✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
ChipSoft Ransomware Attack: A Wake-Up Call for Healthcare Cybersecurity
In April 2026, ChipSoft, a leading Dutch healthcare software provider serving approximately 70% of the country's hospitals, suffered a ransomware attack. The incident led to the company's website going offline and raised concerns about potential unauthorized access to patient records. In response, several hospitals disconnected their systems as a precautionary measure. The full extent of the data breach remains under investigation. This attack underscores the escalating threat of ransomware targeting critical healthcare infrastructure. The incident highlights the urgent need for robust cybersecurity measures and comprehensive incident response plans to protect sensitive patient data and ensure the continuity of healthcare services.
3 months ago
Kill Chain
Google Chrome 2026: Device Bound Session Credentials Enhance Security Against Infostealer Threats
In April 2026, Google introduced Device Bound Session Credentials (DBSC) in Chrome 146 for Windows, aiming to combat the escalating threat of session cookie theft by infostealer malware. DBSC cryptographically binds authentication sessions to a user's specific device using hardware-backed security modules like the Trusted Platform Module (TPM). This binding ensures that even if session cookies are exfiltrated, they cannot be utilized on unauthorized devices, thereby mitigating unauthorized access to user accounts. ([security.googleblog.com](https://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html?utm_source=openai)) The deployment of DBSC is particularly timely given the rise of sophisticated infostealer malware, such as LummaC2, which harvests session cookies to bypass traditional authentication mechanisms, including multi-factor authentication (MFA). By rendering stolen session cookies ineffective on unauthorized devices, DBSC addresses a critical vulnerability in current web authentication practices. ([security.googleblog.com](https://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html?utm_source=openai))
3 months ago
Kill Chain
ClipBanker Malware 2025: Trojanized Proxifier Leads to Crypto Theft
In early 2025, cybersecurity researchers identified a sophisticated malware campaign involving the ClipBanker Trojan, which was distributed through a trojanized version of the Proxifier software. Users searching for Proxifier were led to a GitHub repository hosting a malicious installer. Upon execution, this installer initiated a complex infection chain, ultimately deploying ClipBanker—a malware designed to monitor clipboard activity and replace cryptocurrency wallet addresses with those controlled by attackers, leading to unauthorized fund transfers. ([securelist.com](https://securelist.com/clipbanker-malware-distributed-via-trojanized-proxifier/119341/?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals who exploit trusted platforms and software to distribute malware. The use of trojanized legitimate applications highlights the need for heightened vigilance and the importance of downloading software exclusively from official sources to mitigate such risks.
3 months ago
Kill Chain
EngageLab SDK Flaw Exposes Millions to Data Breach Risks
In April 2026, a critical security vulnerability was discovered in the EngageLab SDK, a widely used third-party Android software development kit. This flaw allowed malicious applications on the same device to bypass Android's security sandbox, granting unauthorized access to private data. The vulnerability exposed approximately 50 million Android users, including 30 million cryptocurrency wallet users, to potential data breaches and financial theft. The issue was promptly addressed with a security patch, mitigating further risks. This incident underscores the escalating threat of supply chain vulnerabilities in mobile applications, particularly those handling sensitive financial information. It highlights the necessity for developers to rigorously vet third-party SDKs and for organizations to implement robust security measures to protect user data against emerging threats.
3 months ago
Kill Chain
Cisco's 2026 Trivy Supply Chain Breach: A Wake-Up Call for Development Security
In March 2026, Cisco's internal development environment was breached through a sophisticated supply chain attack involving the Trivy vulnerability scanner. Threat actors, identified as TeamPCP, compromised Trivy's GitHub Actions pipeline, injecting credential-stealing malware into official releases. This allowed them to harvest credentials from organizations using Trivy, including Cisco. Leveraging these stolen credentials, the attackers infiltrated Cisco's build systems and developer workstations, exfiltrating over 300 private GitHub repositories containing source code for AI-powered products and unreleased items. Additionally, customer repositories belonging to banks, business process outsourcing firms, and U.S. government agencies were among those exfiltrated. AWS keys were also stolen and used for unauthorized activities across Cisco's cloud accounts. Cisco has since isolated affected systems, initiated reimaging, and is performing wide-scale credential rotation to contain the breach. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/?utm_source=openai)) This incident underscores the escalating threat posed by supply chain attacks, where compromising a widely-used tool can have cascading effects across multiple organizations. The breach highlights the critical need for organizations to scrutinize the security of third-party tools integrated into their development pipelines and to implement robust monitoring and incident response strategies to detect and mitigate such sophisticated attacks.
3 months ago
Kill Chain
EngageLab SDK Vulnerability: A Wake-Up Call for Android Developers
In April 2025, a critical intent redirection vulnerability was discovered in the EngageLab SDK, a widely used third-party Android library for managing messaging and push notifications. This flaw allowed malicious applications to exploit the SDK's exported activity, MTCommonActivity, to gain unauthorized access to private data by bypassing Android's security mechanisms. The vulnerability affected numerous applications, including cryptocurrency wallets, with over 30 million installations, exposing sensitive user information to potential risk. EngageLab addressed the issue by releasing version 5.2.1 on November 3, 2025, which set the vulnerable activity to non-exported, mitigating the risk. This incident underscores the significant security implications of vulnerabilities in third-party SDKs, especially in high-value sectors like digital asset management. It highlights the necessity for developers to rigorously review and monitor third-party components integrated into their applications to prevent similar security breaches.
3 months ago
Kill Chain
Anthropic's Claude Mythos AI: A Game-Changer in Cybersecurity
In March 2026, Anthropic's AI model, Claude Mythos, identified thousands of zero-day vulnerabilities across major operating systems and web browsers. This unprecedented discovery included a 27-year-old bug in OpenBSD and a critical flaw in FFmpeg. Due to the model's potential for misuse, Anthropic restricted access to select organizations under Project Glasswing to facilitate responsible vulnerability remediation. ([techcrunch.com](https://techcrunch.com/2026/04/07/anthropic-mythos-ai-model-preview-security/?utm_source=openai)) The incident underscores the dual-use nature of advanced AI in cybersecurity, highlighting the need for stringent access controls and collaborative efforts to mitigate risks associated with powerful AI tools.
3 months ago
Kill Chain
AWS AgentCore IAM God Mode Vulnerability Exposes Critical Security Risks
In April 2026, a security analysis revealed that the Amazon Bedrock AgentCore Starter Toolkit's default IAM roles granted overly permissive access, allowing AI agents to perform actions across all resources within an AWS account. This misconfiguration enabled potential attackers to exfiltrate proprietary ECR images, access other agents' memories, invoke code interpreters, and extract sensitive data. The issue stemmed from the toolkit's auto-create logic, which favored deployment ease over the principle of least privilege. Following disclosure, AWS updated its documentation to warn users that the default roles are intended for development and testing purposes only and are not recommended for production deployments. This incident underscores the critical importance of adhering to the principle of least privilege in IAM configurations, especially as organizations increasingly deploy AI agents in cloud environments. Overly permissive roles can lead to significant security risks, including data breaches and unauthorized access to sensitive resources.
3 months ago
Kill Chain
New macOS Malware Campaign Exploits Script Editor in ClickFix Attack
In April 2026, a new macOS malware campaign emerged, leveraging the Script Editor application to deliver the Atomic Stealer (AMOS) malware. Attackers employed a variation of the ClickFix technique, directing users to malicious websites that prompted them to open Script Editor via the 'applescript://' URL scheme. This method executed obfuscated commands to download and run AMOS, which exfiltrated sensitive data including Keychain information, browser credentials, and cryptocurrency wallets. This incident underscores the evolving tactics of threat actors targeting macOS systems, particularly through trusted applications like Script Editor. The shift from Terminal-based to Script Editor-based ClickFix attacks highlights the need for continuous vigilance and user education to recognize and avoid such sophisticated social engineering schemes.
3 months ago
Kill Chain
Hims & Hers Data Breach: Lessons in Third-Party Security
In early February 2026, telehealth company Hims & Hers Health experienced a data breach when unauthorized individuals accessed support tickets through their third-party customer service platform, Zendesk. The breach, occurring between February 4 and February 7, exposed personal information such as names and contact details of customers. Importantly, no medical records or doctor communications were compromised. The company promptly secured the platform and initiated an investigation upon discovering the suspicious activity on February 5. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hims-and-hers-warns-of-data-breach-after-zendesk-support-ticket-breach/?utm_source=openai)) This incident underscores the vulnerabilities associated with third-party service providers and the critical need for robust security measures. As cyber threats targeting support systems increase, organizations must enhance their security protocols to protect sensitive customer data and maintain trust.
3 months ago
Kill Chain
North Korean Hackers Deploy 1,700 Malicious Packages in Unprecedented Supply Chain Attack
In early April 2026, North Korean state-sponsored hackers, identified as the Contagious Interview group, executed a sophisticated supply chain attack by publishing over 1,700 malicious packages across multiple open-source ecosystems, including npm, PyPI, Go, Rust, and PHP. These packages impersonated legitimate developer tools but functioned as malware loaders, deploying platform-specific payloads capable of data theft and remote access. The attack underscores the persistent threat to software supply chains and the need for vigilant security practices among developers and organizations. ([thehackernews.com](https://thehackernews.com/2026/04/n-korean-hackers-spread-1700-malicious.html?utm_source=openai)) This incident highlights a concerning trend of state-sponsored actors targeting open-source ecosystems to infiltrate developer environments. The scale and coordination of this attack demonstrate the evolving tactics of threat actors and the critical importance of securing software supply chains to prevent widespread compromise.
3 months ago
Kill Chain
Anthropic's Claude Mythos AI Model Uncovers Critical Software Vulnerabilities
In April 2026, Anthropic unveiled its advanced AI model, Claude Mythos, which autonomously identified thousands of high-severity vulnerabilities across major operating systems and web browsers. This unprecedented capability led to the launch of Project Glasswing, a collaborative initiative with tech giants like Amazon, Apple, and Microsoft, aiming to address these security flaws before potential exploitation. The discovery of such extensive vulnerabilities underscores the critical need for proactive cybersecurity measures in the face of rapidly advancing AI technologies. As AI models become more sophisticated, they present both opportunities for enhancing security and risks of being weaponized by malicious actors. Organizations must stay vigilant and adapt their defenses to counteract these evolving threats.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports