The Containment Era is here. →Explore

Industry Category

Internet

Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.

207 threat reports
Page 13 of 18

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Internet Threat Reports

Showing 145156 / 207 reports
RondoDox Botnet Leverages React2Shell to Breach Next.js Servers
Impact· high

RondoDox Botnet Leverages React2Shell to Breach Next.js Servers

In early 2024, the RondoDox botnet launched widespread attacks targeting exposed Next.js servers by exploiting a vulnerability known as React2Shell. The threat actors leveraged this exploit to install cryptomining malware, enroll compromised enterprise and IoT devices into their botnet, and facilitate lateral movement across affected networks. The campaign demonstrates advanced threat sophistication, including rapid deployment of botnet payloads and persistent communication over encrypted channels, resulting in operational disruption and the risk of sensitive data exposure for impacted organizations. This incident underscores an uptick in supply chain and application-layer attacks, particularly on modern frameworks like Next.js. With attackers automating exploitation of recently disclosed vulnerabilities, organizations must prioritize patch management and adopt Zero Trust controls to defend against evolving botnet campaigns.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
SmarterMail 2025: Critical Pre-Auth File Upload Flaw Threatens Global Email Servers
Impact· low

SmarterMail 2025: Critical Pre-Auth File Upload Flaw Threatens Global Email Servers

In December 2025, Singapore's Cyber Security Agency (CSA) issued an alert concerning a critical pre-authentication vulnerability (CVE-2025-52691) in SmarterTools SmarterMail email servers. The flaw allows unauthenticated remote attackers to upload arbitrary files to any location on the server, leveraging an unvalidated GUID parameter for path traversal via the '/api/upload' endpoint. An attacker could exploit this for remote code execution, potentially resulting in full compromise of the server, with malicious files executed under system privileges. Although no in-the-wild exploitation has been confirmed, more than 16,000 vulnerable public-facing servers were identified globally. This incident underscores growing risks from exposed infrastructure and rapid exploitation of high-severity application flaws. With threat actors increasingly targeting business-critical communication platforms, organizations face mounting pressure to quickly remediate vulnerabilities and bolster segmentation and detection capabilities in line with zero trust frameworks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Evasive Panda APT Uses DNS Poisoning for Prolonged Espionage: 2022–2024 Campaign
Impact· medium

Evasive Panda APT Uses DNS Poisoning for Prolonged Espionage: 2022–2024 Campaign

Between November 2022 and November 2024, the China-linked Evasive Panda APT group conducted a sophisticated cyber espionage campaign targeting entities in Türkiye, China, and India. The attackers leveraged DNS poisoning techniques to redirect requests for popular software updates (such as SohuVA and Tencent QQ) to attacker-controlled infrastructure. Through adversary-in-the-middle attacks, victims received trojanized loaders, which proceeded to fetch and decrypt highly targeted MgBot backdoors. The attack chain involved supply chain and AitM vectors, advanced encryption and obfuscation methods, and allowed persistent compromise and broad data theft, including keylogging and credential exfiltration. This campaign highlights the growing sophistication of APT operations exploiting core network infrastructure such as DNS to evade perimeter defenses. The increased prevalence of similar DNS-manipulation campaigns and targeted malware delivery emphasizes the urgent need for robust segmentation, encrypted traffic, and thorough network and endpoint visibility.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Evasive Panda: APT Delivers MgBot via DNS Poisoning in Asia (2022–2024)
Impact· medium

Evasive Panda: APT Delivers MgBot via DNS Poisoning in Asia (2022–2024)

Between November 2022 and November 2024, the Evasive Panda APT group executed a sophisticated campaign targeting victims primarily in Türkiye, China, and India. Leveraging adversary-in-the-middle (AitM) techniques and DNS poisoning, the attackers delivered a unique MgBot malware implant through fake software updates and stealthy loaders. The operation employed hybrid encryption, memory injection in signed executables, and evaded traditional defenses to maintain long-term persistence. Multiple new and legacy C2 infrastructures enabled sustained access while attackers tailored payloads based on the victim’s OS. This incident showcases the ongoing evolution of nation-state threat actors, utilizing advanced evasion, supply chain impersonation, and DNS manipulation to bypass security controls. It reflects a broader surge in attacks exploiting trust in software supply chains and underlines the need for continuously adaptive security strategies as actor sophistication grows.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Coupang Suffers Massive 2024 Data Breach: 33.7 Million Users Impacted by Credential Abuse
Impact· high

Coupang Suffers Massive 2024 Data Breach: 33.7 Million Users Impacted by Credential Abuse

In early 2024, Coupang, one of South Korea’s largest e-commerce platforms, suffered a data breach that went undetected for nearly five months, compromising the personal information of approximately 33.7 million users. The attacker, suspected to have leveraged compromised insider credentials, gained unauthorized access to databases containing user details including names, email addresses, and contact information. The breach highlights an extended dwell time during which the threat actor potentially exfiltrated significant data without detection, raising concerns over Coupang’s monitoring and response capabilities. Business impacts include reputational damage, regulatory scrutiny, and increased risk of fraud targeting affected users. This incident is highly relevant as it demonstrates the growing threat of credential and insider abuse, long dwell times, and the necessity for more rigorous data protection practices as regulatory pressure around personal data intensifies worldwide.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
AI Advertising Firm Doublespeed Breached: Over 1,000 Smartphones Compromised in 2025 Attack
Impact· medium

AI Advertising Firm Doublespeed Breached: Over 1,000 Smartphones Compromised in 2025 Attack

In October 2025, AI advertising startup Doublespeed suffered a major security breach when a hacker exploited a vulnerability in the company’s backend systems to gain unauthorized access to its phone farm managing over 1,000 AI-generated social media accounts. The attacker was able to both extract confidential data about undisclosed advertising campaigns and seize remote control of the smartphones used to operate the accounts. This exposure illuminated the company’s covert promotion practices and presented significant risks of both data exfiltration and operational compromise. Despite being notified on October 31, the company had not fully remediated access at the time of reporting, heightening concerns about internal controls and disclosure procedures. The breach underscores growing vulnerabilities in companies that use automation at scale, especially in the context of AI-driven influence operations and digital marketing. It reflects broader industry trends: increasing use of phone farms, sophisticated identity evasion, and regulatory scrutiny around undeclared digital ads, all contributing to a shifting cyber threat landscape.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
React2Shell: How Diverse Exploit Techniques Targeted React Server Components in 2023
Impact· medium

React2Shell: How Diverse Exploit Techniques Targeted React Server Components in 2023

In December 2023, ongoing exploit attempts targeting React Server Components were observed, with attackers leveraging a variant known as 'React2Shell.' The threat actors sent crafted HTTP POST requests containing custom headers and malicious payloads exploiting web application vulnerabilities to execute arbitrary shell commands on compromised systems. Attackers expanded their reach by diversifying target endpoints (e.g., /, /api, /app) as previously vulnerable systems dwindled. The payloads enabled remote code execution, posing a risk of full system compromise and lateral movement across victim networks. The direct business impact includes potential data breach, operational disruptions, compliance failures, and reputational harm for affected organizations. This incident highlights evolving web application exploitation tactics, including the constant adaptation of attackers as defenses improve. The surge in diverse exploit attempts against publicly exposed development components like React reflects broader trends in both sophistication and frequency of web-based threats, stressing the imperative for proactive threat detection and rapid patch management.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SoundCloud 2024 Breach Exposes Member Data and VPN Vulnerabilities
Impact· medium

SoundCloud 2024 Breach Exposes Member Data and VPN Vulnerabilities

In June 2024, SoundCloud experienced a significant security breach where threat actors compromised their infrastructure, resulting in outages and disruption of VPN connectivity. The attackers exfiltrated a database containing users' email addresses and profile information, exposing sensitive member data. The attack led to service interruptions that impacted both staff operations and user access, highlighting vulnerabilities in SoundCloud’s VPN and internal data security protocols. Subsequent investigations revealed that unencrypted network traffic and insufficient segmentation allowed the attackers to move laterally and extract confidential data. This incident exemplifies the growing trend of targeting cloud-based media platforms using sophisticated techniques, including exploiting VPN weaknesses and lateral movement within corporate networks. With regulatory scrutiny increasing around customer data privacy and the persistent rise in credential-driven breaches, organizations face mounting pressure to strengthen east-west security and encrypted network controls.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Parked Domains Weaponized: Inside the 2025 Typosquatting Malvertising Surge
Impact· medium

Parked Domains Weaponized: Inside the 2025 Typosquatting Malvertising Surge

In late 2025, security researchers uncovered that over 90% of parked domains—unused, expired, or misspelled web addresses—were actively redirecting visitors to malicious destinations, including scams, malware, and deceptive subscription offers. Utilizing techniques like device fingerprinting, IP geolocation, and chained redirects, threat actors profited by manipulating the domain parking ecosystem, turning innocuous navigation mistakes into vectors for malware delivery and fraud. The campaign targeted high-profile brands and government offices, often bypassing detection by profiling user access (e.g., residential IPs or VPN use), with some domains weaponized for business email compromise. This incident highlights an alarming shift: parked and typo domains are now a primary malvertising risk, not a minor threat. As domain registration and ad platform policies evolve, attackers rapidly adapt, exploiting weaknesses in digital trust and endpoint security. Organizations must broaden threat detection and policy enforcement to address direct navigation attacks and affiliate-driven malvertising.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ShinyHunters Extort PornHub: 2024 Analytics Breach Exposes Premium Member Data
Impact· high

ShinyHunters Extort PornHub: 2024 Analytics Breach Exposes Premium Member Data

In June 2024, adult content platform PornHub became the target of a significant data breach when the ShinyHunters extortion group claimed to have stolen search and viewing history data linked to the site’s Premium members. Attackers reportedly exploited Mixpanel analytics integrations to exfiltrate sensitive user data, including logs of user activity, then threatened public release unless a ransom was paid. PornHub’s operations and brand reputation face heightened scrutiny, especially given the highly sensitive nature of the data involved, with many users fearing exposure and potential blackmail. This incident underscores the ongoing threats facing organizations that handle sensitive personal data, especially as extortion groups increasingly target user activity logs for leverage. Regulatory and reputational risks are amplified by attackers’ focus on analytics platforms, and similar tactics are expected to proliferate across other high-traffic digital properties in 2024.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
PayPal Subscriptions Abused for Advanced Phishing Campaigns in 2024
Impact· medium

PayPal Subscriptions Abused for Advanced Phishing Campaigns in 2024

In mid-2024, cybercriminals exploited PayPal’s legitimate ‘Subscriptions’ billing feature to send authentic-looking emails with fraudulent purchase notifications. By inserting malicious information into the Customer Service URL field, attackers leveraged PayPal’s trusted platform to bypass spam filters, tricking recipients into believing they had initiated a costly subscription. Victims, startled by these official-looking emails, contacted the provided phone numbers, which connected them to threat actors conducting social engineering attacks, potentially resulting in credential theft or financial loss. This incident highlights a growing trend of attackers abusing trusted platforms and supply chain features to execute highly persuasive phishing campaigns. Increased reliance on platform-generated transactional emails, coupled with social engineering, presents new security and compliance challenges for organizations and consumers alike.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
React2Shell Exploit Wave Exposes Web App Security Gaps in 2025
Impact· high

React2Shell Exploit Wave Exposes Web App Security Gaps in 2025

In December 2025, the critical React2Shell (CVE-2025-55182) vulnerability was actively exploited following its public disclosure. Attackers leveraged unsafe deserialization in React Server Components, impacting frameworks including React and Next.js. Proof-of-concept exploits rapidly spread online, with some functional variants enabling remote code execution. Exploit activity was observed from China-nexus threat groups and opportunistic cybercriminals, resulting in widespread targeting of vulnerable systems with cryptominers, infostealers, and webshells. Security vendors and threat researchers noted that while many PoC attacks were ineffective, validated exploits—some featuring advanced WAF bypasses and in-memory payloads—posed serious risks to organizations relying on web application frameworks. The incident highlights the increasing sophistication of attackers in quickly adapting and bypassing newly deployed defenses such as WAF rules. As automated scanning and exploit release cycles accelerate, enterprises face mounting challenges in promptly identifying, patching, and defending against RCE vulnerabilities across their web application infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports