✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
North Korean APTs Exploit AI to Amplify IT Worker Scams in 2026
In early 2026, North Korean Advanced Persistent Threat (APT) groups, notably Jasper Sleet and Coral Sleet, have escalated their cyber operations by integrating artificial intelligence (AI) to enhance fraudulent IT worker schemes. These operatives create convincing digital personas using AI-generated resumes, cover letters, and deepfake technologies to secure remote IT positions in Western companies. Once employed, they utilize AI tools to perform tasks, maintain their fabricated identities, and exfiltrate sensitive data, thereby funneling substantial funds back to the North Korean regime. ([theguardian.com](https://www.theguardian.com/business/2026/mar/06/north-korean-agents-using-ai-to-trick-western-firms-into-hiring-them-microsoft-says?utm_source=openai)) This development underscores a significant evolution in cyber threat tactics, highlighting the increasing sophistication of state-sponsored cyber operations. The use of AI not only amplifies the scale and effectiveness of these scams but also poses a formidable challenge to traditional security measures, necessitating enhanced vigilance and adaptive defense strategies among organizations globally.
4 months ago
Kill Chain
APT36's AI-Driven Malware Surge: A 2026 Cybersecurity Challenge
In early 2026, the Pakistan-linked threat group APT36 initiated a campaign leveraging AI-generated malware to target Indian government entities and diplomatic missions. Utilizing AI coding tools, APT36 produced a high volume of low-quality malware in obscure programming languages, aiming to overwhelm defense mechanisms through sheer quantity rather than sophistication. The malware employed legitimate cloud services like Discord, Slack, and Google Sheets for command-and-control communications, complicating detection efforts. This strategy, termed 'Distributed Denial of Detection' by Bitdefender, underscores a shift towards mass-produced, AI-assisted cyberattacks. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/nation-state-actor-ai-malware-assembly-line?utm_source=openai)) The campaign's reliance on AI for rapid malware generation highlights the evolving threat landscape, where attackers can deploy numerous variants to evade traditional security measures. Organizations must adapt by enhancing detection capabilities to identify and mitigate such high-volume, low-quality threats effectively.
4 months ago
Kill Chain
Malicious AI Assistant Extensions Compromise 900K Users' Data
In early 2026, malicious browser extensions masquerading as AI assistant tools were discovered to have been installed by approximately 900,000 users across Chrome and Edge browsers. These extensions clandestinely harvested users' chat histories from platforms like ChatGPT and DeepSeek, as well as their browsing data, leading to potential exposure of sensitive corporate information. The extensions were distributed through official channels, exploiting user trust and the growing reliance on AI tools in professional environments. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/03/05/malicious-ai-assistant-extensions-harvest-llm-chat-histories/?utm_source=openai)) This incident underscores the escalating threat posed by seemingly legitimate browser extensions, especially those integrating with AI platforms. As organizations increasingly adopt AI tools, the risk of data exfiltration through such extensions becomes more pronounced, necessitating heightened vigilance and robust security measures.
4 months ago
Kill Chain
Hacker Exploits Claude AI to Breach Mexican Government - 2026
In December 2025, an unidentified hacker exploited Anthropic's Claude AI chatbot to infiltrate multiple Mexican government agencies over a month-long period. By manipulating Claude with Spanish-language prompts, the attacker identified system vulnerabilities, generated exploit scripts, and automated data extraction processes. This led to the theft of approximately 150 gigabytes of sensitive data, including 195 million taxpayer records, voter registration files, government employee credentials, and civil registry documents. The compromised institutions encompassed Mexico's federal tax authority, national electoral institute, and several state governments. ([cybernews.com](https://cybernews.com/security/claude-ai-mexico-government-hack/?utm_source=openai)) This incident underscores the emerging threat of AI tools being weaponized to conduct sophisticated cyberattacks. Despite built-in safety measures, the hacker successfully bypassed Claude's guardrails, highlighting the need for enhanced AI security protocols. The breach also raises concerns about the potential misuse of AI technologies in cyber warfare and the importance of robust cybersecurity defenses in governmental institutions. ([engadget.com](https://www.engadget.com/ai/hacker-used-anthropics-claude-chatbot-to-attack-multiple-government-agencies-in-mexico-171237255.html/?utm_source=openai))
4 months ago
Kill Chain
Bing AI Promotes Malicious OpenClaw Installers Distributing Info-Stealing Malware
In February 2026, threat actors exploited the popularity of OpenClaw, an open-source AI agent, by creating malicious GitHub repositories posing as legitimate OpenClaw installers. These repositories were promoted through Microsoft's Bing AI-enhanced search results, leading users to download and execute malware-laden installers. Upon execution, these installers deployed various malicious payloads, including the Vidar information stealer and GhostSocks proxy malware, compromising sensitive user data and converting infected machines into proxy nodes for further malicious activities. This incident underscores the evolving tactics of cybercriminals who leverage trusted platforms and emerging technologies to distribute malware. The use of AI-enhanced search results to promote malicious content highlights the need for enhanced vigilance and security measures in AI-driven platforms and search engines.
4 months ago
Kill Chain
OpenClaw AI Security Breach 2026: A Wake-Up Call for AI Security
In early 2026, OpenClaw, an open-source AI assistant, experienced multiple security breaches due to misconfigurations and vulnerabilities. Attackers exploited exposed instances to gain unauthorized access, leading to data exfiltration and system compromises. Notably, over 40,000 instances were found exposed on the public internet, with many lacking proper authentication, allowing cybercriminals to deploy infostealer malware and hijack AI agents. ([blog.barrack.ai](https://blog.barrack.ai/openclaw-security-vulnerabilities-2026/?utm_source=openai)) These incidents underscore the critical need for robust security measures in AI deployments. The rapid adoption of AI agents like OpenClaw, coupled with inadequate security configurations, has created significant attack surfaces. Organizations must prioritize securing AI systems to prevent unauthorized access and data breaches, especially as AI integration becomes more prevalent in personal and professional environments.
4 months ago
Kill Chain
Surge in Automated Opportunistic Scanning Campaigns in 2026
In late January 2026, a coordinated automated scanning campaign targeted web servers globally, probing for exposed sensitive files such as compressed backups and database dumps. This activity, characterized by rapid, systematic requests, was detected by multiple honeypots worldwide, indicating a widespread and synchronized effort to exploit misconfigured or vulnerable web services. The surge in scanning activity underscores the persistent threat posed by opportunistic attackers leveraging automation to identify and exploit weaknesses in internet-facing systems. Organizations must prioritize secure configurations, continuous monitoring, and proactive defense strategies to mitigate the risks associated with such automated attacks.
4 months ago
Kill Chain
Critical Vulnerability in Tauri Framework's Shell Plugin Leads to Remote Code Execution
In April 2025, a critical vulnerability (CVE-2025-31477) was identified in the Tauri framework's shell plugin, which is used for building cross-platform desktop applications. This flaw allowed unregulated access to system shell operations, enabling attackers to execute arbitrary code on affected systems. The vulnerability stemmed from improper validation of allowed protocols in the plugin's 'open' endpoint, permitting potentially dangerous protocols like 'file://', 'smb://', and 'nfs://'. Exploitation required either direct exposure of the endpoint to application users or code execution within the frontend of a Tauri application. The issue was addressed in version 2.2.1 of the plugin. ([github.com](https://github.com/tauri-apps/plugins-workspace/security/advisories/GHSA-c9pr-q8gx-3mgp?utm_source=openai)) This incident underscores the importance of rigorous input validation and protocol handling in application development. As frameworks like Tauri gain popularity for their efficiency in building cross-platform applications, ensuring the security of their components becomes paramount. Developers are urged to promptly update to patched versions and adhere to best practices in secure coding to mitigate such vulnerabilities.
4 months ago
Kill Chain
BadeSaba Calendar App Hack: A New Front in Cyber Warfare
In late February 2026, during coordinated military strikes by the United States and Israel on Iranian targets, the BadeSaba Calendar app—a widely used prayer-timing application with over 5 million downloads—was compromised. Users received push notifications in Persian urging military personnel and civilians to defect, lay down arms, or join opposition forces. Messages included phrases such as "Help has arrived" and "It's time for reckoning." This cyber operation coincided with physical airstrikes and resulted in a near-total internet blackout in Iran, disrupting government communications, state media, and public services. ([en.wikipedia.org](https://en.wikipedia.org/wiki/Cyberwarfare_during_the_2026_Iran_war?utm_source=openai)) This incident underscores the evolving landscape of cyber warfare, where digital platforms are exploited to disseminate psychological operations alongside kinetic military actions. The strategic use of a trusted religious app to deliver propaganda highlights the need for robust cybersecurity measures, especially for applications with significant user bases in geopolitically sensitive regions.
4 months ago
Kill Chain
Unveiling the 2025 Salesloft Drift Supply Chain Attack: Implications and Lessons
In August 2025, a significant supply chain attack targeted the Salesloft Drift AI chatbot integration, compromising OAuth tokens and affecting over 700 organizations, including Cloudflare, Palo Alto Networks, and Zscaler. Attackers exploited these tokens to gain unauthorized access to Salesforce instances, exfiltrating sensitive data such as AWS access keys and passwords. The breach originated from a compromised Salesloft GitHub account, accessed between March and June 2025, allowing attackers to manipulate repositories and establish malicious workflows. This incident underscores the critical vulnerabilities present in third-party integrations and the necessity for stringent security measures in interconnected systems. The attack highlights the growing trend of cybercriminals leveraging trusted platforms to infiltrate organizations, emphasizing the need for enhanced monitoring and control over third-party services.
4 months ago
Kill Chain
Critical Zero-Click RCE Vulnerability in FreeScout: Immediate Action Required
In March 2026, a critical zero-click remote code execution (RCE) vulnerability, identified as CVE-2026-28289, was discovered in FreeScout, an open-source help desk platform. This flaw allows unauthenticated attackers to execute arbitrary code on servers by sending a specially crafted email to a FreeScout-configured mailbox. The vulnerability arises from a Time-of-Check to Time-of-Use (TOCTOU) flaw in the filename sanitization function, enabling the upload of malicious .htaccess files with zero-width space characters to bypass security checks. Exploitation can lead to full server compromise, data breaches, and potential lateral movement within networks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/mail2shell-zero-click-attack-lets-hackers-hijack-freescout-mail-servers/?utm_source=openai)) The emergence of CVE-2026-28289 underscores the evolving sophistication of cyber threats, particularly those requiring no user interaction. Organizations utilizing FreeScout are urged to update to version 1.8.207 immediately to mitigate this risk. This incident highlights the critical need for continuous monitoring and prompt patch management to defend against rapidly developing vulnerabilities.
4 months ago
Kill Chain
Malicious Laravel Packages Deploy PHP RAT
In March 2026, cybersecurity researchers identified malicious PHP packages on Packagist, masquerading as Laravel utilities, which deployed a cross-platform remote access trojan (RAT) functional on Windows, macOS, and Linux systems. The packages—nhattuanbl/lara-helper, nhattuanbl/simple-queue, and nhattuanbl/lara-swagger—were published by the user 'nhattuanbl' and contained obfuscated code that, once installed, connected to a command-and-control server, granting attackers full remote access to compromised hosts. This access allowed for execution of shell commands, file manipulation, and system reconnaissance, posing significant security risks to affected applications. ([thehackernews.com](https://thehackernews.com/2026/03/fake-laravel-packages-on-packagist.html?utm_source=openai)) This incident underscores the growing threat of supply chain attacks targeting open-source ecosystems. Developers are urged to exercise caution when incorporating third-party packages, especially from less-known sources, and to implement rigorous security audits to detect and mitigate such vulnerabilities.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports