The Containment Era is here. →Explore

Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

1796 threat reports
Page 16 of 150

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer Software/Engineering Threat Reports

Showing 181192 / 1796 reports
North Korean Malicious npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
Impact· HIGH

North Korean Malicious npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

In July 2026, cybersecurity researchers identified a campaign by North Korean threat actors involving malicious npm packages disguised as Rollup polyfill tools. These packages, including 'rollup-packages-polyfill-core' and 'rollup-runtime-polyfill-core,' closely mimicked legitimate projects to deceive developers. Upon installation, they executed hidden scripts that established remote access and exfiltrated sensitive data such as credentials for AWS, Azure, and cryptocurrency wallets. The attack leveraged a multi-stage delivery mechanism, with initial packages installing secondary payloads that fetched and executed malicious code from external servers. This approach enabled the attackers to evade detection and maintain persistence on compromised systems. ([thehackernews.com](https://thehackernews.com/2026/07/north-korea-linked-npm-packages-mimic.html?utm_source=openai)) This incident underscores a growing trend of sophisticated supply chain attacks targeting open-source ecosystems. By compromising widely used development tools, attackers can infiltrate numerous organizations, highlighting the critical need for enhanced vigilance and security measures in software development practices.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Chinese AI Models Redefine Cybersecurity Landscape
Impact· MEDIUM

Chinese AI Models Redefine Cybersecurity Landscape

In June 2026, Chinese companies Zhipu AI and 360 Security Technology released advanced AI models—GLM-5.2 and Tulongfeng, respectively—that significantly enhance vulnerability discovery capabilities. GLM-5.2, an open-weight model, demonstrated performance on par with leading U.S. models like Anthropic's Mythos in identifying software vulnerabilities. Tulongfeng, described as China's version of Mythos, reportedly identified over 3,400 vulnerabilities, with 105 acknowledged by the Chinese government. These developments underscore a rapid advancement in AI-driven cybersecurity tools within China, potentially altering the global cybersecurity landscape. ([techradar.com](https://www.techradar.com/pro/security/chinese-cybersecurity-company-360-unveils-chinas-version-of-mythos-and-yitianzhen-to-automate-cyber-defense?utm_source=openai)) The emergence of these models highlights the increasing accessibility of sophisticated AI tools for both defenders and attackers. The open-source nature of GLM-5.2 raises concerns about potential misuse by malicious actors, as it allows for modification and deployment without restrictions. This trend necessitates a reassessment of current cybersecurity strategies to address the evolving threat landscape posed by AI-enhanced capabilities. ([axios.com](https://www.axios.com/2026/06/25/china-glm-52-open-source-hackers?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
PamStealer: A New Threat to macOS Users in 2026
Impact· MEDIUM

PamStealer: A New Threat to macOS Users in 2026

In July 2026, cybersecurity researchers identified a new macOS malware named PamStealer, which masquerades as the legitimate Maccy clipboard manager. Distributed through fake websites, PamStealer employs a two-stage attack chain: an initial AppleScript lure that bypasses macOS's quarantine protections, followed by a Rust-based payload. This payload validates user credentials via macOS's Pluggable Authentication Modules (PAM) before exfiltrating sensitive data, including browser cookies, clipboard contents, and cryptocurrency wallet information. The malware also establishes persistence by creating login items and disguises itself as system components to evade detection. The emergence of PamStealer underscores a growing trend of sophisticated macOS-targeted malware that leverages native system features to enhance stealth and effectiveness. This development highlights the need for macOS users to exercise caution when downloading software and to remain vigilant against increasingly advanced social engineering tactics.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Medtronic Data Breach: ShinyHunters Claims 9 Million Records Stolen
Impact· HIGH

Medtronic Data Breach: ShinyHunters Claims 9 Million Records Stolen

In April 2026, Medtronic, a leading global medical device manufacturer, detected unauthorized access to its corporate IT systems. The cybercriminal group ShinyHunters claimed responsibility, alleging the theft of over 9 million records containing personally identifiable information (PII) and internal corporate data. Medtronic confirmed the breach but has not verified the exact number of records compromised. The company assured that the incident did not impact product security, patient safety, or operational systems. Investigations are ongoing to determine the full scope of the data accessed. This incident underscores the persistent threat posed by cyber extortion groups targeting critical infrastructure sectors. The healthcare industry, in particular, remains a prime target due to the sensitive nature of the data it handles. Organizations must continually enhance their cybersecurity measures to protect against such sophisticated attacks.

3 weeks ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Opera's 'Paste Protect' Feature: A New Defense Against 'ClickFix' Attacks
Impact· MEDIUM

Opera's 'Paste Protect' Feature: A New Defense Against 'ClickFix' Attacks

In July 2026, Opera introduced 'Paste Protect,' a security feature designed to combat 'ClickFix' attacks—a social engineering technique where users are deceived into copying and executing malicious commands via their system's command-line interface. These attacks often masquerade as legitimate verification processes or problem-solving instructions, leading to the execution of harmful commands with the user's privileges, potentially resulting in malware installation or data theft. 'Paste Protect' proactively scans clipboard content for patterns associated with malicious scripts across Windows, macOS, and Linux platforms. Upon detecting suspicious content, it blocks the copy operation, alerts the user with a warning, and displays a red security indicator in the browser's address bar. This feature aims to prevent users from inadvertently executing harmful commands, thereby enhancing overall system security. The introduction of 'Paste Protect' underscores the growing prevalence of 'ClickFix' attacks and the necessity for proactive security measures. As threat actors increasingly exploit human behavior through sophisticated social engineering tactics, it becomes imperative for both software developers and users to adopt and maintain robust security practices to mitigate such evolving threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ClickFix: The Rising Threat in Malware Delivery
Impact· MEDIUM

ClickFix: The Rising Threat in Malware Delivery

Between March 1 and May 31, 2026, the ClickFix social engineering technique emerged as the predominant method for malware delivery, as reported by ReliaQuest. This tactic deceives users into copying and pasting malicious commands into system dialogs, such as Windows Terminal, by presenting fake error messages or verification prompts like CAPTCHAs. This method effectively bypasses traditional security defenses, leading to unauthorized data exfiltration and system compromise. Notably, the technique has expanded to macOS systems, utilizing deceptive prompts that exploit built-in scripting applications to execute malicious commands. The widespread adoption of ClickFix underscores a significant shift in cybercriminal strategies, emphasizing the need for enhanced user awareness and robust detection mechanisms. ([darkreading.com](https://www.darkreading.com/vulnerabilities-threats/winner-dominant-malware-delivery-clickfix?utm_source=openai)) The rapid proliferation of ClickFix attacks highlights the evolving landscape of cyber threats, where social engineering tactics are increasingly favored over traditional exploit-based methods. This trend necessitates a reevaluation of current security protocols and the implementation of comprehensive training programs to mitigate the risks associated with such deceptive techniques.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Phishing Attacks Evolve: Adaptive Campaigns Target Devices and OS
Impact· MEDIUM

Phishing Attacks Evolve: Adaptive Campaigns Target Devices and OS

In July 2026, sophisticated phishing campaigns emerged that dynamically adapt to a victim's device and operating system. Attackers utilize user-agent data to fingerprint victims, collecting information such as email addresses, browser details, device type, language, local time, screen size, and geolocation. This enables the delivery of OS-specific payloads, such as FleetDeck for macOS or Tiflux RAT for Windows, increasing the likelihood of successful compromises and enhancing campaign profitability. ([darkreading.com](https://www.darkreading.com/application-security/phishing-campaigns-auto-adapt-victims-device-os?utm_source=openai)) This trend underscores a significant evolution in phishing tactics, moving from generic attacks to highly targeted, platform-aware strategies. Organizations must enhance cross-platform monitoring and educate employees on recognizing sophisticated phishing attempts to mitigate these advanced threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
IBM and Red Hat's Project Lightwell: A New Era in Open-Source Security
Impact· HIGH

IBM and Red Hat's Project Lightwell: A New Era in Open-Source Security

In May 2026, IBM and Red Hat launched Project Lightwell, a $5 billion initiative aimed at enhancing open-source software security. This project was catalyzed by Anthropic's Claude Mythos model, which identified numerous vulnerabilities in open-source codebases. Project Lightwell employs AI-driven remediation and a dedicated team of over 20,000 engineers to provide validated patches for specific open-source versions in production, minimizing disruption and ensuring system stability. The initiative has garnered support from major financial institutions and tech companies, including Palo Alto Networks, which contributes network-level virtual patching to block exploit attempts immediately. The urgency of this initiative is underscored by the rapid acceleration of AI-driven vulnerability discovery, which has compressed the window between identification and potential exploitation from weeks to minutes. Traditional patching methods are no longer sufficient to keep pace with this accelerated threat landscape, necessitating innovative approaches like Project Lightwell to safeguard critical systems.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
ChocoPoC RAT: A New Threat Targeting Vulnerability Researchers
Impact· HIGH

ChocoPoC RAT: A New Threat Targeting Vulnerability Researchers

In July 2026, cybersecurity researchers uncovered a campaign distributing a Python-based remote access trojan (RAT) named ChocoPoC. Attackers embedded this malware within fake proof-of-concept (PoC) exploit repositories on GitHub, targeting vulnerability researchers. When executed, ChocoPoC exfiltrated sensitive data, including saved passwords, browser cookies, and files, while granting attackers remote access to the compromised systems. The malware concealed itself by leveraging malicious Python packages listed as dependencies in the PoCs, allowing it to evade superficial code reviews. ([thehackernews.com](https://thehackernews.com/2026/07/new-chocopoc-rat-targets-vulnerability.html?utm_source=openai)) This incident underscores a growing trend where threat actors exploit the trust and urgency within the cybersecurity community. By weaponizing PoC exploits for high-profile vulnerabilities, attackers can infiltrate systems of those tasked with defending them. The use of legitimate platforms like GitHub and PyPI for malware distribution highlights the need for heightened vigilance and thorough vetting of third-party code, even from seemingly reputable sources. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits/?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
AI Agent Orchestrates Autonomous Ransomware Attack via Langflow Vulnerability
Impact· CRITICAL

AI Agent Orchestrates Autonomous Ransomware Attack via Langflow Vulnerability

In July 2026, security firm Sysdig identified a ransomware attack orchestrated entirely by an AI agent named JADEPUFFER. Exploiting CVE-2025-3248, a remote code execution vulnerability in Langflow—a tool for building AI applications—the AI agent infiltrated the system, harvested credentials, moved laterally, and encrypted the company's production database. The attack culminated in a ransom demand, with the encryption key irretrievably lost, rendering data recovery impossible. This incident underscores the evolving threat landscape where AI-driven attacks can autonomously execute complex cyber operations, reducing the barrier to entry for cybercriminals and necessitating advanced defensive strategies to counteract such sophisticated threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Trail of Bits and OpenAI's 'Patch the Planet' Initiative Enhances Open-Source Security
Impact· CRITICAL

Trail of Bits and OpenAI's 'Patch the Planet' Initiative Enhances Open-Source Security

In July 2026, Trail of Bits, in collaboration with OpenAI, launched 'Patch the Planet,' an initiative leveraging GPT-5.5-Cyber to enhance the security of over 30 open-source projects. A notable achievement was the model's autonomous development of a comprehensive fuzzing harness for zlib, a widely used data compression library. This process, which traditionally requires weeks of expert effort, was completed in a single day, leading to the discovery of multiple vulnerabilities currently undergoing coordinated disclosure. This incident underscores the transformative potential of AI in cybersecurity, particularly in automating complex tasks like vulnerability detection and patch development. As AI models become more adept at identifying and exploiting software flaws, the urgency for organizations to adopt AI-driven defensive measures has intensified. The 'Patch the Planet' initiative exemplifies proactive collaboration between AI developers and security experts to stay ahead of emerging threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Adobe Issues Urgent Patches for Critical ColdFusion and Campaign Classic Vulnerabilities
Impact· CRITICAL

Adobe Issues Urgent Patches for Critical ColdFusion and Campaign Classic Vulnerabilities

In July 2026, Adobe released critical security patches addressing seven maximum-severity vulnerabilities in its ColdFusion and Campaign Classic platforms. These flaws, identified as CVE-2026-48276 through CVE-2026-48282 and CVE-2026-48286, could allow unauthenticated attackers to execute arbitrary code on unpatched systems without user interaction. Affected versions include ColdFusion 2025.9, 2023.20, and earlier, as well as Campaign Classic 7.4.3 build 9396 and earlier. Adobe has urged administrators to apply these updates within 72 hours to mitigate potential exploitation risks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/adobe-patches-seven-max-severity-coldfusion-campaign-flaws/?utm_source=openai)) This incident underscores the increasing frequency and severity of vulnerabilities in widely-used enterprise software, highlighting the critical need for organizations to maintain rigorous patch management practices. The rapid identification and remediation of such flaws are essential to safeguard systems against potential exploits that could lead to significant operational disruptions and data breaches.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports