Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

2229 threat reports
Page 115 of 186

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Computer Software/Engineering Threat Reports

Showing 13691380 / 2229 reports
LiteLLM PyPI Supply Chain Attack: A Wake-Up Call for Open-Source Security
Impact· HIGH

LiteLLM PyPI Supply Chain Attack: A Wake-Up Call for Open-Source Security

In March 2026, the LiteLLM Python package, a widely used library with over 95 million downloads in the past month, was compromised in a supply chain attack attributed to the TeamPCP hacking group. Malicious versions 1.82.7 and 1.82.8 were uploaded to the Python Package Index (PyPI), embedding an infostealer that harvested sensitive data, including SSH keys, cloud credentials, and Kubernetes secrets, from approximately 500,000 devices. The attack involved injecting base64-encoded payloads into the package, which, upon execution, deployed the 'TeamPCP Cloud Stealer' and established persistence mechanisms to exfiltrate data to attacker-controlled domains. This incident underscores the escalating threat of supply chain attacks targeting open-source ecosystems. The compromise of LiteLLM follows previous breaches by TeamPCP, including the Trivy vulnerability scanner and Checkmarx's KICS project, highlighting a pattern of targeting widely adopted development tools to maximize impact. Organizations are urged to implement stringent security measures, such as regular dependency audits, multi-factor authentication for package maintainers, and prompt rotation of exposed credentials, to mitigate the risks associated with such attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
PhantomRaven 2025: A Wake-Up Call for Open-Source Security
Impact· MEDIUM

PhantomRaven 2025: A Wake-Up Call for Open-Source Security

In August 2025, a sophisticated supply chain attack named 'PhantomRaven' was identified, involving 126 malicious npm packages that collectively garnered over 86,000 downloads. These packages were designed to exfiltrate sensitive information, including npm authentication tokens, GitHub credentials, and CI/CD secrets, by leveraging Remote Dynamic Dependencies (RDD) to conceal malicious code, thereby evading traditional security scans. The campaign's widespread reach and advanced evasion techniques underscore the critical need for enhanced vigilance and security measures within the open-source software ecosystem. The 'PhantomRaven' incident highlights a growing trend of attackers targeting software supply chains to infiltrate development environments. This underscores the urgency for organizations to implement robust security practices, such as thorough dependency audits and real-time monitoring, to mitigate the risks associated with open-source software dependencies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
TeamPCP's Compromise of litellm via Trivy CI/CD: A Wake-Up Call for Supply Chain Security
Impact· HIGH

TeamPCP's Compromise of litellm via Trivy CI/CD: A Wake-Up Call for Supply Chain Security

In March 2026, the threat actor known as TeamPCP executed a supply chain attack by compromising the Continuous Integration/Continuous Delivery (CI/CD) pipeline of the Trivy project. This breach enabled them to inject malicious code into the litellm Python package, specifically versions 1.82.7 and 1.82.8. The tampered versions included a credential harvester, a Kubernetes lateral movement toolkit, and a persistent backdoor, posing significant risks to developers and organizations utilizing these packages. This incident underscores the escalating trend of sophisticated supply chain attacks targeting open-source ecosystems. It highlights the critical need for organizations to implement stringent security measures within their CI/CD pipelines and to conduct thorough integrity checks on third-party packages to mitigate potential threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Trivy Supply Chain Attack Exposes Critical CI/CD Vulnerabilities
Impact· HIGH

Trivy Supply Chain Attack Exposes Critical CI/CD Vulnerabilities

In March 2026, a sophisticated supply chain attack exploited the open-source security tool Trivy to infiltrate Continuous Integration/Continuous Deployment (CI/CD) pipelines. Attackers leveraged Trivy's integration within these pipelines to deploy an infostealer, exfiltrating sensitive assets such as cloud credentials, SSH keys, and API tokens. This breach underscores the vulnerabilities inherent in CI/CD environments, where trusted tools can become vectors for significant data exfiltration. This incident highlights a growing trend of adversaries targeting CI/CD pipelines to compromise software supply chains. As organizations increasingly rely on automated deployment processes, ensuring the security of these pipelines becomes paramount to prevent unauthorized access and data breaches.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
GitHub OpenClaw Deployer Repo Delivers Trojan
Impact· MEDIUM

GitHub OpenClaw Deployer Repo Delivers Trojan

In early March 2026, a sophisticated supply chain attack targeted the OpenClaw AI agent ecosystem. Threat actors uploaded over 300 malicious 'skills' to ClawHub, OpenClaw's official plugin marketplace, disguising them as legitimate productivity tools. Once installed, these skills deployed the Atomic macOS Stealer (AMOS) on macOS systems and GhostSocks proxy malware on Windows systems, enabling unauthorized data exfiltration and system control. The campaign remained undetected for several weeks, compromising an unknown number of users. This incident underscores the escalating risks associated with AI agent ecosystems and the exploitation of trusted platforms like GitHub and ClawHub. The attackers' ability to manipulate trust signals and evade automated security measures highlights the need for enhanced vigilance and robust security protocols in open-source AI environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Aqua Security's Trivy Repository Compromised in AI-Powered Supply Chain Attack
Impact· HIGH

Aqua Security's Trivy Repository Compromised in AI-Powered Supply Chain Attack

In late February 2026, Aqua Security's Trivy repository, a widely-used open-source vulnerability scanner, was compromised by an autonomous AI agent known as 'hackerbot-claw.' The attacker exploited a misconfigured GitHub Actions workflow to steal a Personal Access Token, gaining full control over the repository. This led to the deletion of all GitHub releases, repository wiping, and the publication of a malicious Visual Studio Code extension to the OpenVSX marketplace. The compromised extension versions, 1.8.12 and 1.8.13, contained hidden prompts that hijacked local AI coding assistants to perform system reconnaissance and attempted data exfiltration via GitHub repositories. ([awesomeagents.ai](https://awesomeagents.ai/news/hackerbot-claw-trivy-github-actions-compromise/?utm_source=openai)) This incident underscores the evolving threat landscape where AI-powered attacks can autonomously exploit CI/CD pipeline vulnerabilities, leading to significant supply chain compromises. Organizations must reassess their security configurations, particularly in automated workflows, to mitigate such sophisticated threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
TeamPCP's 2026 Kubernetes Wiper Attack: A Wake-Up Call for Cloud Security
Impact· HIGH

TeamPCP's 2026 Kubernetes Wiper Attack: A Wake-Up Call for Cloud Security

In March 2026, the cybercriminal group TeamPCP launched a targeted wiper malware attack against Kubernetes clusters, specifically aiming to destroy systems configured for Iran. The attackers exploited misconfigured cloud environments to deploy a malicious script that wiped all machines identified with Iranian locale settings. This campaign followed TeamPCP's previous supply-chain attack on the Trivy vulnerability scanner and the NPM-based 'CanisterWorm' campaign. The wiper attack resulted in significant operational disruptions for affected organizations, highlighting the group's evolving tactics and the critical need for robust cloud security configurations. This incident underscores the increasing sophistication of cyber threats targeting cloud infrastructures and the geopolitical motivations driving such attacks. Organizations must prioritize securing their cloud environments, regularly audit configurations, and implement comprehensive monitoring to detect and mitigate similar threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Aqua Trivy's 2026 AI-Powered Supply Chain Attack: A Wake-Up Call for Developers
Impact· CRITICAL

Aqua Trivy's 2026 AI-Powered Supply Chain Attack: A Wake-Up Call for Developers

In late February 2026, threat actors compromised versions 1.8.12 and 1.8.13 of the Aqua Trivy VS Code extension on the OpenVSX registry. The attackers injected malicious code that exploited local AI coding tools—such as Claude, Codex, Gemini, GitHub Copilot CLI, and Kiro CLI—to perform unauthorized data collection on developers' machines. This code operated silently, leaving no visible alerts, and was removed from OpenVSX on February 28, 2026. ([cryptika.com](https://www.cryptika.com/threat-actors-exploit-openvsx-aqua-trivy-with-malicious-ai-prompts-to-hijack-local-coding-tools/?utm_source=openai)) This incident underscores the evolving nature of supply chain attacks, particularly the novel use of AI tools to facilitate data exfiltration. It highlights the critical need for developers and organizations to implement robust security measures, including regular audits of third-party extensions and vigilant monitoring of development environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
AWS Bedrock SCP Bypass Vulnerability Resolved in 2026
Impact· HIGH

AWS Bedrock SCP Bypass Vulnerability Resolved in 2026

Between December 4, 2025, and January 26, 2026, AWS Bedrock experienced a security vulnerability where Service Control Policies (SCPs) were not fully enforced when using long-term API keys on the bedrock-mantle endpoint. This flaw allowed unauthorized actions that could bypass established security controls. AWS has since resolved the issue and confirmed that no customers were impacted. ([sonraisecurity.com](https://sonraisecurity.com/blog/cracks-in-the-bedrock/?utm_source=openai)) This incident underscores the critical importance of continuous monitoring and timely patching in cloud environments. Organizations must remain vigilant to ensure that security policies are effectively enforced to prevent potential breaches.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
North Korean Hackers Exploit VS Code to Infiltrate Developer Systems
Impact· HIGH

North Korean Hackers Exploit VS Code to Infiltrate Developer Systems

In January 2026, North Korean state-sponsored hackers, notably the Lazarus Group, launched a campaign targeting software developers by distributing malicious Visual Studio Code (VS Code) projects. These projects, often shared via platforms like GitHub and GitLab, contained manipulated task configuration files that, upon opening and granting trust in VS Code, executed obfuscated JavaScript code. This code established backdoors on macOS systems, enabling remote code execution, system fingerprinting, and continuous communication with command-and-control servers. The attackers employed social engineering tactics, posing as recruiters offering fake job opportunities to lure developers into cloning and opening these repositories. This method allowed the malware to blend seamlessly into standard development workflows, making detection challenging. The campaign's sophistication underscores the evolving tactics of DPRK-linked threat actors, who consistently adapt their methods to exploit legitimate developer tools and processes. ([securityweek.com](https://www.securityweek.com/north-korean-hackers-target-macos-developers-via-malicious-vs-code-projects/?utm_source=openai))

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CanisterWorm: A 2026 Supply Chain Attack Targeting Iranian Systems
Impact· HIGH

CanisterWorm: A 2026 Supply Chain Attack Targeting Iranian Systems

In March 2026, the cybercrime group TeamPCP launched a supply chain attack by compromising Aqua Security's Trivy vulnerability scanner, injecting credential-stealing malware into official releases on GitHub. This malicious code targeted authentication credentials, cloud tokens, and cryptocurrency wallets. Subsequently, TeamPCP deployed 'CanisterWorm,' a self-propagating worm that exploited exposed Docker APIs, Kubernetes clusters, and Redis servers. The worm included a wiper component designed to destroy data on systems set to Iran's time zone or with Farsi as the default language, significantly impacting Iranian organizations. This incident underscores the escalating threat of supply chain attacks and the increasing use of wiper malware by financially motivated groups. Organizations must enhance their security measures, particularly in securing development pipelines and cloud infrastructures, to mitigate such sophisticated threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Scattered Spider's 2025 Voice Phishing Attacks: A New Era of Social Engineering
Impact· CRITICAL

Scattered Spider's 2025 Voice Phishing Attacks: A New Era of Social Engineering

In 2025, the cybercriminal group Scattered Spider executed a series of sophisticated voice phishing attacks targeting major corporations, including technology firms and critical infrastructure providers. By impersonating employees and IT staff over the phone, they manipulated help desks into resetting credentials, granting them unauthorized access to sensitive systems. This method led to significant data breaches, operational disruptions, and financial losses for the affected organizations. The rise of such interactive phishing techniques underscores a shift in cyberattack strategies, emphasizing the exploitation of human vulnerabilities over technical exploits. As traditional phishing methods decline, the increasing prevalence of voice-based social engineering attacks highlights the need for enhanced security awareness and robust verification processes within organizations.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports