Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

2227 threat reports
Page 168 of 186

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Computer Software/Engineering Threat Reports

Showing 20052016 / 2227 reports
TEE.Fail Side-Channel Attack Exposes Flaws in Confidential Computing Across Intel, AMD, and NVIDIA CPUs
Impact· high

TEE.Fail Side-Channel Attack Exposes Flaws in Confidential Computing Across Intel, AMD, and NVIDIA CPUs

In early 2024, researchers uncovered a novel hardware vulnerability named TEE.Fail, capable of extracting cryptographic secrets from the trusted execution environments (TEEs) of major CPUs, including Intel SGX/TDX, AMD SEV-SNP, and NVIDIA H100. Exploiting side-channel flaws in the hardware design, attackers could bypass the isolated security boundary provided by TEEs, accessing sensitive data once thought to be well-protected. No evidence of attacks in the wild has surfaced, but proof-of-concept exploitation demonstrates wide-ranging risk for cloud providers and enterprises relying on confidential computing for regulatory compliance and sensitive workloads. The TEE.Fail disclosure highlights a growing trend of advanced research targeting the hardware roots of modern security. As organizations adopt confidential computing to strengthen privacy and regulatory posture, attackers may increasingly seek to exploit hardware and microarchitecture flaws beyond conventional software vulnerabilities.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Inside the GhostCall & GhostHire Malware Campaigns: BlueNoroff’s 2025 Cryptocurrency Heists
Impact· high

Inside the GhostCall & GhostHire Malware Campaigns: BlueNoroff’s 2025 Cryptocurrency Heists

In October 2025, cybersecurity researchers uncovered new attack chains, GhostCall and GhostHire, attributed to BlueNoroff—a sub-group of North Korea's Lazarus Group—targeting the Web3 and blockchain sectors. The campaigns form part of SnatchCrypto, an ongoing operation active since 2017, characterized by sophisticated spear-phishing, malware-laden documents, and social engineering tactics to infiltrate cryptocurrency firms and financial technology startups. Once initial access is gained, attackers deploy custom malware, bypass defenses, and ultimately exfiltrate sensitive data and digital assets, resulting in significant cryptocurrency thefts and disruption across targeted organizations. This campaign is especially concerning amid a surge of advanced persistent threats exploiting trust gaps in rapidly evolving blockchain and cryptocurrency environments. Regulators and cybersecurity teams are on high alert as major financial losses and reputational impacts drive urgency for improved controls, detection, and Zero Trust strategies.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Memento Labs Leverages Chrome Zero-Day to Deploy LeetAgent Spyware in 2025
Impact· high

Memento Labs Leverages Chrome Zero-Day to Deploy LeetAgent Spyware in 2025

In March 2025, a critical zero-day vulnerability (CVE-2025-2783) in Google Chrome was exploited in the wild, enabling threat actors to escape the browser sandbox and deliver espionage-focused LeetAgent spyware attributed to Italian firm Memento Labs. Security researchers from Kaspersky identified targeted campaigns leveraging this flaw to compromise high-value victims via crafted web content, resulting in covert surveillance, data exfiltration, and unauthorized system access before Google patched the issue. This breach underscores the rapid weaponization of browser vulnerabilities by sophisticated actors to distribute espionage tools, often before defenders can respond. Incidents like this demonstrate an uptick in exploitation of high-impact zero-day flaws, especially in widely used software like Chrome, allowing elite cyber espionage operators to rapidly compromise organizations. The trend poses mounting risks as zero-days are increasingly used for targeted intrusions ahead of public disclosure and patch deployment.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Atroposia RAT: How Turnkey Malware Is Changing Enterprise Threats in 2024
Impact· low

Atroposia RAT: How Turnkey Malware Is Changing Enterprise Threats in 2024

In early 2024, a sophisticated Remote Access Trojan (RAT) named Atroposia emerged for public sale on cybercrime forums, offering low-level attackers turnkey access to advanced capabilities such as persistent remote control, stealth, and evasion. Distributed as a ready-to-use toolkit, Atroposia enables affiliates to deploy the malware with minimal technical skill, significantly lowering the barrier to conducting targeted attacks against organizations. Key behaviors include encrypted communications, lateral movement, and data exfiltration, leveraging evasion techniques to bypass traditional security controls. The rapid adoption of Atroposia among threat actors increases operational risk for organizations lacking modern defenses. The prevalence of Atroposia highlights a growing trend in the cybercrime ecosystem: advanced malware-as-a-service platforms democratize sophisticated attacks, making high-impact breaches increasingly accessible. Enterprises face urgent pressure to modernize lateral movement controls, incident detection, and segmentation as attacker toolkits continue to evolve.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Memento Spyware: Chrome Zero-Day Attack Sheds Light on Evolving Spyware Threats
Impact· low

Memento Spyware: Chrome Zero-Day Attack Sheds Light on Evolving Spyware Threats

In early 2024, cybersecurity researchers identified active exploitation of a zero-day vulnerability in Google Chrome by Memento Labs, deploying sophisticated spyware against select targets worldwide. Memento Labs, known as the successor to the notorious Hacking Team, leveraged the undocumented Chrome exploit to remotely compromise endpoints and gain persistent access. The campaign allowed attackers to harvest sensitive data, monitor communications, and exfiltrate information from compromised browsers, with initial infections traced via malicious websites distributing tailored payloads. Businesses affected faced risks of data breaches, espionage, and unauthorized surveillance impacting operational and reputational trust. This attack is significant due to the revival of commercially available offensive spyware targeting widely used software through zero-days. As high-profile threat actors increasingly exploit browser vulnerabilities, organizations face a heightened threat landscape requiring advanced detection and zero trust protections.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
North Korean BlueNoroff APT Hits Fintech and Web3 in Sophisticated 2024 Crypto Heist
Impact· low

North Korean BlueNoroff APT Hits Fintech and Web3 in Sophisticated 2024 Crypto Heist

In early 2024, the North Korean APT group BlueNoroff (a sub-group of Lazarus) launched sophisticated cross-platform campaigns against fintech executives and Web3 developers worldwide. The attackers utilized fake business collaboration and job recruitment lures distributed via phishing documents and messaging apps to implant malware on both Windows and macOS devices. Once in the network, BlueNoroff leveraged their established toolkits—including custom backdoors and credential stealers—to escalate privileges and ultimately exfiltrate cryptocurrency assets. This activity resulted in significant fund theft for several organizations, eroding trust in targeted fintech sectors. This incident highlights the continuous evolution of state-sponsored cybercrime groups, who now use highly adaptive social engineering paired with platform-agnostic malware. The financial sector, especially emerging blockchain and crypto startups, remains a primary focus amid a surge of advanced financially-motivated nation-state attacks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Operation ForumTroll: How Memento Labs Used a Chrome Zero-Day for Global Spyware Attacks in 2024
Impact· medium

Operation ForumTroll: How Memento Labs Used a Chrome Zero-Day for Global Spyware Attacks in 2024

In early 2024, a sophisticated cyber campaign, identified as Operation ForumTroll, exploited a Google Chrome zero-day vulnerability to deploy spyware linked to Memento Labs, an Italian commercial surveillance vendor. Attackers leveraged previously unknown browser flaws to quietly infect targets’ systems, enabling unauthorized espionage and data exfiltration. The malware was distributed through malicious websites and fully bypassed standard security defenses. This campaign has drawn special attention due to Memento Labs’ history—emerging from the notorious Hacking Team’s acquisition by IntheCyber Group—and its potential targeting of high-value individuals and organizations. This incident underscores the persistent threat of zero-day attacks sponsored by private spyware vendors, and signals an ongoing trend in commoditized surveillance. The rise of commercial spyware and browser-based exploits increases regulatory scrutiny and highlights gaps in enterprise endpoint and data-in-transit security.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Google Refutes False Gmail Breach Claims: 2024’s Disinformation Lessons
Impact· low

Google Refutes False Gmail Breach Claims: 2024’s Disinformation Lessons

In June 2024, widespread news reports falsely claimed that Google suffered a massive Gmail data breach affecting 183 million accounts. These reports, originating from threat actors attempting to sell alleged stolen data, quickly circulated across media outlets and online forums. Google promptly denied these claims, confirming after internal and external investigations that no breach had occurred and user data remained secure. The incident stemmed from recycled or previously disclosed information being misrepresented as new, leading to confusion and unwarranted concern among users and industry observers. This incident underscores the growing prevalence of cybersecurity disinformation campaigns aiming to erode trust in major service providers. Such false claims can create unnecessary panic, damage reputations, and distract from real threats, emphasizing the urgent need for robust threat validation and information hygiene in the modern digital landscape.

8 months ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Prompt Injection Flaw in ChatGPT Atlas Browser Enables Hidden Command Execution
Impact· medium

Prompt Injection Flaw in ChatGPT Atlas Browser Enables Hidden Command Execution

In October 2025, security researchers at NeuralTrust identified a prompt injection vulnerability in the newly launched OpenAI ChatGPT Atlas Browser, allowing attackers to disguise malicious prompts as benign URLs in the omnibox. The attack exploits how the omnibox interprets user input, confusing it as either a navigation destination or a natural-language command to the agent. Malicious actors can craft deceptive URLs that bypass basic user scrutiny and trigger hidden commands, exposing users to unauthorized actions, potential data leaks, and unintended system manipulations. OpenAI was notified and subsequently began working on mitigations to address this risk. This incident underscores a rising wave of sophisticated prompt injection attacks targeting AI-powered web interfaces. As AI tools become widely integrated in everyday applications, the attack surface expands, making seamless human-computer interactions susceptible to exploitation from both classic and emerging attack vectors.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
ChatGPT Atlas Browser Hack Reveals Persistent AI Command Exploit
Impact· low

ChatGPT Atlas Browser Hack Reveals Persistent AI Command Exploit

In October 2025, cybersecurity researchers revealed a critical vulnerability in OpenAI’s ChatGPT Atlas web browser, enabling attackers to plant persistent hidden commands within the AI assistant’s memory. Exploiting weaknesses in browser-based AI integration, adversaries were able to inject malicious code that allowed system compromise, privilege escalation, and malware deployment. This attack vector bypassed traditional security controls, proving effective in environments that heavily relied on browser AI plugins for business workflows. The exploit was notable for its ease of delivery through crafted websites or malicious scripts and posed significant operational and reputational risks to affected organizations. This incident underscores the urgent need for robust AI security governance as businesses rapidly integrate AI-powered tools into daily operations. The exploit spotlights a growing class of AI/ML-driven attacks leveraging browser interfaces, echoing wider industry concerns on shadow AI risks and prompting fresh regulatory scrutiny.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Threat Actors Exploit AzureHound for Cloud Reconnaissance in 2024
Impact· low

Threat Actors Exploit AzureHound for Cloud Reconnaissance in 2024

In early 2024, threat actors were observed misusing AzureHound, a powerful cloud pentesting and reconnaissance tool, to discover and map sensitive resources within Microsoft Azure environments. Instead of supporting authorized security assessments, malicious groups leveraged AzureHound's automation to enumerate identities, permissions, and relationships with the intent to facilitate lateral movement and privilege escalation. The attackers accessed cloud APIs with stolen or compromised credentials, largely evading detection until telemetry patterns indicative of broad cloud discovery were identified by Unit 42 researchers. The incident highlighted the urgent need for robust monitoring and threat detection tailored for cloud-specific attack vectors. This incident underscores an accelerating trend in the weaponization of legitimate security tools by adversaries to attack cloud infrastructure. As organizations rapidly adopt multi-cloud strategies, the risk surface expands, magnifying the necessity for proactive defense strategies and comprehensive visibility into cloud-based TTPs.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Pwn2Own Ireland 2025: Researchers Unveil 73 Zero-Day Vulnerabilities
Impact· low

Pwn2Own Ireland 2025: Researchers Unveil 73 Zero-Day Vulnerabilities

In June 2025, the Pwn2Own Ireland hacking competition saw security researchers successfully exploit 73 unique zero-day vulnerabilities across a variety of enterprise software and devices. Over $1,024,750 in rewards were awarded as teams identified and demonstrated live, working exploits, many targeting critical business platforms. These zero-days, by definition previously unknown to vendors, highlight the rapid pace at which vulnerabilities are discovered and the ongoing challenges organizations face in maintaining strong security posture against both sophisticated and opportunistic attackers. This event underscores the persistent risk of zero-day vulnerabilities and the growing sophistication of offensive security research. The scale and speed of exploit identification at Pwn2Own reflect broader industry trends, including increased investment in bug bounties and rising regulatory expectations for vulnerability management and disclosure.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports