Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
CISA Adds Adobe/Magento & WSUS Exploits to 2025 KEV Catalog
In October 2025, CISA added two newly discovered, actively exploited vulnerabilities—CVE-2025-54236 impacting Adobe Commerce and Magento, and CVE-2025-59287 impacting Microsoft Windows Server Update Services—to its Known Exploited Vulnerabilities (KEV) Catalog. Both vulnerabilities are believed to be leveraged by threat actors to gain unauthorized access and facilitate lateral movements within victim networks. Federal Civilian Executive Branch (FCEB) agencies are now required by BOD 22-01 to remediate these specific threats by the mandated due date, minimizing risk to critical government infrastructure and mission-critical digital assets. This inclusion highlights a rising trend of attackers weaponizing public-facing application and misconfigured update service vulnerabilities, reflecting an escalation in both attack sophistication and speed of exploitation. Organizations of all types face mounting regulatory and operational pressure to harden security posture and accelerate remediation response times.
8 months ago
Kill Chain
Vertikal Systems 2025: Healthcare Data at Risk via Hospital Manager Backend Vulnerabilities
In September 2025, Vertikal Systems disclosed two critical vulnerabilities affecting its Hospital Manager Backend Services. The first flaw (CVE-2025-54459) allowed unauthorized, remote access to the ASP.NET tracing endpoint, potentially exposing sensitive data such as authorization tokens and server metadata. The second (CVE-2025-61959) disclosed verbose error pages on invalid requests, inadvertently leaking application stack traces and configuration files. Both issues were exploitable without authentication, posing significant data privacy and operational risk across healthcare sites globally. This incident spotlights ongoing risks to healthcare organizations due to misconfigurations and unnecessary exposure of sensitive developer endpoints. With increasing regulatory pressure on patient data security and the healthcare sector's targeted threat profile, such vulnerabilities could lead to compliance violations or facilitate wider attacks.
8 months ago
Kill Chain
PhantomRaven’s Malicious npm Packages: 2024 Supply-Chain Risk with Invisible Dependencies
In early 2024, the "PhantomRaven" campaign targeted the open-source software ecosystem by distributing 126 malicious npm packages containing concealed, 'invisible' dependencies. These packages, published over several months, bypassed detection mechanisms and were downloaded over 86,000 times by unsuspecting developers. Threat actors leveraged these supply chain attacks to potentially exfiltrate sensitive data, propagate malware, or serve as initial entry points for deeper compromises in downstream applications and organizations dependent on these packages. The campaign highlighted significant vulnerabilities in supply-chain security and the risks associated with open-source package management. This incident is part of a rising trend of sophisticated supply-chain attacks leveraging trusted developer tools and repositories. With increasing regulatory scrutiny and mounting pressure to harden software dependencies, organizations must assess their exposure and implement robust controls to thwart similar attacks in the future.
8 months ago
Kill Chain
PhantomRaven Floods npm with Malicious Credential-Stealing Packages
In April 2024, the 'PhantomRaven' threat campaign targeted the JavaScript software ecosystem by flooding the npm package repository with dozens of malicious packages. These packages, aimed at developers and CI/CD environments, were crafted to harvest authentication tokens, CI/CD secrets, and GitHub credentials when installed. Attackers employed typosquatting and deceptive package naming techniques to trick developers into integrating the compromised code into their applications, thereby enabling broad access to source code and sensitive internal systems. The attack underscores the growing risk posed by software supply chain compromises, impacting thousands of potential downstream applications and organizations. This incident highlights an ongoing surge in supply chain attacks leveraging public code repositories, targeting both individual developers and enterprise development pipelines. Attackers are increasingly employing credential harvesting via trusted open-source channels, intensifying regulatory scrutiny and driving immediate needs for enhanced software integrity controls and threat detection across development workflows.
8 months ago
Kill Chain
Malicious npm Package Attack Exposes Software Supply Chain Risks in 2024
In June 2024, security researchers identified a supply chain attack involving at least ten malicious npm packages uploaded to the public registry. Masquerading as legitimate software components, these packages were designed to infect developer environments across Windows, Linux, and macOS. Once installed, they downloaded and executed an information-stealing payload capable of harvesting sensitive data such as credentials and environment variables, potentially enabling lateral movement or further breaches within affected organizations. The attack leveraged trusted software distribution channels to bypass traditional defenses and amplify impact among open-source users. This incident underlines escalating risks in the software supply chain, highlighting how open-source package ecosystems have become prime targets for attackers. The trend represents a growing challenge for organizations relying on third-party code, driving new urgency around vetting procedures, continuous monitoring, and enforcing granular security controls in developer pipelines.
8 months ago
Kill Chain
10 Malicious npm Packages Expose Global Supply Chain Risks in 2025 Credential Stealer Attack
In October 2025, security researchers uncovered a coordinated supply chain attack targeting the npm ecosystem. Ten malicious npm packages, collectively downloaded over 5,000 times, were found to contain sophisticated multi-platform information stealers. These packages, distributed via the npm registry and impersonating legitimate developer tools, leveraged obfuscated code to deploy a payload capable of extracting sensitive credentials and environment data from Windows, macOS, and Linux developer workstations. The malware used deceptive tactics like a fake CAPTCHA screen and fingerprinted victims prior to exfiltrating stolen data to attacker-controlled infrastructure. This incident underscores the growing trend of software supply chain attacks, as developer tool ecosystems like npm remain high-value targets for both financially motivated cybercriminals and state-sponsored groups. The event has fueled concerns about package registry hygiene, developer workstation security, and the need for stronger zero trust and anomaly detection controls across the software development lifecycle.
8 months ago
Kill Chain
Cloaking Attack Against AI Crawlers Uncovers New Context Poisoning Risks
In October 2025, cybersecurity researchers uncovered a sophisticated cloaking attack that targets AI-driven web crawlers used by popular agentic browsers such as OpenAI ChatGPT Atlas and Perplexity. Threat actors deployed malicious websites capable of serving misleading or false content only to AIbots, while displaying legitimate information to typical users. This context poisoning technique allows harmful actors to manipulate AI models at scale, tricking them into citing fabricated facts as verified information, and undermines AI trustworthiness with widespread downstream effects on automated decision-making and knowledge dissemination. This incident highlights the mounting risks from adversarial attacks targeting AI supply chains. As AI systems increasingly rely on real-time internet data, attackers are innovating new manipulation tactics to poison context and subvert trust. The surge in such TTPs coincides with tighter regulations and industry push towards Responsible AI frameworks.
8 months ago
Kill Chain
Aisuru Botnet’s 2025 Shift: From DDoS Disruptor to Proxy Powerhouse
In mid-2025, the Aisuru botnet—already infamous for record-shattering distributed denial-of-service (DDoS) attacks—shifted tactics, repurposing hundreds of thousands of compromised Internet of Things (IoT) devices to fuel residential proxy networks. Initially detected in August 2024, Aisuru rapidly infected over 700,000 vulnerable routers and cameras, enabling DDoS attacks reaching up to 30 terabits per second. As global internet providers struggled to mitigate these waves, Aisuru’s operators began renting bot-infected devices as residential proxies, granting cybercriminals more effective means to anonymize web scraping, credential stuffing, and data harvesting operations. This incident marks a significant escalation in how botnets are monetized, as botnet-powered residential proxies become a key enabler for content scraping—especially by AI firms seeking vast datasets. The pivot highlights a rising convergence between traditional cybercrime and emerging AI-driven abuse, challenging defenders to address both volumetric attack trends and subtle, persistent data exfiltration.
8 months ago
Kill Chain
AI-Powered Social Engineering Attacks Surge Across Africa in 2024
In early 2024, a surge of AI-powered social engineering attacks swept across Africa, targeting both government agencies and private enterprises. Threat actors utilized AI-generated phishing campaigns, deepfake technology, and sophisticated impersonation tactics to gain unauthorized access to sensitive systems and data. The attackers rapidly evolved their techniques by testing them in diverse African markets, often bypassing conventional security controls using realistic AI-driven lures and voice/video spoofing. The outcome included data breaches, operational interruptions, increased fraud, and reputational harm to affected organizations, while also exposing gaps in detection and response capabilities. This incident highlights the accelerating adoption of AI by cybercriminals, who now leverage machine learning to refine attack vectors and increase success rates. As similar TTPs proliferate globally, organizations face heightened regulatory scrutiny and must rapidly adapt cybersecurity frameworks to counter increasingly intelligent and deceptive threats.
8 months ago
Kill Chain
How Botnets Exploited Cloud Flaws in 2024: A Modern Security Wake-Up Call
In early 2024, security researchers observed an escalating wave of activity from botnets such as Mirai, leveraging vulnerabilities and misconfigurations across cloud environments and Internet-exposed assets. Attackers targeted PHP servers, IoT devices, and cloud gateways, exploiting both known flaws and weak security controls. Once compromised, these assets were co-opted into large-scale botnets used for distributed denial-of-service (DDoS) attacks, cryptomining, and lateral movement into business networks. The campaign underscored gaps in east-west traffic visibility, workload segmentation, and egress filtering, significantly increasing operational and reputational risk for enterprises. This incident is part of a growing trend where botnets and automated threat actors shift focus to cloud and hybrid environments, capitalizing on common misconfigurations. Organizations face mounting pressure to modernize defenses, as attackers rapidly adapt to evolving architectures and compliance expectations.
8 months ago
Kill Chain
Nation-State Supply Chain Attack: Airstalk Malware Targets AirWatch API in 2024
In June 2024, security researchers uncovered a sophisticated supply chain attack leveraging a new Windows-based malware dubbed "Airstalk." This campaign, attributed to a suspected nation-state threat actor, involved the misuse of the AirWatch API to exfiltrate sensitive browser data from targeted organizations. Attackers infiltrated the software ecosystem, enabling wide-scale distribution without initial detection. The breach highlighted the attackers' advanced techniques, including API abuse, stealthy data exfiltration, and lateral movement, severely impacting digital supply chains and putting both direct victims and downstream customers at risk. Airstalk exemplifies the growing threat posed by supply chain attacks, where trusted software platforms may be subverted for espionage or data theft. The attack underscores an urgent industry need for robust east-west traffic controls, zero trust segmentation, and continuous anomaly detection to mitigate evolving adversary tactics targeting critical infrastructure.
8 months ago
Kill Chain
OpenAI Atlas Browser Exposed: LLM Cloaking and Security Weaknesses in 2024
In early 2024, security researchers at SPLX and LayerX exposed significant vulnerabilities in OpenAI’s ChatGPT Atlas browser agent and similar AI-powered web agents. Through cloaking techniques, malicious actors can serve manipulated web content specifically to AI crawlers by altering the user-agent header, causing the agent to process misleading information while human users see normal content. This opens doors for smear campaigns, scam promotions, and manipulation of automated tasks like recruitment screening. Additional flaws in Atlas were discovered, including weak OAuth token storage and susceptibility to memory corruption exploits, raising serious concerns for business and consumer users. These vulnerabilities highlight the pressing need for AI governance and protection as adoption accelerates, with compliance and supply chain risk in sharp focus. With the rapid growth of generative AI in enterprise settings and lagging regulatory frameworks, businesses face mounting risks tied to both intentional adversarial content and platform design oversights.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports