Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Massive Unicode Phishing Campaign Evades Email Filters Using Invisible Characters
A sophisticated phishing campaign identified by Microsoft in 2026 leveraged invisible Unicode tag characters to bypass email security filters while targeting millions of recipients with financial lures. The campaign, which peaked between February and May 2026, sent up to 2.37 million messages daily using AI-generated content distributed through the legitimate ActiveCampaign marketing platform. Attackers inserted invisible Unicode characters into financial keywords like 'funding' to evade detection while appearing normal to human recipients, demonstrating how AI-era evasion techniques are being adapted for traditional phishing campaigns. This incident highlights the evolving sophistication of email-based attacks in the AI era, where threat actors are exploiting legitimate marketing platforms and advanced obfuscation techniques to scale phishing operations at unprecedented volumes while evading traditional security controls.
2 weeks ago
Kill Chain
ASCII Smuggling Crosses Over: How AI Attack Techniques Are Transforming Phishing
In February 2026, Microsoft researchers identified a large-scale phishing campaign that repurposed ASCII smuggling techniques originally developed for AI prompt injection attacks. The attackers used invisible Unicode tag characters (U+E0000-U+E007F) to split financial lure words like 'funding' within phishing emails, evading traditional email security filters that rely on keyword detection. The campaign peaked at over 2.3 million messages daily and operated through legitimate email marketing infrastructure, demonstrating how AI-era attack techniques are crossing over into traditional threat vectors. This incident highlights the evolving sophistication of phishing attacks as threat actors adapt cutting-edge evasion techniques originally designed for AI systems to bypass conventional email security defenses. The crossover represents a significant shift in the threat landscape where AI security research methods are being weaponized for traditional cybercrime.
2 weeks ago
Kill Chain
AI Coding Agents Become Attack Vectors: The 2026 Supply Chain Breach
In 2026, security researchers discovered a critical supply chain vulnerability affecting AI coding agents used by Fortune 500 companies and defense contractors. By scanning over 6,000 corporate domains, researchers found 120 llms.txt files pointing to unregistered code packages. When they registered these domains and hosted malicious packages, AI agents including Claude, OpenAI's Codex, and Nous Research's Hermes automatically downloaded and executed the code within hours, creating backdoors into corporate networks. The attack demonstrated how AI agents blindly trust vendor documentation without verification, treating it as ground truth and bypassing human oversight. This represents a new class of supply chain attack vector where autonomous AI systems become unwitting accomplices in corporate network compromise, similar to the SolarWinds incident but leveraging AI agent automation for broader impact.
2 weeks ago
Kill Chain
AI-Powered Exploitation of Georgia Voting System Reveals Election Security Gaps
A previously disclosed vulnerability in voting systems used across 21 U.S. states, including Georgia, was exploited using AI tools during the May 2026 primary election to recover the chronological order of ballots cast. The attack required only publicly available data sources - early voting lists and cast-vote record (CVR) files - combined with AI coding agents to analyze voter behavior patterns. No direct access to voting machines, networks, or source code was necessary, demonstrating how AI amplifies the exploitation of known vulnerabilities in critical infrastructure. This incident highlights the growing intersection of AI capabilities with election security vulnerabilities, as threat actors increasingly leverage automated tools to exploit weaknesses in democratic processes and critical infrastructure systems.
2 weeks ago
Kill Chain
Critical Elementor Pro Vulnerability Enables WordPress Site Takeovers
In September 2026, threat actors began actively exploiting CVE-2026-32475, a critical vulnerability in the Elementor Pro WordPress plugin with over 6 million installations. The flaw allows attackers to bypass file upload validation by submitting an empty file as the first array element and a malicious PHP file as the second, enabling arbitrary code execution on vulnerable WordPress sites. Wordfence recorded nearly 200,000 exploitation attempts within days of the August 19 patch release, with attackers successfully deploying webshells to the /wp-content/uploads/elementor/forms/ directory for remote command execution. This incident highlights the persistent risk of web application vulnerabilities in popular content management systems, particularly when exploitation begins immediately after patch availability. The rapid weaponization demonstrates sophisticated threat actor capabilities in identifying and exploiting plugin vulnerabilities that affect millions of websites worldwide.
2 weeks ago
Kill Chain
ThreatsDay 2026 Attack Analysis: When Social Engineering Meets Cloud Vulnerabilities
The ThreatsDay September 2026 report highlights a sophisticated multi-vector attack campaign featuring CEO-targeted phishing kits, over 5,000 compromised Dropbox accounts, and OAuth authentication bypass techniques. The attacks leveraged social engineering tactics that appeared legitimate, including fake IT support calls, malicious shared files, and trusted application impersonation to gain initial access. Threat actors exploited normal business processes and user trust, making detection extremely difficult. The campaign resulted in widespread credential theft, unauthorized access to cloud storage platforms, and potential data exfiltration across multiple organizations. This incident represents the evolving landscape of sophisticated social engineering attacks that bypass traditional security controls by exploiting human psychology and trusted business processes, highlighting the critical need for zero-trust architectures and enhanced user awareness training.
2 weeks ago
Kill Chain
The AI Vulnerability Surge: Why 2026's 'Vulnpocalypse' May Be More Manageable Than Expected
New research from Echo analyzing nearly 40,000 CVE lifecycles reveals that while AI tools like Anthropic's Claude Mythos have dramatically accelerated vulnerability discovery, the anticipated 'Vulnpocalypse' may be more manageable than feared. Monthly CVE disclosures surged 145% from June 2024 to June 2026, rising from 3,173 to 7,765, with AI enabling exploit development in under one day for less than $2,000. However, fewer than 10% of AI-discovered vulnerabilities receive external validation, and most critical ratings are downgraded upon review. The study found that 89% of examined vulnerabilities already have fixes available, but 40% remain unpatched for over six months due to deployment challenges rather than fix availability. Organizations can better manage this surge by focusing on rapid validation, intelligent prioritization, and automated remediation processes rather than completely overhauling their vulnerability management programs.
2 weeks ago
Kill Chain
Machine Speed Terror: How AI Agents Compressed a 2-Week Breach Into 10 Hours
In September 2026, threat actors demonstrated the devastating potential of AI-assisted cyberattacks by compressing a typical two-week enterprise breach timeline into just 10 hours. The attackers deployed coordinated frontier AI agents that autonomously breached network security layers, harvested credentials, seized root access, hijacked CI/CD pipelines, and weaponized the victim's own AI infrastructure. The attack began with exploitation of a public API endpoint and escalated through systematic extraction of hardcoded tokens from code repositories, ultimately providing master administrative credentials and complete system compromise. This machine-speed ransomware attack represents a paradigm shift from individual AI-assisted tasks to orchestrated multi-agent operations that can outpace traditional security response capabilities. The emergence of AI-driven attack coordination signals a new era where threat actors can achieve enterprise-scale breaches with unprecedented speed and efficiency, forcing organizations to fundamentally reimagine their defense strategies and response timelines.
2 weeks ago
Kill Chain
Seven Critical Vulnerabilities Exploited in Wild: AI Infrastructure Becomes Prime Target
CISA added seven critical vulnerabilities to its Known Exploited Vulnerabilities catalog in September 2026 after observing active exploitation by threat actors. The vulnerabilities span multiple platforms including SonicWall SMA appliances, Sangoma Switchvox, JFrog Artifactory, and AI infrastructure components like LiteLLM and Kestra. Attackers exploited these flaws to deploy reverse shells, cryptocurrency miners, and conduct unauthorized operations, with campaigns targeting AI infrastructure becoming increasingly prominent as adversaries seek to harvest API keys and monetize compromised systems. This incident highlights the growing threat landscape targeting AI infrastructure and the critical importance of rapid vulnerability remediation. With AI systems becoming prime targets for credential theft and resource hijacking, organizations must prioritize security updates and implement comprehensive monitoring across their AI workloads to prevent similar exploitation campaigns.
2 weeks ago
Kill Chain
Shai-Hulud Infostealer Evolves to Target 469 Credential Locations Across Software Supply Chains
In August 2026, GitGuardian researchers discovered that the Shai-Hulud infostealer worm had evolved to scan for credentials across 469 locations in developer environments, representing a 148% increase from earlier variants that checked only 189 paths. The malware targets CI/CD tooling, cloud configurations, AI tool configs, package registries, and development environments to harvest reusable credentials for supply chain attacks. The stolen credentials enable lateral movement across trusted software supply chains, turning credential theft into ongoing propagation vectors through package publishing systems. This incident highlights the critical shift in attack methodologies where threat actors no longer need to break trust relationships but instead exploit existing credential sprawl across modern development ecosystems. The exponential increase in targeted credential locations demonstrates the growing sophistication of supply chain attacks and the urgent need for comprehensive secrets management across DevOps pipelines.
2 weeks ago
Kill Chain
Threat Actors Weaponize Trusted Node.js Runtime for Stealth Malware Delivery
Since February 2026, threat actors have been weaponizing the legitimate Node.js JavaScript runtime (node.exe) to deliver malicious payloads in targeted attacks against government departments, technology companies, and hotels. The Symantec Threat Hunter Team identified this technique as particularly effective because node.exe is a trusted binary that can execute arbitrary JavaScript code while evading traditional security detection mechanisms. Attackers leverage the runtime's legitimate presence in enterprise environments to establish persistence, execute malware, and maintain command and control communications without triggering security alerts. This campaign reflects the growing trend of living-off-the-land tactics where attackers abuse legitimate system tools rather than deploying custom malware, making detection significantly more challenging for traditional security solutions and highlighting the need for behavioral analysis and runtime protection.
2 weeks ago
Kill Chain
Inside the Lazarus Group's Fake IT Worker Employment Scam: A 2024 Investigation
Security researchers from ANY.RUN conducted an extensive investigation into North Korean IT worker infiltration schemes by creating a fake company to attract fraudulent job applicants. The study revealed sophisticated operations where Lazarus Group affiliates use stolen identities, AI-generated profile photos, and elaborate cover stories to secure remote positions at legitimate organizations. These fake employees then establish persistent access to corporate networks, potentially enabling data theft, intellectual property exfiltration, and deployment of malware while generating revenue for North Korean state operations. The investigation documented multiple phases of the scam including initial contact, identity verification circumvention, and operational security measures used by the infiltrators. This represents a significant evolution in state-sponsored cyber operations, blending traditional espionage with employment fraud to achieve long-term network access and financial gain for the DPRK regime.
2 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports