Validated Containment Architectures are here. →Explore

Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

1839 threat reports
Page 144 of 154

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer Software/Engineering Threat Reports

Showing 17171728 / 1839 reports
ShinyHunters Target Salesforce: Social Engineering Breach Exposes SaaS Security Gaps
Impact· low

ShinyHunters Target Salesforce: Social Engineering Breach Exposes SaaS Security Gaps

In early 2024, Google’s Mandiant research team identified a targeted campaign by the ShinyHunters threat group leveraging advanced social engineering techniques against Salesforce environments. The attackers—tracked as UNC6040—used convincing phishing lures and manipulation of Salesforce user credentials to gain unauthorized access to sensitive corporate data. By circumventing authentication measures and exploiting insufficient internal network segmentation and monitoring, ShinyHunters exfiltrated confidential business records, customer data, and intellectual property. The breach highlighted the group’s evolving tactics and the risks posed to organizations that rely on cloud SaaS platforms like Salesforce for critical operations. This incident underscores the increasing sophistication of social engineering attacks, with criminals exploiting both technical and human vulnerabilities in cloud platforms. As SaaS adoption accelerates, similar threats are expected to rise, placing renewed emphasis on identity security, comprehensive threat detection, and adherence to zero trust principles.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Red Hat's 2024 GitLab Breach: Supply Chain Risks and the Rise of Crimson Collective
Impact· high

Red Hat's 2024 GitLab Breach: Supply Chain Risks and the Rise of Crimson Collective

In September 2024, Red Hat disclosed a breach of its self-managed GitLab instance used by its Consulting services, following claims by the Crimson Collective ransomware group of compromising over 28,000 private repositories. The attackers allegedly exfiltrated software source code and Customer Engagement Reports (CERs), which may contain network details, configuration data, and sensitive credentials. Red Hat initiated remediation steps and assured that its primary software supply chain and core products were not impacted. Belgian authorities warned of potential high-risk exposure for organizations with ties to Red Hat Consulting. This incident underscores a growing trend of supply chain attacks targeting private code repositories and related assets, especially in environments where critical infrastructure and third-party integrations are involved. As ransomware groups pivot to extortion and supply chain vectors, organizations must urgently review their repository and credential management, even on self-managed systems.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Allianz Life Data Breach 2025: Cloud CRM Attack Exposes 1.5 Million
Impact· high

Allianz Life Data Breach 2025: Cloud CRM Attack Exposes 1.5 Million

In July 2025, Allianz Life, a major American insurance provider, suffered a significant data breach after threat actors—suspected to be part of the ShinyHunters extortion group—gained unauthorized access to a third-party cloud-based CRM system. The breach exposed sensitive personal information including names, addresses, dates of birth, and Social Security numbers for nearly 1.5 million individuals, encompassing customers, financial professionals, and employees. The incident was publicly disclosed shortly after it occurred, with Allianz confirming that Allianz SE, its global parent company, was not impacted. In response, Allianz initiated notifications to affected parties and regulatory authorities and is offering two years of free identity theft monitoring. This incident highlights the persistent risks posed by supply chain and third-party service vulnerabilities, especially as attackers increasingly target trusted cloud-based platforms such as Salesforce. The breach underscores the necessity for vigilant monitoring, rigorous access controls, and enhanced segmentation within cloud ecosystems for all organizations handling sensitive data.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Motility Software Suffers Major Ransomware Breach Impacting Over 766,000 Clients
Impact· high

Motility Software Suffers Major Ransomware Breach Impacting Over 766,000 Clients

In June 2024, Motility Software Solutions, a prominent provider of dealer management software, suffered a ransomware attack that resulted in the unauthorized access and exposure of sensitive data from approximately 766,000 clients. The attackers infiltrated Motility's networks, deployed ransomware to encrypt critical systems, and exfiltrated customer data, including personal and financial information. The attack caused significant operational disruptions for both Motility and its dealership clients, who rely on the platform for daily business operations. The incident highlights the persistent threat ransomware actors pose to software supply chains serving multiple downstream businesses. This breach is especially noteworthy amid an ongoing rise in ransomware targeting SaaS and vertical market providers, with attackers prioritizing data exfiltration for extortion. Regulators and business partners are increasing their demands for improved security controls and rapid incident disclosure, especially for service providers entrusted with large volumes of sensitive client data.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Wiretap Unveiled: DDR4 Side-Channel Attack Extracts Intel SGX ECDSA Keys in 2025
Impact· medium

Wiretap Unveiled: DDR4 Side-Channel Attack Extracts Intel SGX ECDSA Keys in 2025

In October 2025, cybersecurity researchers from Georgia Institute of Technology and Purdue University disclosed a novel hardware-based attack that compromises Intel SGX enclaves by exploiting the DDR4 memory bus. By physically placing a wiretap interposer on the memory channel, the attackers were able to observe and ultimately extract ECDSA private keys used for remote attestation, undermining the core protection mechanisms of Intel’s SGX. This passive attack method does not require malware on the target, posing risk for highly sensitive operational environments and organizations reliant on enclave-based security. This incident underscores the growing sophistication of hardware side-channel research and the urgent need to assess trust boundaries in server environments. With critical infrastructure and cloud offerings often relying on SGX for confidential computing, organizations must scrutinize physical and hardware-layer exposures amid a surge of advanced hardware attack demonstrations.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Breaking Confidential Computing: 2024 Hardware Attack Reveals Hidden Risks
Impact· medium

Breaking Confidential Computing: 2024 Hardware Attack Reveals Hidden Risks

In early 2024, cybersecurity researchers demonstrated a major hardware vulnerability impacting modern Intel and AMD processors' confidential computing features. Using a low-cost, hardware-based "battering RAM" side-channel attack, the team was able to extract sensitive data from memory that is meant to be encrypted and protected even during active use. The exploit bypasses both software and hardware encryption of data in use, undermining key assumptions of secure enclave technologies widely deployed in cloud and enterprise environments. This proof-of-concept exposes clients to risks of data theft or tampering, especially in multitenant or shared infrastructure. This incident underscores a growing trend of sophisticated hardware exploitation that threatens cloud workloads employing confidential computing for compliance and security. With confidential computing adoption rising across regulated industries, vulnerabilities at the silicon level present urgent business and regulatory risks, especially as attackers adapt to target trusted execution environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Google Gemini AI 2025: Prompt Injection and Cloud Exploit Flaws Revealed
Impact· high

Google Gemini AI 2025: Prompt Injection and Cloud Exploit Flaws Revealed

In September 2025, cybersecurity researchers disclosed three critical, now-patched vulnerabilities in Google’s Gemini AI assistant platform. Attackers were able to exploit prompt injection and log-to-prompt injection flaws within Gemini’s Search Personalization Model and Cloud deployment, risking unauthorized data access, privacy compromise, and potential theft of sensitive information. The exploited vulnerabilities allowed crafted prompts or manipulated logs to execute unintended commands, bypass safeguards, and potentially leak user data, highlighting major security gaps in generative AI-driven workflows before emergency updates were deployed by Google. This incident underscores the growing risk of prompt injection and supply-chain-type threats in the AI/ML ecosystem. The attack reflects a surge in adversarial tactics targeting large language models and cloud-based AI assistants, drawing regulatory attention and prompting security leaders to reassess AI deployment controls in enterprise environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Battering RAM: $50 Hardware Attack Breaks Intel & AMD Cloud Defenses
Impact· medium

Battering RAM: $50 Hardware Attack Breaks Intel & AMD Cloud Defenses

In October 2025, researchers from KU Leuven and the University of Birmingham unveiled a significant vulnerability dubbed "Battering RAM" affecting both Intel and AMD cloud processor architectures. By inserting a $50 hardware interposer into the memory bus, attackers demonstrated the ability to bypass state-of-the-art cloud security mechanisms. This approach allowed them to intercept, manipulate, and extract both encrypted and unencrypted in-memory data flows intended to remain protected by hardware and virtualization-layer defenses. The attack's stealth and low cost highlight the practical risk to multi-tenant and cloud environments relying on trusted chipset-based security. The Battering RAM disclosure comes amid growing concerns around hardware-level threats capable of undermining software-managed frameworks, especially in multi-cloud and highly regulated sectors. This incident underscores the need for enhanced hardware threat modeling, rapid detection capabilities, and updated compliance guidance tailored to physical vector risks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Apple Rushes Security Fix for Critical FontParser Vulnerability (CVE-2025-43400)
Impact· medium

Apple Rushes Security Fix for Critical FontParser Vulnerability (CVE-2025-43400)

In September 2025, Apple released urgent security updates for iOS, iPadOS, macOS, and visionOS to address CVE-2025-43400—a vulnerability in the FontParser component allowing maliciously crafted fonts to trigger app termination or corrupt process memory. This flaw affects recent and some older OS versions, with Apple pushing out rapid patches to prevent potential exploitation. As of release, there is no evidence of active attacks or remote code execution stemming from this bug, but the vulnerability represents a serious risk due to the widespread use of affected products and the low-complexity of font-based exploits. This incident highlights how even routine OS updates can carry vital security fixes against emerging threats. With font parsing bugs being favored by both criminals and spyware operators in recent years, broad and proactive patching remains essential, especially as quick-moving threat actors seek early exploit opportunities.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Malicious MCP Server Abuses AI Email Automation for Covert Secrets Exfiltration
Impact· medium

Malicious MCP Server Abuses AI Email Automation for Covert Secrets Exfiltration

In June 2024, researchers uncovered a supply-chain attack involving a malicious Managed Communication Platform (MCP) AI server deployed by enterprises for automating routine email tasks, such as password resets, account confirmations, and invoicing. Threat actors subverted the platform to silently exfiltrate sensitive information by routing copies of key emails via BCC fields to attacker-controlled addresses. This tactic enabled attackers to capture credentials, personally identifiable information (PII), and financial data from authentic business processes, making detection extremely challenging and extending the risk across multiple organizations leveraging the affected platform. The incident highlights a growing trend of attackers abusing trusted third-party SaaS and AI service integrations to conduct covert exfiltration at scale. As supply-chain vectors proliferate, organizations face increased pressure to monitor internal communication workflows and enforce egress controls on platform-generated messaging.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Google Gemini AI Model Vulnerabilities: The 2024 Security Wake-Up Call
Impact· medium

Google Gemini AI Model Vulnerabilities: The 2024 Security Wake-Up Call

In early 2024, significant security and privacy vulnerabilities were discovered across multiple Google Gemini AI models, exposing users and enterprises to attack vectors that could have led to data leakage, privilege escalation, and AI-assisted exploitation. Researchers identified a 'trifecta' of flaws enabling prompt injection, sensitive data exposure, and circumvention of embedded safety controls, highlighting weaknesses in current generative AI guardrails. While no widespread attacker exploitation was confirmed, proof-of-concept attacks demonstrated how these flaws could weaponize Gemini models as an attack surface and vehicle for secondary threats. The disclosure prompted urgent reviews of AI usage and mitigations for enterprise consumers. This incident underscores escalating risks as generative AI platforms become embedded across business workflows. It illustrates the urgent challenge of securing large language models (LLMs) against novel exploitation methods and the rapidly intensifying focus by both attackers and regulators on AI/ML supply chain security.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Malicious MCP Server Uncovered in 'postmark-mcp' npm Package Supply Chain Breach
Impact· medium

Malicious MCP Server Uncovered in 'postmark-mcp' npm Package Supply Chain Breach

In September 2025, cybersecurity researchers identified the first active malicious deployment of a Model Context Protocol (MCP) server, delivered through a compromised open-source npm package called "postmark-mcp." The attacker, masquerading as a legitimate developer, introduced rogue code into the package to stealthily exfiltrate user emails to an adversary-controlled MCP server. The package closely mimicked the official Postmark Labs library, making detection challenging for organizations relying on the trusted supply chain. The incident highlights the growing sophistication and operational impact of supply chain compromise, especially within widely used repositories like npm. This supply chain breach underscores a wider trend of attackers targeting open-source ecosystems to weaponize trusted libraries for data theft and persistent access, driving regulatory scrutiny and risk to software providers and their customers. With the acceleration of software supply chain attacks, organizations face increased pressure to enhance dependency audits and adopt zero trust controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports