Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Sitecore Zero-Day Breach: ViewState Exploits Lead to Remote Code Execution
In early 2024, threat actors exploited a zero-day vulnerability in Sitecore's ASP.NET-based content management system by weaponizing exposed machine keys, enabling remote code execution via malicious ViewState deserialization. Attackers bypassed authentication controls to inject arbitrary code and gain persistent control over vulnerable web servers, leading to potential data exfiltration and site takeover. Multiple Sitecore installations globally were at risk, highlighting weaknesses in secure key management and web application security monitoring. Organizations faced reputational and operational impacts as attackers abused trusted digital experiences to deliver malware and conduct further intrusions. The incident is part of a broader surge in deserialization and code injection attacks targeting legacy .NET applications. Zero-day exploitation against business-critical CMS platforms increases urgency for robust segmentation, runtime detection, and zero trust controls to defend against rapidly evolving attack techniques.
8 months ago
Kill Chain
Sitecore Vulnerabilities: Cache Poisoning and RCE Exploit Chain Uncovered (2025)
In August 2025, researchers disclosed an exploit chain in the Sitecore Experience Platform involving three newly uncovered vulnerabilities—CVE-2025-53693 (HTML cache poisoning), CVE-2025-53691 (remote code execution via insecure deserialization), and CVE-2025-53694 (not yet detailed). The flaws allow attackers to first poison cached content by manipulating reflected inputs, and then leverage insecure deserialization to remotely execute arbitrary code on targeted Sitecore servers. If exploited, these issues can expose sensitive data and potentially compromise the full web application environment of affected organizations, particularly in sectors relying on large-scale digital experience management. This incident highlights the persistent risk of chained application vulnerabilities enabling critical attacks, such as lateral movement and RCE, within enterprise environments. With web applications being frequent targets and exploit code often surfacing soon after disclosures, organizations must prioritize proactive vulnerability management and robust segmentation to contain blast radius.
8 months ago
Kill Chain
Scattered Spider SIM-Swapping & Wire Fraud: Anatomy of a 2022 Corporate Breach
In 2022, a cybercriminal cell known as Scattered Spider orchestrated a widespread campaign of SIM-swapping and sophisticated social engineering attacks against major US companies. Led in part by 20-year-old Noah Michael Urban (alias "King Bob"), the group tricked mobile provider and corporate employees into divulging credentials and approving phishing requests, allowing attackers to hijack authentication flows and gain deep access to internal systems, including Okta and VPN platforms. Over several months, their schemes compromised more than 130 organizations—including Twilio, LastPass, DoorDash, and others—resulting in the theft of corporate and customer data, and millions in cryptocurrency. The operational impact included large-scale operational disruption and significant financial losses for victims. Scattered Spider’s tactics showed a fusion of SIM-swapping, credential phishing, and insider targeting that has reshaped industry concerns over identity-driven breaches and lateral movement. The group’s use of persistent social engineering, paired with technical exploitation, highlights the urgent need for organizations to strengthen multi-factor authentication, enforce Zero Trust principles, and adopt modern anomaly detection for internal east-west traffic.
8 months ago
Kill Chain
AI Turbocharges Exploit Development: Are You Ready for Machine-Speed Cyber Threats?
In mid-2024, two independent Israeli cybersecurity researchers developed an AI-powered system, "Auto Exploit," that can generate proof-of-concept exploit code for new vulnerabilities in as little as 15 minutes. Leveraging large language models like Anthropic's Claude and open-source LLMs, the system parses CVE advisories and code patches, quickly creating vulnerable test environments and customized exploit code. This approach successfully produced exploits for 14 open source software vulnerabilities, dramatically shortening the typical window for defenders to patch their systems before seeing exploitation in the wild. The project highlights the risk posed by adversaries who can now weaponize vulnerabilities and bypass LLM guardrails at machine speed, raising the stakes for enterprise security teams. As automation and AI further accelerate exploit development, organizations face increasing pressure to adapt their vulnerability management and incident response processes. The emergence of such techniques indicates a shift where traditional exploitability scoring is less relevant, and exposure of assets becomes the key risk consideration.
8 months ago
Kill Chain
Critical SAP S/4HANA Code Injection Vulnerability Exploited in 2025
In August 2025, a critical code injection vulnerability (CVE-2025-42957) in SAP S/4HANA was exploited in the wild, enabling attackers with even low-privileged user access to inject ABAP code and achieve full compromise of both the SAP environment and the underlying host OS. Publicly disclosed and patched by SAP in its August security updates, the flaw affects both private cloud and on-premise deployments. The exploit requires only a basic user account and a remote function call, after which attackers can manipulate or delete SAP data, create persistent admin backdoors, exfiltrate sensitive data, and control the OS. Exploitation attempts surged following patch publication, with confirmed abuse reported by specialist vendors. This incident highlights the increasing risk of low-complexity, high-impact ERP vulnerabilities, especially as attackers rapidly weaponize disclosed flaws. It underscores the continued targeting of critical business platforms by threat actors leveraging phishing and privileged escalation, emphasizing the urgent need for swift patching and stronger access controls.
8 months ago
Kill Chain
Argo CD 2025 API Flaw Exposes Repository Credentials: What Enterprises Must Know
In September 2025, a critical vulnerability (CVE-2025-55190) in Argo CD—a widely used Kubernetes-native continuous deployment platform—was discovered that allowed API tokens, including those with minimal project-level permissions, to access API endpoints and retrieve all repository credentials for a given project. While the flaw required possession of a valid Argo CD API token, even low-privileged users could exploit this issue to bypass established isolation mechanisms and exfiltrate sensitive repository usernames and passwords. This exposure could enable attackers to clone proprietary codebases, inject malicious configurations, and potentially initiate supply chain compromises or further lateral movement, particularly impactful given Argo CD's widespread enterprise adoption by organizations like Adobe, Google, IBM, and Capital One. The incident underscores the ongoing risks posed by misconfigured API permissions in CI/CD pipelines, particularly as attackers increasingly target software supply chains. With credential-based attacks on the rise and major regulatory and industry scrutiny on API security, organizations must act quickly to patch, enhance access controls, and apply zero-trust principles in DevOps contexts.
8 months ago
Kill Chain
How Attackers Are Sidestepping macOS Built-in Security in 2024
In 2024, researchers and incident responders observed a sophisticated wave of cyberattacks targeting macOS systems, where adversaries adapted to built-in security protections such as Keychain, Gatekeeper, TCC, and System Integrity Protection. Threat actors leveraged utilities like Chainbreaker to extract password data, employed social engineering to bypass File Quarantine and Gatekeeper, and manipulated permission prompts through clickjacking techniques. By exploiting command-line utilities, attackers disabled or evaded standard protections, leading to potential exposure of sensitive credentials and increased risk of full system compromise. The macOS attack landscape continues to evolve, with adversaries innovating to evade resilient, native defenses. Rising adoption of macOS in enterprise environments and the seamless integration with personal devices make these evasion TTPs especially critical for security teams and compliance requirements focused on regulated and sensitive data.
8 months ago
Kill Chain
Inside the 2025 Salesloft Supply Chain Breach: Token Theft at Scale
In August 2025, Salesloft, a leading AI chatbot provider, suffered a significant supply chain compromise when attackers exfiltrated authentication tokens via its Drift integration. The breach allowed unauthorized access to hundreds of customer-connected services, including Salesforce, Slack, Google Workspace, Amazon S3, Azure, and OpenAI, impacting more than 5,000 customers. The attackers, tracked as UNC6395 and possibly linked to ShinyHunters or Scattered Spider, began siphoning sensitive corporate data from at least August 8 to August 18, 2025. The incident led to mass data theft, urgent token invalidation efforts, and subsequent blocking of Drift integrations by Salesforce. This breach highlights the surging threats posed by identity-driven attacks and the risks of over-permissive third-party integrations in the enterprise cloud ecosystem. As attackers increasingly exploit centralized authentication and SSO environments, organizations face urgent pressure to revisit access controls and strengthen detection of abuse within legitimate user sessions.
8 months ago
Kill Chain
Phishing Empire Unmasked: How Cloud Phishing-as-a-Service Campaigns Evade Detection
In 2024, a sophisticated phishing-as-a-service (PhaaS) operation leveraged Google and Cloudflare infrastructure to host undetectable phishing sites for over three years. By employing advanced cloaking techniques and encrypted traffic, threat actors were able to evade detection by security platforms and browsers, targeting users globally and harvesting credentials at scale. The persistent campaign highlights the effectiveness of public cloud abuse for malicious operations and the operational difficulties organizations face in detecting and mitigating such well-cloaked threats. This incident underscores a growing trend: cybercriminals turning to public cloud providers for reliable infrastructure and exploiting their reputation to bypass security controls. It also signals the adaptability of phishing campaigns and the need for enhanced monitoring and zero trust strategies in response to evolving attacker TTPs.
8 months ago
Kill Chain
Inside the Salesloft Drift Supply Chain Breach: How OAuth Token Theft Exposed SaaS Leaders
In August 2023, the threat group UNC6395 exploited a vulnerability in Salesloft’s Drift SaaS marketing platform, targeting OAuth and refresh tokens stored within its Salesforce integration. By leveraging these stolen tokens, attackers performed lateral movement into several customer Salesforce environments, extracting business contact records, support case data, and in some instances, sensitive configuration details and access credentials from high-profile clients such as Zscaler, Palo Alto Networks, Cloudflare, Proofpoint, and Tenable. Salesloft and Salesforce responded by revoking tokens and disabling integrations, while impacted organizations rushed to assess and mitigate the damage. This incident underscores the persistent risk of supply chain compromises targeting SaaS integrations and identity-based authentication mechanisms. As attackers increasingly leverage token theft for stealthy, authorized access, organizations must adopt granular permissions, token security best practices, and rapid credential rotation to safeguard against similar threats.
8 months ago
Kill Chain
Nx npm Supply Chain Breach 2025: AI Stealer Exposes Over 1,000 Developer Secrets
In late August 2025, a highly automated supply chain attack compromised the popular Nx build system on npm, enabling unidentified attackers to infect more than 1,000 JavaScript developers within just four hours. Malicious packages, leveraging artificial intelligence through CLI integrations, actively scanned victim environments for GitHub tokens, npm credentials, SSH keys, cloud secrets, and cryptocurrency wallets—exfiltrating roughly 20,000 sensitive files. Instead of using traditional command and control servers, the attackers published victims’ stolen data into public GitHub repositories, complicating detection and enabling rapid collection by threat actors. This incident marks a significant escalation in software supply chain threats by demonstrating the abuse of AI-driven reconnaissance and novel exfiltration via legitimate platforms. The swift, large-scale impact underscores rising attacker sophistication and amplified operational risk, especially as AI and developer tooling become more deeply embedded in build pipelines and cloud-native workflows.
8 months ago
Kill Chain
Amazon Disrupts APT29 Credential Theft Leveraging Cloudflare and Device Code Abuse
In early 2024, Amazon identified and disrupted a credential theft campaign orchestrated by the Russian-linked threat actor APT29 (also known as Cozy Bear or Midnight Blizzard). Attackers redirected targeted users to fraudulent Cloudflare verification pages and abused Microsoft's device code authentication flow to harvest credentials. This sophisticated phishing operation targeted employees with access to sensitive resources and leveraged social engineering along with technical exploits to bypass multi-factor authentication controls. Amazon’s security team coordinated rapid takedown efforts, mitigating potential compromise before widespread damage or data loss could occur. This incident exemplifies the increasing sophistication of nation-state actors, particularly in leveraging supply chain services and authentication protocols. The widespread adoption of identity and device-based authentication has introduced new attack surfaces, highlighting the urgent need for adaptive security measures and ongoing user vigilance in credential management.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports