Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
CISA Adds CVE-2026-48907 to Known Exploited Vulnerabilities Catalog
In June 2026, a critical vulnerability identified as CVE-2026-48907 was discovered in the Joomla Content Editor (JCE) extension, allowing unauthenticated attackers to create new editor profiles and upload arbitrary PHP code, leading to remote code execution. This flaw affects JCE versions prior to 2.9.99.5. The Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on June 16, 2026, following evidence of active exploitation. Joomla released patches on June 3 and June 6, 2026, to address this issue. ([securityweek.com](https://www.securityweek.com/joomla-litespeed-vulnerabilities-exploited-in-attacks/?utm_source=openai)) The active exploitation of CVE-2026-48907 underscores the persistent threat posed by web application vulnerabilities, particularly in widely used content management systems like Joomla. Organizations are urged to promptly apply the latest security updates to mitigate potential risks associated with this vulnerability.
3 months ago
Kill Chain
CISA Issues Warning on Actively Exploited Joomla JCE Vulnerability
In June 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical vulnerability, CVE-2026-48907, affecting the Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities catalog. This flaw, present in JCE versions 1.0.0 through 2.9.99.4, allows unauthenticated users to create new editor profiles, enabling the upload and execution of arbitrary PHP code on the server. The vulnerability has been actively exploited, with attackers leveraging it to gain unauthorized access and control over affected Joomla installations. The active exploitation of this vulnerability underscores the persistent threat posed by improper access controls in widely used content management systems. Organizations utilizing Joomla with the JCE extension are urged to update to version 2.9.99.5 or later to mitigate this risk. Additionally, administrators should audit their systems for unauthorized editor profiles and monitor server logs for suspicious activity to prevent potential breaches.
3 months ago
Kill Chain
Mastra npm Supply Chain Attack: 144 Packages Compromised
In June 2026, a significant supply chain attack targeted the Mastra npm ecosystem, compromising 144 packages associated with the '@mastra' namespace. The attack was initiated through the hijacking of a former contributor's npm account, 'ehindero'. The attackers introduced a malicious dependency named 'easy-day-js', which masqueraded as the legitimate 'dayjs' library. Initially, 'easy-day-js' appeared benign, but subsequent versions contained obfuscated post-install scripts designed to exfiltrate sensitive information from developers' systems. This incident underscores the vulnerabilities inherent in open-source software supply chains, particularly when trusted contributor accounts are compromised. The Mastra framework, widely used for building AI applications, saw its core components, such as '@mastra/core', affected, amplifying the potential impact on downstream projects and organizations. The attack highlights the critical need for robust security measures in package management and dependency verification processes. The increasing frequency of such supply chain attacks emphasizes the urgency for the developer community to adopt stringent security practices, including regular audits of dependencies, implementation of multi-factor authentication for contributor accounts, and continuous monitoring for anomalous activities within software ecosystems.
3 months ago
Kill Chain
Malicious JetBrains Plugins Compromise AI API Keys in 2026
In June 2026, cybersecurity researchers identified a coordinated malware campaign involving at least 15 malicious plugins on the JetBrains Marketplace. These plugins, masquerading as AI coding assistants built on DeepSeek and other large language models, were designed to exfiltrate artificial intelligence (AI) provider keys. The plugins offered functionalities such as chat, commit messages, code review, bug finding, and unit tests, thereby enticing developers to install them. Once installed, the plugins covertly transmitted sensitive API keys to attacker-controlled servers, potentially compromising the security of AI-driven applications and services. This incident underscores a growing trend where threat actors exploit the trust in developer tools and marketplaces to distribute malicious software. The increasing integration of AI into development workflows makes such platforms attractive targets. Organizations must remain vigilant, ensuring the integrity of the tools they incorporate and regularly auditing their development environments to prevent unauthorized access and data exfiltration.
3 months ago
Kill Chain
Critical cPanel Plugin Vulnerability (CVE-2026-48172) Actively Exploited
In May 2026, a critical privilege escalation vulnerability (CVE-2026-48172) was discovered in the LiteSpeed User-End cPanel Plugin versions prior to 2.4.5. This flaw allows authenticated cPanel users to execute arbitrary scripts with root privileges by exploiting the 'lsws.redisAble' function. The vulnerability has been actively exploited in the wild, leading to full system compromises on affected shared hosting servers. LiteSpeed released patches in May 2026, urging users to update to version 2.4.7 or later to mitigate the risk. The active exploitation of this vulnerability underscores the persistent threat posed by privilege escalation flaws in widely used web hosting platforms. Organizations must prioritize timely patching and implement robust monitoring to detect and prevent unauthorized access, especially in shared hosting environments where a single compromised account can jeopardize the entire server.
3 months ago
Kill Chain
GhostTree Attack: Exploiting NTFS Junctions to Evade Detection
In May 2026, Varonis Threat Labs identified a novel evasion technique named 'GhostTree' that exploits NTFS junctions in Windows systems. By creating recursive directory loops, attackers can generate an effectively infinite number of file paths, causing Endpoint Detection and Response (EDR) tools to hang during recursive scans. This manipulation allows malicious files to remain undetected, as the scanning process becomes trapped in the loop and fails to complete. The technique requires only standard user permissions, making it accessible without administrative rights. ([varonis.com](https://www.varonis.com/blog/ghosttree-ntfs-trick?utm_source=openai)) The discovery of GhostTree underscores the evolving sophistication of malware evasion tactics. As attackers increasingly exploit legitimate system features to bypass security measures, organizations must enhance their detection capabilities and adopt comprehensive monitoring strategies to identify and mitigate such advanced threats.
3 months ago
Kill Chain
Malicious JetBrains Plugins Compromise Developer API Keys
In June 2026, Aikido Security uncovered a coordinated malware campaign involving at least 15 malicious plugins on the JetBrains Marketplace. These plugins, masquerading as AI coding assistants and Git utilities, were designed to steal AI API keys from developers. Upon users entering their API keys and clicking 'Apply,' the credentials were transmitted to a hardcoded server controlled by the attackers. The plugins, published under seven vendor accounts since October 2025, amassed nearly 70,000 installations. Notably, some plugins offered a paid tier, potentially redistributing stolen API keys to paying users. This incident underscores the escalating threat of supply chain attacks targeting developer ecosystems. As AI-powered tools become integral to software development, malicious actors are increasingly exploiting trusted platforms to distribute credential-stealing malware, highlighting the need for enhanced vigilance and security measures within developer communities.
3 months ago
Kill Chain
Malware Campaign Targets Steam Users via Wallpaper Engine
In June 2026, cybersecurity researchers uncovered a campaign where threat actors exploited Steam Workshop and the Wallpaper Engine application to distribute malware. Malicious actors uploaded infected wallpaper packages to Steam Workshop, which, when installed via Wallpaper Engine, executed payloads leading to Steam account hijacking, system backdoors, or cryptomining operations. This campaign primarily targeted users in China and Russia but also affected individuals in Singapore, Hong Kong, Germany, Vietnam, India, and Canada. The malware was often concealed within password-protected archives or bundled directly in the wallpaper packages, executing automatically upon installation. This incident underscores the evolving tactics of cybercriminals who leverage trusted platforms and user-generated content to disseminate malware. The exploitation of application wallpapers highlights the need for enhanced scrutiny of community-driven content and the importance of robust security measures to detect and prevent such sophisticated attacks.
3 months ago
Kill Chain
Malicious Wallpapers on Steam Workshop Compromise User Accounts
In late 2025, a significant malware campaign was identified targeting users of Steam's Workshop, particularly through the Wallpaper Engine application. Attackers embedded malicious code within shared wallpaper packages, exploiting the application's feature that allows users to set animated wallpapers. Upon installation, these compromised wallpapers deployed malware capable of hijacking Steam accounts, installing backdoors, or deploying cryptocurrency miners. The primary targets were gamers in China and Russia, with additional victims in Singapore, Hong Kong, Germany, Vietnam, India, and Canada. This campaign underscores the vulnerabilities inherent in user-generated content platforms and the need for vigilant security practices. The incident highlights a growing trend where cybercriminals exploit trusted platforms to distribute malware, leveraging user-generated content as a vector. This approach not only increases the reach of malicious campaigns but also complicates detection and mitigation efforts. As user-generated content continues to proliferate across various platforms, the importance of robust security measures and user awareness becomes increasingly critical.
3 months ago
Kill Chain
Critical Vulnerability in Google Vertex AI SDK: 'Pickle in the Middle' Attack Exposed
In March 2026, a critical vulnerability was discovered in the Google Cloud Vertex AI SDK for Python, allowing attackers to hijack machine learning model uploads via a technique known as 'bucket squatting.' By preemptively creating Cloud Storage buckets with predictable names derived from a victim's project ID and region, attackers could intercept model uploads and execute arbitrary code within Google's serving infrastructure. This flaw, identified by Palo Alto Networks Unit 42 and termed 'Pickle in the Middle,' was patched by Google in April 2026 with the release of SDK version 1.148.0. Organizations using affected versions are urged to update immediately to mitigate potential risks. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/?utm_source=openai)) This incident underscores the critical importance of securing cloud-based machine learning workflows against supply chain attacks. As AI adoption accelerates, ensuring the integrity of model deployment processes becomes paramount to prevent unauthorized code execution and data breaches.
3 months ago
Kill Chain
New Malware Loaders Deployed in ClickFix Campaigns via Fake Updates
In June 2026, cybersecurity researchers identified multiple ClickFix campaigns deploying three new malware loaders: BabaDeda Loader, Lorem Ipsum Loader, and Potemkin. These campaigns utilized fake software update lures to infiltrate systems, primarily targeting the education and financial sectors. The attackers' methods included sophisticated social engineering tactics to deceive users into executing malicious payloads, leading to unauthorized access and potential data exfiltration. This incident underscores a growing trend of threat actors employing novel malware delivery mechanisms and deceptive tactics to compromise organizations. The emergence of these loaders highlights the need for enhanced vigilance and adaptive security measures to counter evolving cyber threats.
3 months ago
Kill Chain
'Lorem Ipsum' Malware Shifts to ClickFix Delivery in 2026
In May 2026, the operators of the 'Lorem Ipsum' malware campaign transitioned from using Trojanized Microsoft Teams installers to employing ClickFix lures hosted on compromised WordPress sites. This shift followed Microsoft's takedown of the Fox Tempest infrastructure, which had previously supplied the attackers with fraudulent Microsoft Trusted Signing certificates. The new delivery method involves fake browser update notifications that prompt users to execute malicious PowerShell commands, leading to the silent installation of the malware. This change significantly broadens the potential victim pool, as any visitor to the compromised sites is now at risk. The 'Lorem Ipsum' campaign is now believed to be linked to the Vice Society ransomware group, also known as Rapid Brigantine or Vanilla Tempest. Vice Society has a history of targeting sectors such as education, healthcare, and manufacturing, employing double extortion tactics by encrypting data and threatening to leak it unless a ransom is paid. The group's ability to rapidly adapt its delivery methods in response to disruptions underscores the evolving nature of cyber threats and the importance of robust, adaptive cybersecurity measures.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports