The Containment Era is here. →Explore

Industry Category

Internet

Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.

207 threat reports
Page 9 of 18

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Internet Threat Reports

Showing 97108 / 207 reports
Understanding Cookie-Controlled PHP Web Shells in Linux Hosting
Impact· CRITICAL

Understanding Cookie-Controlled PHP Web Shells in Linux Hosting

In early 2026, threat actors increasingly exploited PHP web shells on Linux servers, utilizing HTTP cookies as control channels. This method allowed malicious code to remain dormant during normal operations, activating only when specific cookie values were present, thereby evading traditional detection mechanisms. The attackers employed various obfuscation techniques, including layered encoding and dynamic function reconstruction, to conceal their activities. This approach enabled persistent access, often through scheduled tasks that reinstated the web shell if removed, complicating remediation efforts. The incidents underscored the need for enhanced monitoring of web server processes and stricter controls over scheduled tasks to prevent unauthorized access and maintain system integrity. The rise of cookie-controlled PHP web shells highlights a significant shift in attacker tactics, emphasizing stealth and persistence. Organizations must adapt by implementing advanced detection strategies, such as behavior-based monitoring and anomaly detection, to identify and mitigate these sophisticated threats effectively.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Magecart E-Skimmer Infections Reach Record Highs in 2025
Impact· CRITICAL

Magecart E-Skimmer Infections Reach Record Highs in 2025

In 2025, Magecart e-skimming attacks surged, compromising over 23 million online transactions across more than 10,500 unique infections. These attacks involved injecting malicious JavaScript into e-commerce checkout pages to steal payment data. The proliferation of full-stack e-skimmer kits and Malware-as-a-Service offerings enabled less technically skilled threat actors to execute large-scale compromises, significantly impacting the security of online merchants and consumers. ([recordedfuture.com](https://www.recordedfuture.com/resources/guides/annual-payment-fraud-intelligence-report-2025?utm_source=openai)) The industrialization of the fraud ecosystem, characterized by standardized attack tools and services, has lowered the barrier to entry for cybercriminals. This trend underscores the urgent need for financial institutions and e-commerce platforms to adopt proactive, intelligence-driven defenses to mitigate the escalating threat of payment fraud. ([recordedfuture.com](https://www.recordedfuture.com/resources/guides/annual-payment-fraud-intelligence-report-2025?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Unveiling the March 2026 Fraud Attack: Bot Signups and Account Takeovers
Impact· HIGH

Unveiling the March 2026 Fraud Attack: Bot Signups and Account Takeovers

In March 2026, a sophisticated fraud campaign was identified, leveraging automated bots to create large volumes of fake accounts using compromised emails and residential proxies. These accounts, appearing legitimate, were later exploited for account takeovers through credential stuffing and phishing, leading to unauthorized transactions and data breaches. The attackers' use of automation and human-driven sessions allowed them to bypass traditional security measures, resulting in significant financial losses and reputational damage for affected organizations. This incident underscores the evolving nature of cyber threats, highlighting the need for multi-layered security approaches that integrate behavioral analytics, device fingerprinting, and real-time threat intelligence to detect and prevent such complex fraud schemes.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Phishing Campaign Targets TikTok Business Accounts in 2026
Impact· HIGH

Phishing Campaign Targets TikTok Business Accounts in 2026

In March 2026, a sophisticated phishing campaign targeted TikTok for Business accounts, exploiting their extensive reach and credibility. Attackers employed Cloudflare-hosted phishing pages, registered via NiceNIC, to impersonate TikTok's business services. Victims were lured through legitimate Google Storage URLs, which redirected them to malicious sites after bypassing security bots using Cloudflare Turnstile checks. These sites mimicked TikTok's 'Schedule a Call' pages, prompting users to enter business email addresses and login credentials. The attackers utilized reverse proxy techniques to capture credentials and session cookies, effectively bypassing two-factor authentication and enabling unauthorized access to accounts. This incident underscores the evolving tactics of cybercriminals in targeting high-profile business accounts for malicious activities. The campaign's sophistication, including the use of legitimate services to mask malicious intent and the ability to circumvent multi-factor authentication, highlights the need for enhanced vigilance and security measures among businesses utilizing social media platforms for marketing and outreach.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites
Impact· CRITICAL

WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites

In March 2026, cybersecurity researchers identified a novel web skimming attack targeting e-commerce platforms. This attack leverages WebRTC data channels to exfiltrate payment information, effectively bypassing traditional security measures such as Content Security Policy (CSP) controls. The skimmer, implemented in JavaScript, establishes a direct, encrypted communication channel with a command-and-control server, facilitating the stealthy transmission of stolen credit card data. This method allows attackers to circumvent standard detection mechanisms, posing a significant threat to online retailers and their customers. The emergence of this WebRTC-based skimming technique underscores the evolving sophistication of cyber threats in the e-commerce sector. As attackers develop more advanced methods to exploit web technologies, it is imperative for organizations to enhance their security protocols and monitoring systems to detect and mitigate such innovative attack vectors.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Operation Alice 2026: Unveiling the Dark Web's Deceptive CSAM Network
Impact· MEDIUM

Operation Alice 2026: Unveiling the Dark Web's Deceptive CSAM Network

In March 2026, an international law enforcement operation named Operation Alice, led by German authorities with Europol's support, dismantled over 373,000 dark web sites that falsely advertised child sexual abuse material (CSAM). These fraudulent sites, operated by a 35-year-old suspect based in China, lured approximately 10,000 users into paying between EUR 17 and EUR 250 in Bitcoin, amassing around $400,000, without delivering any illicit content. The operation resulted in the seizure of 287 servers, including 105 located in Germany, and an international arrest warrant issued for the suspect. This incident underscores the persistent threat posed by cybercriminals exploiting the dark web to perpetrate fraud and distribute illicit content. It highlights the necessity for continuous international collaboration and vigilance in monitoring and dismantling such networks to protect vulnerable individuals and uphold cybersecurity standards.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Aisuru and Kimwolf Botnets' 2025 Record-Breaking DDoS Attacks
Impact· HIGH

Aisuru and Kimwolf Botnets' 2025 Record-Breaking DDoS Attacks

In December 2025, the Aisuru and Kimwolf botnets orchestrated a record-breaking Distributed Denial of Service (DDoS) attack, peaking at 31.4 terabits per second (Tbps) and delivering 200 million requests per second. This unprecedented assault targeted multiple companies, predominantly in the telecommunications sector, and was part of a broader campaign dubbed "The Night Before Christmas." The attack leveraged a vast network of compromised Internet of Things (IoT) devices, including Android TVs and streaming boxes, to generate massive traffic volumes. ([hackmag.com](https://hackmag.com/news/aisuru-31-4-tbps?utm_source=openai)) The incident underscores the escalating scale and sophistication of DDoS attacks, highlighting the critical need for robust cybersecurity measures. The rapid proliferation of vulnerable IoT devices has provided attackers with extensive resources to launch such large-scale assaults. Organizations must prioritize securing these devices and implementing advanced DDoS mitigation strategies to defend against evolving cyber threats. ([fastnetmon.com](https://fastnetmon.com/2026/02/01/aisuru-botnet-sets-a-new-ddos-record-at-31-4-tbps/?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
DoJ Dismantles Massive IoT Botnet Behind Record-Breaking DDoS Attacks
Impact· HIGH

DoJ Dismantles Massive IoT Botnet Behind Record-Breaking DDoS Attacks

In March 2026, the U.S. Department of Justice (DoJ), in collaboration with international law enforcement agencies, successfully disrupted a massive botnet operation comprising over 3 million compromised Internet of Things (IoT) devices. This botnet, controlled by threat actors including AISURU, Kimwolf, JackSkid, and Mossad, was responsible for launching unprecedented Distributed Denial-of-Service (DDoS) attacks, peaking at 31.4 terabits per second. The operation involved seizing command-and-control infrastructure and arresting key individuals associated with the botnet's administration. The dismantling of this botnet underscores the escalating threat posed by IoT device vulnerabilities. As IoT adoption continues to rise, the potential for such devices to be exploited in large-scale cyberattacks grows, highlighting the urgent need for enhanced security measures and international cooperation to mitigate these risks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Magento's 'SessionReaper' Vulnerability: A Critical Threat to E-Commerce Security
Impact· CRITICAL

Magento's 'SessionReaper' Vulnerability: A Critical Threat to E-Commerce Security

In October 2025, a critical vulnerability known as 'SessionReaper' (CVE-2025-54236) was discovered in Adobe Commerce and Magento Open Source platforms. This flaw, stemming from improper input validation, allows unauthenticated attackers to execute arbitrary code via the Commerce REST API, leading to potential full system compromise and unauthorized access to sensitive customer data. Despite Adobe releasing a patch in September 2025, reports indicate that as of late October, approximately 62% of Magento stores had not applied the necessary fixes, leaving them vulnerable to exploitation. ([threatprotect.qualys.com](https://threatprotect.qualys.com/2025/10/24/adobe-magento-improper-input-validation-vulnerability-exploited-in-attack-cve-2025-54236/?utm_source=openai)) The active exploitation of SessionReaper underscores the critical importance of timely patch management in e-commerce platforms. With attackers increasingly targeting unpatched systems, organizations must prioritize the application of security updates to mitigate risks associated with such vulnerabilities.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AppsFlyer Web SDK Hijacked: A 2026 Supply Chain Attack Analysis
Impact· MEDIUM

AppsFlyer Web SDK Hijacked: A 2026 Supply Chain Attack Analysis

In March 2026, the AppsFlyer Web SDK, utilized by over 100,000 applications for marketing analytics, was compromised in a supply chain attack. Malicious JavaScript code was injected into the SDK, enabling attackers to intercept and replace cryptocurrency wallet addresses entered by users on affected websites, diverting funds to attacker-controlled wallets. The attack targeted major cryptocurrencies, including Bitcoin, Ethereum, Solana, Ripple, and TRON, potentially impacting a vast number of end users. The incident underscores the critical vulnerabilities inherent in widely deployed third-party SDKs and the significant risks they pose to downstream applications and their users. Organizations relying on such SDKs must implement rigorous security measures and maintain vigilant monitoring to detect and mitigate potential compromises promptly.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
SocksEscort Botnet Dismantled in 2025: A Major Blow to Cybercrime
Impact· HIGH

SocksEscort Botnet Dismantled in 2025: A Major Blow to Cybercrime

In May 2025, an international law enforcement operation dismantled the SocksEscort botnet, a vast network of compromised small office/home office (SOHO) routers infected with the AVrecon malware. This botnet, active since at least 2023, had infiltrated over 70,000 devices across 20 countries, creating a covert network used for various cybercriminal activities, including digital advertising fraud and password spraying. The takedown involved seizing 34 domains and 23 servers across seven countries, as well as freezing $3.5 million in cryptocurrency linked to the botnet's operations. The operation also led to the indictment of four foreign nationals charged with conspiracy and damage to protected computers. ([justice.gov](https://www.justice.gov/usao-ndok/pr/botnet-dismantled-international-operation-russian-and-kazakhstani-administrators?utm_source=openai)) The SocksEscort botnet's extensive reach and prolonged undetected activity underscore the critical need for enhanced security measures in SOHO routers. This incident highlights the growing trend of cybercriminals exploiting less secure devices to build large-scale botnets, emphasizing the importance of regular firmware updates, robust security configurations, and vigilant monitoring to prevent similar infiltrations.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Meta's 2026 Crackdown on Southeast Asia Scam Networks
Impact· LOW

Meta's 2026 Crackdown on Southeast Asia Scam Networks

In March 2026, Meta, in collaboration with international law enforcement agencies, disabled over 150,000 Facebook and Instagram accounts linked to sophisticated scam centers operating in Southeast Asia. This coordinated effort, involving authorities from countries including Thailand, the U.S., the U.K., and Singapore, also led to 21 arrests by the Royal Thai Police. The crackdown targeted criminal networks in countries like Cambodia, Myanmar, and Laos, which have been running large-scale scam operations designed to evade detection and cause significant harm to individuals globally. ([about.fb.com](https://about.fb.com/news/2026/03/meta-global-law-enforcement-disrupt-major-southeast-asia-criminal-scam-networks/?utm_source=openai)) This operation underscores the escalating threat posed by industrialized online scams and highlights the necessity for continuous collaboration between tech companies and global law enforcement to protect users from increasingly sophisticated fraudulent activities. ([about.fb.com](https://about.fb.com/news/2026/03/meta-global-law-enforcement-disrupt-major-southeast-asia-criminal-scam-networks/?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports