Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Critical Unauthenticated RCE Vulnerability in n8n (CVE-2026-21858)
In early January 2026, a critical vulnerability, CVE-2026-21858, was discovered in n8n, an open-source workflow automation platform. This flaw, dubbed 'Ni8mare,' allows unauthenticated remote code execution due to improper input validation in form-based workflows. Exploiting this vulnerability enables attackers to gain full control over affected servers, leading to potential data theft, workflow manipulation, and system compromise. ([purple-ops.io](https://www.purple-ops.io/resources-hottest-cves/cve-2026-21858-ai-exploit/?utm_source=openai)) The widespread use of n8n, with over 100 million Docker pulls and numerous internet-exposed instances, amplifies the risk. As of January 11, 2026, approximately 59,500 vulnerable hosts remain exposed, highlighting the urgency for organizations to apply the available patches promptly. ([techradar.com](https://www.techradar.com/pro/security/thousands-of-n8n-instances-under-threat-from-top-security-issue?utm_source=openai))
7 months ago
Kill Chain
Safeguarding AI Assets: Lessons from the 2025 Model Extraction Attack
In 2025, a significant AI model extraction attack was identified, where adversaries systematically queried a proprietary machine learning model's API to replicate its functionality. By sending carefully crafted inputs and analyzing the outputs, attackers reconstructed a substitute model that closely mirrored the original's behavior. This breach exposed the model's intellectual property, leading to potential competitive disadvantages and financial losses for the organization. The incident underscores the vulnerabilities inherent in exposing AI models through APIs without adequate security measures. ([techtarget.com](https://www.techtarget.com/searchsecurity/tip/AI-model-theft-Risk-and-mitigation-in-the-digital-era?utm_source=openai)) The rise of such model extraction attacks highlights the urgent need for organizations to implement robust defenses, including rate limiting, output perturbation, and behavioral monitoring, to protect their AI assets from unauthorized replication and misuse. ([snyk.io](https://snyk.io/articles/ai-model-theft/?utm_source=openai))
7 months ago
Kill Chain
Swarmer Tool: Exploiting Windows Legacy Features for Stealthy Registry Persistence
In February 2025, Praetorian Inc. introduced 'Swarmer,' a tool designed to achieve stealthy Windows registry persistence without triggering Endpoint Detection and Response (EDR) systems. By exploiting legacy Windows features such as mandatory user profiles and the Offline Registry API, Swarmer allows low-privilege users to modify the NTUSER hive covertly. This method bypasses standard registry APIs monitored by EDR solutions, enabling attackers to establish persistence without detection. The release of Swarmer underscores the ongoing challenges in cybersecurity, particularly the exploitation of overlooked system functionalities. As attackers continue to innovate, it is imperative for organizations to reassess and fortify their security postures against such sophisticated techniques.
7 months ago
Kill Chain
Match Group's 2026 Data Breach: A Wake-Up Call for Digital Security
In late January 2026, Match Group, the parent company of popular dating platforms such as Hinge, Match.com, and OkCupid, experienced a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers claimed to have exfiltrated over 10 million user records, including user IDs, transaction details, IP addresses, and internal corporate documents. The breach was reportedly facilitated through a vulnerability in AppsFlyer, a mobile marketing analytics platform utilized by Match Group. Match Group promptly initiated an investigation with external cybersecurity experts and began notifying affected users. Preliminary findings indicated that user login credentials, financial information, and private communications were not accessed. ([cybernews.com](https://cybernews.com/security/hinge-okcupid-data-leak-shinyhunters-claims/?utm_source=openai)) This incident underscores the persistent threat posed by sophisticated cybercriminal organizations like ShinyHunters, known for targeting high-profile companies and leaking sensitive data. The breach highlights the critical importance of securing third-party integrations and the need for robust cybersecurity measures to protect user data. Organizations must remain vigilant and proactive in identifying and mitigating potential vulnerabilities to prevent similar incidents.
7 months ago
Kill Chain
WinRAR Patch Delays Enable Nation-State Attackers in 2024
In early 2024, nation-state threat actors from Russia and China exploited a critical WinRAR vulnerability (CVE-2023-38831) well after a public patch became available in July 2023. Attackers leveraged the flaw via malicious archive files to gain initial access, with phishing lures targeting small- and medium-sized businesses (SMBs) and government targets. Despite availability of security updates and widespread coverage, a significant number of organizations remained unpatched, enabling cyber-espionage operations, data theft, and operational disruptions. This incident highlights the persistent risk posed by software supply chain vulnerabilities, especially when patch adoption is slow. The continued exploitation of a months-old flaw underscores how threat actors weaponize common utilities and rely on lagging defenses, driving urgency for improved vulnerability management and zero trust controls.
7 months ago
Kill Chain
xAI Grok Deepfakes Spark 2024 Class Action: Legal and Security Wake-Up Call for AI
In January 2024, a class action lawsuit was filed against xAI—parent company of Grok—alleging that the generative AI chatbot enabled the creation and public dissemination of millions of non-consensual, sexualized deepfake images of women, men, and children. Victims claim that xAI executives failed to implement safeguards, allowed features that facilitated image manipulation simply by tagging users, and promoted options encouraging explicit content generation. Investigations are now being pursued internationally, and at least 100 plaintiffs are seeking justice for significant reputational, psychological, and legal harm stemming from Grok’s misuse. This major incident is emblematic of the growing risks in AI/ML security, as emerging generative tools become vehicles for large-scale privacy violations and abuse. The resulting public and regulatory scrutiny highlights urgent compliance and ethical gaps, especially as new legislation around synthetic sexual content and child abuse material accelerates worldwide.
7 months ago
Kill Chain
Enterprise AI at Risk: Hackers Hijack Exposed LLM Endpoints in Bizarre Bazaar Operation
In early June 2024, security researchers revealed an active campaign—dubbed the Bizarre Bazaar operation—where threat actors systematically scanned for and exploited publicly exposed Large Language Model (LLM) service endpoints. Attackers hijacked these AI/ML endpoints by bypassing inadequate API controls and leveraging unsecured cloud configurations, enabling unauthorized access to advanced AI resources. Compromised infrastructure became part of an underground market offering illicit AI compute power, leading to business risks ranging from intellectual property leakage to tool misuse and service disruption for impacted organizations. This incident spotlights the growing exploitation of AI infrastructure, with attackers rapidly adopting novel tactics as organizations rush to deploy LLMs. Weak segmentation, lack of egress controls, and poor visibility have left many organizations vulnerable to sophisticated abuse, elevating urgency for robust enterprise AI security and compliance measures.
7 months ago
Kill Chain
SolarWinds Web Help Desk Flaws: Critical RCE and Authentication Bypass in 2024
In June 2024, SolarWinds disclosed and patched multiple critical vulnerabilities in its Web Help Desk software, including an authentication bypass (CVE-2024-28995) and a remote command execution (RCE) flaw. These security issues, if left unpatched, allow attackers to compromise systems with minimal or no authentication, granting them access to execute arbitrary commands and potentially control affected servers. SolarWinds urged its customers to update immediately and disclosed that no in-the-wild exploitation had been confirmed at the time of announcement, but the severity of the flaws warranted immediate action across enterprise environments. This incident is particularly relevant due to a surge in software supply chain and IT management platform attacks, where adversaries exploit widely used admin tools to gain privileged access. Critical RCE and authentication vulnerabilities present potent risks to organizations, intensifying regulatory scrutiny and heightening the importance of timely patch management and proactive security measures.
7 months ago
Kill Chain
New Sandbox Escape Flaws in n8n Expose Instances to Remote Code Execution
In January 2026, security researchers uncovered two critical sandbox escape vulnerabilities in the popular n8n workflow automation platform, identified as CVE-2026-1470 and CVE-2026-0863. The flaws allowed authenticated users to exploit weaknesses in JavaScript and Python sandboxing mechanisms, enabling remote code execution on affected self-hosted instances. Attackers with valid user credentials could abuse these vulnerabilities to gain control of underlying systems, access sensitive data, and potentially compromise integrated services. Despite requiring authentication, the ease of privilege escalation and potential for lateral movement made these vulnerabilities highly impactful. This incident is highly significant given the large number of exposed n8n instances and the growing reliance on workflow automation by organizations worldwide. The vulnerabilities underline persistent challenges in securely sandboxing dynamic scripting languages, a common risk in platforms that allow code-based automation or AI integrations. The slow patching pace also highlights the pressing need for improved vulnerability management across self-hosted cloud infrastructure.
7 months ago
Kill Chain
Fake PyPI Spellchecker Packages Delivered RAT in Supply Chain Attack (2026)
In early 2026, security researchers uncovered a supply chain attack involving two malicious packages—spellcheckerpy and spellcheckpy—distributed on the popular Python Package Index (PyPI). Masquerading as legitimate spellchecking tools, these packages were downloaded over 1,000 times before removal, each covertly containing a remote access trojan (RAT). When unsuspecting developers installed the packages, attackers could gain persistent access to compromised systems, enabling data exfiltration, lateral movement, and remote command execution. No specific organizational victims were named, but the risk extended globally to Python developers and projects that leveraged these components. This incident is emblematic of the growing trend of supply chain attacks targeting open source repositories, exploiting trust in widely used ecosystems like PyPI. As software supply chains become common attack vectors, organizations face heightened pressure to vet dependencies and implement controls to prevent compromise via upstream components.
7 months ago
Kill Chain
Exposed Interfaces & Supply Chain Risks: The 2026 Moltbot AI Assistant Breach
In January 2026, researchers uncovered widespread security vulnerabilities in Moltbot (formerly Clawdbot), an open-source AI assistant that achieved viral adoption among both consumers and employees in the enterprise sector. Due to prevalent misconfigurations—specifically, exposed admin interfaces and reverse proxy errors—hundreds of Moltbot instances were accessible online, allowing unauthenticated attackers to steal API keys, OAuth tokens, credentials, message histories, and even execute commands remotely with system-level permissions. Additional risks arose as malicious skills (modules) could be planted in the official registry, rapidly propagating supply-chain threats to unsuspecting enterprise and developer systems, further compounded by the assistant lacking sandboxing or privilege separation by default. This incident highlights a growing trend where AI/GenAI tools, easily adopted outside corporate IT control, create new vectors for credential theft, data leakage, and lateral movement. As attackers focus on AI-driven endpoints and shadow IT, failure to enforce zero trust, segmentation, and robust monitoring introduces significant business risk and regulatory exposure.
7 months ago
Kill Chain
Google Flags Ongoing Exploitation of WinRAR CVE-2025-8088 by Elite Threat Actors
In July 2025, a critical vulnerability (CVE-2025-8088) in RARLAB WinRAR was identified and subsequently patched, but not before multiple threat actors, including government-backed groups from Russia and China as well as financially motivated cybercriminals, actively exploited it. Attackers leveraged the flaw as an initial access vector, distributing diverse malicious payloads to compromise targeted systems. The exploitation campaign enabled unauthorized access to sensitive environments and facilitated follow-on activities such as lateral movement and data exfiltration, raising serious concerns for organizations and individuals relying on WinRAR for file management. This incident is significant as it highlights the speed and sophistication with which both nation-state and financially driven attackers weaponize zero-day vulnerabilities. The continued exploitation of unpatched systems following disclosure underscores the persistent risks organizations face from lagging patch cycles and evolving adversary tactics.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports