✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Internet
Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.
Explore Other Sectors
Internet Threat Reports
Cloudflare 2024 Outage: Why Network Resilience and Redundancy Matter More Than Ever
On June 20, 2024, Cloudflare, a major internet infrastructure and security provider, suffered a widespread service outage that disrupted access to thousands of websites and web services globally. The event was characterized by persistent 500 Internal Server Error messages for end users. Cloudflare initiated an internal investigation, ultimately attributing the incident to a critical infrastructure failure rather than a cyberattack or external threat. Throughout the outage, web-facing businesses, SaaS providers, and end-users experienced degraded network performance, extended downtime, and impact to brand trust, illustrating the magnitude of hyperscaler dependencies. The Cloudflare outage highlights the increasing risks associated with concentration of critical internet services and underscores the urgency for organizations to bolster resilience strategies. In an era of heightened service interdependencies and upticks in both incidents and attacks targeting fundamental service providers, outage preparedness and robust incident response planning are more essential than ever.
6 months ago
Kill Chain
How Sophisticated Attackers Exploited the 2025 React2Shell Zero-Day
In June 2025, a critical remote code execution vulnerability named React2Shell (CVE-2025-55182) was exploited in the wild against organizations using React Server Components. Within hours of the public disclosure and patch release, Chinese state-linked groups such as UNC5174 (CL-STA-1015), Earth Lamia, and Jackpot Panda, alongside opportunistic cybercriminals, began mass scanning and targeting exposed systems. The threat actors successfully deployed malware (notably Snowlight and Vshell), established persistent access, conducted credential theft, and attempted to extract Amazon Web Services configuration and credential files. Over 30 organizations across industries suffered breaches, including documented impact on customer cloud environments. This campaign demonstrates the increasing speed and coordination of attackers exploiting newly public vulnerabilities, especially in widely deployed frameworks like React and Next.js. The incident underscores the necessity of rapid patching, improved east-west traffic security, and continuous threat detection, as adversaries quickly weaponize disclosures for initial access and persistent footholds.
6 months ago
Kill Chain
Cloudflare’s 2024 Outage: Lessons from the React2Shell RCE Emergency
In June 2024, Cloudflare experienced a significant outage after emergency patching efforts to address an actively exploited remote code execution (RCE) vulnerability in the React framework, dubbed "React2Shell." The incident unfolded as threat actors began leveraging the vulnerability to attempt unauthorized code execution on internet-facing workloads, prompting Cloudflare to rush critical security mitigations. While the attack itself targeted exploitation routes via React, it was the swift application of mitigations—rather than a direct breach—which triggered widespread downtime, temporarily impacting Cloudflare's global network operations and customer accessibility. This incident underscores the increasing speed and aggression of active exploitation cycles, particularly for zero-day vulnerabilities in widely used frameworks. As attacker sophistication grows and organizations race to patch critical flaws, operational disruptions and collateral damage are becoming more frequent in the ongoing effort to balance security with business continuity.
6 months ago
Kill Chain
Cloudflare Defeats Record 29.7 Tbps DDoS Attack Attributable to AISURU Botnet
In December 2025, Cloudflare successfully detected and mitigated the largest recorded distributed denial-of-service (DDoS) attack, peaking at 29.7 terabits per second. The attack was orchestrated by the AISURU botnet, leveraging up to four million infected hosts to launch a hyper-volumetric assault. The malicious traffic targeted Cloudflare’s infrastructure, testing the limits of web security and putting critical online services at risk of disruption during the 69-second onslaught. This incident illustrates the increasing scale and sophistication of botnet-driven DDoS attacks, forcing organizations to reassess their mitigation strategies. The AISURU attack underscores a troubling trend in the growth of for-hire botnets and record-breaking DDoS volumes seen in 2025. These evolving threats continue to challenge traditional perimeter defenses, making advanced detection, automated response, and robust network segmentation more critical than ever.
6 months ago
Kill Chain
Critical React Flaw Puts Cloud Supply Chains at Immediate Risk
In June 2024, multiple severe vulnerabilities (CVSS 10.0) were discovered in the React JavaScript library, widely used by more than a third of cloud service providers. The flaws, which have been assigned two CVEs, could enable supply-chain attacks by allowing attackers to execute unauthorized code through compromised package updates or dependencies. If exploited, these vulnerabilities may lead to credential theft, lateral movement, and unauthorized access to sensitive cloud workloads, severely impacting the confidentiality and integrity of customer data. Cloud providers were urged to apply emergency patches and audit their environments for suspicious activity. This incident exemplifies the increasing risk posed by software supply-chain vulnerabilities, particularly as critical open-source components underpin cloud and enterprise infrastructures. The speed and scale of exploitation have raised concerns with regulators and CISOs, highlighting escalating threats to core cloud services and compliance programs.
6 months ago
Kill Chain
Critical Supply Chain React Vulnerability Puts Major Web Apps at Risk
In June 2025, a critical deserialization vulnerability (CVE-2025-55182) was discovered in React Server Components, an open-source project underpinning a vast ecosystem of web frameworks. The flaw, initially reported by security researcher Lachlan Davidson, allowed unauthenticated attackers to execute remote code in default configurations of major frameworks—most notably Next.js—and impacted about 39% of cloud environments using vulnerable packages. Meta, Vercel, and affected project maintainers issued emergency patches, with no exploitation observed before public disclosure, but technical details were widely circulated, causing industry-wide urgency for remediation. This incident demonstrates the growing risks associated with open-source supply chain dependencies and highlights how a single upstream vulnerability can propagate rapidly across major SaaS platforms and developer environments. The ease of exploitation and prevalence of the affected components elevate concerns about lateral movement, credential exposure, and long-tail risk in environments slow to update or lacking robust software composition analysis.
6 months ago
Kill Chain
ShadowV2 Botnet Turns AWS Outage into Opportunity: 2024 IoT and Hybrid Cloud Attacks Surge
In June 2024, a new botnet malware known as ShadowV2 emerged, leveraging Mirai source code to target IoT devices, particularly from D-Link and TP-Link, exploiting known vulnerabilities for large-scale infection. Security researchers observed the malware operators using the widespread AWS outage as an opportunity to test command and control resilience, evade detection, and enhance lateral spread across hybrid and cloud networks. Initial access occurred via unpatched vulnerabilities in internet-facing devices, leading to rapid compromise and recruitment of thousands of endpoints, posing heightened risks to corporate and critical infrastructure systems. Detection was challenged by the use of encrypted and east-west traffic, with attackers adapting quickly to shifting network topologies. This incident highlights the increasing sophistication of IoT-focused botnets and their opportunistic exploitation of cloud service disruptions. Organizations with hybrid or cloud-connected assets are strongly urged to reassess east-west traffic controls, segmentation, and anomaly detection, as automated threats now more readily exploit both vulnerable devices and network instability.
6 months ago
Kill Chain
JackFix Campaign Exploits Fake Windows Updates to Spread Infostealers in 2025
In late 2025, cybersecurity researchers uncovered a campaign orchestrated by the JackFix group using cloned adult websites as a phishing lure, distributed primarily through malvertising channels. Victims visiting these sites were presented with fake Windows update pop-ups designed to imitate critical security notifications. Unsuspecting users were tricked into executing malicious payloads that installed multiple information stealers, enabling the attackers to exfiltrate credentials, session tokens, and sensitive browser data. This attack illustrates how adversaries exploit popular platforms and social engineering to bypass traditional security controls, posing significant risks to both individuals and enterprises. The incident is particularly significant given the continued adoption of sophisticated phishing techniques and the blending of legitimate web content with highly convincing fraudulent prompts. Enterprises must remain vigilant as such campaigns highlight persistent weaknesses in endpoint protections, user awareness, and lateral movement defenses against infostealers.
6 months ago
Kill Chain
How Phishing-as-a-Service Scams Exploited USPS and E-Z Pass: The Lighthouse Case
In 2025, Google filed a legal complaint against a China-based cybercriminal group alleged to have developed 'Lighthouse' Phishing-as-a-Service (PaaS) kits. These kits empower low-skilled actors to execute widespread smishing (SMS phishing) and e-commerce scams by providing templates, domain setup tools, and fake websites mimicking trusted brands such as USPS and E-Z Pass. Victims are lured via texts about overdue fees or package deliveries, redirecting them to realistic phishing sites that harvest credentials and financial information. The campaign leveraged legitimate ad platforms and payment methods, increasing its reach and credibility. The incident underscores the rising threat and sophistication of PaaS offerings, which lower the barrier for cybercrime and accelerate the proliferation of phishing campaigns. As threat actors streamline attack automation and mimic reputable organizations, enterprises must adapt with real-time detection, segmented network defenses, and stronger authentication measures.
6 months ago
Kill Chain
Cloudflare's 2024 Outage: What Happens When Cloud Control Goes Wrong?
On June 25, 2024, Cloudflare experienced its most significant outage since 2019, following a change to its database access controls that inadvertently propagated across its global network. This technical misconfiguration caused a cascade of failures, disabling the company's control plane and blocking access to thousands of websites and web services worldwide for nearly six hours. The incident was not attributable to cyberattack or malicious activity, but the widespread and prolonged downtime severely impacted Cloudflare's customers and highlighted the fragility of large-scale, cloud-driven infrastructure when faced with operational errors. This outage underscores a growing concern for enterprises reliant on cloud providers, as administrative mistakes and configuration errors have outsized impacts on digital availability. With rapid cloud adoption and increasingly complex infrastructures, businesses must prioritize robust change controls, real-time monitoring, and automated rollback capabilities to mitigate similar risks.
6 months ago
Kill Chain
Cloudflare 2025 Outage: A Wakeup Call for Web Security Resilience
In November 2025, Cloudflare suffered a significant intermittent outage lasting approximately eight hours, which disrupted access for many major websites relying on its services for security and DNS management. The outage was caused by an internal configuration error that expanded a critical feature file, impacting Cloudflare's Bot Management system and resulting in platform instability. Some organizations temporarily bypassed Cloudflare, exposing themselves directly to internet traffic and revealing vulnerabilities previously shielded by Cloudflare's protective layers, such as web application firewall (WAF), bot filtering, and DNS controls. These exposures led to increased malicious probing, raising concerns about previously undetected weaknesses and an overreliance on single-vendor security solutions. The incident highlights the growing operational and security risks of single-vendor dependency, especially as organizations rely more heavily on integrated cloud platforms for web security and availability. Broad industry adoption of zero trust and multi-cloud strategies is now a pressing priority to mitigate similar service disruptions and emergent threats.
6 months ago
Kill Chain
Cloudflare's 2024 Outage: How a Simple Misconfiguration Led to Global Disruption
In June 2024, Cloudflare, a leading cloud services provider, experienced a major global outage initially suspected to be the result of a distributed denial-of-service (DDoS) attack. Further investigation revealed that the real cause was an internal configuration error: a routine permissions update inadvertently triggered a critical software failure within network infrastructure, disrupting access to innumerable customer websites and business services for several hours worldwide. The incident underscored the fragile interplay between automated change management and resiliency of cloud-based operations. This outage is especially timely as organizations accelerate cloud adoption and automation, increasing their susceptibility to operational lapses and accidental misconfigurations. Regulatory bodies and industry frameworks are now sharpening requirements for cloud governance, real-time visibility, and robust change controls to mitigate such risks.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports