✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Google API Keys Remain Active After Deletion: A Security Concern
In May 2026, security researchers at Aikido Security discovered that Google API keys remain active for up to 23 minutes after deletion, contrary to expectations of immediate revocation. This delay allows attackers possessing deleted keys to continue making authenticated requests, potentially leading to unauthorized data access and financial implications. The research involved multiple trials across different Google Cloud Platform regions, revealing inconsistent revocation times and highlighting a significant security gap in credential management. This finding underscores the critical need for organizations to reassess their API key management practices, especially in light of increasing reliance on cloud services. The delayed revocation poses challenges for incident response teams, emphasizing the importance of continuous monitoring and implementing additional security measures to mitigate potential exploitation during the revocation window.
2 months ago
Kill Chain
CISA Adds Two Known Exploited Vulnerabilities to Catalog
On May 21, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2025-34291, an origin validation error in Langflow, and CVE-2026-34926, a directory traversal flaw in Trend Micro Apex One (on-premise). Both vulnerabilities have been actively exploited, posing significant risks to affected systems. ([thehackernews.com](https://thehackernews.com/2026/05/cisa-adds-exploited-langflow-and-trend.html?utm_source=openai)) The inclusion of these vulnerabilities in the KEV Catalog underscores the ongoing threat posed by unpatched software flaws. Organizations are urged to prioritize remediation efforts to mitigate potential exploitation and safeguard their systems against emerging cyber threats.
2 months ago
Kill Chain
Megalodon Attack: A Wake-Up Call for CI/CD Security
In May 2026, a large-scale automated attack named 'Megalodon' compromised 5,561 GitHub repositories within a six-hour period. The attackers utilized disposable accounts and forged author identities to inject malicious GitHub Actions workflows into these repositories. These workflows contained base64-encoded bash scripts designed to exfiltrate continuous integration (CI) secrets, cloud credentials, SSH keys, and other sensitive information to a command-and-control server. The attack's rapid execution and extensive reach underscore the vulnerabilities present in CI/CD pipelines and the potential for widespread supply chain compromises. This incident highlights the escalating threat landscape targeting software supply chains, emphasizing the need for enhanced security measures in CI/CD processes. Organizations must prioritize the implementation of robust authentication mechanisms, regular audits of automated workflows, and comprehensive monitoring to detect and mitigate such sophisticated attacks.
2 months ago
Kill Chain
Cross-Platform NPM Stealer: A 2026 Supply Chain Threat
In May 2026, a sophisticated cross-platform malware targeting Node.js environments was discovered. This stealer malware, embedded within obfuscated JavaScript code, specifically aimed at Windows, macOS, and Linux systems. It was designed to extract sensitive information, including browser credentials and cryptocurrency wallet data, from various browsers such as Chrome, Brave, Edge, and others. The malware utilized Base64-encoded strings and obfuscation techniques to evade detection, with its payloads embedded in plain text. Notably, it established communication with a command-and-control server at IP address 216.126.225.243, known to be associated with the DPRK OtterCookie C2 infrastructure. This incident underscores the escalating threat posed by supply chain attacks within the npm ecosystem. The malware's ability to operate across multiple platforms and its focus on exfiltrating sensitive data highlight the need for enhanced vigilance among developers and organizations. The use of obfuscation and legitimate-looking code to mask malicious intent further complicates detection efforts, emphasizing the importance of robust security practices and continuous monitoring of software dependencies.
2 months ago
Kill Chain
Strengthening CI/CD Security: Enhancements to zizmor's GitHub Actions Analyzer
In March 2026, attackers exploited a misconfiguration in the `aquasecurity/trivy-action` GitHub Action, leading to the exfiltration of organization and repository secrets. These credentials were subsequently used to backdoor LiteLLM on PyPI. The static analyzer `zizmor` is designed to detect such misconfigurations in GitHub Actions workflows. However, with GitHub Actions' introduction of YAML anchors in September 2025, `zizmor` faced challenges in analyzing workflows utilizing this feature. Over a three-month collaboration, Trail of Bits and `zizmor` maintainers enhanced `zizmor`'s support for YAML anchors, addressing parsing bugs and improving its expression evaluator. This effort involved testing against a corpus of 41,253 workflows from 6,612 high-value open-source repositories, resulting in 20 filed issues and 15 merged pull requests. The enhancements ensure `zizmor` can more effectively identify and prevent misconfigurations in GitHub Actions workflows, bolstering the security of CI/CD pipelines. This incident underscores the critical importance of securing CI/CD pipelines against supply chain attacks. As attackers increasingly target CI/CD automation, tools like `zizmor` play a vital role in identifying and mitigating vulnerabilities before they can be exploited. The collaboration between Trail of Bits and `zizmor` highlights the necessity of continuous improvement and vigilance in the face of evolving threats.
2 months ago
Kill Chain
AI Uncovers Critical macOS Kernel Vulnerability in Record Time
In May 2026, cybersecurity firm Calif utilized Anthropic's advanced AI model, Mythos Preview, to identify and exploit a kernel memory corruption vulnerability in Apple's macOS 26.4.1 running on M5 silicon. This exploit enabled privilege escalation from an unprivileged user to root access by chaining two vulnerabilities, effectively bypassing Apple's Memory Integrity Enforcement (MIE) system, a hardware-assisted security feature introduced in 2025 to mitigate memory-based exploits. The discovery underscores the potential of AI in rapidly uncovering critical system vulnerabilities, as the exploit was developed within five days. ([9to5mac.com](https://9to5mac.com/2026/05/14/calif-team-details-how-anthropic-mythos-helped-build-a-working-macos-exploit-in-five-days/?utm_source=openai)) This incident highlights the evolving cybersecurity landscape where AI tools can both uncover and potentially exploit system vulnerabilities at unprecedented speeds. Organizations must reassess their security postures to address the dual-edged nature of AI in cybersecurity, balancing its defensive capabilities against the risks of adversarial use. ([techradar.com](https://www.techradar.com/pro/security/this-work-is-a-glimpse-of-what-is-coming-security-team-lays-out-how-anthropic-mythos-helped-build-a-working-macos-exploit-in-five-days?utm_source=openai))
2 months ago
Kill Chain
GitHub's 2026 Security Breach: A Supply Chain Attack via Malicious Nx Console Extension
In May 2026, GitHub experienced a significant security breach when an employee inadvertently installed a malicious version of the Nx Console Visual Studio Code extension. This compromised extension, linked to the TanStack npm supply-chain attack orchestrated by the TeamPCP threat group, granted unauthorized access to approximately 3,800 internal repositories. The attackers exfiltrated internal source code and sensitive operational data, subsequently offering the stolen data for sale at a minimum of $50,000. GitHub promptly responded by securing the compromised device, rotating critical secrets, and initiating a comprehensive investigation to assess the full impact of the breach. This incident underscores the escalating threat posed by sophisticated supply chain attacks targeting trusted development tools and platforms. The exploitation of widely used extensions like Nx Console highlights the necessity for heightened vigilance and robust security measures within the software development ecosystem to prevent similar breaches in the future.
2 months ago
Kill Chain
Apple's 2025 App Store Fraud Prevention Milestones
In 2025, Apple intensified its efforts to secure the App Store, preventing over $2.2 billion in potentially fraudulent transactions. The company rejected more than 2 million problematic app submissions, blocked over 1.1 billion fraudulent account creations, and terminated 193,000 developer accounts due to fraud concerns. Additionally, Apple deactivated 40.4 million customer accounts suspected of fraud and abuse, and stopped more than 5.4 million stolen credit cards from being used. These measures reflect a significant increase in Apple's proactive stance against digital fraud compared to previous years. This escalation in fraudulent activities underscores the evolving tactics of malicious actors targeting digital platforms. Apple's comprehensive approach, combining human review with advanced machine learning, highlights the necessity for continuous innovation in fraud detection and prevention strategies to maintain user trust and platform integrity.
2 months ago
Kill Chain
Google's Accidental Disclosure of Unpatched Chromium Vulnerability in 2026
In May 2026, Google inadvertently disclosed details of an unresolved vulnerability in the Chromium browser engine, affecting browsers like Chrome, Edge, and others. This flaw allows JavaScript code to continue running in the background even after the browser is closed, potentially enabling remote code execution on users' devices. Security researcher Lyra Rebane initially reported the issue in December 2022, highlighting risks such as the creation of botnets and unauthorized traffic redirection. Despite being marked as fixed in February 2026, the vulnerability remained unpatched, leading to its accidental public exposure. The incident underscores the critical importance of timely vulnerability management and the potential consequences of premature disclosure. Organizations must remain vigilant, ensuring that security patches are thoroughly tested and deployed promptly to mitigate risks associated with unpatched vulnerabilities.
2 months ago
Kill Chain
Lucifer Drainer: The Rise of Drainer-as-a-Service in Cryptocurrency Theft
In early 2026, cybersecurity researchers uncovered the 'Lucifer Drainer,' a sophisticated Drainer-as-a-Service (DaaS) platform that facilitated large-scale cryptocurrency theft. Operating from January 2025 to early 2026, Lucifer Drainer enabled affiliates to deploy phishing websites that tricked users into connecting their crypto wallets. Once connected, malicious transactions were executed, swiftly transferring assets to attacker-controlled wallets. This operation exemplifies the industrialization of crypto theft, with the DaaS model allowing even low-skilled actors to participate in complex scams. The emergence of platforms like Lucifer Drainer underscores a significant shift in cybercriminal tactics, highlighting the need for enhanced vigilance among cryptocurrency users and platforms. The professionalization of such services indicates a growing threat landscape, necessitating robust security measures and user education to mitigate risks associated with these evolving schemes.
2 months ago
Kill Chain
GitHub Breach 2026: Lessons from the TeamPCP VS Code Extension Attack
In May 2026, GitHub experienced a significant security breach when an employee's device was compromised through a malicious Visual Studio Code (VS Code) extension. This attack, attributed to the threat group TeamPCP, led to the exfiltration of approximately 3,800 internal repositories. The attackers advertised the stolen data for sale on a cybercrime forum, seeking at least $50,000. GitHub responded by removing the malicious extension, isolating the affected endpoint, and rotating critical credentials to mitigate further risk. This incident underscores the escalating threat of supply chain attacks targeting development tools and environments. The use of poisoned extensions to infiltrate systems highlights the need for heightened vigilance and robust security measures within the software development lifecycle.
2 months ago
Kill Chain
Unveiling the 2026 Android Carrier Billing Fraud Campaign
Between March 2025 and January 2026, a sophisticated Android malware campaign targeted users in Malaysia, Thailand, Romania, and Croatia. Disguised as popular applications like Messenger, TikTok, Minecraft, and Grand Theft Auto, the malware covertly enrolled victims in premium, carrier-billed services without their knowledge. The attackers employed techniques such as WebView automation, JavaScript injection, and one-time password (OTP) interception to complete fraudulent subscription processes in the background. This operation affected nearly 250 Android apps and demonstrated a high level of technical sophistication, particularly in automating the subscription process and evading detection mechanisms. This incident underscores the evolving tactics of financially motivated threat actors who exploit legitimate app functionalities to conduct fraud. The campaign's ability to bypass user interaction and leverage platform features like Google's SMS Retriever API highlights significant security gaps in mobile ecosystems. Organizations must remain vigilant, as such attacks not only lead to financial losses for consumers but also erode trust in mobile platforms and services.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports