Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Microsoft 2024: SesameOp Backdoor Hides in OpenAI Assistants API Traffic
In early 2024, Microsoft researchers identified a sophisticated cyberattack campaign leveraging the new SesameOp backdoor malware. This threat exploits the OpenAI Assistants API as a covert command-and-control (C2) channel, enabling attackers to execute commands, exfiltrate data, and maintain persistence within compromised environments while masquerading as legitimate AI-driven traffic. The campaign targets organizations by bypassing traditional detection methods, using this unique abuse of generative AI services to hide communications and evade security controls. The operational impact is significant, posing increased risk for data loss, lateral movement, and regulatory exposure due to the highly obfuscated methodology. This incident underscores a rapid evolution in attacker tradecraft, with adversaries now weaponizing mainstream AI APIs for malicious infrastructure. As organizations accelerate adoption of AI technologies, this event highlights the urgency to address emerging risks of shadow AI and sophisticated backdoors, making robust east-west traffic inspection and AI-risk governance more important than ever.
8 months ago
Kill Chain
Fake Solidity VSCode Extension Backdoors Developers in 2024 Supply Chain Attack
In early 2024, a malicious Visual Studio Code extension impersonating the popular Solidity plugin was discovered on the Open VSX Registry, a prominent open-source extension marketplace. The extension secretly installed the SleepyDuck remote access trojan. Threat actors leveraged an Ethereum smart contract to covertly communicate with infected developer environments, establishing a covert command and control channel. Dozens of unsuspecting developers who installed the fake extension were exposed to potential source code theft, workspace compromise, and broader supply chain risk for any software subsequently produced on affected systems. This incident highlights the escalating threat posed by supply chain attacks via open-source repositories and package registries, particularly those targeting development toolchains. Increasingly, attackers are exploiting trust in popular extensions, emphasizing the urgent need for organizations to bolster code integrity controls and enforce zero trust principles for their build environments.
8 months ago
Kill Chain
SleepyDuck Supply Chain Attack: Malicious VSX Extension Exposes Developers via Ethereum C2
In late October and early November 2025, cybersecurity researchers uncovered a malicious Visual Studio Code extension, 'juan-bianco.solidity-vlang', uploaded to the Open VSX registry. Originally benign, the extension was updated within days to include a remote access trojan called SleepyDuck, which leveraged Ethereum smart contracts to dynamically maintain connectivity with its command-and-control (C2) servers. By exploiting the trust inherent in open-source software supply chains and masquerading as a development tool, attackers enabled remote access and possible data exfiltration from developer environments, posing significant risks to organizations reliant on open-source packages. This breach highlights the persistent threat of supply chain attacks targeting developer tools and marketplaces, a rapidly growing vector as attackers seek to compromise software upstream. It also demonstrates the adoption of blockchain infrastructure for resilient, hard-to-takedown C2 mechanisms, forcing defenders to adapt to increasingly complex threat ecosystems.
8 months ago
Kill Chain
Remote Code Execution in XWiki: CVE-2025-24893 Exploits Hit Enterprise Wikis
In November 2025, attackers began exploiting a critical remote code execution vulnerability (CVE-2025-24893) in the XWiki SolrSearch component, allowing even low-privileged users to trigger system-level commands via manipulated web requests. Although XWiki released a patch and advisory in February, broad exploitation did not emerge until the vulnerability was highlighted in the U.S. Known Exploited Vulnerabilities catalog in late October and weaponized using publicly available PoC code. The exploit chain involved attackers executing shell scripts fetched from an external server, potentially leading to data theft, malware deployment, or full system compromise in exposed enterprise wikis. This incident demonstrates the persistent risk posed by publicly disclosed vulnerabilities with lagging patch adoption; even niche, enterprise-focused applications can become attractive targets once exploitation is automated and high-profile. Organizations face mounting regulatory and business pressure to identify, patch, and harden externally exposed systems—especially as attackers increasingly weaponize proof-of-concept code for opportunistic campaigns.
8 months ago
Kill Chain
Open VSX Access Token Leak Triggers 2024 Supply-Chain Security Incident
In early June 2024, the Open VSX Registry—a key open-source repository for Visual Studio Code extensions—rotated its access tokens after developers inadvertently leaked credentials in public repositories. This exposure enabled unauthorized actors to publish malicious extensions, triggering a supply-chain attack that could have allowed widespread compromise of downstream developers and end users. Upon discovery, Open VSX revoked and replaced the affected tokens, advised pruning of potentially impacted extensions, and began audits to assess the scope of any malicious uploads. While swift action was taken, the incident highlighted ongoing risks associated with leaked credentials in public codebases and the challenges of securing distributed developer ecosystems. This supply-chain breach is highly relevant amid a surge in attacks abusing public software repositories and developer credentials. As threat actors increasingly target development tooling and code packages, organizations face rising pressure to enhance security around code signing, credential management, and extension vetting to reduce systemic software supply-chain risk.
8 months ago
Kill Chain
China-Linked Bronze Butler Exploits Lanscope Zero-Day for Cyber-Espionage in 2024
In early 2024, China-linked APT group Bronze Butler (also known as Tick) exploited an undisclosed zero-day vulnerability in Motex Lanscope Endpoint Manager to deploy an upgraded version of its Gokcpdoor malware. The attackers leveraged this flaw to gain initial access and establish persistent footholds in targeted organizations, primarily for cyber-espionage purposes. Security researchers confirmed that the intrusion campaigns targeted East Asian entities and potentially exfiltrated sensitive data before the vulnerability was publicly disclosed and patched. The attack underscores the evolving sophistication of state-sponsored actors in weaponizing software supply chain vulnerabilities for stealthy intrusion. This incident exemplifies a broader surge in zero-day exploitation by nation-state actors, as well as a growing focus on endpoint management software as an attack vector. It highlights the urgent need for organizations to patch promptly, monitor lateral network traffic, and implement defense-in-depth strategies that reduce dwell time and lateral movement opportunities.
8 months ago
Kill Chain
Eclipse Foundation Supply Chain Risk: Open VSX Token Exposure Sparks Security Response
In June 2025, the Eclipse Foundation, custodians of the Open VSX open-source project, took immediate remedial action after Wiz security researchers reported that authentication tokens had been unintentionally leaked in several Visual Studio Code (VS Code) extensions across official marketplaces. These exposed tokens could have allowed malicious actors to tamper with extensions, inject malicious code, or compromise downstream developer environments. Upon validation, the Eclipse Foundation promptly revoked a limited set of impacted tokens and notified affected extension maintainers, mitigating potential risks before evidence of active exploitation surfaced. This event underscores the inherent risks in software supply chains, particularly in widely-used open-source development tools. Software supply chain vulnerabilities remain a top concern for enterprises as development workflows increasingly depend on publicly distributed packages and extensions. The growing adoption of open-source ecosystems means that even small credential leaks can impact thousands of users, driving new urgency for continuous monitoring and proactive threat detection.
8 months ago
Kill Chain
Airstalk Malware: 2025 Nation-State Supply Chain Attack Hits Mobile Device Ecosystems
In October 2025, a suspected nation-state threat actor, tracked as CL-STA-1009, orchestrated a sophisticated supply chain attack involving the novel 'Airstalk' malware. Investigations by Palo Alto Networks Unit 42 revealed that Airstalk exploited the AirWatch mobile device management (MDM) API to gain unauthorized access to victim organizations' internal networks. This enabled adversaries to compromise large numbers of mobile devices, bypass network controls, and pivot laterally within affected systems, causing operational disruption and data loss. The primary targets were organizations with complex supply chains, where the attackers injected malicious code via trusted software providers, highlighting the vulnerabilities inherent in interconnected IT ecosystems. This incident is especially relevant as supply chain attacks become increasingly prevalent, with attackers leveraging trusted third-party relationships to bypass traditional network defenses. Nation-state actors' use of advanced evasion techniques and MDM abuse underscores the need for enhanced visibility, segmentation, and threat detection across distributed and hybrid IT environments.
8 months ago
Kill Chain
LotL Malware Concealed in Windows Native AI Stack Exposes New Risks
In early 2024, security researchers uncovered a Living-off-the-Land (LotL) attack that leveraged Windows' native AI stack to conceal and deploy malware within trusted AI data files. Attackers exploited the inherent trust that many Windows systems grant to files used by the native AI stack, allowing the threat to bypass traditional detection methods. The malicious payloads used fileless techniques, hiding in AI models and exploiting automated processing pipelines to achieve stealthy initial access and lateral movement. The campaign resulted in significant risks of unauthorized access, data theft, and potential disruption to business operations reliant on AI-driven processes. This incident is a timely reminder of evolving threat tactics using fileless malware and trusted native components. As the adoption of AI and automation accelerates, attackers are adapting by targeting supply chains and leveraging trusted AI data flows to bypass security controls and compliance frameworks.
8 months ago
Kill Chain
When AI Agents Go Rogue: The Risk of Session Smuggling in Agent2Agent Systems
In early 2024, cybersecurity researchers uncovered a novel vulnerability in agent-to-agent (A2A) AI systems, termed 'Agent Session Smuggling.' The attack allowed malicious actors to hijack sessions between AI agents, abusing trust relationships and manipulating agent behavior. Attackers leveraged weaknesses in session authentication and input validation, circumventing security controls to inject unauthorized commands and siphon sensitive data. Demonstrated through proof of concept, the exploit posed risks to organizations deploying sophisticated autonomous AI workflows and threatened the integrity of operational and business data. This incident highlights a rapidly emerging class of AI/ML security threats, where attacks exploit autonomous system intercommunication. As organizations accelerate AI adoption, understanding and mitigating these exploit techniques—especially in east-west, agent-driven environments—has become a pressing priority for security and compliance teams globally.
8 months ago
Kill Chain
Insider at L3Harris Sells Cyber Exploits to Russian Broker in 2024 Breach
In early 2024, Peter Williams, a former executive at L3Harris Trenchant, a U.S. defense contractor, pleaded guilty to stealing and illicitly selling confidential cyber exploit information to a Russian broker. The insider utilized privileged access to exfiltrate sensitive data on cybersecurity vulnerabilities and offensive research, subsequently marketing this intelligence to foreign entities, including actors associated with the Russian cyber underground. The breach exposed L3Harris Trenchant's internal detection gaps, ultimately triggering a federal investigation and leading to Williams' prosecution in U.S. District Court. This incident underscores the growing threat posed by insider actors within critical infrastructure and defense sectors. It highlights the need for advanced detection, segmentation, and strict policy enforcement to counter the insider risk—especially as nation-state and organized crime demand for zero-day vulnerabilities and advanced cyber tools continues to escalate.
8 months ago
Kill Chain
PhantomRaven npm Attack: 2025’s Credential-Stealing Supply Chain Breach
In August 2025, cybersecurity researchers from Koi Security uncovered an extensive software supply chain attack involving over 120 malicious npm packages, collectively named "PhantomRaven." Disguised as legitimate dependencies, these packages were uploaded to the npm registry and, once installed on developers’ machines, exfiltrated sensitive assets such as GitHub authentication tokens, CI/CD secrets, and other credentials. The attacker’s use of common JavaScript project names and spellings facilitated widespread distribution before discovery. The breach triggered rapid mitigation responses across multiple organizations relying on npm in their software development lifecycles, raising concerns about dependency trust and software supply chain hygiene. The PhantomRaven campaign underscores a broader surge in supply chain attacks exploiting open-source ecosystems, with threat actors increasingly leveraging popular package managers as vectors. As the software industry’s reliance on third-party code grows, so does the urgency for proactive controls and real-time monitoring to counter sophisticated credential-stealing methods.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports