Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
macOS Infostealer Campaigns of 2025: Understanding the Threat Landscape
In 2025, a series of sophisticated infostealer campaigns targeted macOS users, exploiting social engineering tactics and trusted platforms to distribute malware. Attackers utilized deceptive websites, fake software installers, and malicious advertisements to deliver infostealers like Atomic macOS Stealer (AMOS), DigitStealer, and MacSync. These malware variants harvested sensitive data, including browser credentials, cryptocurrency wallets, and developer secrets, leading to significant security breaches and financial losses. The increasing prevalence of cross-platform infostealers underscores a critical shift in cyber threats, emphasizing the need for enhanced security measures across all operating systems. Organizations must remain vigilant against evolving tactics, such as the abuse of legitimate platforms and the use of fileless execution methods, to effectively mitigate these risks.
7 months ago
Kill Chain
OpenClaw AI Agent Security Vulnerabilities Exposed in 2026
In early 2026, the OpenClaw AI agent framework, formerly known as Clawdbot and Moltbot, experienced rapid adoption, amassing over 180,000 GitHub stars and 2 million visitors in a single week. This surge exposed significant security vulnerabilities, including over 1,800 instances leaking API keys, chat histories, and account credentials. The extensible nature of OpenClaw allowed malicious actors to upload at least 14 compromised 'skills' to ClawHub, the platform's public registry, between January 27 and 29, 2026. These skills, disguised as crypto trading tools, executed remote scripts to steal sensitive data from users' systems. Additionally, OpenClaw's integration with messaging applications expanded the attack surface, enabling threat actors to craft malicious prompts that led to unintended behaviors. The platform's architecture, which grants AI agents high-level privileges to execute shell commands and access local file systems, further exacerbated these risks. ([venturebeat.com](https://venturebeat.com/security/openclaw-agentic-ai-security-risk-ciso-guide?utm_source=openai)) The OpenClaw incident underscores the urgent need for robust security measures in AI agent frameworks. The rapid proliferation of autonomous AI agents with extensive system access highlights the necessity for organizations to implement stringent access controls, conduct thorough code audits, and establish comprehensive monitoring systems. This event serves as a critical reminder of the potential risks associated with deploying AI agents without adequate security protocols, emphasizing the importance of proactive measures to safeguard sensitive information and maintain system integrity.
7 months ago
Kill Chain
Notepad++ Supply Chain Attack: A 2025 Case Study
In June 2025, the Chinese state-sponsored group Lotus Blossom compromised the update infrastructure of Notepad++, a widely used open-source text editor. By infiltrating the hosting provider's server, the attackers selectively redirected update requests from targeted users to malicious servers, delivering trojanized installers embedded with a custom backdoor named Chrysalis. This sophisticated supply chain attack persisted until December 2025, affecting users in sectors such as government, telecommunications, and financial services. ([cyberscoop.com](https://cyberscoop.com/china-espionage-group-lotus-blossom-attacks-notepad/?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks, where trusted software distribution channels are exploited to infiltrate targeted systems. Organizations must enhance their software supply chain security measures to mitigate such risks. ([orca.security](https://orca.security/resources/blog/notepad-plus-plus-supply-chain-attack/?utm_source=openai))
7 months ago
Kill Chain
NationStates Data Breach Exposes User Information
In late January 2026, NationStates, a popular multiplayer browser-based game, experienced a significant data breach. A long-standing community member, previously recognized for responsible vulnerability disclosures, identified a critical flaw in the game's 'Dispatch Search' feature. While testing this vulnerability, the individual exceeded authorized boundaries, achieving remote code execution on the production server. This unauthorized access led to the copying of sensitive user data, including email addresses, MD5-hashed passwords, IP addresses, and browser UserAgent strings. The breach was publicly disclosed on January 30, 2026, prompting a temporary shutdown of the site for investigation and remediation. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/nationstates-confirms-data-breach-shuts-down-game-site/?utm_source=openai)) This incident underscores the risks associated with inadequate input sanitization and the use of outdated cryptographic practices, such as MD5 for password hashing. It highlights the necessity for organizations to implement robust security measures, including regular code audits, modern encryption standards, and strict access controls, to prevent similar breaches.
7 months ago
Kill Chain
Notepad++ 2025 Supply Chain Attack: Lessons in Software Security
In June 2025, Chinese state-sponsored hackers compromised the update infrastructure of Notepad++, a widely used text editor, by infiltrating its hosting provider. This allowed them to intercept and selectively redirect update requests from targeted users to malicious servers, delivering tampered update manifests. The attackers exploited vulnerabilities in older versions of Notepad++'s WinGUp update tool, which lacked sufficient verification controls. The breach persisted until December 2, 2025, when the hosting provider detected the intrusion and terminated the attackers' access. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/notepad-plus-plus-update-feature-hijacked-by-chinese-state-hackers-for-months/?utm_source=openai))This incident underscores the critical importance of securing software supply chains, as state-sponsored actors increasingly target update mechanisms to distribute malware. Organizations must implement robust verification processes and regularly audit their infrastructure to prevent similar attacks. ([arstechnica.com](https://arstechnica.com/security/2026/02/notepad-updater-was-compromised-for-6-months-in-supply-chain-attack/?utm_source=openai))
7 months ago
Kill Chain
OpenClaw 2026: Malicious Skills Distribute Password-Stealing Malware
Between January 27 and February 1, 2026, over 230 malicious 'skills' were uploaded to OpenClaw's official registry and GitHub repositories. These skills, masquerading as legitimate utilities, contained malware designed to steal sensitive information such as API keys, wallet private keys, SSH credentials, and browser passwords. The attackers exploited OpenClaw's plugin system to distribute these malicious packages, leading to significant data breaches for users who installed them. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/malicious-moltbot-skills-used-to-push-password-stealing-malware/?utm_source=openai)) This incident underscores the growing trend of supply chain attacks targeting open-source platforms. The ease of publishing and distributing plugins or extensions in such ecosystems presents a lucrative vector for cybercriminals. Organizations must exercise heightened vigilance when integrating third-party tools, ensuring thorough vetting processes to mitigate potential security risks.
7 months ago
Kill Chain
Open VSX Registry Compromised: GlassWorm Malware Infiltrates Developer Extensions
In late January 2026, a significant supply chain attack targeted the Open VSX Registry, an open-source marketplace for Visual Studio Code extensions. Threat actors compromised a legitimate developer's account, identified as 'oorzc', to publish malicious versions of four widely-used extensions. These tampered extensions, collectively downloaded over 22,000 times prior to detection, contained the GlassWorm malware loader. Upon installation, GlassWorm executed stealthily, harvesting sensitive data such as browser credentials, cryptocurrency wallet information, and developer authentication tokens. The malware exhibited advanced evasion techniques, including locale checks to avoid Russian systems and utilizing the Solana blockchain for command-and-control communications. The Open VSX security team promptly removed the malicious extensions and initiated measures to prevent future incidents. This incident underscores the escalating threat of supply chain attacks within developer ecosystems. The exploitation of trusted platforms to disseminate malware highlights the critical need for enhanced security protocols in software distribution channels. Organizations are urged to implement rigorous validation processes for third-party extensions and to monitor for unauthorized access to developer accounts to mitigate similar risks.
7 months ago
Kill Chain
GlassWorm macOS Supply Chain Attack: A Wake-Up Call for Developer Security
In January 2026, the GlassWorm malware campaign targeted macOS developers by infiltrating the Open VSX marketplace with malicious Visual Studio Code extensions. These extensions, downloaded over 50,000 times before removal, masqueraded as legitimate tools like 'Prettier Pro' and other productivity enhancers. Once installed, the malware delayed execution to evade detection, then decrypted and executed an AES-256-CBC encrypted JavaScript payload. It established persistence via LaunchAgents, harvested sensitive data—including GitHub and npm credentials, SSH keys, and macOS Keychain entries—and attempted to replace hardware wallet applications such as Ledger Live and Trezor Suite with trojanized versions. Command-and-control communication was maintained through the Solana blockchain, complicating traditional detection and mitigation efforts. This incident underscores the evolving sophistication of supply chain attacks targeting developer ecosystems, emphasizing the need for rigorous extension vetting processes and heightened awareness of the security risks associated with third-party development tools.
7 months ago
Kill Chain
Notepad++ Supply Chain Attack: A 2025 Case Study
Between June and December 2025, the update mechanism of Notepad++, a widely used text editor, was compromised by state-sponsored attackers. These adversaries infiltrated the shared hosting server of notepad-plus-plus.org, allowing them to intercept and redirect update traffic to malicious servers. This redirection led to the distribution of trojanized installers to select users, primarily targeting telecommunications and financial services organizations in East Asia. The attackers maintained access to internal services until December 2, 2025, enabling continued redirection of update traffic even after losing direct server access. ([arstechnica.com](https://arstechnica.com/security/2026/02/notepad-updater-was-compromised-for-6-months-in-supply-chain-attack/?utm_source=openai)) This incident underscores the growing threat of supply chain attacks, where trusted software infrastructure is exploited to distribute malware. Organizations must enhance their security measures, particularly in verifying the integrity of software updates, to mitigate such risks. ([cybernews.com](https://cybernews.com/security/state-sponsored-hackers-behind-notepad-plus-plus-hack/?utm_source=openai))
7 months ago
Kill Chain
OpenClaw's ClawHub Compromised: A 2026 Supply Chain Attack
In early 2026, security researchers uncovered a significant supply chain attack within the ClawHub marketplace, a platform for OpenClaw AI assistant extensions. Over 340 malicious 'skills' were identified, many masquerading as cryptocurrency tools, which, upon installation, executed obfuscated commands leading to the deployment of the Atomic macOS Stealer (AMOS) malware. This malware targeted sensitive user data, including browser information and cryptocurrency wallets, affecting both Windows and macOS users. The incident underscores the vulnerabilities in open-source ecosystems and the critical need for rigorous vetting of third-party extensions. The proliferation of such attacks highlights the evolving tactics of cybercriminals, emphasizing the importance of user vigilance and the implementation of robust security measures to protect against sophisticated social engineering and malware distribution strategies.
7 months ago
Kill Chain
Critical OpenClaw Vulnerability Exposes Systems to Remote Code Execution
In early February 2026, a critical vulnerability (CVE-2026-25253) was identified in OpenClaw, an open-source AI personal assistant. This flaw allowed attackers to execute remote code on a victim's system by exploiting the application's handling of the 'gatewayUrl' parameter. By crafting a malicious link, attackers could trick users into initiating a WebSocket connection that transmitted authentication tokens without validation, leading to full system compromise. The issue was addressed in version 2026.1.29, released on January 30, 2026. ([thehackernews.com](https://thehackernews.com/2026/02/openclaw-bug-enables-one-click-remote.html?utm_source=openai)) This incident underscores the importance of rigorous input validation and user confirmation mechanisms in software development. The ease of exploitation and the potential for widespread impact highlight the need for organizations to promptly apply security patches and educate users about the risks associated with clicking untrusted links.
7 months ago
Kill Chain
ShinyHunters' Exploitation of Salesforce: A 2025 Data Breach Analysis
In mid-2025, the cybercriminal group ShinyHunters orchestrated a series of sophisticated attacks targeting Salesforce instances across multiple organizations. Utilizing voice phishing (vishing) techniques, attackers impersonated IT support staff to deceive employees into authorizing malicious connected applications within their Salesforce environments. This strategy granted the attackers unauthorized access to vast amounts of sensitive customer data, including personally identifiable information (PII) and corporate records. Notable victims included Google, Workday, and Qantas, with data breaches exposing millions of records. The stolen data was subsequently used for extortion, with threats to publicly release the information unless ransom demands were met. ([forbes.com](https://www.forbes.com/councils/forbestechcouncil/2025/12/03/shinyhunters-salesloft-drift-and-the-case-for-dynamic-saas-security/?utm_source=openai)) This incident underscores a significant shift in cybercriminal tactics, highlighting the increasing reliance on social engineering methods to exploit human vulnerabilities within organizations. The collaboration between ShinyHunters and other threat actors, such as Scattered Spider, indicates a trend towards more coordinated and aggressive cyberattacks. Organizations are urged to enhance their security awareness programs, implement robust multi-factor authentication protocols, and scrutinize third-party integrations to mitigate the risk of similar breaches. ([cyberpress.org](https://cyberpress.org/shinyhunters-salesforce-hack/?utm_source=openai))
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports