Validated Containment Architectures are here. →Explore

Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

1840 threat reports
Page 145 of 154

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer Software/Engineering Threat Reports

Showing 17291740 / 1840 reports
Malicious MCP Server Uncovered in 'postmark-mcp' npm Package Supply Chain Breach
Impact· medium

Malicious MCP Server Uncovered in 'postmark-mcp' npm Package Supply Chain Breach

In September 2025, cybersecurity researchers identified the first active malicious deployment of a Model Context Protocol (MCP) server, delivered through a compromised open-source npm package called "postmark-mcp." The attacker, masquerading as a legitimate developer, introduced rogue code into the package to stealthily exfiltrate user emails to an adversary-controlled MCP server. The package closely mimicked the official Postmark Labs library, making detection challenging for organizations relying on the trusted supply chain. The incident highlights the growing sophistication and operational impact of supply chain compromise, especially within widely used repositories like npm. This supply chain breach underscores a wider trend of attackers targeting open-source ecosystems to weaponize trusted libraries for data theft and persistent access, driving regulatory scrutiny and risk to software providers and their customers. With the acceleration of software supply chain attacks, organizations face increased pressure to enhance dependency audits and adopt zero trust controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Microsoft Warns: AI-Powered SVG Phishing Campaign Evades Email Security
Impact· low

Microsoft Warns: AI-Powered SVG Phishing Campaign Evades Email Security

In September 2025, Microsoft disclosed a sophisticated phishing campaign targeting US-based organizations that leveraged large language models (LLMs) to craft highly obfuscated SVG file payloads. Attackers used these LLM-generated SVG attachments to evade traditional email security filters, employing convincing business terminology and synthetic code structures to deliver malicious links or steal credentials. The campaign demonstrates a notable escalation in phishing tactics, exploiting advancements in AI to automate and disguise attack vectors, with the operational impact ranging from compromised accounts to potential supply chain breaches. This incident exemplifies a new era of phishing attacks empowered by generative AI, underlining the growing urgency for advanced detection capabilities and stricter email security policies. The trend highlights a pivot toward more adaptive, machine-generated threats that traditional tools may be ill-equipped to address.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
EvilAI: Malware Masquerading as AI Tools Targets Global Enterprises in 2025
Impact· medium

EvilAI: Malware Masquerading as AI Tools Targets Global Enterprises in 2025

In September 2025, global organizations became targets of a sophisticated malware campaign in which cybercriminals disguised malicious payloads within seemingly legitimate AI productivity tools and software. Security researchers at Trend Micro identified that attackers leveraged the growing popularity and trust in AI-driven solutions to distribute their malware, affecting companies across Europe, the Americas, and AMEA. Adversaries exploited trusted distribution channels, leveraging convincing phishing and software bundling tactics to achieve initial access, with the primary goal of establishing persistent footholds for future attacks, including lateral movement and data exfiltration. The incident disrupted IT operations, forced incident response, and increased the risk of data theft and regulatory exposure. This breach highlights the rapid evolution of social engineering techniques tied to AI trends, with attackers exploiting user demand for productivity tools as an entry point. It underscores an urgent need for heightened vigilance, zero trust policies, and real-time threat detection in the face of shadow AI and increasingly indistinguishable malicious downloads.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fake Microsoft Teams Installers Spread Oyster Malware via Malvertising
Impact· low

Fake Microsoft Teams Installers Spread Oyster Malware via Malvertising

In September 2025, cybercriminals exploited search engine advertisements and SEO poisoning to promote fake Microsoft Teams installers, which covertly delivered the Oyster backdoor (also known as Broomstick or CleanUpLoader) onto Windows devices. By luring users—often IT administrators—to download malicious 'MSTeamsSetup.exe' files from deceptive sites like teams-install[.]top, attackers established remote control over compromised systems. The malware facilitated persistent access by installing a scheduled task and enabled command execution, lateral movement, deployment of additional payloads, and file exfiltration, posing considerable risks to corporate environments. Organizations relying on user trust in branded software searches became targets for subsequent attacks, including potential ransomware deployment. This incident underscores a growing threat: attackers increasingly abuse mainstream search engines and brand impersonation to achieve initial corporate access. As malvertising and SEO poisoning campaigns surge, organizations must prioritize user security awareness, robust endpoint threat detection, and zero trust controls to defend against evolving infostealer delivery mechanisms.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
New XCSSET Variant Hits macOS: Browser Credential Theft and Clipper Risk for Developers
Impact· medium

New XCSSET Variant Hits macOS: Browser Credential Theft and Clipper Risk for Developers

In September 2025, researchers identified a sophisticated new variant of the macOS XCSSET malware, targeting Apple devices with an updated focus on browser credential theft, clipboard hijacking (clipper), and improved persistence. Initially delivered through tainted Xcode projects, the malware leveraged encrypted and obfuscated code to avoid detection, and incorporated a persistence module for sustained access. Key changes included deeper targeting of browsers like Firefox, allowing attackers to intercept credentials, exfiltrate sensitive data, and potentially escalate attacks to other platforms or accounts. The XCSSET variant’s rise mirrors broader trends in information-stealing malware exploiting developer platforms and macOS. This incident highlights growing attacker interest in macOS ecosystems, the sophistication of obfuscation techniques, and the urgent need for endpoint monitoring and microsegmentation across development environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
COLDRIVER’s 2025 ClickFix Malware Campaign: Modular APT Tactics Evolve
Impact· low

COLDRIVER’s 2025 ClickFix Malware Campaign: Modular APT Tactics Evolve

In September 2025, the Russian APT group COLDRIVER launched a multi-stage cyber campaign using newly identified malicious tools, BAITSWITCH and SIMPLEFIX, delivered through ClickFix-style phishing attacks. Zscaler ThreatLabz observed that COLDRIVER targeted Russian-speaking entities with sophisticated social engineering and credential phishing tactics, ultimately compromising victims by deploying lightweight downloaders that enable remote access and further malware deployment. Impacted organizations faced stealthed data exfiltration risks and the threat actor's evolving persistence mechanisms, signifying a leap in their operational security evasion. This incident reflects an accelerating trend of APT actors developing nimble, modular malware to bypass traditional defenses and exploit collaboration platforms. Continued adaptation in attacker tradecraft underscores the growing urgency for zero trust controls, east-west visibility, and anomaly detection across hybrid environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Salesforce Agentforce 2024: ForcedLeak AI Prompt Injection Breach Exposes CRM Data
Impact· medium

Salesforce Agentforce 2024: ForcedLeak AI Prompt Injection Breach Exposes CRM Data

In June 2024, researchers at Noma Security identified a severe vulnerability in Salesforce's Agentforce AI agents, termed 'ForcedLeak'. By exploiting prompt injection via web-to-lead forms, attackers were able to manipulate Agentforce into exfiltrating sensitive CRM data, including PII, corporate secrets, and transactional details, to unauthorized locations. The vulnerability hinged on whitelist misconfigurations of trusted domains and the agent’s overly broad prompt interpretation, leading to an attacker-controlled data leak chain. Salesforce addressed data exfiltration by patching URL restrictions and acquiring an expired trusted domain but ongoing risks persist with agentic AI’s prompt processing logic. The incident underscores the growing challenges as mainstream SaaS platforms rapidly integrate autonomous GenAI features, often lacking robust input validation and security boundaries. High CVSS-scored issues like ForcedLeak exemplify the urgent need for zero trust guardrails and more resilient AI security frameworks given the increasing velocity and sophistication of prompt injection attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Brickstorm Backdoor: UNC5221’s Stealthy Edge Device Supply Chain Attack (2024)
Impact· medium

Brickstorm Backdoor: UNC5221’s Stealthy Edge Device Supply Chain Attack (2024)

In a sophisticated cyber-espionage campaign uncovered in 2024, the China-linked group UNC5221 systematically compromised edge network appliances—such as firewalls, VPNs, and virtualization hosts—unable to run traditional EDR agents. By deploying a newly evolved backdoor known as 'Brickstorm,' the attackers gained highly persistent, stealthy access to organizations in technology, legal, SaaS, and outsourcing sectors. The malware, enhanced with delayed activation and strong obfuscation, leveraged unique command-and-control domains per victim and often exploited both zero-day and publicly known vulnerabilities. High-value credential harvesting and lateral movement to strategic systems, such as VMware vCenter, enabled the threat actor to maintain undetected access for an average of 393 days, facilitating both data theft and potential downstream customer compromise. This incident highlights the evolving risk posed by state-sponsored actors targeting blind spots in infrastructure—especially unmanaged or agentless edge devices critical to supply chains and cloud access. With ongoing innovation in stealth tactics and platform abuse, the Brickstorm campaign marks a serious escalation in the complexity and duration of modern supply chain threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Malicious Rust Crates on Crates.io Compromise Developer Crypto Wallets in 2025
Impact· medium

Malicious Rust Crates on Crates.io Compromise Developer Crypto Wallets in 2025

In September 2025, security researchers uncovered two malicious Rust packages, 'faster_log' and 'async_println', uploaded to the official Crates.io repository. These packages, downloaded nearly 8,500 times, masqueraded as legitimate logging libraries but secretly scanned developers' machines for cryptocurrency wallet private keys and other sensitive secrets. The attackers used cloned documentation and authentic functionality to evade suspicion, while an embedded payload exfiltrated discovered secrets to a hardcoded Cloudflare Worker endpoint controlled by the threat actors. Upon discovery, Crates.io removed the packages and banned the associated users, mitigating the immediate threat. This incident demonstrates the persistent risk posed by supply chain attacks targeting open-source repositories and the increasing focus of cybercriminals on cryptocurrency theft. It underscores the need for rigorous vetting, enhanced code scanning, and heightened awareness among developers regarding open-source dependencies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Unofficial Postmark MCP npm Package: 2024 Supply Chain Breach Exposes Email Data
Impact· high

Unofficial Postmark MCP npm Package: 2024 Supply Chain Breach Exposes Email Data

In February 2024, the unofficial 'postmark-mcp' npm package—a clone of the genuine Postmark MCP email handler—was discovered to have maliciously exfiltrated users' email data. With a single line of code added in its latest update, the package silently sent every processed email to an external domain controlled by the attacker. This supply chain compromise exploited developer trust in open-source libraries, resulting in unintentional leakage of confidential user communications and putting affected organizations and their customers at risk of data exposure or further attacks. This incident underscores the growing frequency and sophistication of supply chain attacks targeting software ecosystems like npm. Organizations face heightened regulatory and reputational risks as attackers leverage trusted distribution platforms to propagate malicious code, making robust dependency monitoring and vendor validation more critical than ever.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft Warns: XCSSET macOS Malware Evolves to Target Xcode Devs in 2025
Impact· medium

Microsoft Warns: XCSSET macOS Malware Evolves to Target Xcode Devs in 2025

In September 2025, Microsoft Threat Intelligence identified a new, advanced variant of the XCSSET macOS malware targeting Xcode developers. This infostealer propagates by infecting Xcode projects—widely shared among software engineers—allowing it to execute malicious code each time a compromised project is built. The updated malware features enhanced browser data theft (including Firefox), clipboard hijacking to steal cryptocurrency via address swapping, and improved persistence mechanisms. Though observed only in limited, targeted attacks so far, XCSSET poses a significant risk to both assets and sensitive developer tooling. This incident is especially relevant today as targeting the software supply chain and developer toolchains is becoming a favored method for threat actors seeking high-privilege access. The sophistication of XCSSET’s mechanisms mirrors broader trends in stealthy, data-focused attacks against development environments, pressing organizations to reassess internal controls and software sharing practices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Massive npm Supply Chain Attack: Shai-Hulud Worm Infects Hundreds of Packages
Impact· medium

Massive npm Supply Chain Attack: Shai-Hulud Worm Infects Hundreds of Packages

In September 2025, a major supply chain compromise hit the npm ecosystem with the discovery of the Shai-Hulud worm. Attackers leveraged malicious npm packages to propagate self-replicating malware, which spread by abusing developer credentials and update permissions across over 500 packages—including widely used libraries from organizations such as CrowdStrike. Malicious code executed on install harvested secrets, exfiltrated sensitive GitHub and cloud data, and published infected releases to additional packages, resulting in widespread risk of source code leaks, credential theft, and downstream infections. This incident typifies the escalating trend of highly automated supply chain attacks targeting open-source repositories. Such events highlight the vulnerabilities of complex dependency networks and reinforce the necessity for robust controls, automated monitoring, and zero trust policies for development and CI/CD ecosystems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports