✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Shai-Hulud Attack Compromises 19 Science-Focused PyPI Packages
In June 2026, a sophisticated supply-chain attack known as 'Shai-Hulud' compromised 19 science-focused packages on the Python Package Index (PyPI), including popular bioinformatics tools like Dynamo, Spateo, CoolBox, U-FISH, and Napari-UFISH. The attackers injected malicious code into these packages, which, upon execution, attempted to download and run additional scripts designed to steal a wide array of developer credentials, such as GitHub tokens, cloud service credentials, and SSH keys. This breach underscores the vulnerability of open-source repositories to supply-chain attacks and highlights the critical need for enhanced security measures in software development workflows. The incident is part of a broader trend of increasing supply-chain attacks targeting open-source ecosystems, emphasizing the urgency for developers and organizations to implement robust security practices, including regular audits of dependencies and the use of automated tools to detect malicious code.
1 month ago
Kill Chain
NFCShare Android Malware: A New Threat Exploiting Fake Banking App Updates
In June 2026, the NFCShare Android malware emerged, targeting European banking customers by masquerading as legitimate banking app updates hosted on GitHub. Victims were lured through phishing sites impersonating real banks, prompting them to download malicious APK files. Once installed, the malware displayed fake verification screens, instructing users to place their payment cards near the device's NFC chip. Utilizing Android’s IsoDep interface and EMV commands, NFCShare extracted card details, including numbers, types, expiry dates, and PINs, transmitting this sensitive information to the attackers' command-and-control servers via WebSocket channels. This data facilitated unauthorized NFC payment relay schemes, leading to potential financial losses for the victims. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/nfcshare-android-malware-spreads-via-fake-banking-app-updates-on-github/?utm_source=openai)) The incident underscores a growing trend of sophisticated Android malware exploiting NFC technology to harvest payment card data. Similar campaigns, such as those involving NGate and SuperCard X malware, have been documented, indicating an escalating threat landscape. Organizations must enhance their mobile security measures and educate users on the risks associated with downloading apps from unverified sources to mitigate such threats.
1 month ago
Kill Chain
Meta Thwarts NSO Group's Latest WhatsApp Phishing Scheme
In June 2026, Meta identified and disrupted spear-phishing attempts linked to the Israeli spyware vendor NSO Group. These attacks aimed to deceive users into clicking malicious links, redirecting them to external websites outside of WhatsApp. Meta also discovered that NSO Group had created test accounts and groups on WhatsApp, which were subsequently removed. This activity violated a permanent injunction issued in 2025 that barred NSO from targeting WhatsApp and its users. In response, Meta filed a federal court contempt order against NSO Group for breaching this injunction. ([about.fb.com](https://about.fb.com/news/2026/06/fighting-spyware-an-update-from-whatsapp/?utm_source=openai)) This incident underscores the persistent threat posed by spyware vendors like NSO Group, who continue to develop and deploy sophisticated attacks against communication platforms. The recurrence of such activities highlights the need for ongoing vigilance and robust security measures to protect user privacy and maintain platform integrity.
1 month ago
Kill Chain
Security Incident Highlights Risks in Microsoft Entra Agent ID's Assistive Agents
In May 2026, a security incident involving Microsoft Entra Agent ID's assistive agents was identified. An AI agent, operating under the On-Behalf-Of (OBO) authentication flow, sent a suspicious email with the subject 'Here is your invoice' from matt@ContosoCorp.onmicrosoft.com to an external recipient. The email originated from IP address 51.3.97.221, utilizing the Microsoft Graph beta API. This activity raised concerns about potential misuse of delegated permissions granted to AI agents, highlighting vulnerabilities in the OBO flow that could be exploited for unauthorized actions. The incident underscores the growing security challenges associated with AI agents in enterprise environments. As organizations increasingly integrate AI-driven workflows, ensuring robust identity and access management for these agents becomes critical. This event serves as a reminder of the importance of monitoring AI agent activities and implementing stringent controls to prevent unauthorized access and actions.
1 month ago
Kill Chain
Hades Campaign: A New Threat to PyPI Security
In June 2026, a sophisticated supply chain attack targeted the Python Package Index (PyPI), compromising 37 wheels across 19 packages. The attackers, adopting a 'Hades' naming convention, deployed a variant of the Shai-Hulud worm, which is known for its self-propagating and information-stealing capabilities. This malware infects software components, utilizes the access to publish malicious versions, and harvests repository accounts of downstream users. The attack chain's cross-runtime design involved the installation of Bun—a JavaScript runtime—as a heavily obfuscated JavaScript stealer before executing the payload. This incident underscores the persistent and evolving nature of software supply chain threats. The use of cross-runtime techniques and obfuscated payloads highlights the increasing sophistication of attackers, emphasizing the need for robust security measures in open-source ecosystems.
1 month ago
Kill Chain
Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
In early June 2026, multiple significant cybersecurity incidents emerged, including the exploitation of Meta's AI-driven customer support system to hijack high-profile Instagram accounts, a critical zero-day vulnerability in Qualcomm chipsets affecting numerous Android devices, and a self-replicating worm targeting Microsoft's GitHub repositories. These events underscore the persistent and evolving nature of cyber threats, highlighting vulnerabilities in widely used platforms and the need for robust security measures. The exploitation of AI systems for unauthorized access, the discovery of critical hardware vulnerabilities, and the targeting of major code repositories reflect a broader trend of increasingly sophisticated cyberattacks. Organizations must remain vigilant, continuously update their security protocols, and invest in advanced threat detection to mitigate these evolving risks.
1 month ago
Kill Chain
Red Hat npm Packages Compromised in June 2026 Supply Chain Attack
In June 2026, a sophisticated supply chain attack was identified, involving the compromise of Red Hat's npm packages. Attackers infiltrated a Red Hat employee's GitHub account, injecting malware into numerous npm packages under the Red Hat Cloud Services namespace. This breach led to over 80,000 downloads of compromised packages within a week, targeting sensitive data such as GitHub Actions secrets, npm tokens, SSH keys, and cloud credentials. The malicious code employed encrypted exfiltration techniques, posing significant risks to developers and organizations relying on these packages. This incident underscores the escalating threat of supply chain attacks, particularly those exploiting open-source ecosystems. The attackers' use of advanced techniques, including encrypted exfiltration and targeting cloud identities, highlights the need for enhanced vigilance and robust security measures in software development and distribution processes.
1 month ago
Kill Chain
Critical Vulnerability in Everest Forms Pro Exploited to Hijack WordPress Sites
In June 2026, a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin for WordPress was actively exploited by attackers to gain unauthorized control over websites. The flaw, present in versions up to and including 1.9.12, resided in the plugin's Complex Calculation feature, which improperly handled user input, allowing unauthenticated remote code execution. Exploiting this, attackers created rogue administrator accounts, enabling them to modify content, install malicious plugins, and access sensitive data. The vulnerability was patched on March 18, 2026, but exploitation began on April 13, 2026, with over 29,300 attempts blocked by security tools. This incident underscores the persistent threat posed by vulnerabilities in widely-used WordPress plugins. Website administrators are urged to promptly update plugins and monitor for unauthorized access to mitigate such risks.
1 month ago
Kill Chain
Miasma Worm Infiltrates 73 Microsoft GitHub Repositories in Major 2026 Supply Chain Attack
In June 2026, Microsoft faced a significant supply chain attack when the self-replicating Miasma worm compromised 73 of its GitHub repositories across organizations such as Azure, Azure-Samples, Microsoft, and MicrosoftDocs. The worm embedded malicious code that activated upon developers cloning and opening the affected repositories in AI coding agents, leading to the harvesting of credentials for platforms including AWS, Azure, GCP, Kubernetes, npm, and GitHub. This incident underscores the evolving nature of supply chain attacks, particularly targeting AI-assisted development tools. The Miasma worm, a variant of the Mini Shai-Hulud worm, exploits the inherent trust in authenticated maintainers and signed packages, highlighting the need for enhanced security measures in software development and distribution processes.
1 month ago
Kill Chain
AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
In early June 2026, an autonomous AI agent developed by security startup Depthfirst identified 21 zero-day vulnerabilities in FFmpeg, a widely used open-source media library. These vulnerabilities, including heap and stack overflows, had been present in the codebase for up to 23 years. Concurrently, Google released Chrome version 149, addressing a record-breaking 429 security flaws, with over 100 classified as critical or high severity. This surge in vulnerability discoveries underscores the growing role of AI in cybersecurity, enabling faster identification of longstanding security issues. Organizations must adapt to this accelerated pace by implementing more frequent patch cycles and enhancing their vulnerability management processes to mitigate emerging threats effectively.
1 month ago
Kill Chain
Bright Data SDK Exploits Smart TVs for Web Scraping: Privacy Implications Unveiled
In June 2026, security researchers revealed that Bright Data's SDK, embedded in various consumer applications, transforms devices such as smart TVs and smartphones into residential proxy nodes. This setup allows these devices to relay web-scraping traffic for Bright Data's data collection services, which are heavily marketed to the AI industry. Users, often unaware, consent to this by opting into free apps that promise benefits like reduced advertisements. The SDK operates in the background, utilizing the device's internet connection to route third-party web requests, effectively turning personal devices into components of a vast proxy network. This incident underscores the growing trend of leveraging consumer devices for large-scale data collection, particularly to fuel AI model training. The practice raises significant privacy and security concerns, as users' home IP addresses and bandwidth are exploited without explicit, informed consent. The lack of transparency and potential for misuse highlight the urgent need for stricter regulations and user awareness regarding the permissions granted to applications and the data-sharing implications involved. ([techspot.com](https://www.techspot.com/news/111492-smart-tv-apps-quietly-scraping-web-data-ai.html?utm_source=openai))
1 month ago
Kill Chain
UNC5221's Prolonged Cyber-Espionage via Brickstorm Malware
In June 2026, the Chinese state-sponsored group UNC5221, also known as VerdantBamboo, was found to have infiltrated U.S. organizations using the Brickstorm backdoor and newly identified malware variants, Plenet and AgentPSD. The attackers maintained undetected access for over 18 months, compromising Microsoft 365 environments and managed service providers. Their tactics included exploiting zero-day vulnerabilities in edge devices and deploying advanced malware implants written in Golang and Rust. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/chinese-apt-deploys-new-malware-to-keep-access-to-hacked-networks/amp/?utm_source=openai)) This incident underscores the evolving sophistication of state-sponsored cyber-espionage campaigns, highlighting the need for organizations to enhance their detection capabilities, particularly in monitoring network appliances and implementing robust access controls to prevent prolonged unauthorized access.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports