Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Supply Chain Attack Compromises Admin Menu Editor Pro Plugin, Backdoors 1,500+ WordPress Sites
In September 2026, threat actors compromised the Admin Menu Editor Pro WordPress plugin distribution infrastructure, affecting over 1,500 websites across 230+ customers. The attackers gained root-level access to adminmenueditor.com and injected malicious code into plugin versions 2.35 and 2.36, creating backdoor access through hidden user accounts and web shells. The compromise lasted approximately seven hours before detection, with the malicious payload (wp-user-consent.php) establishing persistent access on victim sites. Developer Janis Elsts took the distribution site offline and recommended customers restore from pre-September 14 backups to ensure complete remediation. This incident highlights the growing sophistication of supply chain attacks targeting WordPress ecosystems, where attackers increasingly focus on plugin distribution networks to achieve mass compromise. With WordPress powering over 40% of websites globally, such attacks represent a critical threat vector that organizations must address through enhanced vendor security assessments and plugin management practices.
4 days ago
Kill Chain
CVE-2026-87886: Acronis cPanel Backup Plugin Under Active Attack
In September 2026, Acronis disclosed CVE-2026-87886, a high-severity Linux local privilege escalation vulnerability in its backup plugins for cPanel, WebHost Manager (WHM), and Plesk. The vulnerability allows low-privileged attackers to escalate permissions on vulnerable Linux servers without user interaction, potentially enabling access to sensitive data and system disruption. Acronis confirmed active exploitation in limited, targeted attacks against hosting environments, prompting immediate patching recommendations for affected versions. This incident highlights the growing trend of attackers targeting web hosting infrastructure and third-party plugins, which provide attractive attack surfaces due to their privileged access to multiple customer environments and critical business operations.
4 days ago
Kill Chain
KREMLIN Banking Malware: How Brazilian Cybercriminals Weaponize Browser Extensions
The KREMLIN banking malware operation, tracked as REF9334, has been targeting Brazilian financial institutions since May 2025 through sophisticated browser hijacking techniques. The threat actors deploy malicious Chrome and Microsoft Edge extensions that bypass Chromium integrity mechanisms by manipulating Secure Preferences files and regenerating required HMACs. The operation leverages Ethereum smart contracts as dead drop resolvers to dynamically update command-and-control endpoints, making disruption extremely difficult. Over 1,515 infected systems have been identified, with 98% located in Brazil. This incident represents the growing sophistication of banking malware that exploits browser extension ecosystems and blockchain infrastructure for resilient operations. As financial institutions increasingly rely on web-based services and multi-factor authentication through browsers, attackers are adapting with advanced techniques that bypass traditional security controls.
4 days ago
Kill Chain
GitLab's Maximum-Severity Vulnerability: A Supply Chain Security Wake-Up Call
CVE-2026-85706, a maximum-severity path traversal vulnerability in GitLab Community and Enterprise Editions, is being actively exploited by threat actors to compromise software supply chains. The flaw, which received a CVSS score of 10.0, allows unauthenticated attackers to read arbitrary files from GitLab servers, including sensitive credentials and CI/CD secrets. GitLab disclosed and patched the vulnerability on September 10, 2026, but CISA added it to their Known Exploited Vulnerabilities catalog within days due to observed exploitation in the wild. Researchers detected rapid escalation from initial probes to full exploitation, with attackers extracting configuration files and SSH credentials that could enable complete system compromise and lateral movement into development environments. This incident highlights the growing threat to software supply chains as adversaries increasingly target development platforms to gain privileged access to source code, build processes, and deployment pipelines across multiple organizations.
4 days ago
Kill Chain
Chinese APT UTA0560 Weaponizes Chrome-Windows Zero-Day Chain in GRIMWEDGE Campaign
In September 2026, Chinese threat actor UTA0560 conducted a sophisticated spear-phishing campaign targeting multiple NGOs using a zero-day exploit chain dubbed BlueMoon. The attackers chained three vulnerabilities - CVE-2026-85046 and CVE-2026-87491 in Chrome, plus CVE-2026-85880 in Windows ALPC - to deploy the GRIMWEDGE JavaScript backdoor. The campaign leveraged reflected XSS vulnerabilities on legitimate university websites to redirect victims to malicious infrastructure hosting the multi-stage exploit chain, demonstrating advanced persistent threat capabilities. This incident highlights the growing threat of patch-gap exploitation, where attackers rapidly weaponize vulnerabilities that are patched in open-source codebases but not yet released in stable versions. With AI-powered exploit development accelerating vulnerability research timelines, organizations face compressed windows to defend against sophisticated nation-state campaigns targeting critical infrastructure and NGOs.
4 days ago
Kill Chain
Critical SAML Flaw in Siemens Mendix Enables Account Hijacking Across Industrial Systems
A critical authentication bypass vulnerability (CVE-2026-80465) was discovered in Siemens Mendix SAML modules across multiple versions, scoring 8.7 on the CVSS scale. The flaw stems from improper validation of SAML response signatures, allowing unauthenticated remote attackers to hijack user accounts and sessions in specific Single Sign-On (SSO) configurations. Affected versions include Mendix 9.24, 10, and 11 compatible modules, with the vulnerability impacting critical manufacturing and IT infrastructure worldwide. Siemens has released patches requiring immediate updates to versions 3.6.27 or 4.2.3 depending on the Mendix platform version. This incident highlights the growing trend of authentication protocol vulnerabilities targeting enterprise SSO systems, particularly as organizations increasingly rely on federated identity management for cloud and hybrid environments.
4 days ago
Kill Chain
Critical LiteSpeed Enterprise Flaw Exposes Shared Hosting Infrastructure to Root Access Attacks
A critical privilege escalation vulnerability in LiteSpeed Web Server Enterprise versions before 6.3.7 allows low-privilege hosting account users to gain root access on shared hosting servers. Disclosed by cPanel on September 14, 2026, the flaw bypasses security controls including CageFS that normally isolate hosting accounts from each other. The vulnerability enables attackers with basic hosting accounts to access or alter other customers' websites and compromise the entire server infrastructure. LiteSpeed released version 6.3.7 on September 11 to address the issue, though specific technical details and CVE assignment remain pending. This represents the third LiteSpeed-related privilege escalation flaw reported since May 2026, highlighting ongoing security challenges in shared hosting environments where multiple customer websites coexist on single servers.
4 days ago
Kill Chain
Vite Development Servers Under Attack: Mass Campaign Steals Cloud Credentials
In 2024, cybersecurity researchers from F5 Labs disclosed a mass-scanning campaign targeting exposed Vite development servers to extract sensitive cloud credentials and configuration data. The automated attack systematically scanned internet-facing Vite instances, exploiting misconfigurations to steal AWS and Microsoft Azure credentials, infrastructure state files, and other sensitive development artifacts. The campaign demonstrated how exposed development environments can become critical attack vectors for cloud infrastructure compromise, potentially leading to broader cloud account takeovers and data breaches across multiple organizations. This incident highlights the growing threat to cloud-native development workflows as attackers increasingly target DevOps toolchains and CI/CD pipelines. With organizations rapidly adopting cloud-first development practices and infrastructure-as-code approaches, securing development servers and preventing credential exposure has become a critical security imperative for preventing cloud account compromise.
4 days ago
Kill Chain
Apple's Record-Breaking Security Update: 261 Vulnerabilities Patched Across All Platforms
On September 14, 2024, Apple released comprehensive security updates across all operating systems, patching a record-breaking 261 vulnerabilities in iOS 27, macOS Golden Gate 27, and other platforms. The vulnerabilities spanned critical system components including kernel memory corruption, privilege escalation flaws, and sandbox escape vulnerabilities affecting core frameworks like WebKit, Kernel, CUPS, and SMB protocols. While Apple reported no active exploitation, the patches addressed severe security gaps including remote code execution, information disclosure, and authentication bypass vulnerabilities that could enable attackers to gain root privileges or access sensitive user data. This massive patch release reflects the evolving complexity of modern attack surfaces and Apple's proactive approach to security hardening. The scale of vulnerabilities demonstrates the critical importance of comprehensive endpoint security and zero-trust architectures as threat actors increasingly target foundational system components and inter-service communications.
4 days ago
Kill Chain
Machine-Speed Human Attack: CVE-2026-39987 Marimo Exploit Reaches SSH Bastion in 8 Seconds
In September 2026, skilled threat actors demonstrated machine-speed exploitation of CVE-2026-39987, a critical remote code execution vulnerability in Marimo notebooks with a CVSS score of 9.3. The attackers pivoted from initial compromise to SSH bastion host access in just eight seconds, using hand-crafted Python toolkits without AI assistance. Over a nine-hour session, they executed over 850 interactive commands, harvested AWS credentials from Secrets Manager, and established persistent access to cloud infrastructure, showcasing how human expertise can rival AI-assisted attacks in speed and stealth. This incident highlights the evolving threat landscape where skilled human operators are matching the speed traditionally expected from AI-powered attacks, while demonstrating superior evasion techniques that bypass automated defenses and detection systems designed to catch machine-generated attack patterns.
4 days ago
Kill Chain
Yemen Threat Actors Exploit Claude AI for Advanced Weapons Development
In September 2026, Anthropic disclosed that threat actors based in northern Yemen exploited their Claude AI models to develop guidance, navigation, and control software for advanced weapons systems, including guided rockets, ballistic missiles with 2,000+ km range, and hypersonic glide vehicles. The actors used multiple Claude instances simultaneously, assigning specialized roles to each AI system while employing evasion techniques to bypass safety guardrails. Although Anthropic's safeguards blocked many requests, the actors successfully developed software and conducted field tests of a guided rocket, though initial tests failed. This incident represents a concerning escalation in AI-enabled weapons proliferation, demonstrating how generative AI can democratize sophisticated military engineering capabilities previously limited to nation-states and well-funded organizations.
4 days ago
Kill Chain
Active GitLab CVE-2026-85706 Exploitation: CISA Issues Emergency Warning
In September 2026, CISA added GitLab vulnerability CVE-2026-85706 to its Known Exploited Vulnerabilities catalog after hackers began actively exploiting the maximum-severity path traversal flaw. The vulnerability stems from missing authentication enforcement in GitLab's repository commits API, allowing unauthenticated attackers to read credentials, secrets, and sensitive information through a single HTTP request. GitLab patched the flaw in versions 19.3.2, 19.2.6, and 19.1, but watchTowr security researchers detected widespread internet probing for vulnerable servers within 24 hours of the patch release. This incident highlights the accelerating timeline between vulnerability disclosure and active exploitation, as threat actors increasingly weaponize DevSecOps platform vulnerabilities to access critical development infrastructure and secrets management systems used by Fortune 100 companies.
5 days ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports