Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
Shai-Hulud 2.0: Unveiling the 2025 npm Supply Chain Attack
In November 2025, the Shai-Hulud 2.0 supply chain attack emerged as a significant threat to the npm ecosystem. Attackers compromised hundreds of npm packages by injecting malicious preinstall scripts that executed before installation completion. These scripts harvested sensitive data, including credentials and configuration secrets, from developer environments and CI/CD pipelines, exfiltrating them to attacker-controlled repositories. The malware exhibited worm-like behavior, autonomously spreading by publishing malicious versions of accessible packages, thereby propagating across the npm ecosystem. Major projects such as Zapier, Ethereum Name Service (ENS), PostHog, and Postman were affected, with over 25,000 repositories compromised within a few hours. ([blog.checkpoint.com](https://blog.checkpoint.com/research/shai-hulud-2-0-inside-the-second-coming-the-most-aggressive-npm-supply-chain-attack-of-2025/?utm_source=openai)) This incident underscores the escalating sophistication of supply chain attacks targeting open-source ecosystems. The rapid propagation and automation observed in Shai-Hulud 2.0 highlight the urgent need for enhanced security measures in software development pipelines. Organizations must prioritize securing their development environments, implement robust monitoring, and adopt best practices to mitigate the risks associated with such pervasive threats.
3 months ago
Kill Chain
Iranian Hackers Leverage AI and SEO Poisoning in Advanced Cyber Espionage Campaigns
In early 2026, the Iranian state-sponsored threat actor known as Nimbus Manticore (also referred to as Screening Serpens and UNC1549) launched a series of cyber espionage campaigns targeting the aviation and software sectors across the U.S., Europe, and the Middle East. These operations utilized sophisticated techniques, including career-themed phishing lures and search engine optimization (SEO) poisoning, to distribute newly developed backdoors named MiniFast and an updated version of MiniJunk (MiniJunk V2). The campaigns involved impersonating legitimate organizations to deceive employees into downloading malicious software, leading to unauthorized access and potential data exfiltration. Notably, the MiniFast backdoor exhibited characteristics suggesting it was developed with assistance from artificial intelligence, indicating an evolution in the threat actor's capabilities. ([thehackernews.com](https://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.html?utm_source=openai)) This incident underscores a significant shift in cyber threat tactics, with state-sponsored actors increasingly leveraging AI in malware development and employing SEO poisoning to broaden their attack vectors. Organizations must remain vigilant against such evolving threats by enhancing their cybersecurity measures and educating employees on recognizing sophisticated phishing and social engineering tactics.
3 months ago
Kill Chain
Cybercriminals Exploit Claude AI Popularity to Distribute Malware
In early 2026, cybercriminals launched a sophisticated campaign targeting users seeking to download Anthropic's Claude AI tool. By creating fraudulent websites that closely mimicked the official Claude download pages, attackers distributed trojanized installers. These malicious installers appeared legitimate but secretly deployed malware, such as PlugX and ACR Stealer, granting attackers remote access to victims' systems and enabling the theft of sensitive information, including credentials and financial data. The campaign exploited users' trust in search engine results and official-looking websites, leading to widespread infections across both Windows and macOS platforms. This incident underscores a growing trend where threat actors leverage the popularity of AI tools to execute social engineering attacks. The use of fake installation guides and malicious advertisements highlights the need for heightened vigilance among users and organizations. As AI tools become more integrated into daily operations, ensuring the authenticity of download sources and implementing robust cybersecurity measures are imperative to prevent similar attacks.
3 months ago
Kill Chain
Anthropic's Claude Mythos: Revolutionizing Cybersecurity with AI
In April 2026, Anthropic introduced 'Claude Mythos,' an advanced AI model with exceptional capabilities in identifying and exploiting software vulnerabilities. The model demonstrated the ability to autonomously develop sophisticated cyberattacks, raising significant concerns about its potential misuse. To mitigate these risks, Anthropic restricted public access to Mythos, collaborating with select partners through Project Glasswing to enhance cybersecurity defenses. ([euronews.com](https://www.euronews.com/next/2026/04/08/why-anthropics-most-powerful-ai-model-mythos-preview-is-too-dangerous-for-public-release?utm_source=openai)) The emergence of AI models like Claude Mythos signifies a paradigm shift in cybersecurity, where AI can both uncover and exploit vulnerabilities at unprecedented speeds. This development underscores the urgent need for robust security measures and proactive strategies to address the dual-use nature of such technologies. ([cfr.org](https://www.cfr.org/articles/six-reasons-claude-mythos-is-an-inflection-point-for-ai-and-global-security?utm_source=openai))
3 months ago
Kill Chain
TrapDoor Supply Chain Attack Compromises npm, PyPI, and Crates.io Ecosystems
In May 2026, a coordinated supply chain attack named 'TrapDoor' targeted the npm, PyPI, and Crates.io ecosystems, distributing credential-stealing malware through over 34 malicious packages across more than 384 versions. The campaign began on May 22, 2026, with attackers publishing these packages in rapid succession. The malware specifically aimed at developers in the cryptocurrency, DeFi, Solana, and AI sectors, seeking to exfiltrate sensitive information such as crypto wallets, SSH keys, cloud credentials, browser data, and environment variables. The attack employed various methods, including postinstall hooks, remote JavaScript payloads executed during package imports, and malicious build.rs scripts, to infiltrate developer environments and establish persistence. ([thehackernews.com](https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks within open-source ecosystems, highlighting the need for enhanced vigilance and security measures among developers and organizations. The sophisticated techniques used in the TrapDoor campaign reflect a broader trend of attackers exploiting trusted software repositories to distribute malware, emphasizing the importance of robust supply chain security practices.
3 months ago
Kill Chain
Ghost CMS Vulnerability Leads to Massive ClickFix Attack Campaign
In May 2026, threat actors exploited a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS, affecting versions 3.24.0 through 6.19.0. This flaw allowed unauthenticated attackers to read arbitrary data from the database, including admin API keys. Utilizing these keys, attackers injected malicious JavaScript into over 700 websites, including those of Harvard University, Oxford University, and DuckDuckGo. The injected scripts facilitated ClickFix attacks, deceiving visitors into executing harmful commands via fake CAPTCHA verification prompts. ([thehackernews.com](https://thehackernews.com/2026/05/ghost-cms-cve-2026-26980-exploited-to.html?utm_source=openai)) This incident underscores the urgency of timely patch management, as the vulnerability had been addressed in version 6.19.1 released in February 2026. The widespread exploitation highlights the evolving sophistication of social engineering tactics and the critical need for organizations to maintain up-to-date security measures to protect their digital assets. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-26980/?utm_source=openai))
3 months ago
Kill Chain
TeamPCP's Supply Chain Attack: A Wake-Up Call for Software Security
In May 2026, the cybercriminal group TeamPCP executed a sophisticated supply chain attack targeting multiple software ecosystems. The campaign involved compromising the Nx Console VS Code extension, leading to the exfiltration of approximately 3,800 internal GitHub repositories. Additionally, TeamPCP trojanized Microsoft's durabletask Python SDK on PyPI and injected malicious code into 639 versions of 323 npm packages within the @antv ecosystem. These attacks resulted in significant credential theft and potential data loss across affected organizations. This incident underscores the escalating threat posed by supply chain attacks, particularly those targeting widely used development tools and libraries. The rapid succession and scale of these compromises highlight the need for enhanced vigilance and security measures within software development and deployment pipelines.
3 months ago
Kill Chain
Laravel Lang Supply Chain Attack: A Wake-Up Call for Open-Source Security
In May 2026, attackers compromised the Laravel Lang GitHub organization by rewriting existing git tags across multiple repositories, including laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. This manipulation redirected developers to malicious commits in attacker-controlled forks, leading to the installation of credential-stealing malware via Composer. The malware targeted sensitive information such as cloud credentials, SSH keys, and browser data, posing significant risks to developers and organizations relying on these packages. This incident underscores the evolving nature of supply chain attacks, highlighting the need for enhanced security measures in software development pipelines. The exploitation of GitHub's tagging system to distribute malware emphasizes the importance of verifying package integrity and monitoring for unusual repository activities to prevent similar breaches.
4 months ago
Kill Chain
Packagist Supply Chain Attack Highlights Cross-Ecosystem Vulnerabilities
In May 2026, a coordinated supply chain attack compromised eight packages on Packagist, the PHP package repository. The attackers inserted malicious code into the `package.json` files of these Composer packages, targeting projects that incorporate JavaScript build tools alongside PHP code. This code executed a post-installation script that downloaded and ran a Linux binary from a GitHub repository, potentially allowing unauthorized access and control over affected systems. The malicious packages have since been removed from Packagist. This incident underscores the evolving tactics of threat actors who exploit cross-ecosystem dependencies to infiltrate software supply chains. Developers and organizations must remain vigilant, ensuring comprehensive security reviews of all dependencies, including those that span multiple programming languages and ecosystems.
4 months ago
Kill Chain
Italy Dismantles CINEMAGOAL Piracy App Exploiting Streaming Services
In May 2026, Italian authorities dismantled the CINEMAGOAL piracy app, which illicitly provided access to streaming platforms like Netflix, Disney+, and Spotify. The app utilized virtual machines to capture valid authentication codes from legitimate subscriptions every three minutes, redistributing them to users. This operation, named 'Tutto Chiaro,' involved 100 searches nationwide, leading to the seizure of materials to identify involved individuals and assess illegal profits. The operators reportedly earned millions of euros through audiovisual piracy and computer fraud, causing an estimated €300 million in damages to the streaming industry. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/legal/italy-disrupts-cinemagoal-piracy-app-that-stole-streaming-auth-codes/?utm_source=openai)) This incident underscores the evolving sophistication of digital piracy methods, highlighting the need for continuous advancements in cybersecurity measures to protect intellectual property. The use of virtual machines and frequent code capturing demonstrates a significant escalation in piracy tactics, posing challenges for content providers and law enforcement agencies.
4 months ago
Kill Chain
Critical Vulnerability in LiteSpeed cPanel Plugin Exploited for Root Access
In May 2026, a critical vulnerability (CVE-2026-48172) was discovered in the LiteSpeed User-End cPanel Plugin versions 2.3 through 2.4.4, allowing attackers to execute arbitrary scripts with root privileges. This flaw, stemming from incorrect privilege assignment in the 'lsws.redisAble' function, has been actively exploited in the wild, posing significant risks to affected systems. LiteSpeed has addressed this issue in version 2.4.5 and recommends immediate updates to mitigate potential threats. ([thehackernews.com](https://thehackernews.com/2026/05/litespeed-cpanel-plugin-cve-2026-48172.html?utm_source=openai)) The exploitation of this vulnerability underscores the persistent threat posed by privilege escalation attacks, emphasizing the need for organizations to maintain rigorous patch management practices. As cyber threats continue to evolve, staying vigilant and promptly addressing known vulnerabilities is crucial to safeguarding system integrity and data security.
4 months ago
Kill Chain
AI Model Identifies Over 10,000 Critical Software Vulnerabilities in One Month
In April 2026, Anthropic launched Project Glasswing, utilizing its advanced AI model, Claude Mythos Preview, to autonomously identify vulnerabilities in critical software. Within a month, the initiative uncovered over 10,000 high- or critical-severity flaws across major operating systems and web browsers. Notably, the AI detected a 27-year-old bug in OpenBSD and a 16-year-old issue in FFmpeg, highlighting its unprecedented detection capabilities. This rapid discovery rate has effectively ended the traditional "patch window," as over 99% of the identified vulnerabilities remain unpatched, posing significant risks to global economies, public safety, and national security. The emergence of AI-driven vulnerability discovery tools like Claude Mythos Preview signifies a paradigm shift in cybersecurity. While these tools enhance defensive capabilities, they also compress the timeline between vulnerability discovery and potential exploitation. Organizations must adapt by implementing resilience-based security models, hardening binaries, and adopting runtime protections to mitigate the risks associated with this accelerated threat landscape.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports