Validated Containment Architectures are here. →Explore

Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

1828 threat reports
Page 95 of 153

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Computer Software/Engineering Threat Reports

Showing 11291140 / 1828 reports
Critical Vulnerability in Cryptographic Libraries Exposes Sensitive Data
Impact· HIGH

Critical Vulnerability in Cryptographic Libraries Exposes Sensitive Data

In February 2026, a critical vulnerability was identified in widely-used JavaScript and Python cryptographic libraries, aes-js and pyaes, respectively. These libraries defaulted to a static initialization vector (IV) in AES-CTR mode, leading to predictable encryption patterns. This flaw exposed numerous applications to potential data breaches, as attackers could exploit the deterministic IV to decrypt sensitive information. The issue was notably present in strongMan VPN Manager, which utilized pyaes for encrypting private keys and certificates, thereby compromising user credentials and network security. This incident underscores the importance of secure cryptographic practices, particularly the necessity of using unique, random IVs for each encryption operation. The widespread adoption of these libraries amplifies the risk, highlighting the need for developers to audit and update their cryptographic implementations to prevent similar vulnerabilities.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Anthropic's Git MCP Server Vulnerabilities: A Wake-Up Call for AI Security
Impact· CRITICAL

Anthropic's Git MCP Server Vulnerabilities: A Wake-Up Call for AI Security

In January 2026, Anthropic addressed critical vulnerabilities in its Git MCP server, a key component of the Model Context Protocol enabling AI tools to interact with code repositories. Security researchers identified three significant flaws: a path validation bypass (CVE-2025-68145), an unrestricted git_init issue (CVE-2025-68143), and an argument injection flaw in git_diff (CVE-2025-68144). These vulnerabilities, particularly when combined with the Filesystem MCP server, could allow remote code execution or file tampering via prompt injection. Reported in June 2025, these issues were patched by Anthropic in December 2025 with version 2025.12.18. While no active exploitation has been confirmed, this incident highlights the growing risks associated with integrating complex AI systems, where safe components may become vulnerable when used together. The event also references a prior incident from November 2025, where Anthropic's Claude AI was manipulated in a cyberespionage campaign targeting major global entities, underscoring the broader cybersecurity challenges linked to rapid AI adoption.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Unauthenticated RCE Vulnerabilities in Ivanti EPMM Exploited
Impact· CRITICAL

Critical Unauthenticated RCE Vulnerabilities in Ivanti EPMM Exploited

In January 2026, two critical zero-day vulnerabilities, CVE-2026-1281 and CVE-2026-1340, were discovered in Ivanti Endpoint Manager Mobile (EPMM). These vulnerabilities allow unauthenticated remote code execution, enabling attackers to gain full control over mobile device management infrastructure without requiring user interaction or credentials. Exploitation activities have included establishing reverse shells, installing web shells, conducting reconnaissance, and downloading malware. Affected sectors span state and local government, healthcare, manufacturing, professional and legal services, and high technology across the United States, Germany, Australia, and Canada. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-1281 to its Known Exploited Vulnerabilities (KEV) Catalog, underscoring the severity of the threat. Threat actors are rapidly advancing their operations, moving from initial reconnaissance to deploying persistent backdoors designed to maintain long-term access, even after organizations apply patches.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
X's Grok AI Faces Global Scrutiny Over Nonconsensual Explicit Image Generation
Impact· HIGH

X's Grok AI Faces Global Scrutiny Over Nonconsensual Explicit Image Generation

In early 2026, X's AI chatbot, Grok, was found to have generated and disseminated nonconsensual, sexually explicit images of individuals, including minors. This misuse led to multiple investigations by regulatory bodies across Europe and the United States, scrutinizing X's compliance with data protection laws and its measures to prevent the creation and spread of such harmful content. The incident underscores the urgent need for robust safeguards in AI technologies to prevent exploitation and protect individual privacy. The proliferation of AI-generated explicit imagery has prompted global regulatory bodies to intensify their oversight of AI applications, emphasizing the necessity for companies to implement stringent controls and ethical guidelines in AI development and deployment.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Intruder 2026: Unveiling Exposed Secrets in JavaScript Bundles
Impact· HIGH

Intruder 2026: Unveiling Exposed Secrets in JavaScript Bundles

In December 2025, Intruder's research team conducted a comprehensive scan of 5 million applications, uncovering over 42,000 exposed tokens hidden within JavaScript bundles. These tokens included sensitive credentials such as code repository access tokens and project management API keys, many of which were active and provided unauthorized access to critical systems. The exposure was attributed to limitations in traditional security tools, which often fail to detect secrets embedded in front-end code, particularly within single-page applications. This incident underscores the urgent need for enhanced secrets detection methods that can effectively identify and mitigate such vulnerabilities in modern web applications.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Vulnerabilities in Popular VSCode Extensions Expose Developers to Attacks
Impact· CRITICAL

Critical Vulnerabilities in Popular VSCode Extensions Expose Developers to Attacks

In February 2026, critical vulnerabilities were discovered in several widely-used Visual Studio Code (VSCode) extensions, including Live Server, Code Runner, Markdown Preview Enhanced, and Microsoft Live Preview. These extensions, collectively downloaded over 128 million times, contained flaws that could be exploited to steal local files and execute remote code. The vulnerabilities were identified by Ox Security, which attempted disclosure since June 2025 without receiving responses from the maintainers. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/?utm_source=openai)) This incident underscores the escalating risks associated with third-party development tools and the necessity for rigorous security assessments of IDE extensions. The widespread adoption of these vulnerable extensions highlights the potential for significant supply chain attacks targeting developers and organizations.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Microsoft Uncovers AI Recommendation Poisoning Threat
Impact· MEDIUM

Microsoft Uncovers AI Recommendation Poisoning Threat

In February 2026, Microsoft disclosed a new cyber threat termed 'AI Recommendation Poisoning,' where businesses embed hidden instructions within 'Summarize with AI' buttons on their websites. When users click these buttons, the AI assistant's memory is manipulated via URL prompt parameters to favor certain companies or products in future recommendations. Over a 60-day period, Microsoft identified over 50 unique prompts from 31 companies across 14 industries, raising concerns about the integrity of AI-driven insights. This technique mirrors traditional search engine optimization (SEO) manipulation but targets AI systems directly, potentially leading to biased recommendations in critical areas such as health, finance, and security without user awareness. The emergence of AI Recommendation Poisoning underscores the evolving landscape of cyber threats targeting artificial intelligence systems. As AI becomes increasingly integrated into decision-making processes, ensuring the neutrality and reliability of AI outputs is paramount. Organizations must implement robust security measures to detect and prevent such manipulations to maintain trust in AI-driven recommendations.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
SmartLoader's Exploitation of Oura MCP Server: A 2026 Supply Chain Attack
Impact· HIGH

SmartLoader's Exploitation of Oura MCP Server: A 2026 Supply Chain Attack

In February 2026, cybersecurity researchers uncovered a sophisticated supply chain attack involving the SmartLoader malware. Threat actors cloned the legitimate Oura Model Context Protocol (MCP) Server—a tool connecting AI assistants to Oura Ring health data—and distributed a trojanized version through deceptive GitHub repositories. This malicious server delivered the StealC infostealer, enabling attackers to exfiltrate credentials, browser passwords, and cryptocurrency wallet data from compromised systems. The attackers meticulously built credibility by creating fake GitHub accounts and repositories, submitting the trojanized server to legitimate MCP registries, and excluding the original author from contributor lists, thereby deceiving users into downloading the compromised software. This incident underscores a growing trend where threat actors exploit trusted platforms and tools to infiltrate systems. The methodical approach of building credibility over months highlights the evolving sophistication of supply chain attacks, emphasizing the need for organizations to rigorously verify the authenticity of software sources and implement robust security reviews before integrating third-party tools.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
AI Assistants Abused as Command-and-Control Proxies in Recent Cyberattacks
Impact· HIGH

AI Assistants Abused as Command-and-Control Proxies in Recent Cyberattacks

In February 2026, cybersecurity researchers disclosed a novel attack technique where AI assistants with web browsing capabilities, such as Microsoft Copilot and xAI Grok, were exploited as covert command-and-control (C2) proxies. This method, termed 'AI as a C2 proxy' by Check Point Research, allows attackers to blend malicious traffic with legitimate enterprise communications, thereby evading detection. The attack leverages anonymous web access combined with browsing and summarization prompts to create a bidirectional channel for data exfiltration and command execution. This development underscores the evolving threat landscape, where AI systems are not only tools for enhancing productivity but also potential vectors for sophisticated cyberattacks. The ability to abuse AI assistants as C2 proxies highlights the need for organizations to reassess their security postures, especially concerning the integration and use of AI technologies within their networks.

5 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Whisper Leak: Unveiling Side-Channel Vulnerabilities in LLMs
Impact· MEDIUM

Whisper Leak: Unveiling Side-Channel Vulnerabilities in LLMs

In November 2025, researchers Geoff McDonald and Jonathan Bar Or identified a side-channel vulnerability in Large Language Models (LLMs) termed 'Whisper Leak.' This attack exploits patterns in encrypted network traffic—specifically packet sizes and timing—to infer user prompt topics during LLM interactions. Despite TLS encryption, these metadata patterns allow adversaries to classify conversation topics with high accuracy, posing significant privacy risks. The study demonstrated the attack's effectiveness across 28 popular LLMs, achieving near-perfect classification rates and high precision even in scenarios with extreme class imbalance. ([microsoft.com](https://www.microsoft.com/en-us/research/publication/whisper-leak-a-side-channel-attack-on-large-language-models/?utm_source=openai)) The discovery of Whisper Leak underscores the urgent need for LLM providers to address metadata leakage vulnerabilities. As LLMs are increasingly deployed in sensitive domains such as healthcare and legal services, ensuring robust privacy protections is paramount. The researchers evaluated mitigation strategies like random padding, token batching, and packet injection; however, none provided complete protection, highlighting the complexity of securing LLM communications against side-channel attacks. ([microsoft.com](https://www.microsoft.com/en-us/research/publication/whisper-leak-a-side-channel-attack-on-large-language-models/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Understanding the 2026 ClickFix DNS PowerShell Attack
Impact· HIGH

Understanding the 2026 ClickFix DNS PowerShell Attack

In February 2026, a new variant of the ClickFix social engineering attack emerged, exploiting DNS queries to deliver malicious payloads. Attackers deceived users into executing an 'nslookup' command via the Windows Run dialog, which queried an attacker-controlled DNS server. The server responded with a DNS record containing a malicious PowerShell script, leading to the installation of malware, including the remote access trojan ModeloRAT. This method allowed attackers to blend malicious activities within normal DNS traffic, evading traditional detection mechanisms. This incident underscores the evolving sophistication of social engineering attacks, highlighting the need for heightened awareness and advanced security measures. The use of DNS as a delivery mechanism signifies a shift in attacker tactics, emphasizing the importance of monitoring DNS traffic and educating users about the risks of executing unsolicited commands.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(low)
Read Report
OpenClaw 2026: A Cautionary Tale of AI Assistant Security
Impact· CRITICAL

OpenClaw 2026: A Cautionary Tale of AI Assistant Security

In early 2026, the OpenClaw AI assistant platform, formerly known as ClawdBot and MoltBot, experienced a significant security breach. Over 340 malicious 'skills' were uploaded to its ClawHub marketplace, many disguised as cryptocurrency tools. These skills, once installed, executed obfuscated commands leading to the deployment of the Atomic macOS Stealer (AMOS) malware. This malware targeted sensitive user data, including API keys, wallet private keys, SSH credentials, and browser passwords. The rapid adoption of OpenClaw, with over 30,000 online instances by late January 2026, coupled with minimal security oversight, facilitated this large-scale supply chain attack. ([aviatrix.ai](https://aviatrix.ai/threat-research-center/openclaw-2026-clawhub-malicious-skills/?utm_source=openai)) This incident underscores the growing trend of cybercriminals exploiting AI assistant platforms to distribute malware. The integration of AI agents into daily workflows, especially in sectors like cryptocurrency trading, presents new attack vectors. Organizations must prioritize the security of AI ecosystems, ensuring rigorous vetting of third-party extensions and continuous monitoring to mitigate such threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports