The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Internet
Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.
Explore Other Sectors
Internet Threat Reports
Lucifer Drainer: The Rise of Drainer-as-a-Service in Cryptocurrency Theft
In early 2026, cybersecurity researchers uncovered the 'Lucifer Drainer,' a sophisticated Drainer-as-a-Service (DaaS) platform that facilitated large-scale cryptocurrency theft. Operating from January 2025 to early 2026, Lucifer Drainer enabled affiliates to deploy phishing websites that tricked users into connecting their crypto wallets. Once connected, malicious transactions were executed, swiftly transferring assets to attacker-controlled wallets. This operation exemplifies the industrialization of crypto theft, with the DaaS model allowing even low-skilled actors to participate in complex scams. The emergence of platforms like Lucifer Drainer underscores a significant shift in cybercriminal tactics, highlighting the need for enhanced vigilance among cryptocurrency users and platforms. The professionalization of such services indicates a growing threat landscape, necessitating robust security measures and user education to mitigate risks associated with these evolving schemes.
4 months ago
Kill Chain
Underminr Exploit: A New Threat to Web Security
In May 2026, researchers identified a critical vulnerability named 'Underminr' that exploits weaknesses in content delivery networks (CDNs) and Domain Name System (DNS) configurations. This exploit allows threat actors to manipulate web requests, enabling them to mask malicious activities behind the trusted reputations of legitimate websites. By leveraging this technique, attackers can conduct phishing campaigns, distribute malware, and perform data exfiltration while appearing to originate from reputable domains. The widespread nature of this vulnerability poses significant risks to organizations relying on CDNs for web content delivery. The emergence of Underminr underscores the evolving tactics of cyber adversaries who are increasingly targeting foundational internet infrastructure. This trend highlights the necessity for organizations to reassess their security postures, particularly concerning third-party services like CDNs, and to implement robust monitoring and mitigation strategies to defend against such sophisticated attacks.
4 months ago
Kill Chain
Chinese APTs Deploy 'Showboat' Linux Backdoor in Central Asia Telco Attacks
In May 2026, Chinese state-aligned Advanced Persistent Threat (APT) groups were discovered using a Linux-based post-exploitation framework named 'Showboat' to infiltrate telecommunications companies in Central Asia. The malware enables attackers to scan and infect devices on local area networks (LANs) that are not connected to the public Internet, facilitating long-term espionage activities. Notably, the APT group Calypso has been identified leveraging Showboat alongside a Windows backdoor called 'JFMBackdoor' to target entities in Afghanistan, Kazakhstan, Turkey, and India. This incident underscores the evolving tactics of Chinese APTs in targeting critical infrastructure sectors, particularly telecommunications, using cross-platform malware to maintain persistent access and conduct intelligence gathering. The discovery of Showboat highlights the need for enhanced cybersecurity measures to detect and mitigate such sophisticated threats.
4 months ago
Kill Chain
Ukrainian Authorities Uncover Major Infostealer Operation in 2026
In May 2026, Ukrainian cyberpolice, in collaboration with U.S. law enforcement, identified an 18-year-old from Odesa responsible for deploying infostealer malware between 2024 and 2025. This operation targeted users of a California-based online store, compromising 28,000 customer accounts. Of these, 5,800 accounts were exploited to make unauthorized purchases totaling approximately $721,000, resulting in direct losses of $250,000, including chargebacks. The suspect managed the infrastructure for processing and selling stolen session data, which allowed access to victim accounts without credentials, potentially bypassing multi-factor authentication. This incident underscores the escalating threat posed by infostealer malware, which has become increasingly sophisticated and prevalent. Recent reports indicate a surge in such attacks, with infostealers being used to steal billions of credentials annually, facilitating further cybercrimes like ransomware and supply chain attacks. Organizations must enhance their cybersecurity measures to mitigate these evolving threats.
4 months ago
Kill Chain
Typosquatting Supply Chain Attack 2026: A New Era of Cyber Threats
In December 2025, attackers exploited typosquatting techniques to embed AI-generated lookalike domains within legitimate third-party scripts running on web properties. This method allowed malicious code to execute in users' browsers without requiring mistyped URLs or server breaches, leading to significant data exfiltration and financial losses. The Trust Wallet incident exemplifies this trend, where a trojanized Chrome extension resulted in the theft of $8.5 million from 2,500 wallets within 48 hours. This incident underscores a critical shift in cyber threats, highlighting the vulnerability of supply chains to typosquatting attacks. The rapid generation of convincing domain variants by AI tools has outpaced traditional security measures, necessitating enhanced detection capabilities and vigilance in monitoring third-party scripts.
4 months ago
Kill Chain
NGINX CVE-2026-42945: Critical Vulnerability Under Active Exploitation
In May 2026, a critical heap buffer overflow vulnerability, CVE-2026-42945, was disclosed in NGINX's ngx_http_rewrite_module, affecting versions 0.6.27 through 1.30.0. This flaw allows unauthenticated attackers to send specially crafted HTTP requests, potentially causing worker process crashes and, under certain conditions, remote code execution. The vulnerability stems from improper handling of unnamed PCRE captures combined with rewrite directives containing a question mark in the replacement string. ([thehackernews.com](https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html?utm_source=openai)) The public availability of a proof-of-concept exploit has heightened the risk of widespread attacks, especially given NGINX's extensive use across the internet. Organizations are urged to update to patched versions—NGINX Open Source 1.31.0 or 1.30.1, and NGINX Plus R37, R36 P4, or R32 P6—to mitigate potential threats. ([thehackernews.com](https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html?utm_source=openai))
4 months ago
Kill Chain
Critical Vulnerabilities in Avada Builder Plugin Affect Over One Million WordPress Sites
In May 2026, two critical vulnerabilities were discovered in the Avada Builder WordPress plugin, affecting over one million active installations. The first, CVE-2026-4782, is an arbitrary file read vulnerability exploitable by authenticated users with at least subscriber-level access, allowing them to read sensitive files on the server. The second, CVE-2026-4798, is a time-based blind SQL injection vulnerability that can be exploited without authentication, enabling attackers to extract sensitive information from the database, including password hashes. Both vulnerabilities have been patched in version 3.15.3 of the plugin. This incident underscores the importance of timely software updates and the potential risks associated with widely used plugins. Organizations should prioritize patch management and consider implementing additional security measures to protect against similar vulnerabilities in the future.
4 months ago
Kill Chain
NGINX Vulnerability CVE-2026-42945: What You Need to Know
In May 2026, a critical vulnerability (CVE-2026-42945) was discovered in NGINX's ngx_http_rewrite_module, affecting versions 0.6.27 through 1.30.0. This heap buffer overflow flaw can be exploited by unauthenticated attackers using specially crafted HTTP requests, leading to denial-of-service conditions and, under certain configurations, remote code execution. The issue arises when NGINX configurations utilize both 'rewrite' and 'set' directives, a common pattern in API gateways and reverse proxy setups. The discovery of this 18-year-old vulnerability underscores the importance of regular code audits and timely patching. Given NGINX's widespread use across various industries, organizations are urged to update to the latest versions to mitigate potential risks associated with this flaw.
4 months ago
Kill Chain
Critical Authentication Bypass Vulnerability in Burst Statistics WordPress Plugin (CVE-2026-8181)
In May 2026, a critical authentication bypass vulnerability, CVE-2026-8181, was discovered in the Burst Statistics WordPress plugin, affecting versions 3.4.0 and 3.4.1. This flaw allowed unauthenticated attackers to impersonate administrator accounts by exploiting improper handling of authentication functions, potentially leading to full site compromise. The vulnerability was actively exploited shortly after disclosure, with over 7,400 attacks recorded within 24 hours. This incident underscores the persistent threat posed by vulnerabilities in widely used WordPress plugins. It highlights the importance of prompt patching and vigilant monitoring, as attackers rapidly exploit such flaws to gain unauthorized access and control over websites.
4 months ago
Kill Chain
NGINX Rift: Unveiling the 18-Year-Old CVE-2026-42945 Vulnerability
In May 2026, a critical vulnerability (CVE-2026-42945) was discovered in NGINX's ngx_http_rewrite_module, present since 2008. This heap buffer overflow flaw allows unauthenticated attackers to send crafted HTTP requests, potentially causing worker process crashes or remote code execution, especially on systems with Address Space Layout Randomization (ASLR) disabled. The issue affects NGINX Plus and NGINX Open Source versions up to 1.30.0 and has been patched in subsequent releases. The disclosure of this 18-year-old vulnerability underscores the importance of regular code audits and timely patching. With NGINX's widespread use across the internet, organizations are urged to update their systems promptly to mitigate potential exploitation risks.
4 months ago
Kill Chain
Unveiling AI-Driven E-Commerce Fraud Schemes in 2026
In May 2026, a cybersecurity researcher uncovered a sophisticated e-commerce fraud scheme involving fake online marketplaces. These fraudulent sites, often appearing in search results through SEO poisoning, lured users with attractive deals on various products. Upon attempting to purchase items, victims were redirected through compromised legitimate websites to malicious payment pages designed to steal personal and financial information. The attackers utilized AI-generated content and cloned legitimate product listings to enhance the credibility of their fake marketplaces. This incident highlights the evolving tactics of cybercriminals in exploiting search engine algorithms and AI technologies to perpetrate fraud. The increasing prevalence of such schemes underscores the need for enhanced vigilance and advanced detection mechanisms to protect consumers and businesses from emerging e-commerce threats.
4 months ago
Kill Chain
Škoda Online Shop Data Breach: A Wake-Up Call for E-Commerce Security
In May 2026, Škoda Auto disclosed a data breach affecting its online shop, where attackers exploited a software vulnerability to gain unauthorized access. The compromised data includes customer names, addresses, email addresses, phone numbers, order details, and login credentials. Notably, financial information remained secure as it was processed by external payment service providers. Upon detection, Škoda promptly addressed the vulnerability, reported the incident to authorities, and initiated a forensic investigation. This incident underscores the critical importance of robust cybersecurity measures in e-commerce platforms. With the increasing frequency of such breaches, organizations must prioritize regular security assessments, timely patching of vulnerabilities, and comprehensive incident response plans to protect customer data and maintain trust.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports