The Containment Era is here. →Explore

Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

1801 threat reports
Page 33 of 151

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer Software/Engineering Threat Reports

Showing 385396 / 1801 reports
IronWorm and Miasma Worm Supply Chain Attacks on npm - June 2026
Impact· HIGH

IronWorm and Miasma Worm Supply Chain Attacks on npm - June 2026

In early June 2026, the npm ecosystem faced significant supply chain attacks involving the IronWorm and a new variant of the Miasma worm. Threat actors compromised over 50 legitimate npm packages to distribute a Rust-based information stealer and a self-propagating worm. The IronWorm malware, concealed by an eBPF kernel rootkit, harvested sensitive data from developers' machines and propagated by injecting malicious code into GitHub repositories. Concurrently, the Miasma worm variant targeted 57 npm packages, deploying credential-stealing payloads that executed during package installation, compromising cloud credentials and CI/CD secrets. These attacks underscore the escalating threats to software supply chains, emphasizing the need for robust security measures in package management and development workflows. The rapid propagation and sophisticated techniques employed highlight the urgency for organizations to enhance their defenses against such evolving threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Toshiba and Muji Websites Compromised by Malicious Polyfill.io Scripts
Impact· MEDIUM

Toshiba and Muji Websites Compromised by Malicious Polyfill.io Scripts

In early June 2026, Toshiba and Muji reported unauthorized login prompts appearing on their websites, potentially compromising user credentials. These prompts were linked to the external service polyfill.io, which had previously introduced malicious code in 2024. Both companies advised users who entered their credentials to change their passwords immediately. The issue has since been resolved, with the affected service suspended. This incident underscores the persistent risks associated with third-party services and the importance of regular security audits. Organizations must remain vigilant, especially when integrating external code, to prevent similar vulnerabilities.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Gartner Highlights Four Critical Cybersecurity Threats for 2026
Impact· CRITICAL

Gartner Highlights Four Critical Cybersecurity Threats for 2026

In June 2026, Gartner analysts highlighted four critical cybersecurity threats where attackers currently have the upper hand: deepfakes, software supply chain risks, prompt injections, and AI application compromises. These threats exploit vulnerabilities in enterprise defenses, leading to significant security breaches and operational disruptions. Organizations are urged to enhance their security postures by implementing additional controls and stronger policies to mitigate these emerging risks. The urgency to address these threats is underscored by the rapid evolution of attack techniques and the increasing sophistication of threat actors. Enterprises must proactively adapt their security strategies to counteract these advanced threats and protect their assets effectively.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
IronWorm Malware: A 2026 npm Supply Chain Attack
Impact· HIGH

IronWorm Malware: A 2026 npm Supply Chain Attack

In June 2026, a sophisticated supply chain attack named 'IronWorm' targeted the npm ecosystem, compromising 36 packages with over 32,000 combined monthly downloads. The Rust-written malware infiltrated developers' environments through malicious npm package updates, harvesting sensitive credentials such as API keys, cloud credentials, SSH keys, and npm publishing tokens. Utilizing a rootkit that exploits the Linux kernel's eBPF, IronWorm concealed its activities and communicated with command-and-control servers via the Tor network, enabling it to propagate further across the software supply chain. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/rust-written-ironworm-npm-supply-chain?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks within open-source ecosystems. The use of advanced techniques like eBPF rootkits and Tor-based communications highlights the increasing sophistication of threat actors. Organizations must enhance their security measures to protect development environments and prevent the infiltration of malicious code into trusted software projects. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/rust-written-ironworm-npm-supply-chain?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Adaptive, Agentic AI Worms: A New Era of Cyber Threats
Impact· HIGH

Adaptive, Agentic AI Worms: A New Era of Cyber Threats

In June 2026, researchers from the University of Toronto, the Vector Institute, and the University of Cambridge developed a proof-of-concept AI-driven worm capable of autonomously analyzing and exploiting vulnerabilities across diverse systems. Unlike traditional worms that rely on predefined exploits, this AI worm utilizes open-weight large language models to adapt its attack strategies in real-time, enabling it to propagate through networks by identifying and leveraging unpatched vulnerabilities and misconfigurations. The worm demonstrated the ability to compromise a simulated enterprise network spanning Linux, Windows, and IoT devices, highlighting a significant evolution in malware capabilities. ([arxiv.org](https://arxiv.org/abs/2606.03811?utm_source=openai)) This development underscores the urgent need for organizations to enhance their cybersecurity defenses against adaptive, AI-powered threats. The emergence of such autonomous malware presents a destabilizing economic asymmetry between attackers and defenders, as the worm's propagation incurs minimal cost to the attacker while posing substantial risks to enterprise networks. ([arxiv.org](https://arxiv.org/abs/2606.03811?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Hackers Exploit Critical Everest Forms Pro Plugin Flaw
Impact· CRITICAL

Hackers Exploit Critical Everest Forms Pro Plugin Flaw

In March 2026, a critical vulnerability (CVE-2026-3300) was discovered in the Everest Forms Pro WordPress plugin, affecting versions up to 1.9.12. This flaw allowed unauthenticated attackers to execute arbitrary PHP code via the plugin's 'Complex Calculation' feature, leading to full site compromise. Despite a patch released on March 18, 2026, exploitation began on April 13, 2026, with over 29,300 attempts recorded, including the creation of rogue administrator accounts named 'diksimarina'. This incident underscores the persistent threat posed by vulnerabilities in widely-used WordPress plugins. The rapid exploitation following disclosure highlights the critical need for timely patching and robust security measures to protect web assets from emerging threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft AI Red Team Enhances AI Security with Updated Failure Mode Taxonomy
Impact· HIGH

Microsoft AI Red Team Enhances AI Security with Updated Failure Mode Taxonomy

In June 2026, the Microsoft AI Red Team released an updated taxonomy of failure modes in agentic AI systems, building upon their initial April 2025 publication. This revision introduces seven new failure mode categories, expands mitigation strategies, and incorporates insights from a year of red team engagements. Key developments prompting this update include the rapid mainstream adoption of open-source agentic frameworks like OpenClaw, which, upon its January 2026 launch, revealed significant vulnerabilities such as CVE-2026-25253—a critical WebSocket hijacking flaw. Additionally, the maturation of the Model Context Protocol (MCP) ecosystem has led to an increase in vulnerabilities, with 99 CVEs reported in 2025 alone. The transition of computer-use agents from research to production has further exposed novel attack surfaces, necessitating a comprehensive reevaluation of existing security frameworks. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/06/04/updating-taxonomy-failure-modes-agentic-ai-systems-year-red-teaming-taught-us/?utm_source=openai)) This update is particularly relevant as agentic AI systems become more integrated into critical domains, amplifying the potential impact of their failure modes. The introduction of new categories like Agentic Supply Chain Compromise and Goal Hijacking underscores the evolving threat landscape. Organizations must proactively adapt their security measures to address these emerging risks, ensuring the safe deployment and operation of agentic AI systems in increasingly complex environments.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
AI-Powered Worm Demonstrates Autonomous Cyber Threat Capabilities
Impact· HIGH

AI-Powered Worm Demonstrates Autonomous Cyber Threat Capabilities

In June 2026, researchers at the University of Toronto unveiled a prototype AI-driven computer worm capable of autonomously analyzing and exploiting vulnerabilities across diverse network environments. Unlike traditional worms that rely on predefined exploits, this AI-powered worm utilizes an embedded large language model (LLM) to adapt its attack strategies in real-time, enabling it to compromise nearly 75% of a simulated corporate network within a week without human intervention. The worm operates by deploying its own LLM on infected machines, allowing it to reason about and exploit known vulnerabilities, misconfigurations, and common weaknesses as it propagates. This development marks a significant evolution in malware capabilities, demonstrating the potential for AI to enhance the adaptability and effectiveness of cyber threats. ([fortune.com](https://fortune.com/2026/06/03/a-new-ai-powered-computer-worm-could-prove-to-be-the-stuff-of-cybersecurity-nightmares/?utm_source=openai)) The emergence of AI-driven worms underscores the urgent need for advanced cybersecurity measures capable of countering adaptive and autonomous threats. As AI technologies become more accessible, the likelihood of their exploitation by malicious actors increases, posing significant risks to organizations worldwide. This incident serves as a critical reminder for businesses to invest in AI-aware security solutions and to continuously update their defense strategies to address the evolving threat landscape. ([scientificamerican.com](https://www.scientificamerican.com/article/scientists-just-built-a-powerful-ai-computer-worm-that-learns-as-it-spreads/?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft and Nightmare Eclipse: A 2026 Vulnerability Disclosure Controversy
Impact· HIGH

Microsoft and Nightmare Eclipse: A 2026 Vulnerability Disclosure Controversy

In May 2026, a security researcher known as 'Nightmare Eclipse' publicly disclosed six zero-day vulnerabilities affecting Microsoft products, including Windows Defender and BitLocker. The researcher released proof-of-concept exploit code without prior coordination with Microsoft, leading to the exploitation of three vulnerabilities—BlueHammer, RedSun, and UnDefend—in active attacks before patches were issued. Microsoft responded by threatening legal action through its Digital Crimes Unit, accusing the researcher of irresponsible disclosure that endangered customers. This incident has reignited debates within the cybersecurity community regarding the ethics and protocols of vulnerability disclosure, highlighting the delicate balance between researchers and vendors. The situation underscores the ongoing challenges in establishing trust and effective communication channels between security researchers and software vendors, emphasizing the need for clear and mutually respected disclosure policies to protect end-users.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AI Agents: The New Frontier of Insider Threats
Impact· HIGH

AI Agents: The New Frontier of Insider Threats

In June 2026, DTEX researchers identified significant security vulnerabilities associated with the integration of AI agents, specifically Anthropic's Claude Cowork, into corporate environments. Their study demonstrated how these AI tools, when misused by insiders, could facilitate unauthorized access and exfiltration of sensitive data. By issuing simple prompts, users could instruct the AI to summarize and transfer confidential information from platforms like Salesforce and Outlook, effectively bypassing traditional security controls. This exploitation underscores the potential for AI agents to be leveraged in insider threats, whether through malicious intent or inadequate security measures. The rapid advancement and deployment of AI technologies in business operations have outpaced the development of corresponding security protocols. This incident highlights the urgent need for organizations to implement robust monitoring and control mechanisms for AI tools to prevent misuse and protect sensitive data. As AI becomes more embedded in critical systems, the risk of insider threats exploiting these technologies is expected to rise, necessitating immediate attention and action from cybersecurity professionals.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
IronWorm Malware Infiltrates npm: A Wake-Up Call for Supply-Chain Security
Impact· HIGH

IronWorm Malware Infiltrates npm: A Wake-Up Call for Supply-Chain Security

In June 2026, a sophisticated supply-chain attack introduced the IronWorm malware into 36 npm packages, compromising developer environments and CI/CD systems. IronWorm, written in Rust and concealed by an eBPF kernel rootkit, exfiltrated sensitive credentials—including those for OpenAI, AWS, and npm—via the Tor network. The malware propagated by leveraging stolen credentials to publish trojanized packages, thereby infecting additional systems. This incident underscores the escalating threat of supply-chain attacks targeting open-source ecosystems, emphasizing the need for enhanced security measures in software development pipelines.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Magecart Attack Leverages Stripe API to Steal Credit Card Data
Impact· HIGH

Magecart Attack Leverages Stripe API to Steal Credit Card Data

In June 2026, a sophisticated Magecart campaign exploited Stripe's API infrastructure to host and exfiltrate stolen credit card information from e-commerce checkout pages. Attackers injected malicious JavaScript into Google Tag Manager containers, which activated on checkout pages to capture payment data. The stolen data was then obfuscated and stored within Stripe's customer records, effectively using Stripe as a storage backend for the exfiltrated information. This method allowed the skimmer to bypass traditional security measures by leveraging trusted domains like api.stripe.com. This incident underscores the evolving tactics of cybercriminals who now exploit trusted third-party services to conduct attacks, making detection and prevention more challenging. The use of legitimate platforms for malicious purposes highlights the need for continuous monitoring and advanced security measures to protect sensitive customer data.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports