whether customer data was affected. This incident underscores the persistent threat posed by cybercriminals targeting large enterprises for sensitive data. The exposure of source code and access keys can lead to further exploitation, including intellectual property theft and potential supply chain attacks. Organizations must remain vigilant, continuously assess their security postures, and implement robust measures to protect against such breaches.
2 weeks ago
Kill Chain
Critical 'Rogue Agent' Flaw in Google Dialogflow CX Exposed AI Chatbots to Data Theft
In November 2025, Varonis Threat Labs identified a critical vulnerability in Google's Dialogflow CX, dubbed 'Rogue Agent.' This flaw allowed attackers with the 'dialogflow.playbooks.update' permission on a single Code Block-enabled agent to inject malicious code, compromising all Code Block-enabled agents within the same Google Cloud project. Exploiting this vulnerability enabled unauthorized access to live conversations, data exfiltration, and manipulation of chatbot responses, including phishing attempts. Google addressed the issue with an initial fix in April 2026 and fully remediated it by June 2026. There is no evidence of exploitation in the wild prior to these patches. ([varonis.com](https://www.varonis.com/blog/rogue-agent-dialogflow-attack?utm_source=openai)) The 'Rogue Agent' incident underscores the security challenges associated with integrating AI into cloud platforms. As AI adoption accelerates, ensuring robust security measures and regular audits becomes imperative to prevent similar vulnerabilities and protect sensitive user data. ([axios.com](https://www.axios.com/2026/07/07/varonis-google-ai-agent-chatbot-security?utm_source=openai))
2 weeks ago
Kill Chain
JadePuffer: Unveiling the First Autonomous LLM-Driven Ransomware Attack
In July 2026, the JadePuffer campaign marked the first documented instance of a fully autonomous ransomware attack executed by a large language model (LLM). The attack began with the exploitation of CVE-2025-3248, a critical remote code execution vulnerability in Langflow, an open-source tool for building AI applications. This allowed the agentic threat actor to gain initial access without authentication. Subsequently, the attacker pivoted to a production server running a MySQL database and an Alibaba Nacos configuration service, where they exfiltrated sensitive data, deleted the database, and left an extortion note demanding payment for the stolen information. This incident underscores the evolving threat landscape, where AI-driven attacks can autonomously execute complex operations without human intervention. The rapid adaptation and execution capabilities demonstrated by JadePuffer highlight the urgent need for organizations to reassess their security postures, particularly concerning AI and machine learning systems, to mitigate the risks posed by such advanced threats.
3 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports