Industry Category

Computer Software/Engineering

Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.

2229 threat reports
Page 63 of 186

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Computer Software/Engineering Threat Reports

Showing 745756 / 2229 reports
Understanding the 'SearchLeak' Vulnerability in Microsoft 365 Copilot (CVE-2026-42824)
Impact· HIGH

Understanding the 'SearchLeak' Vulnerability in Microsoft 365 Copilot (CVE-2026-42824)

In June 2026, a critical vulnerability known as 'SearchLeak' (CVE-2026-42824) was discovered in Microsoft 365 Copilot. This flaw allowed attackers to craft malicious links that, when accessed by a user, could exfiltrate sensitive data such as emails, meeting notes, and documents from OneDrive and SharePoint. The attack exploited a parameter-to-prompt injection (P2P) technique, enabling unauthorized data disclosure over the network. Microsoft promptly addressed the issue by releasing a patch to mitigate the vulnerability. The 'SearchLeak' incident underscores the evolving nature of AI-driven cyber threats, particularly those targeting large language model (LLM) systems integrated into enterprise environments. It highlights the necessity for organizations to implement robust security measures, including prompt isolation and output sanitization, to protect against sophisticated prompt-injection attacks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation
Impact· HIGH

CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation

In May 2026, a critical vulnerability (CVE-2026-54420) was identified in the LiteSpeed cPanel Plugin versions prior to 2.4.8, allowing users with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux or CageFS. This flaw, resulting from improper handling of symbolic links, was actively exploited in the wild, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities catalog on June 15, 2026. Administrators were urged to upgrade to LiteSpeed WHM Plugin v5.3.2.1 or later to mitigate the risk. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-54420?utm_source=openai)) The incident underscores the persistent threat posed by privilege escalation vulnerabilities in widely used web hosting environments. It highlights the importance of timely patch management and vigilant monitoring to prevent unauthorized access and potential system compromise.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ShinyHunters Breach Infinite Campus: 137,000 School Staff Accounts Exposed
Impact· MEDIUM

ShinyHunters Breach Infinite Campus: 137,000 School Staff Accounts Exposed

In March 2026, the ShinyHunters extortion group infiltrated Infinite Campus's Salesforce instance, compromising personal information of over 137,000 school staff members. The stolen data included names, email addresses, phone numbers, physical addresses, and support tickets. Infinite Campus, a leading EdTech provider serving over 3,200 school districts across the United States, confirmed the breach but stated that the majority of the exposed information was publicly available directory data. This incident underscores the escalating trend of cybercriminals targeting educational institutions and their service providers. The breach highlights the critical need for robust security measures and vigilant monitoring of third-party platforms to safeguard sensitive information in the education sector.

3 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
OptinMonster WordPress Plugin Hacked in CDN Supply-Chain Attack
Impact· HIGH

OptinMonster WordPress Plugin Hacked in CDN Supply-Chain Attack

In June 2026, a supply-chain attack targeted WordPress plugins OptinMonster, TrustPulse, and PushEngage, all managed by Awesome Motive. Attackers exploited a vulnerability in the UpdraftPlus plugin to access Awesome Motive's marketing server, obtaining credentials for their content delivery network (CDN). They then injected malicious JavaScript into CDN-hosted files, which, when loaded by websites using these plugins, created rogue administrator accounts and installed backdoor plugins, granting full control over the compromised sites. This incident underscores the critical need for robust security measures in third-party integrations and highlights the growing trend of supply-chain attacks targeting widely-used software components.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
North Korean Hackers Exploit Developer Tools in Sophisticated Phishing Campaign
Impact· HIGH

North Korean Hackers Exploit Developer Tools in Sophisticated Phishing Campaign

In early 2026, a North Korean state-sponsored threat actor, identified as UNK_DeadDrop, launched a sophisticated phishing campaign targeting software developers across nearly 100 organizations, primarily in the United States. The attackers sent over 250 emails between April and May, masquerading as recruitment offers or code review requests. These emails directed recipients to clone malicious GitHub or GitLab repositories, which, when opened in code editors like Visual Studio Code, executed embedded malware. This approach enabled the attackers to steal cryptocurrency wallets and sensitive developer credentials. ([theregister.com](https://www.theregister.com/security/2026/06/08/suspected-norks-send-250-fake-dev-job-pitches-to-steal-crypto/5252526?utm_source=openai)) This incident underscores a significant evolution in cyberattack methodologies, where adversaries exploit trusted developer tools and workflows to deliver malware. The campaign's scale and sophistication highlight the increasing targeting of the tech industry by state-sponsored actors, emphasizing the need for heightened vigilance and robust security measures within development environments. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical LiteLLM Vulnerabilities Expose AI Gateways to Unauthenticated RCE
Impact· HIGH

Critical LiteLLM Vulnerabilities Expose AI Gateways to Unauthenticated RCE

In May 2026, a critical vulnerability chain was discovered in LiteLLM, an open-source AI gateway widely used to interface with over 100 large language model providers. The primary flaw, CVE-2026-42271, is a command injection vulnerability affecting versions 1.74.2 through 1.83.6. This vulnerability allows authenticated users, including those with low-privilege internal-user keys, to execute arbitrary commands on the host system by exploiting two Model Context Protocol (MCP) test endpoints. When combined with CVE-2026-48710, an authentication bypass in the Starlette web framework, attackers can achieve unauthenticated remote code execution, granting them full control over the server. This chain of vulnerabilities exposes sensitive API keys and secrets stored by the proxy, potentially compromising connected AI systems and enabling lateral movement within enterprise networks. The active exploitation of these vulnerabilities underscores the increasing targeting of AI gateway infrastructures by threat actors. Organizations relying on LiteLLM are urged to upgrade to version 1.83.7 or later, which addresses these issues by implementing stricter authorization controls and updating dependencies. Additionally, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-42271 to its Known Exploited Vulnerabilities catalog, emphasizing the urgency for immediate remediation to prevent potential breaches and data exfiltration.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
U.S. Government Restricts Access to Anthropic's Advanced AI Models
Impact· HIGH

U.S. Government Restricts Access to Anthropic's Advanced AI Models

In June 2026, the U.S. government issued an export control directive requiring Anthropic to suspend access to its advanced AI models, Fable 5 and Mythos 5, for all foreign nationals, including those within the United States. This action was taken due to national security concerns over potential vulnerabilities that could allow the models to be exploited for identifying software flaws. As a result, Anthropic disabled these models for all users to ensure compliance. This unprecedented move underscores the growing tension between technological advancement and national security, highlighting the challenges in regulating AI technologies. The directive has sparked international debate over the balance between innovation and security, with European leaders expressing concerns about overreliance on American AI providers and advocating for greater technological sovereignty.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Massive WordPress Plugin Supply Chain Attack Exposes Over 1.2 Million Sites
Impact· HIGH

Massive WordPress Plugin Supply Chain Attack Exposes Over 1.2 Million Sites

In June 2026, a sophisticated supply chain attack targeted WordPress sites utilizing the PushEngage, OptinMonster, and TrustPulse plugins. Malicious actors tampered with JavaScript files served by these plugins, embedding code that, when loaded by a logged-in administrator, created unauthorized admin accounts and installed concealed backdoors. This breach potentially compromised over 1.2 million websites, granting attackers full control to exfiltrate data, deploy malware, or manipulate site content. The attack was active for varying durations across the plugins, with OptinMonster and TrustPulse affected for approximately 25 minutes on June 12, while PushEngage's exposure extended over several hours into June 14. This incident underscores the escalating threat of supply chain attacks within the WordPress ecosystem, highlighting the critical need for vigilant monitoring of third-party plugins and the implementation of robust security measures to detect and mitigate unauthorized code modifications.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Unveiling the Threat: 152 Malicious Chrome Extensions Compromise User Security
Impact· MEDIUM

Unveiling the Threat: 152 Malicious Chrome Extensions Compromise User Security

In June 2026, cybersecurity researchers uncovered a network of 152 Google Chrome extensions, primarily offering live wallpaper functionalities, that were distributing potentially unwanted programs (PUPs). These extensions, spanning 38 separate Chrome Web Store publisher accounts and three brand backends—tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com—had collectively amassed 105,000 installations. Despite claiming not to collect user data, the extensions' privacy policies revealed the logging of IP addresses, ISPs, click counts, and referrers, with data shared with Google AdSense, DoubleClick, and third-party ad partners. Additionally, some extensions manipulated browser behavior to simulate organic search traffic, thereby fabricating the origin of their own traffic. This incident underscores the persistent threat posed by malicious browser extensions, which can compromise user privacy and security. The deceptive practices employed highlight the need for vigilant monitoring of browser add-ons and the importance of scrutinizing privacy policies, even for seemingly benign applications.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Google Patches Actively Exploited Chrome Zero-Day Vulnerability CVE-2026-11645
Impact· HIGH

Google Patches Actively Exploited Chrome Zero-Day Vulnerability CVE-2026-11645

In June 2026, Google addressed a high-severity zero-day vulnerability, CVE-2026-11645, in its Chrome browser. This flaw, an out-of-bounds read and write issue in the V8 JavaScript engine, allowed remote attackers to execute arbitrary code via crafted HTML pages. The vulnerability was actively exploited in the wild, prompting Google to release an emergency update to mitigate the risk. Users were urged to update to version 149.0.7827.103 to secure their systems. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/06/09/google-chrome-zero-day-cve-2026-11645/?utm_source=openai)) This incident underscores the persistent targeting of widely used software by threat actors and highlights the critical importance of timely software updates. The exploitation of such vulnerabilities can lead to significant data breaches and system compromises, emphasizing the need for robust cybersecurity practices.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Evil MSI Background: Unveiling the 2026 Phishing Campaign
Impact· MEDIUM

Evil MSI Background: Unveiling the 2026 Phishing Campaign

In June 2026, a sophisticated phishing campaign emerged, leveraging WeTransfer links to distribute malicious JavaScript files. These scripts, upon execution, utilized obfuscation techniques to decode and run PowerShell commands, which subsequently downloaded additional payloads, including a .NET DLL designed to manipulate Windows Task Scheduler. This method facilitated the execution of further malicious activities, potentially leading to persistent system compromise. The campaign notably exploited legitimate cloud services like Cloudflare Workers and R2 storage to host and distribute its malicious components, thereby enhancing its stealth and effectiveness. This incident underscores a growing trend where threat actors increasingly abuse trusted cloud platforms to host and disseminate malware, complicating detection and mitigation efforts. The use of obfuscated scripts and legitimate services highlights the evolving sophistication of phishing attacks, emphasizing the need for enhanced vigilance and advanced security measures to detect and prevent such threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Anthropic's AI Models Disabled Amid National Security Concerns
Impact· HIGH

Anthropic's AI Models Disabled Amid National Security Concerns

In June 2026, the U.S. government ordered Anthropic to suspend foreign access to its advanced AI models, Fable 5 and Mythos 5, citing national security concerns over potential 'jailbreaking' vulnerabilities that could bypass safety restrictions. This directive led Anthropic to disable these models entirely to comply with export controls, affecting both foreign nationals and certain employees. The incident underscores the challenges in balancing AI innovation with security, as similar capabilities exist in other publicly accessible models. The government's stringent response highlights the growing scrutiny over AI technologies and their potential misuse, emphasizing the need for robust security measures and regulatory frameworks in the rapidly evolving AI landscape.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports