Validated Containment Architectures are here. →Explore

Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

2103 threat reports
Page 4 of 176

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Computer Software/Engineering Threat Reports

Showing 3748 / 2103 reports
ClickFix Attackers Exploit Polygon Blockchain in Campaign Against 31 Organizations
Impact· HIGH

ClickFix Attackers Exploit Polygon Blockchain in Campaign Against 31 Organizations

In September 2026, a sophisticated ClickFix campaign compromised at least 31 organizations across e-commerce, professional services, and retail logistics sectors. The attackers employed EtherHiding techniques, abusing the Polygon blockchain as a dynamic command-and-control infrastructure to evade traditional detection methods. Unlike typical ClickFix campaigns that deploy infostealers, this operation functioned as an initial access broker (IAB), installing persistent backdoors that survive reboots and communicate with C2 servers updated via blockchain transactions costing fractions of cents. This incident represents a concerning evolution in cybercriminal tactics, demonstrating how threat actors are weaponizing blockchain technology for resilient C2 infrastructure. The campaign's dual-victim approach, targeting both website owners through mass exploitation and end-users through social engineering, highlights the growing sophistication of modern cyber attacks and the need for comprehensive defense strategies addressing both technical vulnerabilities and human factors.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Anthropic Claude Users Targeted in Multi-Platform Infostealer Campaign
Impact· MEDIUM

Anthropic Claude Users Targeted in Multi-Platform Infostealer Campaign

In August 2026, Anthropic detected unauthorized access to Claude AI accounts after threat actors used multiple infostealer malware variants including Vidar, Lumma, StealC, RedLine, Acreed, and Atomic Stealer to harvest user session cookies and authentication tokens. The attackers bypassed multifactor authentication by stealing active browser sessions rather than credentials, allowing them to consume users' Claude usage quotas and access saved payment information. Anthropic responded by forcibly signing out affected users, removing payment methods, and refunding unauthorized charges. This incident exemplifies the growing shift from credential-based attacks to session hijacking, as organizations strengthen password policies and MFA adoption. The attack highlights emerging threats against AI platforms and the need for enhanced session management controls in cloud-native applications.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Langflow and Rails Vulnerabilities Enable Widespread Credential Harvesting Campaign
Impact· MEDIUM

Critical Langflow and Rails Vulnerabilities Enable Widespread Credential Harvesting Campaign

In August 2026, threat actors launched widespread exploitation campaigns targeting two critical vulnerabilities: CVE-2026-0768 in Langflow (CVSS 9.8) enabling arbitrary Python code execution as root, and CVE-2026-66066 in Ruby on Rails (CVSS 9.5) allowing file disclosure and remote code execution through Active Storage image processing flaws. VulnCheck recorded over 360 detections within days, with attackers primarily originating from Russia conducting credential harvesting, environment variable enumeration, and deploying cryptocurrency miners and remote access tools across vulnerable AI development platforms. This incident highlights the growing threat landscape targeting AI infrastructure and development platforms, as organizations increasingly deploy AI applications without proper security controls, creating new attack surfaces that threat actors are rapidly exploiting for credential theft and lateral movement.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Russian APT UAC-0099 Exploits AI Security Tools with GuardBreaker Prompt Injection
Impact· HIGH

Russian APT UAC-0099 Exploits AI Security Tools with GuardBreaker Prompt Injection

In September 2026, ESET researchers disclosed a new technique called GuardBreaker employed by Russia-aligned threat actor UAC-0099 against Ukrainian targets. The attack involved embedding provocative text about nuclear weapons creation into malicious VBS scripts to deliberately trigger AI safety mechanisms and prevent automated analysis. The technique aims to force large language models into refusal states, allowing malware like the MATCHBOIL loader to evade AI-assisted security workflows. This represents a sophisticated evolution in adversarial prompt injection, specifically designed to exploit the safety guardrails of modern AI security tools. This incident highlights the growing threat of AI-targeted evasion techniques as organizations increasingly rely on automated security analysis. With AI copilots and LLM-based scanners becoming standard in security operations, attackers are developing specific countermeasures to blind these systems, creating new vulnerabilities in modern defense strategies.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
METR Breach Exposes New AI Infrastructure Attack Vectors Worth $600K
Impact· HIGH

METR Breach Exposes New AI Infrastructure Attack Vectors Worth $600K

In March 2026, attackers exploited a fail-open authentication vulnerability in METR's publicly accessible AI research infrastructure to steal API keys and consume approximately $600,000 worth of AI model credits. The breach occurred when a researcher's EC2 instance running agent orchestration software inadvertently exposed authentication-protected endpoints to the public internet for several days. Attackers likely discovered the vulnerable system through certificate transparency monitoring and automated scanning for AI-related infrastructure, then directly prompted the exposed AI agent to reveal its API credentials before establishing persistent access. A second incident in May 2026 involved sustained probing of METR's infrastructure and exploitation of an inadvertently exposed SQL query endpoint that could have provided access to sensitive AI evaluation data. This incident highlights the emerging attack surface created by AI research infrastructure and the growing threat of credential harvesting targeting AI model providers. As organizations increasingly deploy AI agents and automated systems, the combination of high-value API access, complex authentication chains, and rapid development cycles creates new opportunities for financially motivated attackers to exploit cloud misconfigurations for significant monetary gain.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
The Coding Agent Trap: How Rogue AI Endpoints Became the New Supply Chain Threat
Impact· MEDIUM

The Coding Agent Trap: How Rogue AI Endpoints Became the New Supply Chain Threat

In August 2024, security researchers documented a novel supply chain attack where threat actors discovered exposed LLM inference endpoints, relabeled them with popular model names like DeepSeek, and distributed them as 'free' alternatives to attract AI coding agents. A honeypot captured a real coding agent session from China that transmitted 88 messages containing filesystem data, PowerShell command outputs, and tool manifests to an untrusted endpoint. The malicious endpoint operator could have responded with tool calls to execute arbitrary commands, read sensitive files, or exfiltrate data from the victim's machine without exploiting vulnerabilities. This represents a new attack vector where AI agents voluntarily connect to rogue infrastructure, exposing their capabilities and local environment data through normal inference requests with tools enabled and permissive configurations. This incident highlights the emerging risks as AI coding agents become mainstream development tools, with threat actors adapting traditional supply chain tactics to target autonomous systems that can execute code and access filesystems based on remote model responses.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Iranian State Hackers Exploit Tech Job Market to Deploy Advanced Cross-Platform Malware
Impact· HIGH

Iranian State Hackers Exploit Tech Job Market to Deploy Advanced Cross-Platform Malware

Iranian threat group Nimbus Manticore (also known as Mirage Kitten) has expanded their attack methodology by deploying cross-platform remote access trojans (RATs) through sophisticated social engineering campaigns targeting software engineers. The group poses as recruiters from major technology companies on LinkedIn and other job platforms, delivering trojanized coding challenges containing NodeRabbit and PollCat malware. These Node.js and JavaScript-based RATs can infect Windows, Linux, and macOS systems, representing a significant evolution from their traditional C/C++ toolset. The campaign has been observed targeting victims across Afghanistan, Egypt, and Ethiopia, demonstrating the group's expanded geographic reach and technical capabilities. This incident highlights the growing trend of state-sponsored actors adopting cross-platform development frameworks to maximize their attack surface while leveraging legitimate recruitment processes as attack vectors. The sophisticated nature of these fake coding challenges and the pressure tactics employed demonstrate how threat actors are increasingly exploiting the competitive job market in the technology sector.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Iran-Linked Nation-State Actors Launch Coordinated Attacks on US Water Infrastructure
Impact· HIGH

Iran-Linked Nation-State Actors Launch Coordinated Attacks on US Water Infrastructure

In August 2026, Iran-linked threat actors conducted a sophisticated campaign targeting critical water and wastewater systems across at least 12 US states, utilizing advanced persistent threat techniques to infiltrate industrial control systems. The attackers successfully compromised SCADA networks and human-machine interfaces, demonstrating their ability to manipulate critical infrastructure operations. In a parallel attack, the same threat group shut down a UK power plant for four days in July 2026, highlighting the global reach and severity of their capabilities. The incidents caused significant operational disruptions, water service outages affecting hundreds of thousands of residents, and forced emergency response protocols across multiple states. These attacks represent a dangerous escalation in nation-state targeting of critical infrastructure, coinciding with increased geopolitical tensions and sophisticated adversaries developing specialized capabilities for industrial control system compromise. The incidents underscore the urgent need for enhanced OT security measures and zero-trust architectures protecting critical national infrastructure.

4 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Supply Chain Attack: Malicious Packagist Packages Exploit iOS Devices to Steal Cryptocurrency Wallets
Impact· HIGH

Supply Chain Attack: Malicious Packagist Packages Exploit iOS Devices to Steal Cryptocurrency Wallets

In September 2026, cybersecurity researchers discovered 13 malicious Composer theme packages on Packagist targeting Vietnamese movie and comic streaming sites. These supply chain attacks injected JavaScript that deployed spyware on unpatched iOS devices running versions 18.4 through 18.6.x. The campaign exploited WebKit vulnerabilities CVE-2025-31277 and CVE-2025-43529 to break out of Safari's sandbox and install kernel-level malware. The sophisticated attack chain exfiltrated keychain databases, Wi-Fi passwords, SMS data, photos, and cryptocurrency wallet seeds from popular wallets including Bitget, Trust Wallet, and OKX, uploading encrypted data to command and control servers hosted on Funnull infrastructure. This incident highlights the evolving threat landscape where supply chain attacks increasingly target mobile platforms and cryptocurrency assets. The campaign's focus on stealing wallet seeds represents a concerning escalation from traditional data theft to direct financial crime, particularly as mobile cryptocurrency adoption accelerates across Southeast Asia.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Traefik Proxy Vulnerability Exposes HTTP/3 Timeout Bypass
Impact· HIGH

Critical Traefik Proxy Vulnerability Exposes HTTP/3 Timeout Bypass

In December 2024, Bishop Fox disclosed a critical vulnerability in Traefik proxy versions through 3.7.11, identified as CVE-2024-45410. The vulnerability stemmed from Traefik's request read timeout mechanism failing to apply to HTTP/3 connections, despite being enabled by default and documented as universally applied. This gap existed across four years of releases, allowing potential denial-of-service attacks and resource exhaustion through prolonged HTTP/3 connections. Upon responsible disclosure, Traefik maintainers issued a patch within twelve days, addressing the timeout enforcement inconsistency. This vulnerability highlights the growing security challenges in HTTP/3 implementations as organizations rapidly adopt the protocol for performance benefits. With HTTP/3 gaining widespread enterprise adoption and edge proxy deployments increasing, implementation gaps like these represent significant attack surfaces that threat actors are beginning to exploit more frequently.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Federal Whistleblower Exposes Critical Security Flaws in USPS Election Systems
Impact· HIGH

Federal Whistleblower Exposes Critical Security Flaws in USPS Election Systems

A federal whistleblower has exposed critical security and operational flaws in the U.S. Postal Service's rushed deployment of three new IT systems designed to control mail-in ballot processing for the 2026 midterm elections. The complaint reveals that USPS bypassed standard software development practices, including pre-release testing and security validation, to implement systems that could reject entire batches of ballots based on single scanning errors. The Federal Ballot Mail Portal and associated verification systems were developed in a matter of weeks rather than months, creating significant risks to election integrity and voter disenfranchisement. This incident highlights the growing intersection of cybersecurity vulnerabilities and critical infrastructure, particularly as election systems become increasingly digitized without proper security oversight. The rushed deployment of untested systems in mission-critical environments reflects broader challenges organizations face when political pressure overrides established security protocols and development best practices.

4 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
ValleyRAT Backdoor Campaign: When Adware Becomes Advanced Persistent Threat
Impact· MEDIUM

ValleyRAT Backdoor Campaign: When Adware Becomes Advanced Persistent Threat

In 2024, cybersecurity researchers discovered ValleyRAT backdoor malware masquerading as legitimate adware, specifically targeting users through a modified Chinese desktop wallpaper management tool called QN Wallpaper. The attack campaign, attributed to the Silver Fox threat group, affected over 100,000 detections across more than 1,500 unique users, primarily in China and India. The malware used DLL sideloading techniques to execute under signed processes, disabled Windows Defender, and deployed sophisticated backdoor capabilities including keylogging, clipboard monitoring, screenshot capture, and remote module loading for additional payload deployment. This incident highlights the evolving threat landscape where attackers increasingly abuse legitimate software distribution channels and signed binaries to evade detection, representing a significant shift toward supply chain compromises and living-off-the-land techniques that challenge traditional security approaches.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports