✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
GuardFall: Exposing Shell Injection Vulnerabilities in AI Coding Agents
In June 2026, Adversa AI disclosed a vulnerability named 'GuardFall' affecting ten out of eleven popular open-source AI coding agents. This flaw allows attackers to bypass safety checks using decades-old shell injection techniques, enabling the execution of malicious commands that can delete files or exfiltrate sensitive data such as SSH keys and cloud credentials. The vulnerability arises because these agents rely on blocklists that fail to account for how the Bash shell processes commands, leading to discrepancies between filtered and executed commands. ([thehackernews.com](https://thehackernews.com/2026/06/guardfall-exposes-open-source-ai-coding.html?utm_source=openai)) This incident underscores the persistent risks associated with AI coding agents, especially as they become more integrated into development workflows. The exploitation of longstanding shell injection methods highlights the need for robust security measures and continuous vigilance in the deployment of AI tools to prevent potential supply chain attacks.
4 weeks ago
Kill Chain
Silent Swap Crypto Clipper: A New Threat to Cryptocurrency Security
In June 2026, cybersecurity researchers identified a malicious campaign named 'Silent Swap,' which targets cryptocurrency users through a fake 'Google Notes' browser extension. Delivered via unsigned .NET and Golang installers, this extension infiltrates Chromium-based browsers by modifying their settings to install itself without user consent. Once active, it monitors the system clipboard for cryptocurrency wallet addresses and replaces them with attacker-controlled addresses, leading to unauthorized fund transfers. The campaign employs advanced techniques like 'EtherHiding,' utilizing blockchain technology to dynamically update command-and-control servers, enhancing its resilience and evasion capabilities. This incident underscores a growing trend of sophisticated attacks leveraging trusted platforms and applications to distribute malware. The use of blockchain for command-and-control infrastructure highlights the evolving tactics of threat actors, making detection and mitigation more challenging. Organizations and individuals must remain vigilant, ensuring that browser extensions are sourced from reputable developers and regularly reviewing installed extensions for unauthorized additions.
4 weeks ago
Kill Chain
Malicious Chromium Extension Exploits AI Branding for Search Hijacking
In June 2026, a malicious Chromium-based browser extension impersonating the AI-powered search engine Perplexity AI was discovered. This extension intercepted user search queries and real-time suggestions, routing them through attacker-controlled infrastructure before redirecting to legitimate search providers. The primary objective appeared to be data collection for potential misuse, such as profiling or targeted advertising. Microsoft Threat Intelligence reported the extension to Google, leading to its removal from the Chrome Web Store. This incident underscores the evolving tactics of threat actors leveraging AI-related branding to enhance the credibility of their malicious tools. The use of legitimate APIs and advanced permissions highlights the need for heightened vigilance and robust security measures to protect against sophisticated browser-based threats.
4 weeks ago
Kill Chain
GitHub Advisory Database Overwhelmed by Record Vulnerability Reports
In May 2026, the GitHub Advisory Database published 1,560 reviewed advisories, marking a fivefold increase over its typical monthly output and the highest in its history. This surge reflects a structural change in the vulnerability disclosure ecosystem, with private vulnerability reports escalating from approximately 550 per week in January to over 3,000 per week by May. Repository advisories and CVE requests have similarly increased, leading to extended review times and a backlog in processing new advisories. ([github.blog](https://github.blog/security/supply-chain-security/inside-the-advisory-database-and-what-happens-when-vulnerability-volume-breaks-records/?utm_source=openai)) The unprecedented volume of vulnerability reports underscores the need for enhanced coordination among researchers, maintainers, and security teams. It also highlights the importance of submitting complete and accurate vulnerability data to expedite the review process. As the ecosystem adapts to this new scale, stakeholders must collaborate to maintain the quality and timeliness of advisory publications. ([github.blog](https://github.blog/security/supply-chain-security/inside-the-advisory-database-and-what-happens-when-vulnerability-volume-breaks-records/?utm_source=openai))
4 weeks ago
Kill Chain
KDDI Data Breach Exposes 14.2 Million Email Logins Across Six ISPs
In June 2026, KDDI Corporation, a major Japanese telecommunications operator, disclosed a data breach affecting its email systems used by six internet service providers (ISPs). The breach, discovered on June 17, resulted from attackers exploiting a vulnerability in third-party software, potentially exposing up to 14.2 million email addresses and passwords. The affected ISPs include STNet, JCOM, Chubu Telecommunications, NIFTY, BIGLOBE, and KDDI Web Communications. KDDI promptly blocked the attacker and implemented defensive measures upon detection. This incident underscores the critical importance of securing third-party software components within shared infrastructure environments. As cyber threats continue to evolve, organizations must rigorously assess and monitor the security of all integrated software solutions to prevent similar breaches.
4 weeks ago
Kill Chain
Nissan Employee Data Breach Exposes Sensitive Information via Oracle PeopleSoft Exploit
In June 2026, Nissan disclosed a data breach affecting current and former employees across the United States, Canada, Mexico, and Brazil. The breach occurred between May 27 and June 9, 2026, when threat actors exploited a zero-day vulnerability (CVE-2026-35273) in Oracle's PeopleSoft software, which Nissan uses to manage employee information. The attackers, identified as the ShinyHunters extortion group, accessed sensitive personal data, including contact details, banking information, Social Security numbers, and tax information. Nissan promptly activated its incident response plan, engaged external cybersecurity experts, secured affected systems, and is collaborating with Oracle to address the issue. The company is offering free credit and dark web monitoring services to affected individuals and has implemented additional security measures to prevent further unauthorized access. This incident underscores the critical importance of promptly addressing software vulnerabilities and implementing robust security measures to protect sensitive employee data. The exploitation of a zero-day vulnerability by a known threat actor highlights the evolving tactics of cybercriminals and the necessity for organizations to remain vigilant and proactive in their cybersecurity efforts.
4 weeks ago
Kill Chain
Malicious Perplexity Chrome Extension Compromises User Data
In June 2026, Microsoft identified a malicious Chrome extension named "Search for perplexity ai" that impersonated the AI search engine Perplexity. This extension intercepted users' search queries and address bar inputs, routing them through an attacker-controlled server before redirecting to legitimate search results. The extension set itself as the default search engine upon installation, capturing every character typed into the address bar and transmitting this data, along with browser headers, IP addresses, and user agents, to the attacker's server. Microsoft reported the extension to Google, leading to its removal from the Chrome Web Store. ([thehackernews.com](https://thehackernews.com/2026/06/malicious-perplexity-chrome-extension.html?utm_source=openai)) This incident underscores a growing trend of malicious browser extensions exploiting the popularity of AI tools to harvest sensitive user data. Similar campaigns have targeted users by masquerading as AI assistants, leading to significant data breaches. Organizations must remain vigilant, implementing strict policies on browser extensions and educating users about the risks associated with unverified add-ons. ([techradar.com](https://www.techradar.com/pro/security/fake-chrome-ai-extensions-targeted-over-300-000-users-to-steal-emails-personal-data-and-more?utm_source=openai))
4 weeks ago
Kill Chain
Critical Vulnerability in Amazon Q Developer's VS Code Extension Exposes Cloud Credentials
In June 2026, a high-severity vulnerability (CVE-2026-12957) was discovered in Amazon Q Developer's Visual Studio Code extension. This flaw allowed attackers to execute arbitrary code and steal cloud credentials by convincing developers to open malicious repositories. The issue stemmed from the extension's handling of Model Context Protocol (MCP) servers, which automatically loaded and executed configurations from workspace files without user approval, leading to potential exposure of sensitive information such as AWS credentials and API keys. AWS addressed the vulnerability by releasing an update to Language Server version 1.65.0. This incident highlights the growing risks associated with AI coding tools and the importance of scrutinizing their integration into development environments. Organizations are urged to treat AI tools with environment access as potential security risks and implement appropriate guardrails to prevent unauthorized access and data exfiltration.
4 weeks ago
Kill Chain
Hijacked npm and Go Packages Exploit VS Code to Deploy Python Infostealer
In June 2026, cybersecurity researchers identified a sophisticated supply chain attack involving hijacked npm and Go packages designed to deploy a Python-based information stealer across Windows, Linux, and macOS systems. The attackers embedded malicious code within Visual Studio Code (VS Code) tasks, configured to execute automatically when a project folder was opened. This method bypassed traditional npm execution paths, allowing the malware to retrieve encrypted JavaScript from blockchain transactions, establish a backdoor via socket.io, and ultimately deploy the Python infostealer. The compromised npm packages, 'html-to-gutenberg' and 'fetch-page-assets', were uploaded on May 25, 2026, and have since been removed from the registry. This incident underscores a growing trend of attackers exploiting development environments and tools to infiltrate systems, highlighting the need for enhanced security measures within the software supply chain. The use of blockchain as a resilient command-and-control mechanism further complicates detection and mitigation efforts, emphasizing the importance of vigilance and proactive defense strategies among developers and organizations.
4 weeks ago
Kill Chain
Microsoft Eliminates 119 Malicious Edge Extensions Concealing Malware
In June 2026, Microsoft identified and removed 119 malicious extensions from the Edge Add-ons store, collectively known as 'StegoAd.' These extensions, active since at least 2021, utilized steganography to conceal malware within image and font files. After installation, the malware remained dormant, later activating to steal user credentials and conduct ad fraud. The affected extensions, including ad blockers, VPNs, translators, and video downloaders, amassed up to 2.6 million installations. The exact number of compromised users remains undetermined. This incident underscores the evolving sophistication of cyber threats, particularly in the realm of browser extensions. The use of steganography to evade detection highlights the need for enhanced security measures and vigilant monitoring of third-party add-ons. Organizations must prioritize the implementation of robust security protocols to mitigate such risks.
4 weeks ago
Kill Chain
Massive Crypto Scam Operation Exploits DCloud Uni-App Framework
In June 2026, cybersecurity firm Infoblox uncovered that over 236,000 websites were utilizing investment scam templates built with the DCloud Uni-App framework. These sites facilitated a range of fraudulent activities, including fake cryptocurrency exchanges, phishing schemes, and crypto wallet drainers. The malicious domains spanned multiple continents and languages, indicating a coordinated effort by various threat actors. Notably, the RainbowEx platform, implicated in a Ponzi scheme affecting thousands in Argentina in late 2024, was among the identified domains. ([thehackernews.com](https://thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html?utm_source=openai)) The exploitation of legitimate development frameworks like DCloud Uni-App underscores the evolving tactics of cybercriminals. This incident highlights the critical need for organizations to implement robust security measures, including thorough vetting of third-party tools and continuous monitoring for suspicious activities. ([thehackernews.com](https://thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html?utm_source=openai))
4 weeks ago
Kill Chain
Exploiting AI Coding Agents: The New Frontier in Supply Chain Attacks
In June 2026, researchers at Mozilla's Zero Day Investigative Network (0DIN) identified a novel supply chain attack targeting AI coding agents. The attack involved a seemingly benign GitHub repository containing standard setup instructions. When an AI coding agent, such as Claude Code, cloned and initialized the repository, it encountered an error message prompting the execution of an initialization command. This command triggered a shell script that retrieved and executed a payload from a DNS TXT record controlled by the attacker, resulting in the establishment of an interactive shell on the developer's machine. This method allowed attackers to gain unauthorized access to sensitive information without any malicious code present in the repository itself. This incident underscores the evolving sophistication of supply chain attacks, particularly those exploiting AI-driven development tools. As AI coding agents become more integrated into software development workflows, they present new vectors for exploitation. Organizations must enhance their security protocols to address these emerging threats, ensuring that AI tools are configured to disclose and verify the full execution chain of setup commands to prevent unauthorized code execution.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports