✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Internet
Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.
Explore Other Sectors
Internet Threat Reports
KDDI Data Breach 2026: Zero-Day Vulnerability Exploited
In June 2026, Japanese telecommunications giant KDDI detected unauthorized access to its email platform, affecting multiple internet service providers (ISPs) including STNet, JCOM, Chubu Telecommunications, NIFTY Corporation, and BIGLOBE. The breach, initiated on May 16, exploited a zero-day vulnerability in third-party software, leading to the exposure of approximately 12.23 million email addresses and 7.61 million passwords. KDDI promptly blocked the attackers upon discovery on June 17 and implemented defensive measures to secure the compromised systems. This incident underscores the critical importance of securing third-party software components, as vulnerabilities in such software can serve as entry points for attackers. Organizations are urged to conduct thorough security assessments of third-party tools and implement robust monitoring systems to detect and respond to unauthorized access promptly.
2 weeks ago
Kill Chain
Malicious SDKs on npm and PyPI Compromise Paysafe and Skrill Integrations
In July 2026, a coordinated supply-chain attack targeted developers integrating payment services by distributing at least 17 malicious packages on the npm and PyPI repositories. These packages masqueraded as legitimate SDKs for Paysafe, Skrill, and Neteller, aiming to steal sensitive credentials such as API keys, AWS keys, and GitHub tokens. The attackers employed typosquatting techniques, publishing packages with names closely resembling authentic ones, leading to unauthorized access and potential data breaches. This incident underscores the escalating threat of supply-chain attacks within open-source ecosystems. The attackers' ability to infiltrate multiple package managers simultaneously highlights the need for enhanced vigilance and security measures among developers and organizations to safeguard against such sophisticated threats.
2 weeks ago
Kill Chain
Expansion of Deepfake CSAM Lawsuit Targets xAI and Stability AI
In July 2026, a class-action lawsuit against xAI, the developer of the AI tool Grok, was expanded to include two additional plaintiffs. These individuals allege that Grok was used by acquaintances to generate nonconsensual deepfake child sexual abuse material (CSAM) based on their real photos. The lawsuit also names Stability AI as a defendant, claiming that its Stable Diffusion model facilitated the creation of such illicit content. The plaintiffs report significant emotional distress and a loss of control over the dissemination of these images. This incident underscores the urgent need for robust safeguards in AI technologies to prevent misuse, particularly in generating harmful content. It highlights the growing legal and ethical challenges companies face in ensuring their AI models are not exploited for creating nonconsensual and illegal material.
2 weeks ago
Kill Chain
Google's 2026 Takedown of NetNut Residential Proxy Network
In July 2026, Google, in collaboration with the FBI and Lumen, significantly disrupted the NetNut residential proxy network, also known as Popa. This network, comprising at least 2 million home devices worldwide, was exploited by cybercriminals and espionage groups to mask malicious activities and conduct password-guessing attacks. Google's actions included disabling accounts and services associated with NetNut's command-and-control operations, leading to a substantial reduction in the network's operational capacity. ([thehackernews.com](https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html?utm_source=openai)) The takedown of NetNut underscores the growing threat posed by residential proxy networks, which can be co-opted by malicious actors to obscure their activities. This incident highlights the critical need for enhanced security measures and vigilance among consumers and organizations to prevent their devices from being exploited in such networks.
3 weeks ago
Kill Chain
Iran-Nexus TAG-182 Deploys MarkiRAT Malware in Surveillance Campaign
In early 2026, the Iranian-linked threat group TAG-182 initiated a cyber espionage campaign deploying MarkiRAT malware via counterfeit Android applications, including fake VPNs and media tools, to surveil Iranian citizens domestically and abroad. This operation aligns with Iran's intensified digital surveillance efforts following the partial restoration of internet access on May 26, 2026, targeting perceived dissidents and foreign collaborators. The MarkiRAT samples exhibit tradecraft overlaps with previous variants used by Ferocious Kitten, suggesting a potential operational connection, though further evidence is required to confirm organizational links. ([staging.hawk-eye.io](https://staging.hawk-eye.io/iran-apt-threat-advisory/?utm_source=openai)) The resurgence of TAG-182's activities underscores the persistent threat posed by Iranian state-sponsored cyber operations, particularly in the realm of surveillance and intelligence gathering. Organizations and individuals, especially those involved in human rights advocacy or opposition activities, should remain vigilant against sophisticated social engineering tactics and ensure robust cybersecurity measures are in place to mitigate the risks associated with such targeted campaigns.
3 weeks ago
Kill Chain
Securing AI Endpoints: Lessons from Recent Exploits
Between March and May 2026, Zenity researchers identified three distinct campaigns where threat actors exploited exposed AI inference endpoints, such as those of Ollama and LiteLLM, to conduct offensive operations. These attacks did not require full system compromises; attackers merely needed knowledge of the exposed endpoints to leverage them for activities like autonomous penetration testing and web reverse-engineering. The incidents underscore the critical need for securing AI infrastructure against unauthorized access. This trend highlights a growing tactic among cyber adversaries: exploiting misconfigured or exposed AI endpoints to amplify their offensive capabilities. As organizations increasingly integrate AI into their operations, ensuring the security of these systems becomes paramount to prevent their misuse in cyberattacks.
3 weeks ago
Kill Chain
RustDuck Botnet's Evolution: A New Era of DDoS Threats
Since February 2026, the RustDuck botnet has been actively compromising home routers, IP cameras, Android devices, and poorly secured servers to orchestrate large-scale Distributed Denial-of-Service (DDoS) attacks. Researchers at QiAnXin's XLab have observed its rapid evolution, notably transitioning its core codebase from C to Rust, enhancing its adaptability and resistance to analysis. The malware propagates through weak password brute-forcing on Telnet/SSH services and exploits various remote code execution vulnerabilities in devices from manufacturers like TVT, Ruijie, TP-Link, and ZTE, as well as web applications such as ThinkPHP, Jenkins, and Hadoop YARN. ([thehackernews.com](https://thehackernews.com/2026/06/rustduck-botnet-rebuilds-in-rust-to.html?utm_source=openai)) The emergence of RustDuck underscores a concerning trend in botnet development, where threat actors adopt modern programming languages like Rust to create more resilient and evasive malware. This shift complicates detection and mitigation efforts, highlighting the need for continuous adaptation in cybersecurity defenses. ([thehackernews.com](https://thehackernews.com/2026/06/rustduck-botnet-rebuilds-in-rust-to.html?utm_source=openai))
3 weeks ago
Kill Chain
KDDI Data Breach Exposes 14.2 Million Email Logins Across Six ISPs
In June 2026, KDDI Corporation, a major Japanese telecommunications operator, disclosed a data breach affecting its email systems used by six internet service providers (ISPs). The breach, discovered on June 17, resulted from attackers exploiting a vulnerability in third-party software, potentially exposing up to 14.2 million email addresses and passwords. The affected ISPs include STNet, JCOM, Chubu Telecommunications, NIFTY, BIGLOBE, and KDDI Web Communications. KDDI promptly blocked the attacker and implemented defensive measures upon detection. This incident underscores the critical importance of securing third-party software components within shared infrastructure environments. As cyber threats continue to evolve, organizations must rigorously assess and monitor the security of all integrated software solutions to prevent similar breaches.
3 weeks ago
Kill Chain
Critical Vulnerability in Popular Chrome Extension Puts Millions at Risk
In June 2026, security researchers discovered that the popular Chrome extension 'Adblock for YouTube' (ID: cmedhionkhpnakcndndgjdbohmhepckk), with over 11 million installs, contained a dormant capability to execute arbitrary JavaScript code on any website. This vulnerability could be activated remotely by a server-side configuration change, potentially allowing attackers to read user data, steal sensitive information, and perform actions on behalf of the user across various web applications. The extension's permissions and architecture facilitated this exploit without requiring an update or user intervention, posing a significant security risk to its extensive user base. This incident underscores the growing threat posed by malicious or compromised browser extensions, especially those with large user bases and extensive permissions. As browser ecosystems evolve, the potential for such extensions to be weaponized increases, highlighting the need for rigorous security assessments, continuous monitoring, and user education to mitigate risks associated with third-party extensions.
1 month ago
Kill Chain
DraftKings 2022 Credential Stuffing Attack: A Case Study
In November 2022, DraftKings, a prominent fantasy sports and betting platform, experienced a credential stuffing attack that compromised approximately 60,000 user accounts. The attackers, led by Nathan Austad, known online as "Snoopy," exploited reused login credentials to gain unauthorized access. In about 1,600 cases, they added new payment methods to the compromised accounts and withdrew funds, resulting in approximately $600,000 in losses. The remaining compromised accounts were sold on cybercriminal marketplaces. Austad was sentenced to 18 months in federal prison, ordered to serve three years of supervised release, pay over $1.3 million in restitution, and forfeit an additional $463,000. This incident underscores the persistent threat of credential stuffing attacks, particularly in the online betting industry, where user accounts often contain sensitive financial information. It highlights the critical need for robust password policies, multi-factor authentication, and user education to prevent unauthorized access and financial losses.
1 month ago
Kill Chain
Unveiling the World Cup 2026 Purchase Scam Tactics
In 2026, cybercriminals exploited the FIFA World Cup's global appeal by compromising legitimate websites to redirect users to fraudulent domains selling non-existent tickets and merchandise. This tactic involved embedding malicious code into high-ranking sites, enabling scammers to hijack organic search traffic without relying on paid advertisements. Victims, believing they were purchasing official products, not only lost money but also had their payment information stolen, leading to further unauthorized transactions. This incident underscores a growing trend where attackers leverage major events to deploy sophisticated scams, bypassing traditional detection methods. The use of compromised legitimate websites for redirection highlights the need for enhanced vigilance and security measures, especially during high-profile events that attract massive online traffic.
1 month ago
Kill Chain
Critical 'PixelSmash' Vulnerability in FFmpeg's MagicYUV Decoder (CVE-2026-8461)
In June 2026, a critical vulnerability known as 'PixelSmash' (CVE-2026-8461) was identified in FFmpeg's MagicYUV decoder, affecting versions prior to 8.1.2. This heap out-of-bounds write flaw allows attackers to execute arbitrary code or cause denial-of-service conditions by tricking users into opening malicious AVI, MKV, or MOV files. Applications utilizing FFmpeg's libavcodec, such as Jellyfin, Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio, are susceptible. Exploitation for remote code execution is feasible if Address Space Layout Randomization (ASLR) is disabled or bypassed. The widespread use of FFmpeg across various media applications amplifies the risk, highlighting the importance of prompt updates to mitigate potential attacks. This incident underscores the critical need for rigorous supply chain security practices and timely patch management to protect against emerging vulnerabilities.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports