✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Global Operation Dismantles SocGholish Botnet Linked to Evil Corp
In June 2026, an international law enforcement operation, including agencies from the United States, Canada, Germany, the Netherlands, and Europol, successfully disrupted the SocGholish botnet, a malware framework linked to the Russian cybercriminal group Evil Corp. The coordinated effort led to the takedown of 106 servers and the remediation of nearly 15,000 infected websites, primarily hosted on WordPress platforms. SocGholish, active since 2017, compromised legitimate websites to redirect users to malicious traffic distribution systems, facilitating further malware infections and enabling ransomware campaigns and espionage activities. This operation significantly impaired Evil Corp's ability to exploit these compromised sites for malicious purposes. The takedown of the SocGholish botnet underscores the persistent threat posed by sophisticated cybercriminal organizations like Evil Corp. Despite this disruption, the group's leaders remain at large, and similar malware campaigns continue to evolve. Organizations must remain vigilant, implementing robust cybersecurity measures to protect against such threats and staying informed about emerging attack vectors. ([moncloa.com](https://www.moncloa.com/2026/06/18/desmantelamiento-evil-corp-2026-3386510/?utm_source=openai))
1 month ago
Kill Chain
ShapedPlugin Supply Chain Attack: A Wake-Up Call for WordPress Security
In May 2026, ShapedPlugin, a WordPress plugin vendor, experienced a supply chain attack where malicious code was injected into their update system. This breach affected three paid plugins—Product Slider Pro, Real Testimonials Pro, and Smart Post Show Pro—leading to the installation of fake plugins that impersonated WooCommerce components. These malicious plugins stole credentials and granted attackers remote file-writing capabilities. The compromise was identified in June 2026, prompting ShapedPlugin to initiate an investigation and release updated, secure versions of the affected plugins. This incident underscores the growing trend of supply chain attacks targeting software vendors to distribute malware through legitimate update channels. It highlights the critical need for robust security measures in software development and distribution processes to prevent such breaches.
1 month ago
Kill Chain
International Crackdown Dismantles SocGholish Botnet Tied to Evil Corp
In June 2026, international law enforcement agencies, including Europol and Eurojust, executed Operation Endgame, targeting the SocGholish botnet linked to the Russian cybercrime group Evil Corp. This coordinated effort resulted in the cleansing of nearly 15,000 malware-infected WordPress websites and the dismantling of over 100 associated servers. SocGholish, active since at least 2017, operates by injecting malicious JavaScript into legitimate websites, tricking visitors into downloading fake browser updates that install malware, thereby granting attackers access to infected systems. The operation significantly disrupted Evil Corp's infrastructure, mitigating further cyber threats posed by this group. The success of Operation Endgame underscores the effectiveness of international collaboration in combating sophisticated cybercriminal networks. It highlights the critical need for organizations to maintain robust cybersecurity practices, including regular software updates, vigilant monitoring of web assets, and user education to recognize and avoid social engineering tactics employed by malware like SocGholish.
1 month ago
Kill Chain
Klue OAuth Breach 2026: A Wake-Up Call for Third-Party Integration Security
In June 2026, market intelligence platform Klue experienced a security breach where attackers, identified as the 'Icarus' group, exploited OAuth tokens to access and exfiltrate Salesforce CRM data from multiple organizations. The attackers infiltrated Klue's backend systems, deployed malicious code to harvest OAuth tokens, and utilized these tokens to query and extract sensitive data from connected Salesforce instances. This incident led to significant data theft and subsequent extortion attempts targeting the affected organizations. This breach underscores the critical vulnerabilities associated with third-party integrations and the exploitation of OAuth tokens. It highlights the necessity for organizations to implement stringent security measures, including regular audits of third-party applications, prompt revocation of compromised tokens, and continuous monitoring of API activities to detect and mitigate unauthorized access promptly.
1 month ago
Kill Chain
Unveiling the 2025 AWS Cryptomining Security Breach
In November 2025, Amazon Web Services (AWS) identified a sophisticated cryptocurrency mining campaign targeting Amazon EC2 and Amazon ECS services. Threat actors utilized compromised AWS Identity and Access Management (IAM) credentials to deploy mining operations rapidly, often within minutes of gaining access. They employed advanced persistence techniques, such as modifying instance attributes to disable termination, complicating incident response efforts. This campaign underscores the critical importance of securing IAM credentials and monitoring for unauthorized activities within cloud environments. The incident highlights a growing trend of attackers leveraging legitimate credentials to exploit cloud resources for illicit purposes. Organizations must prioritize robust access controls, implement multi-factor authentication, and continuously monitor for anomalous behaviors to mitigate such threats effectively.
1 month ago
Kill Chain
Salesforce Data Breach via Klue App Compromise
In June 2026, threat actors exploited OAuth tokens from Klue's Battlecards app to access Salesforce instances, leading to unauthorized data exfiltration. This incident mirrors previous breaches involving third-party integrations like Salesloft's Drift and Gainsight, highlighting the persistent risks associated with SaaS application connections. The attackers authenticated through a compromised Klue integration service account, generating OAuth tokens that granted access to customers' integrated Salesforce environments. The exfiltration process involved automated scripts querying the Salesforce REST API over a 24-hour period, with some instances experiencing concentrated bursts of nearly a thousand queries in 15 minutes. This breach underscores the critical need for organizations to scrutinize third-party integrations and enforce stringent security measures to protect sensitive data. The recurrence of such attacks emphasizes the importance of continuous monitoring and the implementation of robust security protocols to mitigate risks associated with third-party applications.
1 month ago
Kill Chain
DragonForce Ransomware's Stealthy Exploitation of Microsoft Teams
In December 2025, the DragonForce ransomware group infiltrated a major U.S. services firm by exploiting an SQL-related vulnerability. They deployed a custom Go-based remote access trojan (RAT) named Backdoor.Turn, which concealed command-and-control (C2) traffic within Microsoft Teams' TURN relay infrastructure. This method allowed the attackers to remain undetected for one to two months, as the malicious traffic appeared as legitimate Teams communication. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/06/16/dragonforce-microsoft-teams-malware-backdoor-turn/?utm_source=openai)) This incident underscores a significant evolution in cyberattack methodologies, highlighting the increasing sophistication of threat actors in leveraging trusted communication platforms to evade detection. Organizations must reassess their security postures to address such advanced persistent threats.
1 month ago
Kill Chain
Microsoft Uncovers Sophisticated Windows Clipper Malware Campaign
In June 2026, Microsoft disclosed a sophisticated malware campaign targeting Windows users through USB drives containing malicious LNK files. Once executed, these shortcuts leveraged Windows Script Host and ActiveX to initiate a Tor proxy, establishing a connection to a hidden command-and-control (C2) server. The primary objective of this campaign was to deploy a cryptocurrency clipper, designed to intercept and alter clipboard contents, thereby redirecting cryptocurrency transactions to attacker-controlled wallets. This incident underscores the persistent threat posed by USB-based malware and the evolving tactics of cybercriminals who exploit legitimate Windows functionalities to evade detection. The use of Tor for C2 communication highlights the increasing adoption of anonymization techniques by threat actors, complicating traditional network defense strategies.
1 month ago
Kill Chain
Red Hat npm Supply Chain Attack: A Wake-Up Call for Software Security
In June 2026, Red Hat's npm packages were compromised in a significant supply chain attack. Threat actors infiltrated the @redhat-cloud-services namespace, injecting a credential-stealing worm into 32 packages, affecting 96 versions. These malicious packages, downloaded over 116,000 times weekly, exploited GitHub Actions' OpenID Connect to publish the compromised code, indicating a breach in the CI/CD pipeline. The attack led to unauthorized access to sensitive credentials, posing substantial risks to downstream users. ([aikido.dev](https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting trusted software ecosystems. Organizations must enhance their security measures, particularly in CI/CD pipelines, to prevent similar breaches. The event highlights the necessity for continuous monitoring and rapid response strategies to mitigate the impact of such sophisticated attacks.
1 month ago
Kill Chain
Mastra npm Supply Chain Attack: A 2026 Case Study
In June 2026, a significant supply chain attack targeted the Mastra npm ecosystem, compromising over 140 packages. The attack originated from the hijacking of the 'ehindero' npm maintainer account, which was used to publish malicious versions of Mastra packages. These versions introduced 'easy-day-js,' a typosquat of the popular 'dayjs' library. Upon installation, 'easy-day-js' executed a postinstall script that disabled TLS certificate verification, contacted attacker-controlled command-and-control infrastructure, downloaded a second-stage payload, and executed it as a hidden process. This sophisticated attack posed substantial risks to developers and organizations relying on the affected packages. This incident underscores the escalating threat of supply chain attacks within the open-source ecosystem. The attackers' use of typosquatting and account hijacking highlights the need for enhanced security measures in package management and distribution. Organizations must remain vigilant, regularly audit their dependencies, and implement robust security practices to mitigate such risks.
1 month ago
Kill Chain
FreeBSD CVE-2026-3038: Understanding the Critical Kernel Vulnerability
In March 2026, a critical vulnerability identified as CVE-2026-3038 was discovered in the FreeBSD kernel's rtsock_msg_buffer() function. This flaw allows unprivileged users to trigger a stack buffer overflow by crafting malicious routing socket requests, leading to immediate kernel panics due to stack canary corruption. The vulnerability affects FreeBSD versions 13.5, 14.3, and 15.0 prior to specific patches. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2026-3038&utm_source=openai)) The discovery of CVE-2026-3038 underscores the ongoing challenges in securing kernel-level code, highlighting the need for rigorous validation of user-supplied data. This incident serves as a reminder of the importance of timely patching and continuous monitoring to mitigate potential exploits that could lead to system crashes or privilege escalation.
1 month ago
Kill Chain
Malware Developers Use Forbidden Text to Thwart AI Analysis
In June 2026, security researchers identified a novel technique where malware developers embed forbidden text related to nuclear and biological weapons within spyware code. This method aims to disrupt AI-based analysis tools by causing them to refuse processing or misclassify the malware, thereby evading detection. The malicious code is concealed within large JavaScript comments containing sensitive keywords, followed by obfuscated payloads executed at runtime. This approach targets AI systems that lack robust content isolation, leading to analysis failures and potential security breaches. This incident underscores the evolving tactics of cyber adversaries who exploit AI vulnerabilities to bypass detection mechanisms. The use of forbidden text to manipulate AI analysis highlights the need for enhanced security measures in AI-driven systems, emphasizing the importance of developing resilient AI models capable of handling adversarial inputs without compromising performance.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports