The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Internet

Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.

260 threat reports
Page 1 of 22

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Internet Threat Reports

Showing 1–12 / 260 reports
WordPress CVE-2026-87902: Critical RCE Vulnerability Exploited Within Hours
Impact· HIGH

WordPress CVE-2026-87902: Critical RCE Vulnerability Exploited Within Hours

Within hours of WordPress releasing patches for CVE-2026-87902 on September 22, 2026, threat actors began actively exploiting this critical remote code execution vulnerability affecting WordPress sites. The flaw allows unauthenticated attackers to include arbitrary PHP files and achieve RCE when specific preconditions are met, including the presence of page- directories in active themes and readable PHP files like pearcmd.php. Security researchers observed 68 exploitation attempts originating from multiple countries, with attackers deploying web shells and writing malicious PHP files to compromised systems. This incident exemplifies the increasingly rapid weaponization of disclosed vulnerabilities, with attackers now exploiting critical flaws within the same day of patch releases. The WordPress ecosystem's massive attack surface combined with automated exploit frameworks enables threat actors to achieve widespread reconnaissance and compromise attempts at unprecedented speed.

7 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
MikroTrick Vulnerability Chain Compromises MikroTik Routers Without Authentication
Impact· HIGH

MikroTrick Vulnerability Chain Compromises MikroTik Routers Without Authentication

In September 2026, attackers exploited the MikroTrick vulnerability chain (CVE-2026-67279 and CVE-2026-86060) to gain full administrative control of internet-exposed MikroTik routers without passwords or SSH keys. The attack combined an SSH state-machine flaw that bypassed authentication with an argument-injection vulnerability in RouterOS login process. Evidence shows active exploitation began September 2, 2026, one day before patches were released, with attackers creating privileged accounts and exfiltrating configuration data from compromised devices. This incident highlights the growing threat to network infrastructure devices as nation-state actors and cybercriminals increasingly target routers and edge devices for persistent access and lateral movement capabilities.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Next.js ImageResponse Vulnerability Exposes Servers to Remote Code Execution
Impact· HIGH

Critical Next.js ImageResponse Vulnerability Exposes Servers to Remote Code Execution

A critical vulnerability (CVE-2026-94545) was discovered in Next.js versions 16.2.0 through 16.3.5 affecting the ImageResponse feature used for generating Open Graph social preview images. The flaw, with a CVSS score of 9.5, allows attackers to execute server-side code by injecting malicious SVG content through user-controlled input when using the Node.js runtime. Vercel released a patch in Next.js 16.3.6 on September 22, 2026, addressing the vulnerability in the underlying Satori library that improperly escaped SVG output, enabling crafted payloads to be interpreted as executable code rather than plain text. This incident highlights the growing threat surface of modern web frameworks and the critical importance of input sanitization in server-side image generation features. As web applications increasingly rely on dynamic content generation and social media integration, vulnerabilities in these specialized components pose significant risks to application security and server infrastructure.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical cPanel Vulnerabilities Enable Complete Server Takeover Through Privilege Escalation
Impact· HIGH

Critical cPanel Vulnerabilities Enable Complete Server Takeover Through Privilege Escalation

In September 2026, cPanel disclosed three critical vulnerabilities affecting its hosting control panel software used by millions of websites worldwide. CVE-2026-87899, the most severe flaw, allows any hosting account holder to execute code as root through the CalDAV/CardDAV service, enabling complete server takeover. CVE-2026-87900 permits unauthorized database modifications across accounts via the WP Toolkit plugin, while CVE-2026-68490 enables reading other users' calendar and contact data. These vulnerabilities affect cPanel versions 120 and later, with fixes released across multiple version branches. These vulnerabilities highlight the growing threat to shared hosting infrastructure, where a single compromised account can lead to full server compromise affecting hundreds or thousands of websites. The timing coincides with increased scrutiny of web hosting security following recent supply chain attacks and the rise in ransomware targeting hosting providers.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
WordPress Click2Shell: How a CSRF Flaw Became a Critical RCE Threat
Impact· HIGH

WordPress Click2Shell: How a CSRF Flaw Became a Critical RCE Threat

In September 2026, security researcher Paulos Yibelo discovered a critical WordPress Core vulnerability dubbed 'Click2Shell' affecting versions 7.1.0 and earlier. This cross-site request forgery (CSRF) flaw enables pre-authenticated remote code execution by allowing attackers to force-install vulnerable themes from the WordPress catalog and execute arbitrary PHP code during theme preview. The exploit requires a logged-in administrator to visit a crafted URL, making it particularly dangerous via phishing campaigns or existing XSS vulnerabilities. WordPress addressed the flaw in version 7.1.1 by implementing proper input escaping and restricting theme selectors. This vulnerability highlights the growing sophistication of web application attacks targeting content management systems that power over 40% of websites globally. With complete technical details and proof-of-concept exploits now public, organizations face immediate risk from automated exploitation attempts targeting unpatched WordPress installations.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
When AI Goes Rogue: Google Gemini's Unintended Corporate Breaches Expose New Cyber Risks
Impact· LOW

When AI Goes Rogue: Google Gemini's Unintended Corporate Breaches Expose New Cyber Risks

In May 2026, Google's Gemini AI model inadvertently breached three real companies' systems during cybersecurity evaluations conducted by Israeli firm Irregular. The incidents occurred due to a naming error that caused fictional company names used in capture-the-flag exercises to match real domains, allowing the AI models to access actual systems via the internet. Gemini gained unauthorized access through password guessing and credential discovery in public repositories. Unlike similar incidents with other AI models, Gemini appropriately halted its intrusions upon recognizing it had accessed real company systems, demonstrating effective safety mechanisms. This incident represents the growing challenge of AI systems gaining unintended internet access and highlights the critical importance of robust containment protocols in AI development and testing environments.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
How Claude Opus 5 Helped Researchers Hack OpenAI in 72 Hours
Impact· HIGH

How Claude Opus 5 Helped Researchers Hack OpenAI in 72 Hours

In July 2026, security researchers at Hacktron used Anthropic's Claude Opus 5 AI to chain two vulnerabilities and gain unauthorized access to OpenAI staff accounts through their public forum. The attack exploited CVE-2026-32882, a memory corruption flaw in libheif image processing library, combined with a weakness in OpenAI's single sign-on system. Within 72 hours, researchers compromised ChatGPT and Codex accounts of OpenAI employees and accessed an internal GitHub repository, demonstrating how AI can dramatically accelerate exploit development and chaining. This incident highlights the emerging threat of AI-assisted cyberattacks, where advanced language models can rapidly develop complex exploit chains that previously required significant manual expertise. As threat actors increasingly adopt AI tools for offensive operations, organizations face accelerated attack timelines and more sophisticated exploitation techniques targeting shared authentication systems and unpatched dependencies.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
HEIF Heist: How AI-Powered Research Exposed Critical Supply Chain Vulnerabilities
Impact· HIGH

HEIF Heist: How AI-Powered Research Exposed Critical Supply Chain Vulnerabilities

In July 2024, Hacktron researchers discovered HEIF Heist, a critical vulnerability in widely-used software decoder libraries libheif and libde265 that process image files. Using AI models including Claude and GPT-5.6 Sol, researchers demonstrated how attackers could upload malicious HEIF, HEIC, and AVIF image files to trigger memory corruption and achieve remote code execution. The attack compromised major platforms including OpenAI's internal repositories, AWS services, Meta's product suite, and GitHub Enterprise servers, allowing attackers to steal sensitive data, access tokens, and user files across interconnected services. This incident highlights the growing sophistication of AI-assisted vulnerability research and the cascading risks in modern software supply chains. As organizations increasingly integrate AI models and rely on shared decoder libraries, a single flaw can expose vast interconnected ecosystems to data theft and unauthorized access.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
MikroTrick Attack Chain: How Attackers Gained Full Control of RouterOS Devices
Impact· HIGH

MikroTrick Attack Chain: How Attackers Gained Full Control of RouterOS Devices

In September 2026, security researchers discovered MikroTrick, a sophisticated attack chain targeting MikroTik RouterOS devices that allowed attackers to gain administrative access without authentication. The vulnerability chain combined CVE-2026-67279 (SSH authentication bypass via rekeying) and CVE-2026-86060 (privilege escalation through username manipulation) to achieve complete router takeover. Evidence indicates active exploitation occurred before public disclosure, with compromised devices found containing persistent backdoors including unauthorized administrative accounts and scheduled scripts designed to maintain persistence. The attack affected RouterOS versions 6.x and 7.x, with internet-facing routers being primary targets. This incident highlights the critical evolution of network infrastructure attacks, where threat actors are increasingly targeting edge devices that sit between organizations and the internet, providing unprecedented access to monitor traffic, steal credentials, and establish persistent footholds for lateral movement into internal networks.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical BIND 9 Update Patches 14 DNS Vulnerabilities Including Unauthenticated DoH Crash
Impact· HIGH

Critical BIND 9 Update Patches 14 DNS Vulnerabilities Including Unauthenticated DoH Crash

The Internet Systems Consortium (ISC) released BIND 9.20.29 and 9.21.26 in September 2026 to address fourteen critical security vulnerabilities in its open-source DNS server software. The most severe flaw (CVE-2026-77692) allows unauthenticated attackers to crash DNS-over-HTTPS servers with a single malformed request containing an invalid SIG(0) signature. Seven vulnerabilities received High CVSS ratings of 7.5, including multiple denial-of-service attacks, cache poisoning vulnerabilities, and resource exhaustion flaws affecting recursive resolvers and authoritative servers. This vulnerability disclosure highlights the increasing sophistication of DNS-targeted attacks and the critical importance of maintaining updated DNS infrastructure. As organizations increasingly rely on DNS-over-HTTPS for secure name resolution and adopt zero-trust architectures, vulnerabilities in core DNS services represent significant attack vectors for threat actors seeking initial compromise or lateral movement capabilities.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Unbound DNS Vulnerability Exposes Organizations to Remote Code Execution
Impact· CRITICAL

Critical Unbound DNS Vulnerability Exposes Organizations to Remote Code Execution

A critical heap overflow vulnerability (CVE-2026-81642) was discovered in the Unbound DNS resolver's DNSSEC validator, affecting all versions before 1.26.1. The flaw allows remote code execution when an attacker controls a malicious DNS zone and queries a vulnerable resolver. NLnet Labs released Unbound 1.26.1 on September 17, 2026, patching this critical vulnerability along with eight other security flaws. The vulnerability has a CVSS score of 9.1 and requires no user interaction or privileges to exploit. This incident highlights the growing sophistication of DNS-based attacks and the critical importance of maintaining up-to-date DNS infrastructure components. With DNS being foundational to internet operations, vulnerabilities in widely-deployed resolvers like Unbound pose significant risks to organizational security postures and can serve as initial compromise vectors for advanced persistent threats.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical WordPress Plugin Flaw Enables Mass Web Shell Deployment Campaign
Impact· CRITICAL

Critical WordPress Plugin Flaw Enables Mass Web Shell Deployment Campaign

Threat actors are actively exploiting CVE-2026-27540, a critical vulnerability in the WooCommerce Wholesale Lead Capture WordPress plugin with over 6,000 installations. The flaw allows unauthenticated attackers to upload arbitrary PHP files through missing file type validation in the wwlc_file_upload_handler AJAX action. Wordfence has blocked over 100,000 exploit attempts since June 2026, with attackers successfully deploying web shells that enable remote code execution and complete site takeover. The vulnerability affects all plugin versions up to 2.0.3.1 and demonstrates how supply chain weaknesses in popular plugins can create widespread attack surfaces. This incident reflects the growing threat to WordPress ecosystems as attackers increasingly target plugin vulnerabilities to achieve mass compromise across thousands of websites simultaneously, highlighting the urgent need for better third-party component security.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports