Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
CISA Adds CVE-2026-39987: Marimo RCE Vulnerability
In April 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-39987 to its Known Exploited Vulnerabilities (KEV) Catalog, highlighting active exploitation of a critical remote code execution vulnerability in Marimo, a reactive Python notebook application. This flaw, present in versions prior to 0.23.0, allows unauthenticated attackers to gain full pseudo-terminal shell access via the /terminal/ws WebSocket endpoint, enabling arbitrary command execution on the host system. The vulnerability arises from the endpoint's failure to enforce authentication, unlike other WebSocket endpoints in the application. Marimo has addressed this issue in version 0.23.0 by implementing proper authentication checks. Organizations using affected versions are urged to update immediately to mitigate potential risks. ([securityvulnerability.io](https://securityvulnerability.io/vulnerability/CVE-2026-39987?utm_source=openai)) The inclusion of CVE-2026-39987 in CISA's KEV Catalog underscores the ongoing threat posed by unpatched vulnerabilities in widely used development tools. This incident highlights the critical need for organizations to maintain up-to-date software and implement robust security measures to protect against unauthorized access and potential data breaches.
4 months ago
Kill Chain
Checkmarx GitHub Repository Data Breach: A Wake-Up Call for CI/CD Security
In March 2026, Checkmarx experienced a significant supply chain attack when threat actors compromised its GitHub repositories, injecting credential-stealing malware into GitHub Actions workflows and Docker images. This breach enabled attackers to harvest sensitive developer credentials and infrastructure secrets. Subsequent investigations revealed that data from Checkmarx's GitHub repository was published on the dark web, though the company maintains that customer data is not stored in these repositories. The incident underscores the critical importance of securing software supply chains against sophisticated attacks targeting development infrastructure. This breach highlights a growing trend of supply chain attacks targeting development tools and repositories, emphasizing the need for organizations to implement robust security measures within their CI/CD pipelines. The incident serves as a stark reminder of the potential cascading effects such compromises can have on downstream users and the broader software ecosystem.
4 months ago
Kill Chain
Navigating the New Era of AI-Driven Cyber Threats
In April 2026, the cybersecurity community faced a significant challenge with the emergence of advanced large language models (LLMs) like Anthropic's Mythos and OpenAI's GPT-5.5. These models enabled threat actors to automate complex cyberattacks, leading to concerns about industrialized, autonomous exploitation across various platforms. Despite these advancements, experts like Ari Herbert-Voss emphasized the continued necessity of human expertise to validate and address the vulnerabilities identified by these AI systems. This incident underscores the evolving threat landscape where AI-driven attacks are becoming more sophisticated and widespread. Organizations must adapt by integrating AI into their defensive strategies while ensuring human oversight to effectively manage and mitigate these emerging threats.
4 months ago
Kill Chain
PhantomCore's Exploitation of TrueConf Vulnerabilities: A Wake-Up Call for Network Security
In September 2025, the pro-Ukrainian hacktivist group PhantomCore exploited a chain of three vulnerabilities in TrueConf video conferencing software to execute remote commands on servers within Russian organizations. This campaign, active since mid-September 2025, allowed attackers to bypass authentication, gain network access, and deploy malicious payloads for reconnaissance, credential harvesting, and lateral movement. The incident underscores the critical importance of promptly patching software vulnerabilities and implementing robust network segmentation. It also highlights the evolving tactics of politically motivated threat actors targeting communication platforms to infiltrate sensitive networks.
4 months ago
Kill Chain
Claude Mythos: Redefining Vulnerability Discovery in the AI Era
In April 2026, Anthropic unveiled Claude Mythos Preview, an advanced AI model capable of autonomously identifying and exploiting thousands of zero-day vulnerabilities across major operating systems and web browsers. This unprecedented capability has raised significant concerns about the rapid acceleration of vulnerability discovery and the challenges organizations face in timely remediation. The model's restricted release under Project Glasswing aims to mitigate potential misuse, yet unauthorized access incidents have already been reported, highlighting the pressing need for robust security measures. The emergence of AI-driven vulnerability discovery tools like Mythos signifies a paradigm shift in cybersecurity, compressing exploit timelines and necessitating a reevaluation of existing defense strategies. Organizations must adapt to this new landscape by enhancing their vulnerability management processes and investing in proactive security measures to keep pace with the evolving threat environment.
4 months ago
Kill Chain
GlassWorm v2 Malware Targets VS Code Extensions in Supply Chain Attack
In April 2026, cybersecurity researchers identified 73 malicious Visual Studio Code (VS Code) extensions on the Open VSX repository, linked to the GlassWorm v2 malware campaign. These extensions, cloned from legitimate ones, initially appeared benign but later delivered malware through updates. Six extensions were confirmed malicious, while others acted as sleeper agents to build trust before deploying harmful payloads. The attackers employed social engineering tactics, such as typosquatting and mimicking legitimate extension icons and descriptions, to deceive developers into installing these compromised extensions. The malware aimed to steal sensitive data, install remote access trojans, and deploy rogue browser extensions to siphon credentials and other information. This incident underscores the evolving nature of supply chain attacks targeting developer environments and the importance of vigilance when installing third-party extensions. The use of sleeper packages and transitive dependencies highlights the need for robust security measures and thorough vetting processes to prevent such infiltrations.
4 months ago
Kill Chain
Robinhood Account Creation Flaw Exploited for Phishing Attacks
In April 2026, threat actors exploited a flaw in Robinhood's account creation process to send phishing emails from the legitimate noreply@robinhood.com address. By embedding malicious HTML into device metadata fields during account registration, attackers generated emails alerting users to 'unrecognized device' logins, prompting them to click on links leading to credential-stealing phishing sites. This method bypassed standard email security checks, making the phishing attempts highly convincing. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/robinhood-account-creation-flaw-abused-to-send-phishing-emails/?utm_source=openai)) This incident underscores the evolving sophistication of phishing tactics, particularly those leveraging legitimate communication channels to deceive users. Organizations must continuously assess and fortify their email security protocols to prevent similar exploits.
4 months ago
Kill Chain
GlassWorm Malware Resurfaces: 73 OpenVSX Sleeper Extensions Compromise Developer Security
In April 2026, the GlassWorm malware campaign resurfaced, targeting the OpenVSX ecosystem with 73 'sleeper' extensions. Initially benign, these extensions were later updated to deliver malicious payloads, compromising developer environments. Six of these extensions have been activated, while the remaining are considered suspicious. This tactic involves cloning legitimate extensions to deceive developers, leading to the theft of sensitive data such as cryptocurrency wallets and credentials. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/glassworm-malware-attacks-return-via-73-openvsx-sleeper-extensions/?utm_source=openai)) This incident underscores the evolving nature of supply chain attacks, highlighting the need for vigilant monitoring of software dependencies. The use of 'sleeper' extensions that activate malicious behavior post-installation represents a sophisticated method to evade initial detection, posing significant risks to software development environments.
4 months ago
Kill Chain
Silk Typhoon Hacker Extradited to US for Cyberespionage
In April 2026, Chinese national Xu Zewei was extradited from Italy to the United States to face charges of cyberespionage. Allegedly operating under the direction of China's Ministry of State Security (MSS) and affiliated with the Silk Typhoon hacking group, Xu is accused of conducting cyber intrusions between February 2020 and June 2021. These operations targeted COVID-19 research organizations and exploited vulnerabilities in Microsoft Exchange Server to gain unauthorized access, deploy malware, and exfiltrate sensitive data. The widespread exploitation impacted thousands of organizations globally before patches were available. This incident underscores the persistent threat posed by state-sponsored cyber actors targeting critical infrastructure and sensitive information. The extradition of Xu Zewei highlights the international cooperation in addressing cyber threats and the ongoing need for robust cybersecurity measures to protect against sophisticated espionage campaigns.
4 months ago
Kill Chain
Supply Chain Attack: 'elementary-data' Package Compromised to Deliver Infostealer
In April 2026, the popular Python package 'elementary-data' (version 0.23.3) was compromised through a GitHub Actions script injection vulnerability. Attackers exploited this flaw to execute malicious code, leading to the unauthorized publication of a backdoored package on PyPI and a malicious Docker image. The compromised package, downloaded over 1.1 million times monthly, contained a secrets stealer targeting SSH keys, cloud credentials, and cryptocurrency wallets. Users who installed this version were advised to rotate all exposed credentials and restore their environments from a known safe point. This incident underscores the critical need for secure CI/CD pipelines and vigilant monitoring of open-source dependencies to prevent supply chain attacks.
4 months ago
Kill Chain
Anthropic's Claude Mythos AI Model Unveils Thousands of Zero-Day Vulnerabilities
In April 2026, Anthropic unveiled Claude Mythos Preview, an advanced AI model capable of autonomously identifying and exploiting zero-day vulnerabilities across major operating systems and web browsers. This model discovered thousands of high-severity vulnerabilities, including a 27-year-old bug in OpenBSD, and demonstrated the ability to chain multiple flaws to bypass security mechanisms. Due to the potential risks associated with its capabilities, Anthropic restricted access to Mythos, providing it only to select industry partners under Project Glasswing to allow for remediation before broader release. The emergence of AI models like Claude Mythos signifies a paradigm shift in cybersecurity, where the speed and scale of vulnerability discovery and exploitation are dramatically increased. This development underscores the urgent need for organizations to enhance their defensive strategies, prioritize rapid patch management, and adopt AI-driven security solutions to keep pace with evolving threats.
4 months ago
Kill Chain
Analyzing GitHub's March 2026 RCE Vulnerability (CVE-2026-3854)
In March 2026, GitHub identified a critical remote code execution (RCE) vulnerability (CVE-2026-3854) affecting its platforms, including GitHub.com and GitHub Enterprise Server. The flaw allowed users with push access to execute arbitrary commands on the server during a git push operation by exploiting unsanitized push options. GitHub promptly validated the issue, deployed a fix within two hours, and confirmed no evidence of exploitation. This incident underscores the importance of rigorous input sanitization and rapid response mechanisms in mitigating supply chain vulnerabilities. As software supply chains grow increasingly complex, organizations must prioritize proactive security measures to prevent similar threats.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports