✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
GitHub Actions Supply Chain Attack 2025: Lessons Learned
In March 2025, a significant supply chain attack targeted GitHub Actions, specifically compromising the widely-used 'tj-actions/changed-files' repository. Attackers injected malicious code into this action, causing it to expose sensitive secrets from Continuous Integration/Continuous Deployment (CI/CD) workflows by printing them into public logs. This breach, identified as CVE-2025-30066, affected thousands of repositories relying on the compromised action, leading to potential unauthorized access and data breaches. This incident underscores the escalating threats to software supply chains, particularly within CI/CD environments. It highlights the critical need for organizations to implement stringent security measures, such as pinning dependencies to specific versions, regularly auditing third-party components, and enhancing monitoring of CI/CD pipelines to detect and mitigate such vulnerabilities promptly.
3 months ago
Kill Chain
GitHub's 2025 Open Source Vulnerability Report: Key Insights
In 2025, GitHub's Advisory Database reported 4,101 reviewed advisories, marking the lowest count since 2021. This decline is attributed to a reduction in backfilling older vulnerabilities, while newly reported vulnerabilities increased by 19% year-over-year. Notably, npm malware advisories surged by 69%, driven by large-scale campaigns like SHA1-Hulud. Additionally, there was a significant rise in vulnerabilities related to resource exhaustion, unsafe deserialization, and server-side request forgery. These trends underscore the evolving threat landscape in open-source software. ([github.blog](https://github.blog/security/supply-chain-security/a-year-of-open-source-vulnerability-trends-cves-advisories-and-malware/?utm_source=openai)) The current relevance of this incident lies in the persistent and growing threats targeting open-source ecosystems. The increase in new vulnerabilities and sophisticated malware campaigns highlights the need for continuous vigilance and proactive security measures among developers and organizations relying on open-source components.
3 months ago
Kill Chain
CPUID 2026 Supply Chain Attack: A Wake-Up Call for Software Security
In April 2026, CPUID's official website was compromised for approximately six hours, leading to the distribution of malware through its popular CPU-Z and HWMonitor tools. Attackers exploited a secondary API to redirect download links to malicious installers, which deployed the STX RAT—a remote access trojan designed to steal browser credentials and other sensitive information. The malware utilized advanced evasion techniques, operating primarily in-memory to bypass standard detection mechanisms. CPUID has since resolved the breach and restored the integrity of its download links. This incident underscores the growing trend of supply chain attacks targeting widely-used software utilities. The reuse of infrastructure from previous campaigns, such as the FileZilla incident in March 2026, highlights the persistent threat posed by sophisticated threat actors. Organizations and individuals are advised to exercise caution when downloading software, even from trusted sources, and to implement robust security measures to detect and prevent such compromises.
3 months ago
Kill Chain
Safeguarding AI Systems: Addressing Indirect Prompt Injection Vulnerabilities
In April 2026, security researchers identified a critical vulnerability in AI-integrated customer service solutions utilizing Large Language Models (LLMs). The attack, termed 'indirect prompt injection,' involves embedding malicious instructions within user profile fields or external data sources that the LLM processes as context. This method allows attackers to bypass supervisor agents designed to monitor direct user inputs, leading to unauthorized actions by the AI system. The exploitation of this vulnerability underscores the need for comprehensive security measures that encompass all data sources influencing LLM behavior. As AI systems become more integrated into critical workflows, the prevalence of such sophisticated attacks is expected to rise, highlighting the urgency for organizations to reassess and fortify their AI security protocols.
3 months ago
Kill Chain
CPUID's 2026 Supply Chain Breach: A Wake-Up Call for Software Security
In April 2026, CPUID's website was compromised through a secondary API, leading to the distribution of trojanized versions of CPU-Z and HWMonitor. For approximately six hours between April 9 and April 10, attackers altered download links to serve malicious executables, exposing millions of users to potential malware infections. The malicious files, notably named HWiNFO_Monitor_Setup.exe, utilized advanced evasion techniques, including multi-stage, in-memory execution and NTDLL proxying from a .NET assembly, to bypass detection by endpoint detection and response (EDR) systems and antivirus software. CPUID has since identified and rectified the breach, confirming that their original signed binaries remained uncompromised. This incident underscores the escalating threat of supply chain attacks targeting widely used utilities. The attackers' sophisticated methods highlight the need for enhanced vigilance and robust security measures in software distribution channels. Organizations must prioritize the integrity of their software supply chains to prevent similar breaches and protect end-users from malicious software distribution.
3 months ago
Kill Chain
Smart Slider 3 Pro Supply Chain Attack: A 2026 Case Study
In April 2026, unknown threat actors compromised Nextend's update infrastructure to distribute a malicious version (3.5.1.35) of the Smart Slider 3 Pro plugin for WordPress and Joomla. This backdoored update, available for approximately six hours on April 7, allowed attackers to create hidden administrator accounts, execute remote commands, and establish multiple persistence mechanisms, leading to unauthorized access and potential data exfiltration on affected websites. The incident underscores the critical risks associated with supply chain attacks, where trusted software distribution channels are exploited to deliver malware. Such attacks bypass traditional security measures, emphasizing the need for enhanced vigilance and monitoring of software update processes to detect and mitigate unauthorized modifications promptly.
3 months ago
Kill Chain
GlassWorm Campaign 2026: Unveiling the Zig Dropper Threat to Developer IDEs
In April 2026, the GlassWorm campaign introduced a new attack vector targeting developers by distributing a malicious Visual Studio Code (VS Code) extension named "specstudio.code-wakatime-activity-tracker." This extension, masquerading as the legitimate WakaTime tool, included a Zig-compiled native binary designed to stealthily infect all integrated development environments (IDEs) on a developer's machine. Once installed, the binary identified and compromised various IDEs, including VS Code, VSCodium, Positron, and AI-powered coding tools like Cursor and Windsurf. The attack involved downloading a second-stage malicious extension from an attacker-controlled GitHub account, which exfiltrated sensitive data and deployed a remote access trojan (RAT) that installed an information-stealing Google Chrome extension. ([thehackernews.com](https://thehackernews.com/2026/04/glassworm-campaign-uses-zig-dropper-to.html?utm_source=openai)) This incident underscores the evolving sophistication of supply chain attacks targeting developer environments. The use of native binaries compiled in Zig to propagate malware across multiple IDEs highlights the need for enhanced vigilance and security measures within the software development community. Developers are advised to scrutinize extensions before installation and monitor their systems for unauthorized changes to prevent similar compromises.
3 months ago
Kill Chain
Anthropic's Claude Mythos AI Model: A Double-Edged Sword in Cybersecurity
In April 2026, Anthropic unveiled Claude Mythos Preview, an advanced AI model capable of autonomously identifying and exploiting zero-day vulnerabilities across major operating systems and web browsers. This model discovered thousands of critical security flaws, including a 27-year-old bug in OpenBSD, raising significant concerns about its potential misuse. To mitigate risks, Anthropic restricted access to select organizations through Project Glasswing, collaborating with tech giants like Apple, Microsoft, and Google to enhance cybersecurity defenses. The emergence of AI models like Claude Mythos underscores the urgent need for robust security measures and regulatory frameworks to prevent malicious exploitation. As AI capabilities advance, organizations must proactively adapt their cybersecurity strategies to address these evolving threats.
3 months ago
Kill Chain
Cirro Cloud Security Breach 2026: Lessons Learned and Future Precautions
In 2026, Cirro, a cloud security tool, experienced a significant security incident where attackers exploited vulnerabilities in its platform, leading to unauthorized access to sensitive client data. The breach was initiated through a compromised administrative account, allowing threat actors to navigate internal systems undetected for several days. This intrusion resulted in the exfiltration of confidential information, affecting numerous organizations relying on Cirro for cloud security solutions. The incident underscores the critical importance of robust access controls and continuous monitoring in cloud environments. As cloud adoption accelerates, the frequency and sophistication of such breaches have increased, highlighting the need for organizations to implement comprehensive security measures and stay vigilant against evolving cyber threats.
3 months ago
Kill Chain
Obfuscated JavaScript Phishing Attack Delivers FormBook Malware - April 2026
In April 2026, a sophisticated phishing campaign was identified, distributing the FormBook infostealer malware through obfuscated JavaScript files. The attack began with phishing emails containing RAR archives that, when extracted, revealed large, obfuscated JavaScript files. These scripts utilized Windows-specific ActiveXObjects to establish persistence via scheduled tasks and dropped multiple files, including AES-encrypted data and .NET DLLs. The payloads were decrypted and executed using PowerShell scripts, ultimately injecting the FormBook malware into legitimate processes like MSBuild.exe. This multi-stage attack chain effectively evaded traditional detection mechanisms by leveraging obfuscation, encryption, and living-off-the-land techniques. The resurgence of such sophisticated phishing campaigns underscores the evolving tactics of threat actors and the necessity for organizations to enhance their email security measures and endpoint detection capabilities to mitigate the risks associated with advanced malware delivery methods.
3 months ago
Kill Chain
Google's 2026 Announcement: Accelerating the Shift to Post-Quantum Cryptography by 2029
In March 2026, Google announced an accelerated timeline to migrate its systems to post-quantum cryptography (PQC) by 2029, moving up from the previously anticipated mid-2030s. This decision was driven by rapid advancements in quantum computing, particularly in hardware development, error correction, and factoring resource estimates, which suggest that quantum computers capable of breaking current encryption methods could emerge sooner than expected. Google's proactive approach aims to safeguard its systems, devices, and data against potential quantum threats. ([blog.google](https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/?utm_source=openai)) This move underscores the urgency for organizations to assess and enhance their cryptographic resilience. The looming possibility of quantum computers rendering existing encryption obsolete necessitates immediate action to transition to quantum-resistant algorithms, ensuring the continued security of sensitive information in the near future.
3 months ago
Kill Chain
Supply Chain Attack on Smart Slider 3 Pro Compromises Websites in 2026
In April 2026, attackers compromised the update system of the Smart Slider 3 Pro plugin, affecting version 3.5.1.35 for both WordPress and Joomla platforms. This malicious update introduced multiple backdoors, created hidden administrator accounts, and exfiltrated sensitive data from affected websites. The incident underscores the critical importance of securing software supply chains to prevent unauthorized code distribution and maintain the integrity of widely used web applications. This event highlights a growing trend of supply chain attacks targeting popular web plugins, emphasizing the need for vigilant monitoring of software updates and the implementation of robust security measures to detect and prevent unauthorized modifications.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports