Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Malicious NuGet Packages Drop Sabotage Time Bombs in 2024 Supply Chain Attack
In early June 2024, security researchers uncovered a targeted supply-chain attack involving several malicious NuGet packages. These packages, posing as legitimate software dependencies, contained 'time bomb' sabotage payloads programmed to activate years in the future—specifically in 2027 and 2028. The malicious code was designed to disrupt database operations and potentially target Siemens S7 industrial control systems, representing a novel form of delayed-detonation supply chain attack. The technique leverages trust in package ecosystems, making detection difficult and threatening both IT and operational technology environments with considerable disruption. This incident highlights an emerging trend where attackers plant long-term, stealthy threats within software supply chains to evade short-term detection and maximize impact. With the increasing adoption of open-source components and growing regulatory scrutiny, organizations must urgently reassess their software sourcing and supply-chain risk controls.
8 months ago
Kill Chain
Time-Bomb Malware Hidden in NuGet Packages Signals Alarming Supply Chain Threat
In 2023 and 2024, a set of nine malicious NuGet packages, attributed to the user 'shanhai666', were found to infect software supply chains by deploying time-delayed logic bombs. These packages, available through the official NuGet repository, hid code designed to execute malicious activities—such as sabotaging database operations and corrupting industrial control systems—on predefined future dates starting in August 2027. The sophisticated campaign leveraged delayed payload triggers, allowing attackers to infiltrate developer environments undetected for years before activation, thus maximizing potential operational and business disruption. This incident highlights the ongoing risks facing software supply chains, where attackers increasingly employ delayed and concealed attack mechanisms to evade early detection. Businesses across all sectors relying on third-party code repositories must reinforce supply chain security practices and continuously monitor for latent threats that could surface well after initial compromise.
8 months ago
Kill Chain
Ollama and Nvidia AI Infrastructure Vulnerabilities: A Wake-Up Call for Enterprise Security in 2024
In June 2024, security researchers identified multiple critical vulnerabilities within key AI infrastructure products, most notably affecting Ollama and Nvidia platforms. The most severe flaws enabled authenticated remote code execution and unauthorized access to sensitive AI environments. Attackers could exploit insecure network interfaces and misconfigurations to laterally move across workloads or escalate privileges. These risks threaten the confidentiality, integrity, and availability of AI-powered operations, exposing organizations to theft of proprietary models, service disruption, and downstream compromise. The rapidly maturing adversary tactics around supply chain and platform vulnerabilities magnified these risks. This incident highlights an urgent trend: attackers are now aggressively targeting foundational AI infrastructure in enterprise and cloud settings, focusing on underlying software weaknesses rather than solely data or application layers. As AI adoption accelerates, so does the attack surface, making robust segmentation, encryption, and zero trust approaches vital for resilience.
8 months ago
Kill Chain
Malicious AI Extension Sneaks onto VS Code Marketplace in Supply Chain Breach (2024)
In early June 2024, a malicious extension possessing rudimentary ransomware functionality, allegedly built with the aid of artificial intelligence, was discovered in Microsoft's Visual Studio Code (VS Code) Marketplace. The extension leveraged VS Code's trusted distribution to sneak past safeguards and, once installed, had the capability to encrypt targeted user files and demand a ransom. This supply chain attack was detected before it could be widely abused, but it highlights how adversaries are using AI to generate and deploy sophisticated threats within software ecosystems. This incident demonstrates a growing trend where supply chain platforms, such as code repositories and marketplaces, are exploited to gain privileged entry within developer environments. The blending of AI-enabled malware automation and trusted application channels raises urgent visibility, compliance, and policy enforcement concerns for organizations.
8 months ago
Kill Chain
Nikkei Data Breach: Slack Compromise Exposes Employee and Partner Information in 2024
In early June 2024, Japanese media conglomerate Nikkei disclosed a cybersecurity breach involving the unauthorized compromise of its Slack workspace. Attackers gained access to Slack accounts and chat histories, potentially exposing sensitive information belonging to thousands of employees and business partners. The incident is believed to have occurred via stolen Slack credentials, granting threat actors access to business communications and personal data. Nikkei swiftly launched an investigation, engaged incident response expertise, and notified affected individuals while reporting the matter to regulatory authorities. This attack highlights the continuing risk of platform-based credential compromises affecting collaboration tools. The frequency of SaaS-targeted breaches is growing, underlining the urgent need for robust identity, access management, and segmentation controls on corporate communication channels.
8 months ago
Kill Chain
Capital One’s 2019 Cloud Breach: Insider Threats & Misconfiguration Risks
In 2019, Capital One suffered a major data breach when Paige Thompson, a former AWS engineer, exploited a cloud misconfiguration—specifically a poorly secured firewall running in Capital One's AWS environment—to access the personal information of over 100 million customers. The attacker leveraged insider knowledge and a misconfigured identity and access management policy to move laterally and exfiltrate sensitive data, including social security numbers and bank account details. The breach resulted in substantial financial costs, regulatory scrutiny, and reputational damage to Capital One, with Thompson ultimately convicted of wire fraud and computer intrusion. This incident remains relevant as organizations increasingly migrate to the cloud and face similar risks of configuration errors, compounded by the complexity of managing access controls and real-time monitoring in cloud-native infrastructures. The Capital One breach exemplifies the critical need for robust cloud security measures and continuous compliance with evolving regulatory requirements.
8 months ago
Kill Chain
Google's 2024 Warning: AI-Powered Malware Leveraging LLMs in the Wild
In early 2024, Google's Threat Intelligence Group (GTIG) detected a rise in cyberattacks involving new malware families leveraging artificial intelligence, particularly large language models (LLMs), to enhance evasiveness, automate code generation, and increase payload adaptability in real time. Attackers orchestrated campaigns using AI-enhanced malware to breach enterprise environments through sophisticated spear-phishing, malicious attachments, and exploited vulnerabilities, successfully bypassing traditional detection methods. Some campaigns were linked to known advanced persistent threat (APT) groups, causing disruptions to business operations, data confidentiality, and elevating the risk profile for organizations across various sectors. This incident underscores a pivotal shift in the cyber threat landscape toward swift, adaptive attacks driven by AI capabilities. The integration of LLMs into malware enables more dynamic compromise techniques, signaling urgent need for advanced threat detection and revised security controls across industries.
8 months ago
Kill Chain
CentOS Web Panel Suffers Wide Scale Attacks Via Remote Command Execution Flaw
In early 2024, a critical remote command execution (RCE) vulnerability in CentOS Web Panel (CWP) was actively exploited by threat actors, as publicly warned by the U.S. Cybersecurity & Infrastructure Security Agency (CISA). Attackers leveraged this flaw, tracked as CVE-2022-44877, to gain unauthorized access to servers running CWP, enabling them to execute arbitrary commands and potentially take full control of affected systems. This exploitation campaign targeted internet-facing CWP instances, presenting significant risks to organizations relying on the popular Linux-based server management tool. The fallout included possible data compromise, deployment of additional malware, and interruption of web services. This incident highlights a growing trend in mass exploitation of critical web application vulnerabilities, with attackers increasingly focusing on widely-adopted open-source platforms. High-profile government advisories and the prevalence of ransomware toolkits leveraging RCE flaws have driven organizations to reinforce patch management and incident response as regulatory and operational priorities.
8 months ago
Kill Chain
US Sanctions North Korean Network for $12.7M Crypto Laundering and IT Fraud
In November 2025, the U.S. Treasury Department sanctioned ten North Korean individuals and entities after uncovering a multi-year scheme involving crypto laundering and IT-related financial fraud totaling $12.7 million. These actors, linked to North Korea’s state-sponsored cyber operations, leveraged encrypted and unencrypted channels to move illicit funds across international financial systems. Their activities supported North Korea’s nuclear weapons ambitions and exploited gaps in network segmentation, egress controls, and threat detection processes. This incident underscores an escalation in nation-state cryptocurrency laundering methods and demonstrates continued exploitation of global IT workforce outsourcing, heightening regulatory focus and increasing the cyber risk to organizations transacting digitally or hiring remote technical staff.
8 months ago
Kill Chain
Google Uncovers PROMPTFLUX: AI-Driven Malware Raises the Stakes for 2025 Security
In November 2025, Google’s threat intelligence team identified a novel malware campaign involving PROMPTFLUX, a Visual Basic Script (VBScript) threat that leverages the Gemini AI model API for rapid self-obfuscation and evasion. Unattributed attackers deployed PROMPTFLUX to rewrite its own source code hourly using AI-driven prompts, significantly complicating detection and dismantling efforts. The malware infiltrated enterprise endpoints using social engineering and malicious email attachments before laterally propagating within corporate environments, thus undermining traditional endpoint and network defense measures. As a result, organizations faced heightened risk of data exfiltration, operational disruption, and increased response complexity. This incident highlights an emerging class of threats that weaponize generative AI models for polymorphic malware development. The ability to dynamically morph malicious code in real time increases attacker agility and strains legacy detection and compliance controls, reflecting a wider shift toward autonomous, AI-powered cyberattacks.
8 months ago
Kill Chain
Major Supply-Chain Exposure Discovered in Popular Software Update Tool – 2024
In early 2024, a critical supply-chain vulnerability was identified in a widely used software update tool, threatening some of the world's largest technology enterprises. Attackers exploited insecure update mechanisms within this tool, enabling the potential injection of malware directly into production software across multiple organizations. The breach exposed businesses to risks including unauthorized access, lateral movement, and possible data theft. While no confirmed exploitation has been publicly reported to date, the threat mirrors the scale and impact of the infamous SolarWinds compromise, underscoring the profound risks inherent in trusted third-party code dependencies. This incident highlights the urgent and growing threat from software supply-chain attacks, which have rapidly increased in frequency and sophistication over the past two years. It spotlights the cybersecurity community’s intensified focus on software bill of materials (SBOM), continuous monitoring, and robust supply-chain controls as regulatory and industry expectations tighten.
8 months ago
Kill Chain
WordPress Sites Under Siege: Critical Post SMTP Plugin Flaw Exposes 400,000+ Websites
In June 2024, a critical vulnerability was discovered in the Post SMTP mailer plugin for WordPress, widely used by over 400,000 sites. This flaw allows unauthenticated attackers to reset admin accounts and take full control of affected websites. Threat actors have already exploited the vulnerability by leveraging malicious password reset links, leading to complete site compromise, potential data theft, and abuse of compromised infrastructure for further attacks. The vulnerability prompted emergency patching and urgent advisories from both the plugin authors and security firms. This incident underscores the persistent threat posed by plugin vulnerabilities in the WordPress ecosystem, which remains a popular target for cybercriminals due to its vast user base. The surge in attacks exploiting supply chain and third-party plugin weaknesses highlights the need for rapid vulnerability management and robust security controls for web applications.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports