Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Chinese APT 'Jewelbug' Compromises Russian IT Provider in Stealthy 2025 Attack
In early 2025, the Chinese state-linked threat group known as 'Jewelbug' stealthily infiltrated a prominent Russian IT service provider over a five-month period, according to findings from Symantec. The attackers gained initial access in January, likely leveraging supply chain or credential compromise vectors, and subsequently maintained persistent, undetected presence until May. Jewelbug is known for sophisticated tactics, including advanced lateral movement, encrypted traffic, and covert exfiltration. As a result, sensitive data and core IT systems within the provider’s infrastructure were at risk, potentially impacting downstream Russian clients who relied on its managed services. This incident highlights the expanding global reach of advanced persistent threats (APTs), with Jewelbug moving beyond historical targets in Southeast Asia and South America to now conduct espionage in Russia. The breach demonstrates increasing sophistication in supply chain and east-west attack techniques, underscoring urgent need for robust lateral movement prevention, segmentation, and cloud visibility controls.
8 months ago
Kill Chain
Adobe AEM 2025 Breach: CISA Flags Critical Application Flaw Under Active Attack
In June 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) raised alarms about a critical misconfiguration vulnerability (CVE-2025-54253) impacting Adobe Experience Manager (AEM). This flaw, assigned a CVSS score of 10.0, allows remote unauthenticated attackers to achieve arbitrary code execution on vulnerable AEM instances. Active exploitation was confirmed as attackers leveraged the bug to gain foothold, escalate privileges, and deploy malware on targeted organizations, potentially exposing sensitive data and compromising internal operations. The incident highlights the risks of unpatched enterprise software within digital supply chains and data-driven organizations. The AEM vulnerability is currently notable due to increased exploitation by multiple threat actors, coinciding with a larger trend of critical zero-day application flaws being used in advanced persistent attacks. Regulatory agencies and security experts underscore the urgency for patching exposed business applications given the frequency and sophistication of exploitation campaigns in 2025.
8 months ago
Kill Chain
Pwn2Own Ireland 2025: Security Researchers Expose 34 Zero-Day Vulnerabilities
On the first day of Pwn2Own Ireland 2025, security researchers successfully exploited 34 unique zero-day vulnerabilities across a range of enterprise technologies, earning $522,500 in awards. The event, renowned for responsible disclosure and sponsored by leading vendors, demonstrated both the speed and sophistication with which zero-day flaws can be discovered and exploited in widely used software and hardware platforms. While no criminal group was involved (these are sanctioned research efforts), the findings underscore prevailing vulnerabilities in enterprise defenses and often result in rapid product updates and critical security advisories. This incident highlights the ongoing arms race between researchers and vendors to identify and remediate unknown security gaps. The large number of zero-days found in a single day signals both the growing complexity of attack surfaces and the pressing need for automated detection and proactive patching mechanisms across the digital ecosystem.
8 months ago
Kill Chain
How UNC5142 Hijacked WordPress & Blockchain for Next-Gen Stealer Attacks (2025)
In October 2025, threat actor UNC5142 leveraged compromised WordPress sites to distribute a wave of information-stealing malware using an innovative attack method dubbed 'EtherHiding.' The adversaries abused blockchain-based smart contracts to conceal malicious code, enabling malware such as Atomic Stealer, Lumma, Rhadamanthys, and Vidar to infect both Windows and macOS endpoints. This technique allowed attackers to rapidly update payloads beyond the reach of static blocklists and frequently evade traditional security controls. Victims included a variety of enterprises and individuals, with attackers capitalizing on the popularity and trust of infected WordPress content management platforms. This incident highlights an emerging TTP where blockchain infrastructure is repurposed to enhance delivery persistence and obfuscation for criminal campaigns. The rapid uptake of such blockchain-based methods demonstrates the need for organizations to evolve threat detection and response strategies as attackers diversify beyond conventional web infrastructure.
8 months ago
Kill Chain
Cursor & Windsurf IDEs Hit by 94+ Chromium Vulnerabilities – Supply-Chain Exposure in 2024
In early 2024, security researchers identified that the latest releases of the Cursor and Windsurf integrated development environments (IDEs) were vulnerable to over 94 known and patched security vulnerabilities within the embedded Chromium browser and V8 JavaScript engine. These n-day vulnerabilities exist because the IDEs relied on outdated Chromium builds, exposing users to a range of critical issues, including remote code execution, privilege escalation, and data leakage. The supply-chain nature of the incident means development teams using these IDEs could inadvertently introduce risk across their entire workflow and environments. This incident underscores the persistent risk posed by vulnerable software dependencies and highlights an urgent need for improved supply-chain security. With attackers increasingly targeting development tools for initial access or lateral movement, organizations must re-evaluate their patch management, vendor risk assessments, and layered network protections.
8 months ago
Kill Chain
North Korean Hackers Employ EtherHiding for Unprecedented Cryptocurrency Heist
In October 2025, threat group UNC5342—attributed to North Korea—executed an advanced cryptocurrency theft operation by leveraging the novel EtherHiding technique. Attackers embedded malicious code within blockchain smart contracts to distribute malware, evading conventional detection mechanisms. Google Threat Intelligence Group (GTIG) identified this as the first known use of EtherHiding by a state-sponsored actor, resulting in the covert compromise of multiple cryptocurrency platforms and significant asset loss. The incident underscores an evolving trend: nation-state actors are adopting increasingly sophisticated blockchain-based attack methods. With rising blockchain adoption, such TTPs present serious risks for organizations involved in digital assets, regulation, and financial technology.
8 months ago
Kill Chain
North Korean APT Combines BeaverTail and OtterCookie in Major 2025 JS Malware Campaign
In October 2025, a North Korean state-sponsored hacking group with ties to the Contagious Interview campaign was observed integrating features from its BeaverTail and OtterCookie malware into a sophisticated new JavaScript-based attack. Security research from Cisco Talos revealed the group’s evolving approach: combining credential theft, evasion, and persistent access in targeted spear-phishing campaigns directed at global enterprises, which enabled stealthy lateral movement and prolonged network compromise. Analysis showed that this fusion malware increased the attackers’ efficiency and resilience, leading to significant data exposure risks and operational disruptions for affected organizations. This incident highlights a broader trend—North Korean APTs are rapidly developing multipurpose malware platforms capable of bypassing traditional defenses. The blending of well-established tools signals a new level of technical maturity, raising the urgency for organizations to shore up east-west traffic security, zero trust segmentation, and advanced threat detection controls.
8 months ago
Kill Chain
New CAPI Backdoor Targets Russian Auto & E-Commerce with Phishing ZIPs
In October 2025, cybersecurity researchers uncovered a sophisticated phishing campaign targeting Russian automobile and e-commerce firms. The attackers distributed phishing emails containing malicious ZIP files, which, when opened, triggered the deployment of a never-before-seen .NET-based malware known as the CAPI Backdoor. Once installed, the malware established persistent access, enabling threat actors to conduct internal network reconnaissance, exfiltrate sensitive information, and potentially disrupt business operations. Seqrite Labs, who analyzed the activity, report that the campaign’s execution appears highly tailored to exploit Russia’s rapidly digitizing sectors. This incident is significant amid a sharp increase in spear phishing and backdoor campaigns against supply chain and commercial organizations across Eastern Europe. The novelty of the CAPI Backdoor highlights evolving attacker sophistication and amplifies regulatory attention around encrypted traffic inspection, zero trust, and rapid anomaly detection.
8 months ago
Kill Chain
131 Chrome Extensions Hijack WhatsApp Web: The 2025 Brazilian Spam Campaign
In October 2025, a coordinated cyberattack was uncovered where 131 malicious Chrome browser extensions—clones of a popular WhatsApp Web automation tool—were used to hijack users’ sessions and launch an automated spam campaign targeting Brazilian users. Researchers from security company Socket found that these plugins, sharing an identical codebase and infrastructure, infected over 20,000 users by enticing them to install seemingly legitimate add-ons, enabling attackers to take control of browser sessions, inject spam messages, and exfiltrate private data at scale. The incident underscores the risks associated with browser extension supply chain threats, exposing enterprises and individuals to large-scale account compromise and privacy breaches. This breach is particularly significant as it demonstrates the adaptability and persistence of threat actors in abusing browser supply routes and leveraging rebranded extensions to evade traditional security controls. The campaign’s targeting of WhatsApp Web also signals a shift toward exploiting widely-used communication channels for coordinated spam and fraud, spotlighting the critical need for proactive browser extension vetting and user awareness.
8 months ago
Kill Chain
Inside the Synthient Stealer Log Threat Data: 2025's Monumental Infostealer Breach
In late 2025, a vast dataset known as the 'Synthient Stealer Log Threat Data' surfaced, aggregating over 3.5 terabytes and 23 billion rows of stolen credentials and website entries collected from infostealer malware and credential stuffing campaigns. This dataset comprised logs exfiltrated via platforms like Telegram, social media, and dark web forums, predominantly sourced from malware-infected endpoints. Analysis revealed 183 million unique email addresses, with over 8% never before seen in data breach collections, confirming both scale and uniqueness. The data's authenticity was validated through subscriber checks and corroborating evidence from exposed accounts. This incident underscores the escalating risks posed by mass infostealer malware campaigns, highlighting their ability to industrialize credential theft and rapidly distribute sensitive personal data. As attackers continuously refine malware arsenals and leverage broader distribution networks, organizations and individuals must act urgently to address credential reuse, enhance detection, and mitigate lateral movement threats.
8 months ago
Kill Chain
US Court Bars NSO Group from Targeting WhatsApp Users with Spyware
In June 2024, a U.S. federal judge issued a permanent injunction against NSO Group, prohibiting the Israeli spyware developer from targeting WhatsApp users with its surveillance products. The case originated from a 2019 incident in which NSO Group exploited flaws in WhatsApp's messaging platform to compromise user privacy, prompting Meta (WhatsApp's parent company) to launch a protracted legal battle. The court recognized the significant risk posed to Meta's business and user trust, as WhatsApp's core value proposition is secure, end-to-end encrypted communications. The injunction was coupled with a major reduction in damages, from $167.3 million to $4 million, marking a significant legal precedent in the spyware industry. This decision highlights mounting regulatory and legal scrutiny on commercial spyware vendors and underscores the increasing stakes for companies offering encrypted services. The ruling signals judicial awareness of privacy threats from advanced surveillance tools and may embolden similar litigation or policy action worldwide.
8 months ago
Kill Chain
GlassWorm Supply Chain Malware: VS Code & OpenVSX Infected in 2025
In October 2025, a highly sophisticated supply chain attack involving the GlassWorm malware targeted developers via the OpenVSX and Microsoft Visual Studio Code (VS Code) extension marketplaces. Malicious actors inserted invisible Unicode characters into multiple popular extensions, enabling self-spreading malware to infect users without detection during automatic updates. GlassWorm stole credentials for developer services and cryptocurrency wallets, established remote access, and transformed compromised workstations into nodes within a broader criminal infrastructure. The malware leveraged blockchain (Solana) transactions, Google Calendar events, and distributed Peer-to-Peer protocols for resilient command-and-control, impacting at least 35,800 installations and keeping several malicious extensions available before remediation. This incident highlights the growing threat of self-propagating malware in software supply chains, especially via extension ecosystems critical to development workflows. Its combination of advanced evasion tactics, automated propagation, and leveraging of decentralized infrastructure sets a new precedent, signaling broader risks for organizations relying on trusted code repositories and accelerating regulatory and industry scrutiny on supply chain security.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports