Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Dialogflow CX 'Rogue Agent' Flaw: A Wake-Up Call for AI Security
In November 2025, Varonis researchers identified a critical vulnerability, termed 'Rogue Agent,' in Google Cloud Platform's Dialogflow CX AI platform. This flaw allowed attackers to exploit the Code Blocks feature by modifying a single permission—dialogflow.playbooks.update—on a Dialogflow agent. Such exploitation enabled the injection of persistent malicious code into the agents' pipeline, facilitating the silent exfiltration of conversations and the execution of large-scale phishing campaigns. Google addressed the issue with an initial patch in April 2026 and fully resolved it by June 2026, ensuring that all affected components were remediated. ([darkreading.com](https://www.darkreading.com/application-security/dialogflow-cx-rogue-agent-flaw-enabled-ai-chatbot-data-theft?utm_source=openai)) The 'Rogue Agent' vulnerability underscores the expanding attack surface introduced by integrating AI services into cloud platforms. It highlights the necessity for organizations to rigorously evaluate and secure their AI infrastructures, as attackers increasingly target these systems to access sensitive data and conduct sophisticated cyber operations. ([varonis.com](https://www.varonis.com/blog/rogue-agent-dialogflow-attack?utm_source=openai))
2 months ago
Kill Chain
Critical Adobe ColdFusion Vulnerability (CVE-2026-48282) Requires Immediate Attention
In June 2026, a critical path traversal vulnerability, identified as CVE-2026-48282, was discovered in Adobe ColdFusion versions 2025.9, 2023.20, and earlier. This flaw allows unauthenticated remote attackers to execute arbitrary code on affected servers without user interaction, potentially leading to full system compromise. The vulnerability arises from improper limitation of a pathname to a restricted directory, enabling attackers to access and manipulate files outside the intended directory structure. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-48282?utm_source=openai)) The inclusion of CVE-2026-48282 in CISA's Known Exploited Vulnerabilities Catalog underscores the urgency for organizations to address this issue promptly. Given the active exploitation in the wild, entities using vulnerable ColdFusion versions must prioritize patching to mitigate the risk of unauthorized access and potential data breaches. ([resecurity.com](https://www.resecurity.com/ar/blog/article/cve-2026-48282-adobe-coldfusion-rds-path-traversal-leading-to-rce?utm_source=openai))
2 months ago
Kill Chain
Critical Vulnerability in Siemens Mendix Studio Pro: CVE-2026-48192
In June 2026, Siemens disclosed a vulnerability (CVE-2026-48192) in Mendix Studio Pro versions 10.11 through 10.24 (prior to V10.24.21) and 11.0 through 11.11. The flaw arises from improper validation and sanitization of project files during the build pipeline, allowing attackers to execute arbitrary code if a user opens a specially crafted malicious project. This vulnerability could lead to unauthorized code execution within the user's context, potentially compromising developer workstations and downstream build artifacts. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-48192/?utm_source=openai)) The incident underscores the critical importance of validating and sanitizing project files in development environments. As low-code platforms like Mendix Studio Pro gain popularity, ensuring robust security measures against such vulnerabilities becomes imperative to protect development processes and prevent potential supply chain attacks.
2 months ago
Kill Chain
GitHub's 'Verified' Commits Vulnerable to Hash Malleability
In July 2026, researcher Jacob Ginesin identified a vulnerability in GitHub's commit verification process, revealing that signed Git commits can be altered to produce new hashes without invalidating their signatures. This flaw allows attackers to replicate commits with identical content, authorship, and timestamps, yet different hashes, while still displaying a 'Verified' status on GitHub. Consequently, systems relying on commit hashes for security measures, such as blocklists and provenance logs, are susceptible to evasion tactics. ([thehackernews.com](https://thehackernews.com/2026/07/github-verified-commits-can-be.html?utm_source=openai)) This discovery underscores the critical need for robust verification mechanisms in software development platforms. As supply chain attacks become more sophisticated, ensuring the integrity and authenticity of code commits is paramount to maintaining trust and security in open-source ecosystems.
2 months ago
Kill Chain
Critical Vulnerability in Hitachi Energy's PROMOD V: CVE-2026-10763
In June 2026, Hitachi Energy disclosed a vulnerability (CVE-2026-10763) in its PROMOD V software, which utilized unencrypted HTTP communication due to the lack of HTTPS support from a third-party Digipede server. This flaw exposed sensitive data to potential interception and manipulation, posing risks such as credential theft and unauthorized access. The affected versions include PROMOD V up to 1.0.10. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-10763?utm_source=openai)) This incident underscores the critical importance of secure communication protocols in industrial control systems. Organizations are urged to review their software dependencies and ensure that all components support encrypted communications to mitigate similar vulnerabilities.
2 months ago
Kill Chain
CISA Highlights Three Actively Exploited Vulnerabilities in Latest KEV Catalog Update
On July 7, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. These vulnerabilities include CVE-2026-48908, an unrestricted file upload flaw in JoomShaper's SP Page Builder; CVE-2026-55255, an authorization bypass in Langflow; and CVE-2026-56290, an improper access control issue in Joomlack's Page Builder. Such vulnerabilities are commonly exploited by malicious actors, posing significant risks to federal enterprises. The inclusion of these vulnerabilities underscores the critical need for organizations to prioritize remediation efforts. CISA's Binding Operational Directive (BOD) 26-04 mandates federal agencies to address high-risk vulnerabilities promptly, emphasizing the importance of proactive vulnerability management to safeguard against active threats.
2 months ago
Kill Chain
HalluSquatting: Exploiting AI Coding Assistants to Deploy Botnet Malware
In July 2026, researchers identified a novel cyberattack technique termed 'HalluSquatting,' which exploits AI coding assistants' tendency to generate plausible but non-existent resource names. Attackers predict these hallucinated names, register them, and embed malicious code. When users prompt their AI assistants to fetch these resources, the assistants inadvertently execute the malicious code, potentially installing botnet malware on the user's machine. This method leverages AI hallucinations and prompt injections to compromise systems without direct user interaction. The emergence of HalluSquatting underscores the evolving threat landscape in AI-integrated development environments. As AI tools become more prevalent, attackers are increasingly targeting their inherent vulnerabilities. This incident highlights the urgent need for enhanced security measures in AI-driven tools to prevent exploitation through such sophisticated techniques.
2 months ago
Kill Chain
Expansion of Deepfake CSAM Lawsuit Targets xAI and Stability AI
In July 2026, a class-action lawsuit against xAI, the developer of the AI tool Grok, was expanded to include two additional plaintiffs. These individuals allege that Grok was used by acquaintances to generate nonconsensual deepfake child sexual abuse material (CSAM) based on their real photos. The lawsuit also names Stability AI as a defendant, claiming that its Stable Diffusion model facilitated the creation of such illicit content. The plaintiffs report significant emotional distress and a loss of control over the dissemination of these images. This incident underscores the urgent need for robust safeguards in AI technologies to prevent misuse, particularly in generating harmful content. It highlights the growing legal and ethical challenges companies face in ensuring their AI models are not exploited for creating nonconsensual and illegal material.
2 months ago
Kill Chain
Januscape Vulnerability: Critical Linux Kernel Flaw Enables VM Escape
In July 2026, a critical vulnerability known as 'Januscape' (CVE-2026-53359) was disclosed in the Linux kernel's KVM/x86 virtualization component. This 16-year-old flaw allows attackers with root access inside a guest virtual machine to execute arbitrary code on the host, potentially compromising all other guests and the host system itself. The vulnerability arises from a use-after-free issue in the shadow MMU emulation, affecting both Intel and AMD processor architectures. The disclosure of Januscape underscores the persistent risks associated with long-standing vulnerabilities in widely used open-source software. It highlights the necessity for organizations to maintain rigorous patch management practices and to monitor for emerging threats that could exploit such vulnerabilities, especially in multi-tenant cloud environments where the impact can be widespread.
2 months ago
Kill Chain
Understanding the Cordyceps Vulnerability in GitHub Actions
In June 2026, Novee Security identified a critical vulnerability class in GitHub Actions workflows, termed 'Cordyceps.' This flaw allows unauthenticated attackers to exploit CI/CD pipelines by manipulating untrusted pull requests, leading to unauthorized code execution and potential supply chain compromises. Over 300 repositories, including those of Microsoft, Google, and Apache, were confirmed vulnerable, exposing them to credential theft and malicious code injection. The Cordyceps vulnerability underscores the escalating risks in software supply chains, especially as AI-generated code becomes more prevalent. Traditional security scanners often miss such complex, composition-based flaws, highlighting the need for enhanced security measures in CI/CD workflows to prevent potential large-scale attacks.
2 months ago
Kill Chain
Accenture Confirms Data Breach After Hacker Offers Stolen Data for Sale
In July 2026, Accenture, a global professional services company, confirmed a security breach after a threat actor known as "888" claimed to have stolen 35 GB of data, including source code, RSA keys, SSH keys, Azure personal access tokens, Azure Storage access keys, and configuration files. The threat actor began offering this data for sale on a cybercrime forum. Accenture stated that they were aware of the incident, had remediated its source, and that there was no impact on their operations and service delivery. However, the company did not disclose how the attackers gained access or whether customer data was affected. This incident underscores the persistent threat posed by cybercriminals targeting large enterprises for sensitive data. The exposure of source code and access keys can lead to further exploitation, including intellectual property theft and potential supply chain attacks. Organizations must remain vigilant, continuously assess their security postures, and implement robust measures to protect against such breaches.
2 months ago
Kill Chain
Critical 'Rogue Agent' Flaw in Google Dialogflow CX Exposed AI Chatbots to Data Theft
In November 2025, Varonis Threat Labs identified a critical vulnerability in Google's Dialogflow CX, dubbed 'Rogue Agent.' This flaw allowed attackers with the 'dialogflow.playbooks.update' permission on a single Code Block-enabled agent to inject malicious code, compromising all Code Block-enabled agents within the same Google Cloud project. Exploiting this vulnerability enabled unauthorized access to live conversations, data exfiltration, and manipulation of chatbot responses, including phishing attempts. Google addressed the issue with an initial fix in April 2026 and fully remediated it by June 2026. There is no evidence of exploitation in the wild prior to these patches. ([varonis.com](https://www.varonis.com/blog/rogue-agent-dialogflow-attack?utm_source=openai)) The 'Rogue Agent' incident underscores the security challenges associated with integrating AI into cloud platforms. As AI adoption accelerates, ensuring robust security measures and regular audits becomes imperative to prevent similar vulnerabilities and protect sensitive user data. ([axios.com](https://www.axios.com/2026/07/07/varonis-google-ai-agent-chatbot-security?utm_source=openai))
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports