The Containment Era is here. →Explore

Industry Category

Internet

Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.

207 threat reports
Page 17 of 18

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Internet Threat Reports

Showing 193204 / 207 reports
Vane Viper Powers 1 Trillion DNS Queries in 2025 Malvertising Mega-Breach
Impact· high

Vane Viper Powers 1 Trillion DNS Queries in 2025 Malvertising Mega-Breach

In September 2025, the threat actor group known as Vane Viper was revealed to be operating a vast and covert ad fraud and malvertising network, leveraging a staggering one trillion DNS queries to enable malware distribution globally. According to a detailed Infoblox technical report, Vane Viper manipulated core internet infrastructure using shell companies and complex ownership structures to obfuscate responsibility and perpetuate malicious adtech practices. Their operations enabled widespread malvertising campaigns, significantly impacting advertising platforms and exposing users worldwide to illicit downloads and credential theft. This breach underscores a recent surge in the use of advanced DNS tunneling and obfuscation tactics in cybercrime, particularly within ad fraud and malvertising schemes. The incident exemplifies how attackers increasingly exploit foundational internet protocols, challenging traditional detection and defense measures while prompting urgent regulatory attention and industry-wide response.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Webshells Hidden in .well-known Directories: The 2024 Web Application Attack Trend
Impact· medium

Webshells Hidden in .well-known Directories: The 2024 Web Application Attack Trend

In September 2024, cybersecurity researchers observed a surge in malicious actors targeting the .well-known directory on web servers to deploy PHP-based webshells. Attackers exploited this typically-overlooked directory, intended for status and authentication files, as it remains web-accessible but hidden within the Unix filesystem. Logs and honeypot data detailed repeated attempts to probe and establish footholds via .well-known and its subdirectories, such as acme-challenge and pki-validation, with the clear goal of persistent, covert remote control. This technique illustrates an evolving trend in web application attacks, where multistage threats exploit common web standards and overlooked controls. Organizations face heightened risk from such stealthy compromises, underscoring the need for continuous monitoring and adaptive defense in the current threat landscape.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Iframe Security Exposed: The 2025 Rise of Payment Skimmer Attacks
Impact· high

Iframe Security Exposed: The 2025 Rise of Payment Skimmer Attacks

In September 2025, a widespread web application attack exploited payment iframes across major online retailers to deploy advanced payment skimmer malware. Attackers leveraged vulnerabilities in embedded iframe components on e-commerce checkout pages, bypassing client-side security controls and web isolation policies to secretly harvest customer credit card data. The campaign remained undetected for weeks, affecting thousands of transactions globally and prompting emergency mitigation efforts, reputational impact, and regulatory scrutiny for affected organizations. This incident highlights the urgent need for stronger web application and iframe security, as payment skimming through novel overlay techniques continues to surge. Organizations are under increased regulatory pressure to harden PCI compliance and prevent supply chain-driven client-side attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Cloudflare Thwarts Record-Breaking 22.2 Tbps DDoS Assault in 2025
Impact· high

Cloudflare Thwarts Record-Breaking 22.2 Tbps DDoS Assault in 2025

In September 2025, Cloudflare successfully mitigated a record-breaking Distributed Denial-of-Service (DDoS) attack that peaked at 22.2 Tbps and 10.6 billion packets per second. Orchestrated over just 40 seconds, the massive volumetric attack overwhelmed network infrastructure, pushing the limits of firewalls, routers, and load balancers. Prior research links recent large-scale DDoS campaigns—including those hitting Cloudflare—to the AISURU botnet, which leveraged a sudden increase in infected devices globally, stemming in part from exploited router firmware vulnerabilities. Business impact was minimized due to Cloudflare’s rapid mitigation, but the attack underscores the ever-increasing scale and sophistication of DDoS threats. Record-breaking DDoS attacks are climbing in frequency and intensity, with attackers exploiting IoT vulnerabilities and leveraging formidable botnets. This surge highlights the urgent need for resilient, scalable mitigation strategies, and amplifies ongoing regulatory and industry pressure to strengthen defenses against large-scale infrastructure threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Operation Rewrite: Chinese SEO Poisoning Surges in 2024, Compromising Trusted Web Servers
Impact· low

Operation Rewrite: Chinese SEO Poisoning Surges in 2024, Compromising Trusted Web Servers

In early 2024, security researchers identified 'Operation Rewrite,' a sophisticated SEO poisoning campaign linked to a suspected Chinese threat actor. The attackers compromised numerous legitimate web servers, injecting malicious content designed to boost the search ranking of infected sites for financial gain. Unsuspecting users were redirected from popular search results to websites hosting malware or phishing content. The campaign leveraged legitimate server infrastructure to evade traditional detection, complicating mitigation and exposing visitors to potential credential theft, malware infections, and broader data compromise. The attackers’ tactics allowed them to rapidly spread harmful payloads while remaining concealed among normal web traffic. This incident underscores a sharp increase in SEO poisoning and supply chain abuse, as adversaries prioritize techniques that abuse trust in widely visited websites and search engines. With web browsing essential to daily business operations, organizations face mounting risks from threats that bypass perimeter defenses by posing as reputable content.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
SystemBC Malware: How Infected VPS Systems Became a Global Proxy Highway (2025)
Impact· medium

SystemBC Malware: How Infected VPS Systems Became a Global Proxy Highway (2025)

In September 2025, security researchers from Lumen Technology’s Black Lotus Labs uncovered a significant increase in the activity of the SystemBC proxy botnet, which compromised an average of 1,500 commercial virtual private servers (VPS) daily by exploiting unpatched and critically vulnerable systems. SystemBC enabled threat actors, including ransomware gangs and criminal proxy networks, to route malicious traffic through infected VPS infrastructures, obscuring command-and-control activity and facilitating large-scale cyberattacks, such as WordPress brute-forcing and malware distribution. Impacted servers often had dozens of security flaws, with infection lifespans exceeding a month and some systems exhibiting over 100 vulnerabilities. The prevalence of SystemBC underscores a growing shift away from traditional residential botnets toward high-bandwidth, stable VPS resources easily abused due to lax patching. The incident amplifies urgent concerns around lateral movement, proxy abuse, and the need for robust network segmentation and real-time anomaly detection as attackers leverage compromised enterprise-grade infrastructure for persistent threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Dshield Honeypot Exposes IoT Botnet Worm Using Default Credentials in 2024
Impact· high

Dshield Honeypot Exposes IoT Botnet Worm Using Default Credentials in 2024

In September 2024, analysis of a Dshield honeypot deployed on AWS revealed a campaign targeting internet-exposed systems with IoT-focused botnet malware. Attackers attempted to upload shell scripts and architecture-specific binaries using known default credentials and exploited weak or unchanged passwords, particularly on Raspberry Pi and IoT devices. The payloads, often delivered over unencrypted FTP and SSH methods, led to the installation of UNIX_PIMINE.A malware, which achieves persistence, removes competing malware, and connects to IRC-based command-and-control channels, highlighting an active botnet spreading via automated credential stuffing and remote file uploads. This incident underscores a persistent threat: legacy systems and embedded devices with default or weak credentials remain a prime target for botnets. With continued rises in IoT deployments and exposed services, automated malware propagation using basic scripts and known default logins is resurging, driving renewed regulatory scrutiny and best-practice emphasis for credential management and east-west traffic security.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Fake Madgicx Plus & SocialMetrics Browser Extensions Hijack Meta Business Accounts in 2025
Impact· medium

Fake Madgicx Plus & SocialMetrics Browser Extensions Hijack Meta Business Accounts in 2025

In September 2025, cybersecurity researchers reported a targeted infostealer campaign involving fake browser extensions, notably "Madgicx Plus" and "SocialMetrics Pro." Threat actors distributed these malicious extensions via malvertising and fraudulent websites, tricking users into installing them under the guise of gaining Meta Verified blue checkmarks on Facebook and Instagram. Once installed, the extensions stole business account credentials and session tokens, enabling attackers to hijack and monetize Meta Business accounts, potentially leading to widespread financial and reputational harm for affected organizations and individuals. This incident exemplifies the evolution of social engineering and supply-chain abuse targeting digital marketing and social media tools. The ongoing rise in sophisticated browser-based infostealers underscores the urgent need for organizations to monitor for fraudulent browser plugins, enforce software controls, and educate employees about new methods of business account compromise.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
HiddenGh0st, Winos & kkRAT Malware: How SEO & Cloud Hosting Fueled a 2025 Chinese-Focused Attack
Impact· low

HiddenGh0st, Winos & kkRAT Malware: How SEO & Cloud Hosting Fueled a 2025 Chinese-Focused Attack

In September 2025, a sophisticated malware campaign targeted Chinese-speaking users through SEO poisoning and fake software sites, resulting in the widespread distribution of HiddenGh0st, Winos, and kkRAT malware. Attackers manipulated search results using SEO plugins, registered lookalike domains, and leveraged GitHub Pages to host malicious files. Unsuspecting users, believing they were downloading legitimate utilities, instead installed remote access trojans that enabled full compromise of their systems, data theft, and prolonged adversary presence. The campaign demonstrates coordinated threat actor use of both social engineering and modern cloud hosting platforms to bypass traditional security controls. This incident highlights an escalating trend of threat actors combining SEO manipulation with cloud-native infrastructure to launch convincing malware campaigns at scale. The use of popular developer tools like GitHub Pages for payload delivery complicates traditional egress controls, detection, and response, requiring organizations to bolster threat intelligence, web filtering, and zero-trust segmentation strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
SlopAds: How 224 Android Apps Fueled a $Billion Ad Fraud Scam in 2025
Impact· high

SlopAds: How 224 Android Apps Fueled a $Billion Ad Fraud Scam in 2025

In late 2025, the SlopAds ad fraud ring was exposed running a sophisticated scheme across 224 Android applications, amassing more than 38 million downloads globally. The attackers covertly embedded steganography-based payloads within these apps, enabling them to generate hidden WebViews and surreptitiously route ad clicks and impressions to threat actor-controlled cashout sites. This campaign resulted in a staggering 2.3 billion daily fraudulent ad bids, undermining advertiser spending and trust in mobile advertising. Investigations revealed that the fraud operated across 228 countries and leveraged advanced techniques to evade security controls and detection. This incident highlights a growing trend in large-scale, automated digital ad fraud utilizing supply chain infiltration and advanced evasion. With mobile devices as primary attack surfaces and threat actors exploiting application distribution ecosystems, organizations face heightened regulatory scrutiny, financial risk, and an urgent need for granular visibility, segmentation, and anomaly detection capabilities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
VMScape: 2025’s Critical Hypervisor Isolation Attack Exposes Cloud Risks
Impact· medium

VMScape: 2025’s Critical Hypervisor Isolation Attack Exposes Cloud Risks

In September 2025, security researchers from ETH Zurich disclosed 'VMScape,' a sophisticated side-channel attack that breaks guest-host isolation in virtualized environments by exploiting incomplete speculative execution mitigations in modern AMD and Intel CPUs. The exploit enables a malicious guest VM to leak sensitive data, such as cryptographic keys, from the unmodified QEMU hypervisor memory, bypassing existing Spectre defenses without requiring host compromise. The attack impacts AMD Zen 1–5 and Intel Coffee Lake CPUs, allowing memory leaks at rates that threaten cloud multi-tenancy and data privacy. While VMScape requires deep technical expertise and sustained attack duration, its discovery highlights ongoing challenges in securing virtualization infrastructure against novel hardware-level threats. The incident underscores the need for prompt hardware and software mitigation deployment and a renewed focus on isolation techniques amid rising CPU vulnerability disclosures.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
2025 NPM Supply Chain Breach: Phishing Attack on JavaScript Developer Risks Crypto Theft
Impact· medium

2025 NPM Supply Chain Breach: Phishing Attack on JavaScript Developer Risks Crypto Theft

In September 2025, a targeted supply chain attack compromised at least 18 widely used JavaScript packages on the NPM repository after a key developer, Josh Junon, was phished. The attackers created a convincing fake NPM login website, stealing both credentials and a one-time 2FA token to access the developer's account. They injected malicious code into popular packages, enabling browser-based interception of cryptocurrency transactions and redirection of funds to attacker-controlled wallets. The breach was discovered rapidly by Aikido, which alerted the maintainer, enabling a swift cleanup and limiting broader damage. This incident underscores the persistent risks lurking in open-source software supply chains, particularly as threat actors evolve their tactics to bypass conventional security controls using phishing and social engineering. The rapid containment averted a potentially devastating impact, but the episode highlights ongoing vulnerabilities in software ecosystems reliant on centralized package maintainers.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports