✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
AI-Assisted Cyberattack Compromises 600+ FortiGate Firewalls Globally
In early 2026, a sophisticated cyberattack leveraging artificial intelligence (AI) tools compromised over 600 FortiGate firewalls across 55 countries. The attackers utilized AI to automate reconnaissance, vulnerability scanning, and exploitation processes, significantly accelerating the attack timeline and reducing the need for human intervention. By exploiting weak security configurations and exposed management interfaces, the threat actors gained unauthorized access to critical network infrastructure, leading to potential data breaches and operational disruptions. This incident underscores the escalating threat posed by AI-enhanced cyberattacks, which enable adversaries to conduct large-scale operations with unprecedented speed and efficiency. Organizations must recognize the evolving capabilities of AI in the cyber threat landscape and implement robust security measures to defend against such advanced attacks.
3 months ago
Kill Chain
Storm-1175's High-Velocity Medusa Ransomware Attacks in 2026
In April 2026, the financially motivated cybercriminal group Storm-1175 launched rapid ransomware attacks targeting healthcare, education, professional services, and finance sectors across Australia, the UK, and the US. Exploiting both zero-day and recently disclosed vulnerabilities, the group moved swiftly from initial access to data exfiltration and deployment of Medusa ransomware, often within 24 hours. Their tactics included creating new user accounts, deploying remote monitoring tools, stealing credentials, and disabling security software to facilitate their operations. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/?utm_source=openai)) This incident underscores the critical need for organizations to promptly patch vulnerabilities and enhance monitoring of web-facing assets. The speed and efficiency of Storm-1175's attacks highlight a growing trend among threat actors to exploit the narrow window between vulnerability disclosure and patch deployment, emphasizing the importance of proactive cybersecurity measures. ([darkreading.com](https://www.darkreading.com/threat-intelligence/storm-1175-medusa-ransomware-high-velocity/?utm_source=openai))
3 months ago
Kill Chain
Understanding the Rise of Web Shell Attacks in 2026
In early 2026, a significant surge in web shell attacks was observed, targeting vulnerabilities in web servers and applications. Attackers exploited these weaknesses to deploy malicious scripts, enabling remote control over compromised systems. This escalation led to unauthorized data access, service disruptions, and substantial financial losses for affected organizations. The rapid deployment and stealthy nature of web shells posed significant challenges to traditional security measures. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/02/cookie-controlled-php-webshells-tradecraft-linux-hosting-environments/?utm_source=openai)) This trend underscores the evolving tactics of cyber adversaries, emphasizing the need for enhanced monitoring and proactive defense strategies. Organizations must prioritize the detection and mitigation of web shell threats to safeguard their digital assets and maintain operational integrity.
3 months ago
Kill Chain
LiteLLM Supply Chain Compromise: A Wake-Up Call for Open-Source Security
In March 2026, the LiteLLM Python package, widely used for routing large language model (LLM) API calls, was compromised through a supply chain attack. Malicious versions 1.82.7 and 1.82.8 were uploaded to the Python Package Index (PyPI) after attackers gained access to the maintainer's credentials via a compromised Trivy security scanner in LiteLLM's CI/CD pipeline. These versions contained a credential-stealing payload that executed automatically on Python startup, exfiltrating sensitive information such as SSH keys, cloud provider credentials, and Kubernetes secrets to an attacker-controlled server. The malicious packages were available for approximately three hours before being removed from PyPI. ([snyk.io](https://snyk.io/blog/poisoned-security-scanner-backdooring-litellm/?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting open-source ecosystems. The rapid propagation of malicious code through widely used packages highlights the need for enhanced security measures in software development pipelines, including stringent credential management, regular security audits, and the implementation of tools like Software Bill of Materials (SBOMs) and SigStore for verifying package integrity. ([ionix.io](https://www.ionix.io/threat-center/litellm-supply-chain-compromise-backdoored-pypi-packages-1-82-7-1-82-8/?utm_source=openai))
3 months ago
Kill Chain
Anthropic's Project Glasswing: Revolutionizing Cybersecurity with AI
In April 2026, Anthropic launched Project Glasswing, a collaborative initiative with major technology companies including Amazon, Apple, Microsoft, and Cisco, to enhance cybersecurity defenses using advanced AI. Central to this project is Claude Mythos Preview, an unreleased AI model that has identified thousands of previously undetected vulnerabilities across critical software systems, including a 27-year-old bug in OpenBSD and a 16-year-old flaw in FFmpeg. To mitigate potential misuse, Anthropic has restricted access to this powerful model to select partners and has committed significant resources to support open-source security organizations. ([anthropic.com](https://www.anthropic.com/project/glasswing?utm_source=openai)) This initiative underscores the growing importance of AI in cybersecurity, highlighting both its potential to fortify defenses and the risks associated with its misuse. As AI capabilities advance, the industry faces the dual challenge of leveraging these tools for protection while preventing their exploitation by malicious actors. ([cyberscoop.com](https://cyberscoop.com/project-glasswing-anthropic-ai-open-source-software-vulnerabilities/?utm_source=openai))
3 months ago
Kill Chain
Flowise 2026 RCE Vulnerability Exploitation
In April 2026, security researchers identified active exploitation of a critical remote code execution (RCE) vulnerability, CVE-2025-59528, in Flowise, an open-source platform for building AI agents and large language model (LLM) workflows. This flaw, residing in the CustomMCP node, allows attackers to execute arbitrary JavaScript code without security validation, leading to potential full system compromise. Despite a patch being available since September 2025, many instances remain unpatched, exposing organizations to significant risks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/max-severity-flowise-rce-vulnerability-now-exploited-in-attacks/?utm_source=openai)) The exploitation of this vulnerability underscores the persistent threat posed by unpatched software in widely used AI development tools. Organizations leveraging Flowise must prioritize immediate updates to mitigate potential breaches and safeguard sensitive data. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/max-severity-flowise-rce-vulnerability-now-exploited-in-attacks/?utm_source=openai))
3 months ago
Kill Chain
Critical Remote Code Execution Vulnerability in Flowise AI: CVE-2025-59528
In September 2025, a critical remote code execution (RCE) vulnerability, identified as CVE-2025-59528, was discovered in Flowise AI's version 3.0.5. This flaw resided in the CustomMCP node, which improperly executed user-supplied JavaScript code without validation, granting attackers full Node.js runtime privileges. Exploitation of this vulnerability could lead to complete system compromise, unauthorized command execution, and data exfiltration. Flowise addressed this issue by releasing version 3.0.6, which rectified the vulnerability. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-59528?utm_source=openai)) As of April 2026, active exploitation of CVE-2025-59528 has been observed, with over 12,000 Flowise instances exposed to potential attacks. This resurgence underscores the critical need for organizations to ensure their systems are updated to the latest secure versions to mitigate such high-severity threats. ([thehackernews.com](https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html?utm_source=openai))
3 months ago
Kill Chain
Critical Security Flaw in Ninja Forms Plugin Puts WordPress Sites at Risk
In early 2026, a critical vulnerability (CVE-2026-0740) was discovered in the Ninja Forms File Uploads plugin for WordPress, affecting versions up to 3.3.26. This flaw allowed unauthenticated attackers to upload arbitrary files, including malicious PHP scripts, leading to potential remote code execution and complete site takeover. The vulnerability stemmed from inadequate validation of file types and extensions during the file upload process. The issue was reported on January 8, 2026, and a full patch was released on March 19, 2026, with version 3.3.27. Despite the availability of a fix, exploitation attempts surged, with over 3,600 attacks blocked in a single day. This incident underscores the critical importance of timely software updates and robust security practices in mitigating emerging threats.
3 months ago
Kill Chain
Critical Docker Authorization Bypass Vulnerability (CVE-2026-34040) Discovered
In March 2026, a high-severity vulnerability (CVE-2026-34040) was identified in Docker Engine, allowing attackers to bypass authorization plugins (AuthZ) by sending oversized HTTP request bodies. This flaw enables unauthorized users to perform privileged container operations, potentially leading to full host system compromise. The issue affects Docker Engine versions prior to 29.3.1 and is a result of an incomplete fix for a previous vulnerability (CVE-2024-41110) addressed in July 2024. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-34040/?utm_source=openai)) The discovery of this vulnerability underscores the persistent risks associated with authorization bypass flaws in critical infrastructure. Organizations relying on Docker for container management must promptly update to version 29.3.1 or later to mitigate this threat. ([cyera.com](https://www.cyera.com/blog/cyera-research-discovers-docker-authorization-bypass-that-silently-disables-security-policies?utm_source=openai))
3 months ago
Kill Chain
ComfyUI Cryptomining Botnet Attack 2026
In April 2026, over 1,000 internet-exposed instances of ComfyUI, a popular stable diffusion platform, were targeted in a sophisticated cryptomining botnet campaign. Attackers utilized a custom Python scanner to identify vulnerable ComfyUI deployments, exploiting misconfigurations that allowed remote code execution via custom nodes. Upon successful exploitation, compromised hosts were enlisted into a botnet mining Monero and Conflux cryptocurrencies, managed through a Flask-based command-and-control dashboard. The campaign also employed persistence mechanisms to maintain control over infected systems. This incident underscores the critical need for securing internet-facing applications and services, as attackers continue to exploit misconfigurations and vulnerabilities to deploy cryptomining operations. Organizations must prioritize regular security assessments, implement robust authentication mechanisms, and monitor for unauthorized activities to mitigate such threats.
3 months ago
Kill Chain
AI-Driven Supply Chain Attack Compromises GitHub Repositories
In March 2026, a threat actor utilized AI-assisted automation to execute over 450 exploit attempts against open-source repositories on GitHub. The campaign, identified as 'prt-scan,' specifically targeted repositories misconfigured with the 'pull_request_target' workflow trigger. While less than 10% of these attempts were successful, the attacker managed to compromise at least two NPM packages, leading to the exposure of ephemeral GitHub credentials. This incident underscores the growing trend of AI-enhanced supply chain attacks, where adversaries leverage automation to scale their operations and exploit common misconfigurations. Organizations are urged to review and secure their CI/CD pipelines to mitigate such risks.
3 months ago
Kill Chain
UNC1069's Social Engineering Compromise of Axios: A 2026 Supply Chain Attack
In late March 2026, the popular JavaScript HTTP client library Axios, with over 100 million weekly downloads, was compromised through a sophisticated social engineering attack. The North Korean state-sponsored group UNC1069 targeted lead maintainer Jason Saayman, gaining access to his npm account. The attackers published two malicious versions of Axios (1.14.1 and 0.30.4) that included a trojanized dependency, 'plain-crypto-js@4.2.1', which executed a post-install script to deploy a cross-platform Remote Access Trojan (RAT) upon installation. The malicious packages were available for approximately two to three hours before being removed, but the potential impact was significant due to Axios's widespread use. This incident underscores the increasing industrialization of social engineering attacks targeting open-source maintainers, highlighting the need for enhanced security measures within the software supply chain. The rapid detection and removal of the compromised packages prevented a more extensive breach, but the event serves as a critical reminder of the vulnerabilities inherent in widely used open-source projects.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports