Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Integrating MCP Agents into Penetration Testing Workflows
In July 2026, Bishop Fox published an article detailing the integration of Model Context Protocol (MCP) agents into penetration testing workflows. This approach leverages AI to automate and enhance various testing phases, including external, application, and cloud penetration tests. By utilizing MCP agents, penetration testers can expand coverage, reduce time-to-findings, and identify vulnerabilities more efficiently. The article highlights practical tooling and prompting patterns, emphasizing the importance of maintaining human oversight and ethical considerations when deploying AI in security assessments. The adoption of AI-enhanced penetration testing methods, such as MCP agents, addresses the growing complexity and scale of modern attack surfaces. As cyber threats evolve rapidly, integrating AI into security testing enables organizations to identify and remediate vulnerabilities more swiftly, ensuring robust defense mechanisms against potential breaches.
2 months ago
Kill Chain
NadMesh Botnet Exploits Exposed AI Services to Steal Cloud Credentials
In early July 2026, the NadMesh botnet emerged, targeting exposed AI services such as ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio. The botnet exploits these unsecured services to harvest sensitive cloud credentials, including AWS keys and Kubernetes tokens. QiAnXin's XLab reported that the botnet operator's dashboard claimed possession of 3,811 unique AWS keys, indicating a significant breach of cloud security. The malware employs a Shodan harvester to continuously scan for vulnerable AI services, emphasizing the critical need for securing such deployments. This incident underscores the growing trend of cyber attackers exploiting misconfigured AI and automation tools to gain unauthorized access to cloud infrastructures. Organizations must prioritize the security of AI services, ensuring proper authentication and network configurations to prevent such breaches.
2 months ago
Kill Chain
ViteVenom: Unveiling the Blockchain-Powered Supply Chain Attack on Vite npm Packages
In July 2026, cybersecurity researchers identified a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem. This campaign, dubbed ViteVenom, expanded upon the earlier ChainVeil attack by utilizing a sophisticated four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron, Aptos, and Binance Smart Chain. The attackers, attributed to the group SuccessKey, employed this infrastructure to deliver a remote access trojan (RAT) capable of reverse shell operations, credential harvesting, file exfiltration, and persistent backdoor injection. The malicious packages, published between June 29 and July 3, 2026, impersonated legitimate Vite packages, thereby deceiving developers into incorporating them into their projects. This incident underscores the escalating complexity and persistence of supply chain attacks, particularly those leveraging decentralized technologies to evade detection and takedown efforts. The use of blockchain for C2 infrastructure presents significant challenges for traditional security measures, highlighting the need for enhanced vigilance and advanced threat detection capabilities within the software development community.
2 months ago
Kill Chain
wp2shell: Critical WordPress Core Vulnerability Exposes Sites to Unauthenticated RCE
In July 2026, a critical vulnerability known as 'wp2shell' was discovered in WordPress core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. This flaw allowed unauthenticated remote code execution (RCE) via anonymous HTTP requests, making even default installations without plugins susceptible. The vulnerability was identified by Adam Kues of Searchlight Cyber and reported through WordPress's HackerOne program. In response, WordPress released emergency security updates—versions 6.9.5 and 7.0.2—on July 17, 2026, and initiated forced auto-updates to mitigate the risk. ([thehackernews.com](https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html?utm_source=openai)) The 'wp2shell' incident underscores the persistent threat of unauthenticated RCE vulnerabilities in widely used platforms. It highlights the critical importance of timely software updates and proactive security measures to protect against emerging exploits targeting core system functionalities.
2 months ago
Kill Chain
AI Exploit Highlights Risks of Autonomous Systems in Financial Transactions
In May 2026, an attacker exploited vulnerabilities in AI systems by sending a Morse code message to Grok, an AI chatbot developed by xAI. Grok decoded the message and relayed it to Bankrbot, an autonomous financial agent, which then executed unauthorized cryptocurrency transactions totaling approximately $200,000. This incident underscores the risks associated with AI systems possessing excessive autonomy and the potential for 'authority laundering,' where AI systems transform untrusted input into authorized actions without adequate oversight. As organizations increasingly integrate AI into critical operations, it is imperative to implement robust governance frameworks to prevent such exploits and ensure AI systems operate within clearly defined authority boundaries.
2 months ago
Kill Chain
BoryptGrab Malware Campaign Exploits Fake GitHub Repositories in 2026
In July 2026, cybersecurity researchers uncovered a large-scale malware campaign involving 292 fake GitHub repositories impersonating legitimate software projects. These repositories distributed a variant of the BoryptGrab infostealer, which targets sensitive data from web browsers, cryptocurrency wallets, and messaging applications. The malware was delivered through trojanized installers that exploited DLL side-loading techniques, allowing attackers to harvest credentials and financial information from unsuspecting users. The campaign primarily targeted users in the United States, Germany, Romania, and Venezuela, leading to significant data breaches and financial losses. This incident underscores the growing trend of cybercriminals leveraging trusted platforms like GitHub to distribute malware. The sophistication of the campaign, including the use of search engine optimization to promote malicious repositories, highlights the need for enhanced vigilance and verification processes when downloading software from online sources.
2 months ago
Kill Chain
Phishing Attacks Exploit Hidden Text to Bypass AI Security Filters
Since April 2026, Barracuda Networks has identified over one million phishing emails employing 'text salting' techniques to evade both traditional and AI-powered email security filters. These emails, often retail-themed, use hidden text within their HTML code to manipulate security gateways, allowing malicious content to bypass detection and reach users' inboxes. ([darkreading.com](https://www.darkreading.com/threat-intelligence/1m-emails-hidden-text-dupe-ai-security-filters?utm_source=openai)) The resurgence of text salting, facilitated by large language models (LLMs), highlights the evolving sophistication of phishing attacks. This trend underscores the need for advanced security measures capable of analyzing the full context of email content, including hidden elements, to effectively combat such evasive tactics. ([blog.barracuda.com](https://blog.barracuda.com/2026/07/16/text-salting-ai-email-security?utm_source=openai))
2 months ago
Kill Chain
Google's Agentic Defense: Revolutionizing Cybersecurity with AI
In March 2026, Google completed its $32 billion acquisition of cloud security firm Wiz, aiming to enhance its cloud-native security capabilities. Wiz's graph-based analysis technology enables correlation of cloud assets, identities, vulnerabilities, and exposures across multi-cloud environments. This acquisition led to the development of Google's 'agentic defense' platform, which automates threat detection, investigation, and remediation using intelligent security agents. The platform addresses the increasing speed and sophistication of AI-powered cyberattacks by shifting from human-led to AI-led cyber defense strategies. ([darkreading.com](https://www.darkreading.com/cloud-security/google-bets-agentic-defense-strategy-outpace-attackers?utm_source=openai)) The urgency of adopting AI-driven security measures is underscored by the rapid acceleration of machine-based attacks. According to Google Cloud's Mandiant threat detection unit, the average time from initial breach to handoff of access to another threat actor has decreased from 8 hours to just 22 seconds over the past three years. This trend highlights the necessity for organizations to implement automated, AI-driven defense mechanisms to effectively counteract evolving cyber threats. ([darkreading.com](https://www.darkreading.com/cloud-security/google-bets-agentic-defense-strategy-outpace-attackers?utm_source=openai))
2 months ago
Kill Chain
CISA Adds Three Exploited Vulnerabilities to KEV Catalog
On July 16, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. The vulnerabilities include two OS command injection flaws in Fortinet FortiSandbox (CVE-2026-25089 and CVE-2026-39808) and a deserialization of untrusted data vulnerability in Microsoft SharePoint (CVE-2026-58644). These vulnerabilities are commonly exploited by malicious actors and pose significant risks to federal enterprises. The inclusion of these vulnerabilities in the KEV Catalog underscores the critical need for organizations to prioritize patching and remediation efforts. With the increasing frequency of such exploits, it is imperative for entities to adopt risk-based vulnerability management practices to safeguard their systems against potential breaches.
2 months ago
Kill Chain
North Korean Hackers Exploit Fake Coding Tests to Deploy OtterCookie Malware via Steganography
In July 2026, North Korean state-sponsored hackers initiated a sophisticated campaign targeting software developers through fake job postings and coding assessments. These assessments contained repositories with malicious code concealed within SVG image files, employing steganography to evade detection. Upon execution, the code deployed a multi-stage payload associated with the OtterCookie malware, capable of stealing browser credentials, cryptocurrency wallets, and sensitive files, as well as establishing remote access via a Socket.IO-based trojan. This operation underscores the persistent threat posed by North Korean cyber actors to the software development community, aiming to exfiltrate valuable data and financial assets. The use of steganography in SVG files highlights the evolving tactics employed by these adversaries to bypass traditional security measures, emphasizing the need for heightened vigilance and advanced detection capabilities within the industry.
2 months ago
Kill Chain
ACR Stealer 2026: Unveiling the ClickFix Intrusion Chains
Between late April and mid-June 2026, Microsoft Defender Experts observed a surge in ACR Stealer activity targeting enterprise environments. Attackers employed 'ClickFix' social engineering tactics to deceive users into executing malicious commands, leading to the theft of browser credentials, authentication tokens, and sensitive documents. The campaigns utilized two primary intrusion chains: one leveraging WebDAV for payload delivery with Python-based loaders and blockchain-backed command-and-control mechanisms, and another employing MSHTA-initiated PowerShell scripts with steganographic techniques for in-memory payload execution. These sophisticated methods enabled attackers to evade detection and maintain persistence within compromised systems. The significance of this incident lies in the advanced techniques used to bypass traditional security measures, highlighting the evolving nature of cyber threats. Organizations must remain vigilant against such deceptive tactics and enhance their security protocols to detect and mitigate similar attacks effectively.
2 months ago
Kill Chain
Russian Hackers Exploit WebEx and Zoom Installers to Deploy Starland RAT
In June 2025, the Russian threat actor UAT-11795 initiated a campaign targeting users primarily in the United States, with additional victims in Germany, Romania, and Venezuela. The attackers distributed trojanized installers of legitimate software, including WebEx and Zoom, to deploy the Starland RAT malware. This backdoor enabled the exfiltration of browser data, cryptocurrency wallet assets, system details, and Active Directory information. The malware also facilitated remote command execution, screenshot capture, and the deployment of additional payloads such as CastleStealer and Remcos RAT. This incident underscores the increasing sophistication of supply chain attacks, where trusted software is weaponized to infiltrate systems. The use of trojanized installers highlights the critical need for organizations to enforce strict software sourcing policies and to educate users on the risks of downloading software from unofficial sources.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports