✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Supply Chain Attack on Hola Browser Leads to Cryptominer Distribution
In June 2026, the Windows version of the Hola Browser was compromised through a supply chain attack, leading to the distribution of an unauthorized executable identified as a cryptocurrency miner. This incident was uncovered during routine certification checks by AppEsteem, revealing that the compromised software installed an undeclared file named 'me.exe' in the 'C:\Program Files\Hola\' directory. Further analysis confirmed that this file was a Monero cryptocurrency miner, which added a Windows Defender exclusion rule, copied itself as 'HolaMonitorService.exe,' created an auto-starting Windows service named 'hola_monitor_svc,' and operated when the computer was idle. Hola's CEO, Avi Raz Cohen, acknowledged the breach, stating that approximately 0.1% of users were affected, with no evidence of user data access or theft. In response, Hola rebuilt its distribution pipeline, implemented advanced code-signing verification, and introduced stricter access controls and continuous monitoring across its infrastructure. This incident underscores the persistent threat of supply chain attacks targeting widely used software applications. The compromise of Hola Browser highlights the importance of rigorous security measures in software distribution channels to prevent unauthorized code insertion. Organizations and individual users must remain vigilant, ensuring that software updates and installations come from verified sources and are subjected to thorough security assessments to mitigate the risks associated with such attacks.
1 month ago
Kill Chain
AI-Powered Malware Testing: A New Era of EDR Evasion
In June 2026, Sophos X-Ops analysts identified a threat actor utilizing artificial intelligence (AI) technologies to develop and test malware designed to evade endpoint detection and response (EDR) systems. The attackers employed AI-generated Python scripts, written in Russian, to automate the creation and evaluation of malicious payloads against EDR agents from Sophos, CrowdStrike, and Windows Defender. This process involved an automated Active Directory panel that coordinated tasks, dispatched work to remote agents, and iteratively refined the malware based on testing outcomes. The attackers' infrastructure included multiple virtual machines running Windows Server 2022, each dedicated to testing EDR evasion techniques, and a Sliver post-exploitation framework C2 server operating on Ubuntu. This incident underscores a significant evolution in cyberattack methodologies, highlighting the integration of AI to enhance the efficiency and effectiveness of malware development. The structured and automated approach observed indicates a trend towards more sophisticated and scalable attack frameworks, posing increased challenges for cybersecurity defenses.
1 month ago
Kill Chain
Critical Vulnerability in Mirasvit Full Page Cache Warmer: Immediate Action Required
In May 2026, a critical vulnerability (CVE-2026-45247) was identified in Mirasvit's Full Page Cache Warmer extension for Magento 2, versions prior to 1.11.12. This flaw allows unauthenticated attackers to execute arbitrary code on affected servers by exploiting a PHP object injection via the 'CacheWarmer' cookie. The vulnerability arises from the unsafe use of PHP's 'unserialize()' function, enabling remote code execution without authentication. ([sansec.io](https://sansec.io/research/mirasvit-cache-warmer-object-injection?utm_source=openai)) The inclusion of this vulnerability in CISA's Known Exploited Vulnerabilities catalog underscores its active exploitation and the significant risk it poses to e-commerce platforms. Organizations using the affected versions are urged to update to version 1.11.12 immediately to mitigate potential breaches and data compromises. ([blog.gridinsoft.com](https://blog.gridinsoft.com/mirasvit-cve-2026-45247-cachewarmer-rce/?utm_source=openai))
1 month ago
Kill Chain
Beware: Fake Open-Source Tool Sites Spreading Malware via TDS
In June 2026, cybersecurity researchers identified a large-scale campaign where threat actors created counterfeit websites mimicking popular open-source and freeware tools such as Ghidra, dnSpy, and SpiderFoot. These deceptive sites, designed to appear legitimate, employed a Traffic Distribution System (TDS) to redirect users to malicious payloads, including Remus Stealer, AnimateClipper, and the SessionGate framework. The attackers utilized search engine optimization (SEO) techniques to rank these fake sites prominently on search engines like Google, increasing the likelihood of user engagement and subsequent malware infections. This incident underscores a growing trend where cybercriminals exploit SEO and TDS mechanisms to distribute malware through seemingly trustworthy channels. The sophistication of these attacks highlights the need for heightened vigilance among users and organizations, emphasizing the importance of verifying the authenticity of software download sources to mitigate the risk of malware infections.
1 month ago
Kill Chain
Operation FlutterBridge: Unveiling the FlutterShell Backdoor Targeting macOS Users
In June 2026, cybersecurity researchers identified 'Operation FlutterBridge,' a sophisticated malvertising campaign targeting macOS users. This operation distributes a new backdoor named 'FlutterShell,' built using Google's Flutter framework. The campaign employs malicious Google and YouTube advertisements to lure users into downloading seemingly legitimate desktop applications, which, upon execution, install FlutterShell. This malware combines adware functionalities with backdoor capabilities, including shell command execution and file system manipulation. Some variants also exploit AI summarization features for data exfiltration by routing documents through attacker-controlled servers. The campaign is linked to the cybercrime group CL-CRI-1089, previously associated with the JSCoreRunner campaign detected in August 2025. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/flutterbridge-new-fluttershell-backdoor/?utm_source=openai)) The use of the Flutter framework in malware development is notable, as it allows attackers to dynamically alter the malware's behavior without recompiling or redistributing the application. This adaptability, combined with the extensive reach of malvertising through trusted platforms like Google and YouTube, underscores the evolving sophistication of cyber threats targeting macOS systems. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/flutterbridge-new-fluttershell-backdoor/?utm_source=openai))
1 month ago
Kill Chain
Critical Vulnerability in Claude Code GitHub Action Leads to Repository Hijacking
In June 2026, a critical vulnerability was discovered in Anthropic's Claude Code GitHub Action, allowing attackers to hijack public repositories by exploiting a flaw in the action's workflow permissions. By opening a malicious GitHub issue, attackers could execute arbitrary code, potentially compromising the integrity of affected repositories and their downstream projects. This vulnerability was promptly addressed by Anthropic with the release of claude-code-action v1.0.94. This incident underscores the escalating risks associated with supply chain attacks in software development, particularly those leveraging continuous integration and deployment (CI/CD) pipelines. Organizations must remain vigilant, regularly updating their CI/CD tools and scrutinizing third-party actions to mitigate such vulnerabilities.
1 month ago
Kill Chain
Unveiling 'Otto Support': A Deep Dive into MCP Server Security Flaws
In April 2026, Bishop Fox released 'Otto Support,' a deliberately vulnerable Model Context Protocol (MCP) server designed to expose security flaws in AI agent integrations. This tool demonstrated how AI agents could exploit misconfigurations to escalate privileges and access sensitive data, highlighting critical vulnerabilities in MCP implementations. The project underscored the necessity for robust authentication, authorization, and input validation controls in AI systems. The release of 'Otto Support' is particularly relevant now, as the rapid adoption of AI agents has outpaced the implementation of essential security measures. This initiative serves as a crucial reminder for organizations to proactively assess and fortify their AI infrastructures against emerging threats.
1 month ago
Kill Chain
Meta AI Chatbot Exploited in High-Profile Instagram Account Hijacks
In June 2026, a significant security vulnerability was discovered in Meta's AI-powered customer support chatbot, allowing attackers to hijack high-profile Instagram accounts. Hackers exploited the chatbot by requesting password reset codes for target accounts, which the AI provided without proper identity verification. This flaw enabled unauthorized access to accounts such as the Obama-era White House handle and Sephora's official page. Meta promptly addressed the issue and secured the affected accounts. ([techcrunch.com](https://techcrunch.com/2026/06/01/hackers-hijacked-instagram-accounts-by-tricking-meta-ai-support-chatbot-into-granting-access/?utm_source=openai)) This incident underscores the risks associated with automating sensitive user functions without adequate safeguards. It highlights the necessity for robust security measures and human oversight in AI-driven systems, especially as organizations increasingly rely on automation for customer support and account management. ([investing.com](https://www.investing.com/news/stock-market-news/analysishighprofile-meta-ai-chatbot-breach-spotlights-security-risks-of-automation-4723672?utm_source=openai))
1 month ago
Kill Chain
Navigating the New Era of AI-Driven Cybersecurity Threats
In early 2026, Moderna's development environment experienced a significant disruption when XBOW's autonomous offensive security platform identified and exploited a vulnerability, leading to a complete system takedown. This incident underscored the rapid advancements in AI-driven vulnerability discovery, where models like Claude Mythos have demonstrated the capability to autonomously uncover and exploit critical vulnerabilities across various systems. The accelerated pace of AI in identifying security flaws has outstripped traditional remediation processes, posing challenges for organizations in maintaining secure infrastructures. As AI continues to evolve, the cybersecurity landscape faces a pressing need to adapt, emphasizing the importance of integrating AI-driven tools for both offensive and defensive strategies to effectively manage and mitigate emerging threats.
1 month ago
Kill Chain
WeedHack Malware Campaign Compromises Over 116,000 Minecraft Systems
In early 2026, a large-scale malware campaign named 'WeedHack' targeted Minecraft players, infecting over 116,000 systems by June. The malware was disseminated through malicious Minecraft mods, clients, cheats, and utilities promoted via YouTube videos and SEO poisoning techniques. Once installed, WeedHack functioned as a malware-as-a-service (MaaS) infostealer, providing attackers with dashboards to access stolen credentials and information from compromised systems. The campaign primarily affected users in the United States, Germany, India, and the UK, with an average of 2,000 to 3,000 new infections daily. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/over-116-000-mincraft-systems-infected-in-weedhack-malware-campaign/?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals who exploit popular gaming platforms to distribute malware. The use of trusted platforms like YouTube for distribution highlights the need for increased vigilance among users and the importance of downloading software only from official and reputable sources. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/over-116-000-mincraft-systems-infected-in-weedhack-malware-campaign/?utm_source=openai))
1 month ago
Kill Chain
Critical VS Code Zero-Day Exposes GitHub Repositories
In June 2026, security researcher Ammar Askar disclosed a zero-day vulnerability in Visual Studio Code (VS Code) that enables attackers to steal GitHub OAuth tokens by tricking users into clicking a malicious link. The exploit leverages VS Code's sandboxed webview message-passing system to install malicious extensions, allowing unauthorized access to all private repositories accessible by the victim. This vulnerability remains unpatched, posing a significant risk to developers and organizations relying on VS Code for GitHub repository management. The disclosure underscores the critical need for vigilance in software supply chains, especially concerning widely used development tools. As similar supply chain attacks increase, organizations must implement robust security measures, including regular audits of development environments and cautious evaluation of third-party extensions, to mitigate potential threats.
1 month ago
Kill Chain
Marquis Software 2025 Ransomware Breach: A Wake-Up Call for Third-Party Risk Management
In August 2025, Marquis Software Solutions, a fintech firm serving over 70 banks and credit unions, suffered a ransomware attack that compromised sensitive personal and financial data of more than 1.3 million individuals. The breach was attributed to a vulnerability in SonicWall's firewall backup service, which allowed attackers to access Marquis's internal network. Exposed information included names, addresses, Social Security numbers, and financial account details. This incident underscores the critical importance of securing third-party services and the potential cascading effects of supply chain vulnerabilities. ([claimdepot.com](https://www.claimdepot.com/data-breach/marquis-software-solutions-2025?utm_source=openai)) The Marquis breach highlights the escalating risks associated with third-party service providers in the financial sector. As cyberattacks become more sophisticated and supply chain vulnerabilities more prevalent, organizations must adopt comprehensive security measures, including continuous monitoring and regular penetration testing, to safeguard sensitive data and maintain regulatory compliance.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports