Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
U.S. Nationals Sentenced for Facilitating North Korean IT Worker Infiltration
Between 2021 and October 2024, U.S. nationals Kejia Wang and Zhenxing Wang facilitated a scheme enabling North Korean IT workers to secure remote positions at over 100 U.S. companies, including Fortune 500 firms. By creating fake websites, shell companies, and hosting company-issued laptops in U.S. residences, they masked the workers' true identities, generating over $5 million for the North Korean government and causing approximately $3 million in damages to the affected companies. ([nationaltoday.com](https://nationaltoday.com/us/ma/boston/news/2026/04/16/two-americans-sentenced-for-helping-north-korea-obtain-remote-it-jobs/?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors exploiting remote work infrastructures to infiltrate organizations, emphasizing the need for robust identity verification and cybersecurity measures to protect against such sophisticated schemes.
5 months ago
Kill Chain
McGraw Hill's 2026 Data Breach: A Wake-Up Call for Third-Party Security
In April 2026, McGraw Hill, a leading educational publisher, experienced a data breach orchestrated by the cybercriminal group ShinyHunters. The attackers exploited a misconfiguration in McGraw Hill's Salesforce environment, gaining unauthorized access to a webpage hosted on the platform. This breach led to the exfiltration of personally identifiable information (PII) from approximately 13.5 million user accounts, including names, physical addresses, phone numbers, and email addresses. McGraw Hill confirmed the incident, emphasizing that their internal systems, customer databases, and educational platforms remained secure. The company attributed the breach to a broader issue affecting multiple organizations utilizing Salesforce, highlighting the risks associated with third-party service integrations. ([techradar.com](https://www.techradar.com/pro/security/this-activity-appears-to-be-part-of-a-broader-issue-education-company-mcgraw-hill-becomes-latest-to-see-its-salesforce-data-hacked?utm_source=openai)) This incident underscores the escalating threat posed by cybercriminal groups like ShinyHunters, who have shifted focus from traditional ransomware attacks to data extortion schemes. By exploiting vulnerabilities in widely-used platforms such as Salesforce, these actors can access vast amounts of sensitive data, posing significant risks to organizations and their customers. The McGraw Hill breach serves as a critical reminder for companies to rigorously assess and secure their third-party integrations to prevent similar incidents.
5 months ago
Kill Chain
ATHR: AI-Powered Vishing Platform Revolutionizes Automated Attacks
In April 2026, cybersecurity researchers identified 'ATHR,' a sophisticated cybercrime platform that automates voice phishing (vishing) attacks using AI-driven voice agents. The platform orchestrates the entire attack chain: sending deceptive emails that prompt victims to call a provided number, which connects them to AI agents impersonating legitimate support staff. These agents guide victims through a simulated security verification process to extract sensitive information, such as six-digit verification codes, enabling unauthorized access to accounts on services like Google, Microsoft, and Coinbase. The emergence of ATHR underscores a significant evolution in social engineering tactics, leveraging AI to enhance the scale and believability of vishing attacks. This development highlights the urgent need for organizations to bolster their defenses against AI-powered social engineering threats, as traditional detection methods may be insufficient against such advanced techniques.
5 months ago
Kill Chain
Google's 2025 Gemini AI Initiative: A New Era in Combating Malvertising
In 2025, Google intensified its efforts to combat malvertising by integrating its Gemini AI models into ad detection systems. This initiative led to the blocking or removal of 8.3 billion ads and the suspension of 24.9 million advertiser accounts, including 602 million ads linked to scams. Malvertising campaigns often impersonate legitimate brands to distribute malware or lead users to phishing sites. By leveraging Gemini AI, Google enhanced its ability to analyze vast datasets, including advertiser behavior and campaign patterns, to identify and block malicious ads before they reach users. ([apnews.com](https://apnews.com/article/06d9ef869958555884989e8ec25974be?utm_source=openai)) The urgency of addressing malvertising has grown as cybercriminals increasingly use generative AI to create deceptive ads at scale. Google's proactive measures with Gemini AI have not only improved ad filtering efficiency but also reduced incorrect advertiser suspensions by 80%. This underscores the critical need for advanced AI-driven defenses to maintain the integrity of digital advertising platforms. ([apnews.com](https://apnews.com/article/06d9ef869958555884989e8ec25974be?utm_source=openai))
5 months ago
Kill Chain
Marimo 2026: Exploitation of CVE-2026-39987 to Deploy NKAbuse Malware via Hugging Face
In April 2026, attackers exploited a critical vulnerability (CVE-2026-39987) in Marimo, a reactive Python notebook platform, to deploy a new variant of NKAbuse malware. The flaw allowed unauthenticated remote code execution via the /terminal/ws WebSocket endpoint, enabling attackers to gain full shell access and execute arbitrary commands. Within 10 hours of the vulnerability's disclosure, threat actors began exploiting it to deploy malware hosted on Hugging Face Spaces, a platform for sharing AI applications. The attackers created a typosquatted Space named 'vsccode-modetx' to host a dropper script and a malicious binary named 'kagent,' which mimicked legitimate tools to evade detection. The payload, a variant of the NKAbuse malware, utilized the NKN blockchain for command and control communications, allowing remote execution of shell commands on infected systems. This incident underscores the rapid weaponization of newly disclosed vulnerabilities and the increasing targeting of AI and machine learning development environments by sophisticated threat actors. Organizations using Marimo are urged to upgrade to version 0.23.0 or later immediately to mitigate this critical security risk.
5 months ago
Kill Chain
JanaWare Ransomware: A Persistent Threat to Turkish Homes and SMBs
Since at least 2020, a localized ransomware campaign has been targeting individuals and small to medium-sized businesses (SMBs) in Turkey. The attackers employ phishing emails containing malicious Java archive files that, when executed, deploy a customized variant of the Adwind Remote Access Trojan (RAT). This malware disables security defenses and delivers a ransomware payload known as 'JanaWare,' which encrypts files and demands ransoms between $200 and $400. ([acronis.com](https://www.acronis.com/en/tru/posts/new-janaware-ransomware-targets-turkey-via-adwind-rat/?utm_source=openai)) The campaign's longevity and focus on smaller targets highlight a growing trend where cybercriminals opt for low-value, high-volume attacks. Such operations often evade detection and persist longer due to the limited cybersecurity resources of SMBs and the underreporting of smaller incidents. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/6-year-ransomware-campaign-turkish-homes-smbs/?utm_source=openai))
5 months ago
Kill Chain
Obsidian Plugin Exploitation Leads to PHANTOMPULSE RAT Deployment in Financial Sector
In April 2026, a sophisticated social engineering campaign, identified as REF6598, exploited the Obsidian note-taking application's plugin ecosystem to distribute a previously undocumented Windows remote access trojan (RAT) named PHANTOMPULSE. Targeting professionals in the financial and cryptocurrency sectors, attackers initiated contact via LinkedIn and Telegram, posing as representatives of a venture capital firm. Victims were persuaded to access a shared Obsidian vault, which, upon enabling community plugin synchronization, executed malicious code leading to the deployment of PHANTOMPULSE. This AI-generated backdoor utilized Ethereum blockchain transactions for command-and-control communication, enabling attackers to monitor activity, access sensitive data, and compromise cryptocurrency wallets. ([elastic.co](https://www.elastic.co/security-labs/phantom-in-the-vault?utm_source=openai)) This incident underscores the evolving tactics of threat actors who leverage trusted applications and social engineering to infiltrate targeted industries. The use of blockchain-based command-and-control mechanisms highlights the increasing sophistication of malware, emphasizing the need for heightened vigilance and robust security measures within the financial and cryptocurrency sectors.
5 months ago
Kill Chain
Massive WordPress Plugin Supply Chain Attack Compromises Thousands of Websites
In August 2025, a malicious actor acquired the EssentialPlugin suite, comprising over 30 WordPress plugins, and embedded dormant backdoors into their codebase. These backdoors remained inactive until April 2026, when they were activated to inject spam content and redirects into websites using the compromised plugins. This supply chain attack affected thousands of sites, exploiting the trust placed in widely-used plugins to distribute malware. The incident underscores the critical need for vigilance in monitoring third-party software components and the potential risks associated with software supply chain vulnerabilities. As attackers increasingly target trusted software providers to distribute malicious code, organizations must implement robust security measures to detect and mitigate such threats.
5 months ago
Kill Chain
Critical Nginx UI Vulnerability (CVE-2026-33032) Enables Unauthenticated Server Takeover
In March 2026, a critical vulnerability (CVE-2026-33032) was discovered in Nginx UI, a web-based management interface for the Nginx web server. This flaw allowed unauthenticated remote attackers to invoke Model Context Protocol (MCP) tools without credentials, enabling actions such as restarting Nginx, and creating, modifying, or deleting configuration files. The root cause was an unprotected '/mcp_message' endpoint that, due to an empty default IP whitelist treated as 'allow all,' permitted unrestricted access. Exploitation of this vulnerability could lead to complete server takeover, allowing attackers to intercept traffic, harvest credentials, and disrupt services. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-33032?utm_source=openai)) The vulnerability was actively exploited in the wild, with approximately 2,600 publicly exposed instances identified, primarily in China, the United States, Indonesia, Germany, and Hong Kong. ([thehackernews.com](https://thehackernews.com/2026/04/critical-nginx-ui-vulnerability-cve.html?utm_source=openai)) A patch was released in version 2.3.4 on March 15, 2026, addressing the issue by adding the missing authentication check to the '/mcp_message' endpoint. ([securityaffairs.com](https://securityaffairs.com/190841/hacking/cve-2026-33032-severe-nginx-ui-bug-grants-unauthenticated-server-access.html?utm_source=openai))
5 months ago
Kill Chain
n8n Webhooks Exploited in Phishing Campaigns Since October 2025
In October 2025, threat actors began exploiting n8n, a widely-used AI workflow automation platform, to conduct sophisticated phishing campaigns. By creating malicious webhooks on n8n's trusted infrastructure, attackers were able to bypass traditional security filters and deliver malware or perform device fingerprinting through automated emails. This abuse allowed them to distribute malicious payloads and gather sensitive information from targeted devices. ([thehackernews.com](https://thehackernews.com/2026/04/n8n-webhooks-abused-since-october-2025.html?utm_source=openai)) The exploitation of legitimate automation platforms like n8n underscores a growing trend where attackers leverage trusted services to evade detection. This incident highlights the need for organizations to scrutinize third-party integrations and enhance monitoring of automated workflows to prevent similar abuses. ([blog.talosintelligence.com](https://blog.talosintelligence.com/the-n8n-n8mare/?utm_source=openai))
5 months ago
Kill Chain
Comprehensive Analysis of the 2026 Threat Detection Report
In 2025, Red Canary analyzed over 110,000 threats across more than 4.5 million identities, endpoints, and cloud assets, revealing significant shifts in the cyber threat landscape. Key findings include a surge in identity-related attacks, with adversaries targeting credentials through info stealers, consent phishing, and OAuth abuse. Browsers have become primary attack vectors, serving as both the main workspace for users and a conduit for malicious payloads via compromised extensions and token theft. Additionally, the abuse of Remote Monitoring and Management (RMM) tools has escalated, with adversaries leveraging these tools for unauthorized access and control. ([redcanary.com](https://redcanary.com/blog/threat-detection/2026-threat-detection-report/?utm_source=openai)) These trends underscore the evolving tactics of cyber adversaries and the necessity for organizations to implement layered security controls. The interconnected nature of identity compromise, browser exploitation, and social engineering highlights the importance of comprehensive defense strategies combining device trust, user authentication, and behavioral monitoring to mitigate these emerging threats. ([redcanary.com](https://redcanary.com/resources/videos/secops-weekly-inside-the-2026-threat-detection-report/?utm_source=openai))
5 months ago
Kill Chain
Understanding the TeamPCP Supply Chain Attack of March 2026
In March 2026, the threat actor group TeamPCP executed a sophisticated supply chain attack, compromising widely used developer tools including Aqua Security's Trivy, Checkmarx's KICS, and the LiteLLM Python package. By exploiting stolen credentials, they injected credential-stealing malware into these tools, leading to the exfiltration of sensitive data such as API keys, cloud service credentials, and source code from numerous organizations. The attack unfolded rapidly over a span of five days, with each compromised tool serving as a vector to infiltrate the next, demonstrating the cascading risks inherent in supply chain vulnerabilities. This incident underscores the critical importance of securing the software supply chain, especially as attackers increasingly target trusted development tools to gain unauthorized access. Organizations must implement robust security measures, including regular credential rotation, stringent access controls, and continuous monitoring of CI/CD pipelines, to mitigate the risks associated with such attacks.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports