Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Microsoft's Legal Threats Against 'Nightmare Eclipse' Stir Controversy in Cybersecurity Community
In May 2026, a security researcher known as 'Nightmare Eclipse' publicly disclosed multiple zero-day vulnerabilities affecting Microsoft Windows systems, including a critical flaw named 'YellowKey' that bypassed BitLocker encryption on Windows 11. These disclosures were made without prior coordination with Microsoft, leading to immediate public exposure of the vulnerabilities. Microsoft responded by threatening legal action against the researcher, citing potential risks to customer security due to the uncoordinated release of exploit code. This incident has ignited a broader debate within the cybersecurity community regarding the ethics and responsibilities associated with vulnerability disclosure practices. The situation underscores the delicate balance between the need for transparency in security research and the potential risks posed by the immediate public release of unpatched vulnerabilities. It also highlights the importance of effective communication and collaboration between security researchers and software vendors to ensure the timely mitigation of security flaws.
3 months ago
Kill Chain
AI-Driven Vulnerability Discovery: A New Era in Cybersecurity
In May 2026, leading technology firms such as Cisco, Microsoft, and Palo Alto Networks reported a significant surge in the discovery of software vulnerabilities, attributed to the deployment of advanced AI models like Mythos Preview and GPT-5.5-Cyber. These AI systems autonomously identified thousands of critical security flaws across various platforms, including Windows and OpenBSD, at an unprecedented speed and scale. This rapid identification has overwhelmed traditional patch management processes, leaving many vulnerabilities unaddressed and increasing the risk of exploitation by malicious actors. The current landscape underscores the urgent need for a paradigm shift in vulnerability disclosure and remediation strategies. Organizations must adopt proactive system hardening measures, implement automated patch management solutions, and foster coordinated efforts among governments, software vendors, and infrastructure operators to enhance cybersecurity resilience in the face of AI-driven vulnerability discovery.
3 months ago
Kill Chain
Anthropic's Project Glasswing Expands to Strengthen Global Cybersecurity
In April 2026, Anthropic launched Project Glasswing, granting approximately 50 organizations access to its advanced AI model, Claude Mythos Preview, to identify software vulnerabilities. By June 2026, the initiative expanded to include around 150 additional organizations across 15 countries, focusing on critical infrastructure sectors such as power, water, healthcare, communications, and hardware. The model has uncovered over 10,000 high- or critical-severity vulnerabilities, with partners like Cloudflare and Mozilla reporting significant increases in bug discovery rates. The rapid identification of vulnerabilities has shifted the cybersecurity landscape, highlighting challenges in verifying, disclosing, and patching flaws before exploitation. A joint report from the Cloud Security Alliance, the SANS Institute, and OWASP warns that organizations may be overwhelmed by threat actors using AI to exploit vulnerabilities faster than defenders can address them.
3 months ago
Kill Chain
WordPress Malware Campaign Exploits Steam Profiles - 2026
In July 2025, a sophisticated malware campaign was discovered targeting nearly 2,000 WordPress websites. Attackers exploited vulnerabilities to inject malicious code that fetched encoded payloads from comments on Steam Community profiles. These payloads, concealed using invisible Unicode characters, directed the compromised sites to load external JavaScript from malicious domains, ultimately installing backdoors for remote code execution. The campaign's reliance on Steam's platform allowed it to evade traditional detection methods by blending malicious traffic with legitimate communications. This incident underscores the evolving tactics of cybercriminals who leverage trusted platforms to obfuscate their command-and-control infrastructure. The use of invisible Unicode characters for payload encoding highlights the need for advanced detection mechanisms capable of identifying such covert techniques. Organizations must remain vigilant and implement robust security measures to protect against these sophisticated threats.
3 months ago
Kill Chain
Dashlane Users Experience Account Suspensions Amid Brute-Force Attack Attempts
In late May 2026, Dashlane, a prominent password management service, detected a series of brute-force attacks targeting user accounts. These attacks involved repeated login attempts from unfamiliar locations and devices, prompting Dashlane's automated security protocols to temporarily suspend the affected accounts to prevent unauthorized access. The company confirmed that its internal systems remained uncompromised and that the suspensions were precautionary measures to safeguard user data. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/dashlane-password-manager-users-locked-out-by-brute-force-attacks/?utm_source=openai)) This incident underscores the persistent threat of brute-force attacks in the cybersecurity landscape. It highlights the importance of robust security measures, such as multi-factor authentication and vigilant monitoring, to protect user accounts from unauthorized access attempts.
3 months ago
Kill Chain
Red Hat npm Packages Compromised in 2026 Supply Chain Attack
In June 2026, Red Hat's '@redhat-cloud-services' npm namespace was compromised, leading to the distribution of over 30 backdoored packages containing the 'Miasma' malware. This supply chain attack targeted developer credentials, cloud secrets, SSH keys, and CI/CD tokens. The attackers allegedly gained access through a compromised Red Hat employee's GitHub account, injecting malicious code into multiple repositories. Red Hat promptly removed the affected packages and reported no impact on customer or partner environments. This incident underscores the escalating threat of supply chain attacks in the software development ecosystem. The use of sophisticated malware like 'Miasma' highlights the need for enhanced security measures in CI/CD pipelines and vigilant monitoring of open-source dependencies to prevent unauthorized access and data breaches.
3 months ago
Kill Chain
DriveSurge's Massive Exploitation of Websites via ClickFix and FakeUpdates
In June 2026, the threat actor known as DriveSurge orchestrated large-scale malware distribution campaigns by compromising thousands of legitimate websites. Utilizing techniques such as ClickFix and FakeUpdates, DriveSurge redirected unsuspecting visitors to malicious infrastructure. ClickFix deceives users into executing harmful commands under the guise of resolving technical issues, while FakeUpdates presents fraudulent software update prompts to deliver malware payloads. These attacks were facilitated through the use of zTDS, an open-source Traffic Distribution System, enabling DriveSurge to profile victims and select the most effective lure. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hackers-hijack-thousands-of-sites-for-clickfix-and-fakeupdate-attacks/?utm_source=openai)) This incident underscores the evolving sophistication of social engineering tactics employed by cybercriminals. The widespread nature of the campaign highlights the critical need for organizations to implement robust security measures, including regular website audits and user education, to mitigate the risks associated with such deceptive attacks.
3 months ago
Kill Chain
Miasma Attack: Red Hat npm Packages Compromised in June 2026
In June 2026, a sophisticated supply chain attack, dubbed 'Miasma,' compromised over 30 npm packages under the @redhat-cloud-services scope. The attackers infiltrated Red Hat's GitHub Actions OIDC pipeline, injecting a credential-stealing worm into these packages. Upon installation, the malware executed a preinstall script that harvested sensitive information, including GitHub Actions secrets, npm tokens, cloud credentials, Kubernetes tokens, SSH keys, and Git credentials. The stolen data was exfiltrated to attacker-controlled servers, facilitating further propagation of the malware. This incident underscores the escalating threat of supply chain attacks targeting trusted software repositories. The open-sourcing of the Mini Shai-Hulud malware by the cybercriminal group TeamPCP has lowered the barrier for such attacks, enabling a broader range of threat actors to execute similar campaigns. Organizations must enhance their security measures to protect against these evolving threats.
3 months ago
Kill Chain
Investigating Suspicious AI Workflows in Microsoft Entra Agent ID
In May 2026, a security incident was identified involving a Microsoft Entra Agent ID user account named MrRoboto4@ContosoCorp.onmicrosoft.com. This agent user sent a suspicious Teams message containing a potentially malicious link to https://domoarigato.ai/. The message was reported by a human user, prompting an investigation. Analysis revealed that the agent user had been granted extensive permissions, allowing it to perform actions typically reserved for human users, such as sending messages and emails. The agent's activities were executed via the Graph API from an external IP address, highlighting potential security gaps in monitoring and controlling AI-driven workflows within enterprise environments. This incident underscores the growing security challenges posed by AI agents operating autonomously within organizational systems. As enterprises increasingly integrate AI agents to automate tasks, ensuring proper identity management, access controls, and monitoring mechanisms for these non-human entities becomes critical to prevent unauthorized actions and potential breaches.
3 months ago
Kill Chain
Exploiting AI: The 2026 Instagram Account Takeover Incident
In late May 2026, attackers exploited a vulnerability in Meta's AI support assistant to hijack high-profile Instagram accounts, including those of the Obama White House and the Chief Master Sergeant of the U.S. Space Force. By manipulating the AI bot into adding a new email address during the password reset process, they gained unauthorized access and defaced these accounts with pro-Iranian content. Meta responded by deploying an emergency patch to address the flaw. This incident underscores the emerging risks associated with AI-driven customer support systems. As organizations increasingly integrate AI into sensitive processes, ensuring robust security measures and implementing multi-factor authentication (MFA) become imperative to prevent similar exploits.
3 months ago
Kill Chain
Malicious npm Package 'codexui-android' Compromises OpenAI Codex Tokens
In May 2026, a malicious supply chain attack targeted developers using OpenAI Codex through a seemingly legitimate npm package named 'codexui-android'. This package, advertised as a remote web UI for OpenAI Codex, amassed over 29,000 weekly downloads. Approximately a month after its initial release, the package began exfiltrating users' Codex authentication tokens to an attacker-controlled server, granting unauthorized access to developers' accounts. The malicious code was embedded into a functional npm package that had undergone active development, making it particularly insidious. The associated GitHub repository remained clean, further complicating detection. ([thehackernews.com](https://thehackernews.com/2026/06/openai-codex-authentication-tokens.html?utm_source=openai)) This incident underscores the growing sophistication of supply chain attacks, where threat actors leverage trusted development tools to infiltrate systems. The use of a functional and actively developed package to distribute malicious code highlights the need for heightened vigilance in the software development community. Developers are urged to scrutinize third-party packages, even those with established reputations, to mitigate the risk of credential theft and unauthorized access.
3 months ago
Kill Chain
Tennessee Man Indicted for Child Exploitation Linked to Extremist Group '764'
In May 2026, Zachary Sweeney, a 30-year-old from Columbia, Tennessee, was indicted on multiple counts of child sexual exploitation. Sweeney allegedly groomed and coerced minors into producing child sexual abuse material (CSAM), which he distributed and, in some cases, sold. His activities, dating back to at least 2022, included traveling across several states to meet victims in person, where he reportedly drugged, raped, and filmed sexual acts with minors. Sweeney's involvement with the nihilistic violent extremist group '764' underscores the group's exploitation of vulnerable individuals to further their agenda of societal destabilization. ([justice.gov](https://www.justice.gov/usao-mdtn/pr/nashville-man-connected-nihilistic-violent-extremist-nve-group-indicted-sexual?utm_source=openai)) This case highlights the persistent and evolving threat posed by online extremist networks that exploit digital platforms to perpetrate and disseminate CSAM. The intersection of violent extremism and child exploitation necessitates heightened vigilance and coordinated efforts among law enforcement agencies to combat these multifaceted crimes.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports