Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Understanding the Bucket Hijacking Threat in Cloud Storage
In July 2026, a critical cloud storage attack technique known as 'bucket hijacking' was disclosed, enabling threat actors to silently redirect an organization's active cloud data streams, including audit logs and telemetry, into attacker-controlled external storage buckets across major cloud platforms. This vulnerability exploits the global uniqueness of cloud storage bucket names, allowing attackers to register a previously deleted bucket name and reroute data streams intended for the original bucket. The attack affects major cloud providers, including Google Cloud, Amazon Web Services (AWS), and Microsoft Azure, and detection is extremely challenging once deployed. ([serisec.com](https://serisec.com/index.php/2026/06/27/new-bucket-hijacking-attack-allows-hackers-to-reroute-cloud-data-streams-to-external-storage/?utm_source=openai)) This incident underscores the escalating risks associated with cloud misconfigurations and the critical need for organizations to implement robust monitoring and configuration management practices. As cloud environments become increasingly complex, the potential for such vulnerabilities to be exploited grows, emphasizing the importance of proactive security measures to safeguard sensitive data.
2 months ago
Kill Chain
Dormant GitHub Accounts: A New Vector in Supply Chain Attacks
In July 2026, Datadog Security Labs identified multiple coordinated campaigns systematically enumerating corporate GitHub organizations, repositories, and user accounts via the GitHub API. Attackers utilized automated scraping tools with custom or legitimate-sounding user agents, leveraging dormant 'ghost' accounts—created two to five years prior and left inactive—as well as compromised OAuth tokens and personal access tokens (PATs) from legitimate users. While much of the activity targeted public data, some instances involved cloning private repositories, indicating a significant escalation in threat actor capabilities. This incident underscores the evolving tactics of threat actors who exploit dormant accounts and compromised credentials to conduct reconnaissance and access sensitive information. Organizations must enhance their monitoring of API activities and implement robust access controls to mitigate such risks.
2 months ago
Kill Chain
npm 12 Enhances Security by Disabling Automatic Install Scripts
In July 2026, GitHub released npm version 12, implementing significant security enhancements by disabling install scripts by default. This change prevents automatic execution of preinstall, install, and postinstall scripts during package installation, addressing a major attack vector exploited in previous supply chain attacks. Additionally, npm v12 requires explicit approval for Git and remote URL dependencies, further strengthening the ecosystem's security posture. This update is particularly relevant as supply chain attacks have become increasingly prevalent, with attackers leveraging automatic script execution to compromise systems. By requiring explicit consent for script execution and external dependencies, npm v12 aims to mitigate these risks, promoting a more secure development environment.
2 months ago
Kill Chain
AI-Powered Attack Compromises AWS Environment in Record Time
In July 2026, a lone threat actor utilized agentic AI workflows to orchestrate a sophisticated attack on a large Amazon Web Services (AWS) environment, achieving full compromise within 72 hours. The attacker exploited weaknesses across application services, AWS resources, source code repositories, CI/CD pipelines, runtime components, and data stores, leading to financial extortion of the victim. This incident underscores the evolving threat landscape where AI accelerates the speed and scale of cyberattacks, enabling even individual actors to execute complex operations rapidly. Organizations must adapt by enhancing their detection and response capabilities to counteract AI-assisted threats effectively.
2 months ago
Kill Chain
GodDamn Ransomware: A New Era of BYOVD Attacks
In July 2026, the Hyadina ransomware group launched a sophisticated attack against U.S. organizations using their newly developed 'GodDamn' ransomware. The attackers employed a Bring Your Own Vulnerable Driver (BYOVD) technique, utilizing a malicious kernel driver signed by Microsoft to disable security software and facilitate the ransomware deployment. This method allowed them to infiltrate sectors including healthcare, manufacturing, and education, leading to significant operational disruptions and data encryption. This incident underscores the evolving tactics of ransomware groups, particularly the exploitation of trusted digital certificates to bypass security measures. The use of legitimate tools for malicious purposes highlights the need for enhanced behavioral detection mechanisms and adaptive security strategies to counteract such sophisticated threats.
2 months ago
Kill Chain
AI Gateway Compromise Exposes Critical Security Vulnerabilities
In July 2026, a threat actor compromised an Amazon EC2 server hosting an AI gateway connected to Amazon Bedrock services. The attacker utilized this access to deploy cryptomining software, exploiting the gateway's privileged position to potentially access AI models, manipulate workflows, and infiltrate the organization's cloud infrastructure. This incident underscores the critical vulnerabilities associated with AI gateways, which often serve as central points of access to sensitive data and services. The increasing deployment of AI gateways in enterprise environments highlights the urgent need for robust security measures. As these gateways aggregate access to multiple AI models and datasets, they become attractive targets for attackers seeking to exploit centralized points of control. Organizations must implement stringent access controls, continuous monitoring, and regular security assessments to mitigate the risks posed by such vulnerabilities.
2 months ago
Kill Chain
NotPetya Attack: Lessons in Cybersecurity from a Nation-State Operation
In June 2017, the NotPetya malware attack, orchestrated by the Russian military's GRU Unit 74455 (Sandworm), exploited a compromised update mechanism in M.E.Doc, a widely used Ukrainian tax accounting software developed by Intellect Service. This supply chain attack led to the rapid propagation of the malware, causing extensive disruptions to critical infrastructure in Ukraine and resulting in global damages exceeding $10 billion. Major multinational corporations, including Maersk, Merck, and FedEx, experienced significant operational and financial impacts due to the attack. The incident underscored the vulnerabilities inherent in software supply chains and the potential for nation-state cyber operations to inflict widespread collateral damage. ([cyberbreaches.org](https://www.cyberbreaches.org/en/incidents/notpetya-2017?utm_source=openai)) The NotPetya attack serves as a stark reminder of the evolving nature of cyber warfare, where nation-state actors target civilian infrastructure to achieve strategic objectives. The incident highlights the critical importance for organizations to implement robust cybersecurity measures, particularly in securing their supply chains, to mitigate the risks posed by sophisticated cyber threats.
2 months ago
Kill Chain
Fake 7-Zip Installers Compromise Devices as Residential Proxy Nodes
In early 2026, cybersecurity researchers uncovered a campaign by the threat actor 'Lurking Lizard,' which distributed trojanized 7-Zip installers via the domain '7zip[.]com.' These malicious installers covertly transformed compromised devices into nodes within a residential proxy network, allowing attackers to route illicit traffic through unsuspecting users' IP addresses. The operation, dating back to at least August 2022, involved over 230 lookalike domains and impersonated major proxy providers to expand its reach. This incident highlights the growing trend of cybercriminals exploiting legitimate software and services to build extensive proxy networks, complicating detection and mitigation efforts. The use of residential proxies enables threat actors to mask their activities, posing significant challenges for cybersecurity defenses and emphasizing the need for heightened vigilance against such deceptive tactics. ([fbi.gov](https://www.fbi.gov/investigate/cyber/alerts/2026/evading-residential-proxy-networks-protecting-your-devices-from-becoming-a-tool-for-criminals?utm_source=openai))
2 months ago
Kill Chain
CISA Urges Immediate Patching of Langflow Vulnerability CVE-2026-55255
In July 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) mandated federal agencies to patch a critical vulnerability in Langflow, a popular AI development tool. Identified as CVE-2026-55255, this Insecure Direct Object Reference (IDOR) flaw allows authenticated attackers to execute flows belonging to other users by manipulating the /api/v1/responses endpoint. Exploitation of this vulnerability can lead to unauthorized access to sensitive data and resource consumption. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-prioritize-patching-langflow-auth-bypass-flaw/?utm_source=openai)) The urgency of this directive underscores the increasing targeting of AI development platforms by cyber actors. As AI tools become integral to various sectors, ensuring their security is paramount to prevent potential data breaches and operational disruptions.
2 months ago
Kill Chain
Malicious SDKs on npm and PyPI Compromise Paysafe and Skrill Integrations
In July 2026, a coordinated supply-chain attack targeted developers integrating payment services by distributing at least 17 malicious packages on the npm and PyPI repositories. These packages masqueraded as legitimate SDKs for Paysafe, Skrill, and Neteller, aiming to steal sensitive credentials such as API keys, AWS keys, and GitHub tokens. The attackers employed typosquatting techniques, publishing packages with names closely resembling authentic ones, leading to unauthorized access and potential data breaches. This incident underscores the escalating threat of supply-chain attacks within open-source ecosystems. The attackers' ability to infiltrate multiple package managers simultaneously highlights the need for enhanced vigilance and security measures among developers and organizations to safeguard against such sophisticated threats.
2 months ago
Kill Chain
Understanding and Mitigating System Prompt Leakage in AI Applications
In July 2026, AWS Security highlighted the persistent issue of system prompt leakage in generative AI applications. System prompts, which guide the behavior of large language models (LLMs), often contain sensitive information such as role definitions, behavioral guidelines, and API responses. Threat actors can exploit vulnerabilities to extract these prompts, potentially exposing proprietary data and compromising application integrity. Despite various mitigation strategies, complete remediation remains elusive due to inherent limitations in current AI systems. This underscores the need for continuous vigilance and adaptive security measures in AI deployments. The increasing prevalence of system prompt leakage incidents, as noted in the 2025 OWASP LLM Top 10, reflects a broader trend of sophisticated attacks targeting AI systems. Organizations must prioritize robust security frameworks to safeguard against evolving threats in the AI landscape.
2 months ago
Kill Chain
Vidar Infostealer Exploits Malvertising to Target SMBs in 2026
In April 2026, a sophisticated malvertising campaign targeted consumers and small to midsize businesses (SMBs) globally by delivering the Vidar infostealer and XMRig cryptomining malware. Attackers lured victims with ads for cracked software, leading them to download password-protected archives that concealed a Go-based loader. This loader executed defense-evasion techniques, including an in-memory Antimalware Scan Interface (AMSI) bypass, before deploying Vidar to harvest browser credentials and XMRig to mine Monero cryptocurrency. The campaign utilized the Factory-v3 framework to generate unique binaries, complicating detection efforts. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/vidar-infostealer-smb-malvertising-campaign?utm_source=openai)) This incident underscores the evolving tactics of financially motivated threat actors who combine multiple monetization strategies within a single infection. The use of malvertising, coupled with advanced evasion techniques, highlights the need for organizations to enhance their cybersecurity defenses against such multifaceted threats.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports