Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

2227 threat reports
Page 162 of 186

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Computer Software/Engineering Threat Reports

Showing 19331944 / 2227 reports
North Korean Insider Fraud Breach: How US Firms Were Infiltrated in 2024
Impact· low

North Korean Insider Fraud Breach: How US Firms Were Infiltrated in 2024

In early 2024, the U.S. Department of Justice announced that five individuals pleaded guilty to helping North Korean operatives illicitly obtain remote IT work with American companies. The accused provided support and deception to facilitate North Korean nationals—working under assumed identities—to infiltrate U.S. organizations in a widespread insider threat campaign. These operatives gained access to proprietary data and corporate resources, generating significant revenue for North Korea through fraudulently obtained salaries, often paid in cryptocurrency. The scheme exploited remote work arrangements and weaknesses in identity verification, posing serious risks to sensitive sectors and exposing organizations to data theft and compliance violations. This case illustrates the increasing sophistication of insider threat attacks using stolen or falsified identities, especially targeting remote workforces. Organizations face growing urgency to enhance zero trust security, segment lateral movement, and strengthen controls for detecting and verifying remote personnel as geopolitical actors intensify efforts to bypass western sanctions and exploit globalized IT supply chains.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
ImunifyAV RCE Flaw Puts Millions of Linux Websites at Immediate Risk in 2024
Impact· medium

ImunifyAV RCE Flaw Puts Millions of Linux Websites at Immediate Risk in 2024

In June 2024, a critical remote code execution (RCE) vulnerability was discovered in ImunifyAV, a malware scanner widely deployed on Linux web servers hosting millions of websites globally. Attackers could exploit this unauthenticated flaw to execute arbitrary code on vulnerable servers, potentially gaining full control over hosting environments and compromising customer websites at scale. The flaw threatened the security of hosting providers and their clients, enabling advanced threat actors to launch further attacks, steal data, or deploy additional malware. Immediate patching was required to prevent exploitation in the wild. This incident underscores the increasing risks posed by third-party security tool vulnerabilities, especially in shared and cloud-hosted web environments. Rapid exploitation of newly disclosed software flaws and supply chain attacks continues to rise, highlighting the critical importance of timely patch management and zero trust controls.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
IndonesianFoods npm Worm Floods Registry with 100,000 Packages in Major Supply Chain Incident
Impact· high

IndonesianFoods npm Worm Floods Registry with 100,000 Packages in Major Supply Chain Incident

In June 2024, the npm package ecosystem was targeted by a self-propagating malware dubbed the 'IndonesianFoods' worm. The worm exploited npm’s open publishing model, rapidly flooding the registry with nearly 100,000 malicious, junk packages at a rate of one every seven seconds. Working autonomously, the malware replicated itself using pre-programmed scripts, creating an unprecedented scale of package spam, which overwhelmed the registry, threatened package discovery, and disrupted normal operations for developers worldwide. No evidence so far points to direct compromise of sensitive data or targeted attacks on organizations, but the overwhelming volume affected the trust and stability of the npm supply chain platform. This event spotlights the vulnerability of open-source ecosystems to automated spam and self-replicating threats, underscoring the growing risk in software supply chains from both criminal and experimental actors. The surge in npm-focused attacks amplifies calls for stronger package validation, improved security automation, and supply-chain controls industry-wide.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Flood of Fake npm Packages Reveals Growing Supply Chain Attack Risk
Impact· high

Flood of Fake npm Packages Reveals Growing Supply Chain Attack Risk

In early 2024, a financially-motivated threat actor orchestrated a large-scale spam campaign that flooded the npm package registry with over 67,000 fake packages. By systematically publishing malicious and junk modules, the actor exploited npm’s open nature, allowing the fake packages to persist on the platform for nearly two years. These packages, often uploaded with auto-generated names and code, increased risks for developers by inflating dependency confusion attack surfaces and potentially delivering malware through the software supply chain. The incident underscored ongoing challenges in detecting and mitigating large-scale abuse within open-source ecosystems, disrupting trust and reliability for countless organizations relying on npm. This attack is emblematic of a wider trend in software supply-chain targeting, with threat actors increasingly exploiting public repositories to propagate malicious code or disrupt developer workflows. As software supply chains remain a critical risk focal point, organizations face mounting regulatory scrutiny and require robust governance and anomaly detection controls to safeguard development environments.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
When Vulnerabilities Strike at Machine Speed: The 2026 Supply Chain Attack
Impact· medium

When Vulnerabilities Strike at Machine Speed: The 2026 Supply Chain Attack

In early 2026, a sophisticated global supply chain attack exploited vulnerabilities in widely used software components just hours after new CVEs were publicly disclosed. Threat actors weaponized exploit code at unprecedented speed, targeting unpatched enterprise systems across cloud, hybrid, and on-prem environments. The adversaries leveraged compromised update channels and lateral east-west movement to deploy malicious payloads, exfiltrate data, and disrupt critical services. Businesses faced operational downtime, data loss, and compliance exposures as traditional patch cycles failed to keep pace with machine-speed attacks. This breach underscores how the rapid turn from vulnerability disclosure to global exploitation has become a defining security risk. The event highlights the urgent need for automation, zero trust segmentation, and machine-speed threat detection to mitigate threats that now outpace human-led response.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
2024 Salesloft-Drift Supply Chain Breach: AWS Credential Exposure and Cloud Security Lessons
Impact· low

2024 Salesloft-Drift Supply Chain Breach: AWS Credential Exposure and Cloud Security Lessons

In early 2024, a sophisticated supply chain attack targeted the Salesloft and Drift integration, leading to the compromise of AWS credentials and unauthorized access to cloud environments. Threat actors exploited weaknesses in the integration pipeline, leveraging exposed secrets to move laterally and access sensitive customer data before the breach became public. Red Canary detected anomalous cloud activity tied to this attack, providing early detection prior to broad public awareness and response, thereby helping to mitigate further impact. This incident is significant as it demonstrates the growing frequency and sophistication of supply chain attacks within SaaS and cloud services, especially those exploiting secret leaks and third-party application integrations. The breach highlights the need for heightened vigilance, identity and credential protection, and advanced threat detection capabilities in the cloud ecosystem.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Siemens Altair Grid Engine 2025: Local Privilege Escalation and OT Vulnerability Risks
Impact· medium

Siemens Altair Grid Engine 2025: Local Privilege Escalation and OT Vulnerability Risks

In November 2025, Siemens disclosed two local privilege escalation vulnerabilities affecting all versions of Altair Grid Engine prior to V2026.0.0. These flaws, identified as CVE-2025-40760 (Generation of Error Message Containing Sensitive Information) and CVE-2025-40763 (Uncontrolled Search Path Element), could allow attackers with local access to extract password hashes or execute arbitrary code with superuser permissions by manipulating environment variables or error handling processes. Although there has been no evidence of exploitation in the wild, the vulnerabilities required only low attack complexity and affected critical manufacturing environments globally. This incident highlights ongoing risks posed by improper input validation and error handling in operational technology (OT) environments, especially as attackers increasingly target privilege escalation vectors. Regulatory bodies emphasize swift detection, patching, and IT/OT segmentation to reduce attack surface, as local escalation flaws remain a persistent threat vector in critical infrastructure.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Operation Endgame 2024: Global Law Enforcement Strikes Down Major Malware Networks
Impact· medium

Operation Endgame 2024: Global Law Enforcement Strikes Down Major Malware Networks

In November 2024, a coalition of law enforcement agencies from 11 countries coordinated Operation Endgame, a major crackdown disrupting some of the most prolific malware networks globally. The operation targeted Rhadamanthys infostealer, VenomRAT remote access trojan, and the Elysium botnet—malware that collectively infected hundreds of thousands of computers and enabled the theft of millions of credentials. Authorities arrested the principal VenomRAT suspect in Greece, searched 11 sites across Europe, and dismantled more than 1,000 criminal servers and 20 illicit domains. With assistance from 30-plus cybersecurity companies, the operation also notified thousands of victims and exposed users of these illicit services, mitigating ongoing criminal campaigns. Operation Endgame underscores the rapidly evolving, cross-border nature of malware infrastructure and the growing need for coordinated responses by both public and private sectors. As attackers innovate and leverage distributed networks to evade law enforcement, regular collaborative enforcement actions and heightened detection capability are now critical to cybersecurity defenses worldwide.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
GlobalLogic's 2024 Ransomware Breach: Clop Hits Oracle E-Business Suite Customers
Impact· high

GlobalLogic's 2024 Ransomware Breach: Clop Hits Oracle E-Business Suite Customers

GlobalLogic, a subsidiary of Hitachi, suffered a significant data breach after the Clop ransomware group exploited a zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite. The breach, which began on July 10, 2024, went undetected for months and resulted in the theft of sensitive human resources data for nearly 10,500 current and former employees. Attackers accessed items such as names, SSNs, salary and bank details, passport information, and more, ultimately issuing extortion demands and threatening to leak the stolen data. GlobalLogic promptly initiated incident response actions, notified regulators, and applied Oracle's critical software patches to mitigate the threat after discovering the breach on October 9, 2024. This incident is part of a broader campaign targeting multiple Oracle customers, with ransom demands reaching as high as $50 million and almost 30 organizations named as victims on Clop’s data leak site. This attack underscores the ongoing threat of ransomware groups exploiting enterprise application vulnerabilities and highlights the growing risks posed by sophisticated supply chain and zero-day attacks. Organizations relying on popular ERP software must increase vigilance and prioritize patch management, while regulators and security leaders raise concern over attackers' speed, stealth, and extortion tactics.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
GlobalLogic Employee Data Breach: Lessons from the 2024 Oracle EBS Compromise
Impact· high

GlobalLogic Employee Data Breach: Lessons from the 2024 Oracle EBS Compromise

In early June 2024, GlobalLogic—a Hitachi-owned provider of digital engineering services—disclosed a significant data breach involving its Oracle E-Business Suite (EBS) platform. Attackers gained unauthorized access to EBS, resulting in the theft of sensitive data for over 10,000 current and former employees. The organization responded by launching an investigation, notifying affected individuals, and collaborating with Oracle and security experts to identify the root cause and contain the intrusion. The breach's exposure meant threat actors likely accessed personally identifiable information including names, addresses, and payroll details, elevating the risk of identity theft and further compromise. This incident highlights the ongoing vulnerabilities in complex legacy applications like Oracle EBS, especially as attackers increasingly target enterprise resource systems with sophisticated intrusion techniques. With regulatory scrutiny on employee data protection intensifying, organizations must prioritize robust segmentation, encryption, and visibility controls to counter evolving attack patterns.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Malicious npm Typosquatting Campaign Targets GitHub Supply Chain — 2025 Incident Report
Impact· medium

Malicious npm Typosquatting Campaign Targets GitHub Supply Chain — 2025 Incident Report

In October 2025, cybersecurity researchers detected a supply chain attack involving a malicious npm package named "@acitons/artifact," designed to typosquat the popular GitHub-associated package "@actions/artifact." The attacker attempted to infiltrate GitHub-owned repositories by enticing developers to inadvertently include the rogue package in their build pipelines. Once installed, the malicious code sought to exfiltrate sensitive build environment tokens, which could be exploited to gain unauthorized access to publish or modify code repositories, potentially impacting the integrity and security of widely used open-source projects. This incident highlights a broader trend in threat actor tactics leveraging typosquatting and supply chain vectors to compromise trusted development environments. With the rapid increase in CI/CD automation and open-source dependencies, organizations across industries face mounting risk from similar attacks targeting software supply chains.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CISO Playbook: Responding to the 2025 AI Supply Chain Attack Crisis
Impact· medium

CISO Playbook: Responding to the 2025 AI Supply Chain Attack Crisis

In 2025, the global software development and technology sector faced one of the most disruptive AI-enabled supply chain attacks to date. Threat actors leveraged machine learning to automate the insertion and propagation of malicious packages into widely used open-source repositories, targeting dependencies incorporated by thousands of enterprises worldwide. The initial breach was undetected due to sophisticated code obfuscation and AI-driven capability to mimic legitimate update patterns. As organizations unwittingly integrated these compromised modules, attackers gained unauthorized access, facilitated credential theft, and enabled lateral movement within victim environments, ultimately impacting business operations and exposing sensitive data. This incident underscores the escalating threat posed by AI-assisted supply chain attacks, where attackers rapidly iterate and deploy tactics outpacing traditional detection measures. The significant surge in malicious package uploads, sophisticated polymorphic payloads, and targeted exploitation of widely trusted repositories reveal an urgent need for CISOs to reassess their supply chain defense strategies, especially as regulatory scrutiny around software provenance intensifies worldwide.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports