The Containment Era is here. →Explore

Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

1788 threat reports
Page 5 of 149

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer Software/Engineering Threat Reports

Showing 4960 / 1788 reports
Introducing Google's Gemini 3.5 Flash Cyber: Revolutionizing Vulnerability Detection
Impact· NONE

Introducing Google's Gemini 3.5 Flash Cyber: Revolutionizing Vulnerability Detection

On July 21, 2026, Google's DeepMind announced the release of Gemini 3.5 Flash Cyber, an AI model designed to rapidly identify, validate, and patch software vulnerabilities. Built upon the 3.5 Flash architecture, this specialized model is tailored for cybersecurity applications, offering a cost-effective and efficient alternative to larger models. Initially, Gemini 3.5 Flash Cyber will be available exclusively to governments and trusted partners through CodeMender, an AI-powered agent for vulnerability discovery and patching. In evaluations, the model demonstrated superior performance, uncovering more unique vulnerabilities compared to its predecessors and other models, including Anthropic's Claude Opus 4.6. For instance, when tested on the V8 JavaScript Engine, Gemini 3.5 Flash Cyber identified 55 unique confirmed issues, surpassing the 47 found by Gemini 3.5 Flash and the 36 by Opus 4.6. This advancement underscores Google's commitment to enhancing software security through AI-driven solutions. ([deepmind.google](https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/?utm_source=openai)) The introduction of Gemini 3.5 Flash Cyber is particularly relevant in the current cybersecurity landscape, where the rapid identification and remediation of vulnerabilities are critical. As AI models become more adept at discovering security flaws, tools like Gemini 3.5 Flash Cyber provide defenders with a proactive means to address potential threats before they can be exploited. This development reflects a broader trend towards integrating AI into cybersecurity practices to bolster defenses against increasingly sophisticated attacks. ([deepmind.google](https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/?utm_source=openai))

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Apple's Hide My Email Vulnerability: A Year-Long Privacy Breach
Impact· MEDIUM

Apple's Hide My Email Vulnerability: A Year-Long Privacy Breach

In July 2026, a significant vulnerability was discovered in Apple's 'Hide My Email' feature, which is designed to protect users' real email addresses by generating random aliases. Security researcher Tyler Murphy identified that this flaw allowed attackers to unmask users' actual email addresses, thereby compromising their privacy. Despite being reported to Apple in June 2025, the issue remained unresolved for over a year, with Apple deploying a fix only on July 3, 2026. This delay has raised concerns about the effectiveness of Apple's privacy safeguards and its responsiveness to security vulnerabilities. The incident underscores the critical importance of timely vulnerability management and transparent communication in maintaining user trust. It also highlights the need for organizations to regularly audit and test their privacy features to ensure they function as intended, especially when user data protection is a key selling point.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Hacker 'Trim' Transforms AI Jailbreaks into Offensive Cyber Tool
Impact· MEDIUM

Hacker 'Trim' Transforms AI Jailbreaks into Offensive Cyber Tool

In March 2026, a Russian-speaking hacker known as "Trim" began publishing detailed guides on jailbreaking publicly available large language models (LLMs) to bypass their safety filters. By July 2026, Trim had developed and commercially launched "AI Pentest Checker," an AI-powered penetration-testing platform that integrates these jailbroken models with offensive security tools. This platform automates reconnaissance, vulnerability validation, exploitation reporting, and generates comprehensive reports, effectively weaponizing AI models for cybercriminal activities. This incident underscores the evolving threat landscape where cybercriminals are increasingly leveraging AI technologies to enhance their attack capabilities. The rapid development and commercialization of such tools highlight the urgent need for organizations to reassess their security postures and implement robust defenses against AI-driven threats.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
WP2Shell: Unauthenticated RCE Threatens Millions of WordPress Sites
Impact· CRITICAL

WP2Shell: Unauthenticated RCE Threatens Millions of WordPress Sites

In July 2026, two critical vulnerabilities in WordPress Core, identified as CVE-2026-60137 and CVE-2026-63030, were disclosed. When exploited together, these flaws, collectively termed 'WP2Shell,' allow unauthenticated remote code execution on default WordPress installations. CVE-2026-60137 is an SQL injection vulnerability in the 'author__not_in' parameter of WP_Query, while CVE-2026-63030 is a REST API batch-route confusion issue. Attackers have rapidly developed and disseminated proof-of-concept exploits, leading to widespread exploitation attempts against millions of WordPress sites worldwide. Organizations are urged to update to the latest WordPress versions immediately to mitigate this threat. ([vulncheck.com](https://www.vulncheck.com/blog/wp2shell?utm_source=openai)) The rapid exploitation of WP2Shell underscores the increasing sophistication and speed of threat actors in leveraging newly disclosed vulnerabilities. This incident highlights the critical importance of timely patching and proactive security measures to protect web assets from emerging threats.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Ivanti's AI-Driven Discovery of CVE-2026-10520
Impact· CRITICAL

Ivanti's AI-Driven Discovery of CVE-2026-10520

In June 2026, Ivanti disclosed CVE-2026-10520, a critical OS command injection vulnerability in its Sentry mobile gateway product, allowing remote unauthenticated attackers to execute code with root privileges. Notably, this flaw was identified by Ivanti's deployment of large language models (LLMs) within their engineering and security teams, marking a significant advancement in automated vulnerability detection. This incident underscores the growing role of AI in cybersecurity, highlighting both the potential and challenges of integrating LLMs into security operations. As threat actors increasingly leverage AI for attacks, organizations must adapt by incorporating advanced technologies to enhance their defensive capabilities.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
WordPress wp2shell Vulnerabilities: Immediate Action Required
Impact· CRITICAL

WordPress wp2shell Vulnerabilities: Immediate Action Required

In July 2026, two critical vulnerabilities in WordPress, identified as CVE-2026-63030 and CVE-2026-60137, collectively termed 'wp2shell,' were disclosed. These flaws enable unauthenticated remote code execution (RCE) on default WordPress installations, allowing attackers to fully compromise affected websites. Exploitation began shortly after public disclosure, with attackers deploying persistent webshells and exfiltrating hashed credentials. The vulnerabilities impact WordPress versions 6.9.0 through 7.0.1, with patches available in versions 6.9.5 and 7.0.2. Organizations are urged to apply these updates promptly to mitigate the risk of exploitation. The rapid exploitation of wp2shell underscores the critical need for timely patch management and robust security measures. With WordPress powering a significant portion of the web, the widespread impact of these vulnerabilities highlights the importance of proactive vulnerability management and continuous monitoring to safeguard digital assets.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
ENCFORGE Ransomware Targets AI Model Files via Langflow Exploit
Impact· CRITICAL

ENCFORGE Ransomware Targets AI Model Files via Langflow Exploit

In July 2026, researchers identified a sophisticated ransomware attack targeting AI infrastructure. The threat actor, known as JADEPUFFER, exploited a critical vulnerability (CVE-2025-3248) in Langflow versions prior to 1.3.0, allowing unauthenticated remote code execution. This breach led to the deployment of ENCFORGE, a Go-based ransomware designed to encrypt AI model files, including model weights, vector indexes, and training datasets. The attack compromised the host filesystem, rendering essential AI resources inaccessible and disrupting operations. This incident underscores a concerning trend: cybercriminals are increasingly focusing on AI and machine learning assets. The targeted nature of ENCFORGE highlights the need for organizations to prioritize the security of their AI infrastructure, especially as such attacks can severely impact business continuity and data integrity.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
Bit2Watt Attack: Unveiling a New Cyber-Physical Threat to Power Grids
Impact· HIGH

Bit2Watt Attack: Unveiling a New Cyber-Physical Threat to Power Grids

In July 2026, researchers from Zhejiang University unveiled the 'Bit2Watt' attack, demonstrating how cloud tenants can manipulate GPU workloads to induce high-frequency power oscillations. These oscillations have the potential to destabilize local power grids, especially those heavily reliant on renewable energy sources. The attack operates without exploiting traditional vulnerabilities, instead leveraging legitimate computational processes to create power fluctuations that can lead to significant harmonic distortion and system instability. ([thehackernews.com](https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html?m=1&utm_source=openai)) This discovery underscores the evolving nature of cyber-physical threats, highlighting the need for integrated security measures that consider both computational workloads and their physical impact on infrastructure. As data centers increasingly adopt GPU clusters and renewable energy, understanding and mitigating such vulnerabilities becomes paramount to ensure grid stability and operational continuity.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Unveiling Critical Security Flaws in Open-Source Android AI Agents
Impact· MEDIUM

Unveiling Critical Security Flaws in Open-Source Android AI Agents

In July 2026, researchers identified critical vulnerabilities in five open-source Android AI agent frameworks—AppAgent, AppAgentX, Mobile-Agent-v3, Open-AutoGLM, and MobA. Malicious Android applications with overlay and shared storage permissions can inject invisible text into the device's screen, which these AI agents process, leading to unauthorized command execution on connected host PCs. The attack exploits the agents' reliance on visual inputs and inadequate input sanitization, allowing attackers to execute arbitrary commands remotely. This incident underscores the emerging security challenges posed by AI-driven automation tools, particularly in mobile environments. As AI agents become more integrated into daily operations, their potential as attack vectors increases, necessitating robust security measures and vigilant oversight to prevent exploitation.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
WordPress 'wp2shell' Vulnerability: Immediate Action Required
Impact· CRITICAL

WordPress 'wp2shell' Vulnerability: Immediate Action Required

In July 2026, a critical vulnerability chain known as 'wp2shell' was discovered in WordPress Core, comprising CVE-2026-63030 and CVE-2026-60137. This chain allows unauthenticated remote code execution by exploiting a REST API batch-route confusion and an SQL injection flaw in the 'author__not_in' parameter of 'WP_Query'. Affected versions include WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2. Exploitation in the wild began shortly after disclosure, with attackers deploying persistent webshells on vulnerable servers. Given WordPress's extensive use, this vulnerability poses a significant risk to a vast number of websites worldwide. ([wiz.io](https://www.wiz.io/blog/wp2shell-cve-2026-63030-cve-2026-60137?utm_source=openai)) The rapid exploitation of 'wp2shell' underscores the critical need for timely patching and robust security practices. Organizations must prioritize updating their WordPress installations and consider implementing additional security measures, such as Web Application Firewalls (WAFs), to mitigate potential attacks.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(low)
Read Report
CISA Highlights Four New Exploited Vulnerabilities in KEV Catalog
Impact· CRITICAL

CISA Highlights Four New Exploited Vulnerabilities in KEV Catalog

On July 21, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. These vulnerabilities include CVE-2021-27137, a stack-based buffer overflow in DD-WRT; CVE-2026-0770, an inclusion of functionality from untrusted control sphere in Langflow; CVE-2026-63030, an interpretation conflict in WordPress Core; and CVE-2026-60137, an SQL injection in WordPress Core. Such vulnerabilities are common attack vectors for malicious actors and pose significant risks to federal enterprises. The inclusion of these vulnerabilities in the KEV Catalog underscores the ongoing threat posed by unpatched software. Organizations are urged to prioritize remediation of these vulnerabilities to mitigate potential exploitation and enhance their cybersecurity posture.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Urgent: Patch Critical WordPress Vulnerabilities CVE-2026-63030 & CVE-2026-60137
Impact· CRITICAL

Urgent: Patch Critical WordPress Vulnerabilities CVE-2026-63030 & CVE-2026-60137

In July 2026, two critical vulnerabilities, CVE-2026-63030 and CVE-2026-60137, were discovered in WordPress Core versions 6.8.0 through 7.0.1. These flaws, collectively termed "wp2shell," allow unauthenticated attackers to execute remote code by exploiting a REST API route confusion and an SQL injection vulnerability. The exploitation enables full control over affected WordPress sites, including data access, malicious code installation, and administrative privileges. ([threatprotect.qualys.com](https://threatprotect.qualys.com/2026/07/20/wordpress-wp2shell-vulnerabilities-exploited-in-the-wild-cve-2026-63030-cve-2026-60137/?utm_source=openai)) The widespread use of WordPress, powering over 500 million websites, amplifies the impact of these vulnerabilities. ([threatprotect.qualys.com](https://threatprotect.qualys.com/2026/07/20/wordpress-wp2shell-vulnerabilities-exploited-in-the-wild-cve-2026-63030-cve-2026-60137/?utm_source=openai)) Public proof-of-concept exploits have been released, and active exploitation has been observed in the wild, underscoring the urgency for immediate remediation.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports