✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Critical Spring Security Vulnerability CVE-2026-22732: What You Need to Know
In March 2026, a critical vulnerability identified as CVE-2026-22732 was discovered in Spring Security versions 5.7.0 through 7.0.3. This flaw causes HTTP response headers specified for servlet applications to be omitted, potentially exposing applications to attacks such as Cross-Site Scripting (XSS) and clickjacking. The vulnerability affects applications using the default lazy writing of HTTP headers, leading to the absence of essential security headers in responses. ([spring.io](https://spring.io/security/cve-2026-22732?utm_source=openai)) The omission of these headers undermines client-side protections, increasing the risk of sensitive data exposure and other security breaches. Organizations utilizing affected versions of Spring Security are urged to upgrade to the latest patched versions or apply recommended workarounds to mitigate this risk. ([spring.io](https://spring.io/security/cve-2026-22732?utm_source=openai))
2 months ago
Kill Chain
Quasar Linux Malware: A New Threat to Software Developers in 2026
In May 2026, cybersecurity researchers identified Quasar Linux (QLNX), a sophisticated malware targeting software developers' systems. QLNX combines rootkit, backdoor, and credential-stealing functionalities, deploying across development environments like npm, PyPI, GitHub, AWS, Docker, and Kubernetes. It achieves stealth and persistence through in-memory execution, log wiping, process name spoofing, and multiple persistence mechanisms, including LD_PRELOAD and systemd. The malware's capabilities include interactive shell access, file and process management, credential harvesting (SSH keys, browser data, cloud configurations), keylogging, and lateral movement via SSH-based techniques. By compromising developer workstations, QLNX poses a significant supply chain risk, potentially enabling attackers to publish malicious packages to public repositories. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-stealthy-quasar-linux-malware-targets-software-developers/amp/?utm_source=openai)) The emergence of QLNX underscores a growing trend of sophisticated malware targeting development environments to facilitate supply chain attacks. This incident highlights the critical need for enhanced security measures within software development pipelines to prevent unauthorized access and mitigate potential threats to software supply chains.
2 months ago
Kill Chain
DAEMON Tools Supply Chain Attack: A Wake-Up Call for Software Security
In April 2026, a sophisticated supply chain attack compromised the official installers of DAEMON Tools, a widely used virtual drive emulation software. Attackers injected malicious code into the software's installers, which were distributed from the legitimate DAEMON Tools website and signed with valid digital certificates. This allowed the malware to execute arbitrary commands and remotely control infected devices. The compromised versions, ranging from 12.5.0.2421 to 12.5.0.2434, have been in circulation since April 8, 2026. The attack has affected users in over 100 countries, with significant impacts in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China. Approximately 10% of the affected systems belong to businesses and organizations, exposing enterprise networks to severe risks. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/kaspersky-identifies-ongoing-supply-chain-attack-on-official-daemon-tools-website-distributing-backdoor-malware?utm_source=openai)) This incident underscores the growing threat of supply chain attacks, where trusted software is exploited to distribute malware. The DAEMON Tools compromise highlights the need for organizations to implement stringent software procurement protocols, conduct regular security audits, and enforce strict administrative privileges to mitigate such risks. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/kaspersky-identifies-ongoing-supply-chain-attack-on-official-daemon-tools-website-distributing-backdoor-malware?utm_source=openai))
2 months ago
Kill Chain
Urgent: cPanel Vulnerability CVE-2026-41940 Under Active Exploitation
In late April 2026, a critical authentication bypass vulnerability, CVE-2026-41940, was disclosed in cPanel and WHM software, affecting versions after 11.40. This flaw allows unauthenticated remote attackers to gain administrative access to servers, posing a significant risk to millions of websites. Within 24 hours of disclosure, multiple threat actors began exploiting the vulnerability, leading to server compromises, website defacements, and ransomware deployments. Notably, the "sorry" ransomware encrypts files and appends a ".sorry" extension, with over 7,000 cPanel instances identified as compromised. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/04/multiple-threat-actors-actively-exploit-cpanel-vulnerability-cve-2026-41940/?utm_source=openai)) The rapid exploitation of CVE-2026-41940 underscores the critical need for organizations to promptly apply security patches and implement robust monitoring systems. The incident highlights the increasing speed at which threat actors exploit newly disclosed vulnerabilities, emphasizing the importance of proactive cybersecurity measures.
2 months ago
Kill Chain
ScarCruft's Supply Chain Attack: Deploying BirdCall Malware via Gaming Platform
In late 2024, the North Korea-aligned advanced persistent threat group ScarCruft executed a supply chain attack on the gaming platform sqgame[.]net, which serves ethnic Koreans in China's Yanbian region. The attackers compromised the platform's Windows client through a malicious update, introducing the RokRAT backdoor that subsequently deployed the more sophisticated BirdCall malware. Additionally, Android games available on the platform were trojanized to include an Android variant of BirdCall. This malware enabled extensive surveillance capabilities, including the collection of personal data, documents, screenshots, and voice recordings. The campaign's primary objective appears to be espionage, likely targeting individuals of interest to the North Korean regime, such as refugees or defectors. ([globenewswire.com](https://www.globenewswire.com/news-release/2026/05/05/3288022/0/en/north-korea-aligned-apt-group-scarcruft-compromises-gaming-platform-in-supply-chain-espionage-attack-eset-research-finds.html?utm_source=openai)) This incident underscores the evolving threat landscape, where state-sponsored actors are increasingly leveraging supply chain attacks to infiltrate trusted platforms and distribute malware across multiple operating systems. The use of both Windows and Android variants of BirdCall highlights the adaptability of threat actors in targeting a broad range of devices to achieve their espionage goals. ([thehackernews.com](https://thehackernews.com/2026/05/scarcruft-hacks-gaming-platform-to.html?utm_source=openai))
2 months ago
Kill Chain
MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks
In April 2026, a critical vulnerability identified as CVE-2026-29014 was discovered in MetInfo CMS versions 7.9, 8.0, and 8.1. This unauthenticated PHP code injection flaw allows remote attackers to execute arbitrary code by sending crafted requests containing malicious PHP code. The vulnerability stems from insufficient input neutralization in the execution path, specifically within the "/app/system/weixin/include/class/weixinreply.class.php" script, leading to potential full control over affected servers. ([thehackernews.com](https://thehackernews.com/2026/05/metinfo-cms-cve-2026-29014-exploited.html?utm_source=openai)) As of May 2026, active exploitation of this vulnerability has been observed, with attackers targeting MetInfo CMS instances, particularly in China and Hong Kong. The ease of exploitation and the critical nature of the flaw underscore the urgency for organizations using affected versions to apply the available patches promptly to mitigate the risk of server compromise. ([thehackernews.com](https://thehackernews.com/2026/05/metinfo-cms-cve-2026-29014-exploited.html?utm_source=openai))
2 months ago
Kill Chain
Understanding the 'Copy Fail' Linux Vulnerability (CVE-2026-31431) and Its Implications
In April 2026, Theori disclosed a critical local privilege escalation vulnerability, CVE-2026-31431, dubbed 'Copy Fail,' affecting Linux kernels since 2017. This flaw resides in the 'algif_aead' cryptographic interface, allowing unprivileged users to escalate privileges to root, thereby gaining full system control. Major distributions like Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 10.1, and SUSE 16 are impacted. The vulnerability has been actively exploited in the wild, prompting the Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities catalog. ([tomshardware.com](https://www.tomshardware.com/software/linux/cisa-flags-actively-exploited-copy-fail-linux-kernel-flaw-enabling-root-takeover-across-major-distros-unpatched-systems-may-remain-vulnerable-to-attack?utm_source=openai)) The rapid public disclosure and the availability of a reliable proof-of-concept exploit have heightened concerns, especially in cloud and multi-tenant environments where untrusted code execution is common. Organizations are urged to apply patches promptly and consider temporary mitigations, such as disabling the affected cryptographic modules, to protect against potential exploitation. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/?utm_source=openai))
2 months ago
Kill Chain
PyTorch Lightning Supply Chain Attack: A Wake-Up Call for Developers
In April 2026, versions 2.6.2 and 2.6.3 of the PyTorch Lightning package were compromised and published on the Python Package Index (PyPI). These versions contained malicious code that, upon import, initiated a background process to download and execute an obfuscated JavaScript payload. This payload targeted sensitive information, including environment files, API keys, GitHub tokens, and credentials stored in browsers such as Chrome, Firefox, and Brave. Additionally, it interacted with cloud service APIs (AWS, Azure, GCP) to exfiltrate credentials and had the capability to execute arbitrary system commands. This incident underscores the escalating threat of supply chain attacks in the software development ecosystem. The compromise of widely-used packages like PyTorch Lightning highlights the need for enhanced vigilance and robust security measures in managing software dependencies to prevent unauthorized access and data breaches.
2 months ago
Kill Chain
Weaver E-cology CVE-2026-22679 Exploitation: A Critical Security Alert
In mid-March 2026, attackers began exploiting CVE-2026-22679, a critical unauthenticated remote code execution vulnerability in Weaver E-cology 10.0, an enterprise office automation platform. The flaw resides in an exposed debug API endpoint that allows user-supplied parameters to reach backend Remote Procedure Call (RPC) functionality without authentication or input validation. This enables attackers to execute arbitrary system commands on the server. The attacks commenced five days after the vendor released a security update on March 12, 2026, and two weeks before the vulnerability was publicly disclosed. The exploitation involved multiple phases, including initial reconnaissance through ping commands, attempts to deploy PowerShell-based payloads, and the use of obfuscated, fileless PowerShell scripts to fetch remote scripts. Despite these efforts, the attackers did not establish a persistent session on the targeted hosts.
2 months ago
Kill Chain
Rising Threat: Amazon SES Phishing Abuse in 2026
In May 2026, cybersecurity researchers identified a significant increase in phishing campaigns exploiting Amazon Simple Email Service (SES). Attackers leveraged exposed AWS Identity and Access Management (IAM) access keys, often found in public GitHub repositories, .ENV files, Docker images, and publicly accessible S3 buckets, to send convincing phishing emails that bypass standard security filters. These emails, appearing to originate from trusted sources, included fake document-signing notifications and sophisticated business email compromise (BEC) attacks, leading to unauthorized access and financial losses. This trend underscores the critical need for organizations to implement stringent security measures, such as enforcing least-privilege IAM policies, enabling multi-factor authentication, regularly rotating access keys, and applying IP-based access restrictions. The rise in such attacks highlights the evolving tactics of cybercriminals and the importance of proactive defense strategies to protect sensitive information and maintain trust.
2 months ago
Kill Chain
Exploitation of Amazon SES in Phishing and BEC Attacks: A 2026 Analysis
In early 2026, cybercriminals exploited Amazon Simple Email Service (SES) to conduct sophisticated phishing and Business Email Compromise (BEC) attacks. By leveraging exposed AWS Identity and Access Management (IAM) access keys, attackers sent large volumes of phishing emails that passed standard authentication checks, such as SPF, DKIM, and DMARC. These emails often impersonated trusted services like DocuSign, leading recipients to malicious sites designed to harvest sensitive information. The abuse of Amazon's legitimate infrastructure allowed these phishing campaigns to evade traditional email security measures, resulting in significant data breaches and financial losses for targeted organizations. This incident underscores a growing trend where attackers exploit trusted cloud services to enhance the credibility and effectiveness of their phishing campaigns. The increasing sophistication of such attacks highlights the urgent need for organizations to implement robust security measures, including strict IAM policies, regular key rotation, and comprehensive employee training to recognize and respond to phishing attempts.
2 months ago
Kill Chain
Kaikatsu Club Data Breach 2025: A Wake-Up Call for Cybersecurity in the AI Era
In January 2025, Kaikatsu Club, Japan's largest internet café chain, suffered a significant data breach when a 17-year-old high school student from Osaka exploited vulnerabilities in the company's application server. Utilizing a self-developed program, the attacker illicitly accessed and extracted approximately 7.25 million customer records, including personal information. The breach led to the temporary suspension of certain application functions, disrupting business operations. The individual was arrested in December 2025 under Japan's Unauthorized Access Prohibition Act. This incident underscores the growing accessibility of sophisticated cyberattack tools, even to individuals with limited resources, highlighting the urgent need for robust cybersecurity measures and continuous monitoring to protect sensitive customer data.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports