Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Critical Langflow Vulnerability CVE-2026-33017: Immediate Action Required
In March 2026, a critical vulnerability (CVE-2026-33017) was discovered in Langflow, an AI workflow platform, allowing unauthenticated remote code execution via the /api/v1/validate/code endpoint. Exploitation began within 20 hours of disclosure, leading to potential full system compromise. Organizations using Langflow are urged to update to version 1.8.0 immediately to mitigate this risk. This incident underscores the rapid weaponization of newly disclosed vulnerabilities and the necessity for prompt patching to protect AI infrastructure.
6 months ago
Kill Chain
Trivy Security Scanner Compromised: A Wake-Up Call for CI/CD Security
In late February 2026, Aqua Security's Trivy, a widely-used open-source vulnerability scanner, was compromised through its GitHub Actions workflows. An autonomous AI bot named 'hackerbot-claw' exploited vulnerabilities in Trivy's CI/CD pipeline, leading to unauthorized code execution and the exfiltration of sensitive CI/CD secrets. This breach resulted in the deletion of Trivy's GitHub repository content, disrupting numerous organizations relying on Trivy for security scanning. ([medium.com](https://medium.com/%40abhishekchauhan_68324/your-security-scanner-is-the-attack-vector-6d2a175a4f5b?utm_source=openai)) This incident underscores the escalating threat of AI-driven supply chain attacks targeting CI/CD pipelines. The automation and adaptability demonstrated by 'hackerbot-claw' highlight the urgent need for enhanced security measures in development workflows to prevent similar breaches.
6 months ago
Kill Chain
GSocket Backdoor Delivered Through Bash Script
In March 2026, a malicious Bash script was discovered installing a GSocket backdoor on compromised systems. GSocket, a networking tool, enables peer-to-peer communication using a shared secret, bypassing traditional security controls. The script downloads and executes a copy of gs-netcat, establishing a connection to a remote server. It employs persistence mechanisms such as cron jobs and modifications to the .profile file, ensuring the backdoor remains active. Additionally, the script utilizes anti-forensic techniques by manipulating file timestamps to conceal its activities. This incident underscores the evolving sophistication of malware targeting Unix-based systems, including Linux and macOS, and highlights the need for vigilant security practices to detect and mitigate such threats.
6 months ago
Kill Chain
Magento's 'SessionReaper' Vulnerability: A Critical Threat to E-Commerce Security
In October 2025, a critical vulnerability known as 'SessionReaper' (CVE-2025-54236) was discovered in Adobe Commerce and Magento Open Source platforms. This flaw, stemming from improper input validation, allows unauthenticated attackers to execute arbitrary code via the Commerce REST API, leading to potential full system compromise and unauthorized access to sensitive customer data. Despite Adobe releasing a patch in September 2025, reports indicate that as of late October, approximately 62% of Magento stores had not applied the necessary fixes, leaving them vulnerable to exploitation. ([threatprotect.qualys.com](https://threatprotect.qualys.com/2025/10/24/adobe-magento-improper-input-validation-vulnerability-exploited-in-attack-cve-2025-54236/?utm_source=openai)) The active exploitation of SessionReaper underscores the critical importance of timely patch management in e-commerce platforms. With attackers increasingly targeting unpatched systems, organizations must prioritize the application of security updates to mitigate risks associated with such vulnerabilities.
6 months ago
Kill Chain
Claude Code's 2026 Security Flaw: A Wake-Up Call for Agentic AI
In February 2026, a critical vulnerability (CVE-2026-24052) was identified in Claude Code, an agentic coding tool developed by Anthropic. The flaw involved insufficient URL validation in the trusted domain verification mechanism for WebFetch requests. Specifically, the application used the `startsWith()` function to validate trusted domains, allowing attackers to register subdomains that could bypass this validation. This vulnerability enabled automatic requests to attacker-controlled domains without user consent, potentially leading to data exfiltration. Anthropic addressed this issue by releasing a patch in version 1.0.111. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-24052?utm_source=openai)) This incident underscores the growing security challenges associated with agentic AI systems, which operate autonomously and can interact with external resources. The exploitation of such vulnerabilities highlights the need for robust validation mechanisms and comprehensive security assessments in AI-driven tools to prevent unauthorized data access and exfiltration.
6 months ago
Kill Chain
LeakNet Ransomware's Innovative Use of ClickFix and Deno Runtime in 2026 Attacks
In March 2026, the LeakNet ransomware group initiated a sophisticated attack campaign leveraging the ClickFix social engineering technique and the Deno JavaScript runtime. By presenting fake prompts, they tricked users into executing malicious commands, leading to the deployment of a Deno-based loader that executed JavaScript payloads directly in system memory. This method minimized forensic evidence and enhanced evasion of traditional security measures. The adoption of legitimate tools like Deno for malicious purposes underscores a growing trend among threat actors to evade detection. Organizations must remain vigilant against such evolving tactics, emphasizing the need for comprehensive security awareness training and advanced threat detection mechanisms.
6 months ago
Kill Chain
LayerX Uncovers Font-Rendering Exploit Targeting AI Assistants
In March 2026, LayerX researchers unveiled a novel font-rendering attack that exploits discrepancies between how AI assistants and web browsers interpret HTML content. By utilizing custom fonts and CSS techniques, attackers can display malicious commands to users while presenting benign content to AI tools analyzing the same page. This method effectively deceives AI assistants into endorsing harmful instructions, leading users to execute potentially dangerous commands under false assurances of safety. This incident underscores a critical vulnerability in AI-assisted browsing, highlighting the need for enhanced security measures that account for the visual rendering of web content. As AI tools become increasingly integrated into daily workflows, understanding and mitigating such sophisticated social engineering tactics is imperative to maintain user trust and system integrity.
6 months ago
Kill Chain
Amazon Bedrock AgentCore 2026 DNS Exfiltration Vulnerability
In March 2026, cybersecurity researchers identified a vulnerability in Amazon Bedrock AgentCore's Code Interpreter, allowing attackers to exfiltrate sensitive data via DNS queries. The flaw permitted outbound DNS requests from the sandbox environment, enabling unauthorized data transmission. This vulnerability underscores the critical need for robust security measures in AI code execution platforms to prevent data breaches. Organizations utilizing AI agents must implement stringent controls to mitigate such risks.
6 months ago
Kill Chain
Warlock Ransomware Group's 2025 Exploitation of SharePoint Vulnerabilities
In mid-2025, the Warlock ransomware group exploited unpatched Microsoft SharePoint servers to gain initial access to various organizations across North America, Europe, Asia, and Africa. Utilizing known vulnerabilities (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771), they deployed web shells via HTTP POST requests, enabling reconnaissance, credential theft, and lateral movement. The attack culminated in the deployment of ransomware, encrypting files with the .x2anylock extension and exfiltrating data using RClone. ([clearphish.ai](https://www.clearphish.ai/news/warlock-ransomware-sharepoint-attacks-2025?utm_source=openai)) This incident underscores the critical importance of timely patch management, especially for widely used enterprise applications like SharePoint. The Warlock group's rapid escalation from forum discussions to impactful campaigns highlights the evolving threat landscape and the need for organizations to bolster their cybersecurity defenses against sophisticated ransomware operations.
6 months ago
Kill Chain
GlassWorm Malware: A 2026 Supply Chain Attack on Developer Ecosystems
In early 2026, the GlassWorm malware resurfaced, compromising the Open VSX Registry by infiltrating trusted developer accounts. Attackers published malicious updates to widely used VS Code extensions, embedding loaders that executed encrypted payloads to steal sensitive information, including developer credentials and cryptocurrency wallets. The malware employed advanced evasion techniques, such as using invisible Unicode characters and leveraging the Solana blockchain for command-and-control communication, making detection and mitigation challenging. This incident underscores the escalating sophistication of supply chain attacks targeting developer ecosystems. The use of decentralized infrastructures and obfuscation methods highlights the need for enhanced vigilance and security measures within software development communities to prevent similar breaches.
6 months ago
Kill Chain
Introducing Augustus: Praetorian's Open-Source LLM Vulnerability Scanner
In February 2026, Praetorian released Augustus, an open-source vulnerability scanner designed to test Large Language Models (LLMs) against a comprehensive suite of adversarial attacks. Augustus automates over 210 distinct attack vectors, including prompt injections and jailbreaks, across 28 LLM providers. This tool addresses the growing need for robust security testing as enterprises rapidly integrate generative AI into their products. By providing a portable, single-binary solution, Augustus facilitates seamless integration into continuous integration/continuous deployment (CI/CD) pipelines, enabling security teams to identify and mitigate vulnerabilities efficiently. The release of Augustus underscores the escalating threats targeting LLMs, as adversaries increasingly exploit these models for malicious purposes. The tool's comprehensive testing capabilities highlight the necessity for organizations to proactively assess and fortify their AI systems against evolving attack methodologies.
6 months ago
Kill Chain
ClickFix Campaigns Exploit AI Tool Installers to Deploy MacSync Infostealer
In late 2025 and early 2026, multiple ClickFix campaigns emerged, targeting macOS users with the MacSync infostealer. These campaigns utilized malicious Google Ads and AI-generated content to lure users into executing terminal commands that installed the malware. The MacSync infostealer is capable of exfiltrating credentials, browser data, and cryptocurrency wallet information. ([cybernews.com](https://cybernews.com/security/hackers-spread-mac-infostealer-using-google-ads/?utm_source=openai)) This incident underscores a growing trend of sophisticated social engineering attacks that exploit user trust in AI tools and search engine results. The increasing prevalence of such tactics highlights the need for heightened vigilance and user education to prevent similar breaches. ([techmonk.economictimes.indiatimes.com](https://techmonk.economictimes.indiatimes.com/news/security-alert/security-alert-clickfix-campaign-abuses-claude-artifacts-and-google-ads-to-drop-macos-infostealer/128334810?utm_source=openai))
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports