The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Internet
Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.
Explore Other Sectors
Internet Threat Reports
DoJ Dismantles Massive IoT Botnet Behind Record-Breaking DDoS Attacks
In March 2026, the U.S. Department of Justice (DoJ), in collaboration with international law enforcement agencies, successfully disrupted a massive botnet operation comprising over 3 million compromised Internet of Things (IoT) devices. This botnet, controlled by threat actors including AISURU, Kimwolf, JackSkid, and Mossad, was responsible for launching unprecedented Distributed Denial-of-Service (DDoS) attacks, peaking at 31.4 terabits per second. The operation involved seizing command-and-control infrastructure and arresting key individuals associated with the botnet's administration. The dismantling of this botnet underscores the escalating threat posed by IoT device vulnerabilities. As IoT adoption continues to rise, the potential for such devices to be exploited in large-scale cyberattacks grows, highlighting the urgent need for enhanced security measures and international cooperation to mitigate these risks.
6 months ago
Kill Chain
Magento's 'SessionReaper' Vulnerability: A Critical Threat to E-Commerce Security
In October 2025, a critical vulnerability known as 'SessionReaper' (CVE-2025-54236) was discovered in Adobe Commerce and Magento Open Source platforms. This flaw, stemming from improper input validation, allows unauthenticated attackers to execute arbitrary code via the Commerce REST API, leading to potential full system compromise and unauthorized access to sensitive customer data. Despite Adobe releasing a patch in September 2025, reports indicate that as of late October, approximately 62% of Magento stores had not applied the necessary fixes, leaving them vulnerable to exploitation. ([threatprotect.qualys.com](https://threatprotect.qualys.com/2025/10/24/adobe-magento-improper-input-validation-vulnerability-exploited-in-attack-cve-2025-54236/?utm_source=openai)) The active exploitation of SessionReaper underscores the critical importance of timely patch management in e-commerce platforms. With attackers increasingly targeting unpatched systems, organizations must prioritize the application of security updates to mitigate risks associated with such vulnerabilities.
6 months ago
Kill Chain
AppsFlyer Web SDK Hijacked: A 2026 Supply Chain Attack Analysis
In March 2026, the AppsFlyer Web SDK, utilized by over 100,000 applications for marketing analytics, was compromised in a supply chain attack. Malicious JavaScript code was injected into the SDK, enabling attackers to intercept and replace cryptocurrency wallet addresses entered by users on affected websites, diverting funds to attacker-controlled wallets. The attack targeted major cryptocurrencies, including Bitcoin, Ethereum, Solana, Ripple, and TRON, potentially impacting a vast number of end users. The incident underscores the critical vulnerabilities inherent in widely deployed third-party SDKs and the significant risks they pose to downstream applications and their users. Organizations relying on such SDKs must implement rigorous security measures and maintain vigilant monitoring to detect and mitigate potential compromises promptly.
6 months ago
Kill Chain
SocksEscort Botnet Dismantled in 2025: A Major Blow to Cybercrime
In May 2025, an international law enforcement operation dismantled the SocksEscort botnet, a vast network of compromised small office/home office (SOHO) routers infected with the AVrecon malware. This botnet, active since at least 2023, had infiltrated over 70,000 devices across 20 countries, creating a covert network used for various cybercriminal activities, including digital advertising fraud and password spraying. The takedown involved seizing 34 domains and 23 servers across seven countries, as well as freezing $3.5 million in cryptocurrency linked to the botnet's operations. The operation also led to the indictment of four foreign nationals charged with conspiracy and damage to protected computers. ([justice.gov](https://www.justice.gov/usao-ndok/pr/botnet-dismantled-international-operation-russian-and-kazakhstani-administrators?utm_source=openai)) The SocksEscort botnet's extensive reach and prolonged undetected activity underscore the critical need for enhanced security measures in SOHO routers. This incident highlights the growing trend of cybercriminals exploiting less secure devices to build large-scale botnets, emphasizing the importance of regular firmware updates, robust security configurations, and vigilant monitoring to prevent similar infiltrations.
6 months ago
Kill Chain
Meta's 2026 Crackdown on Southeast Asia Scam Networks
In March 2026, Meta, in collaboration with international law enforcement agencies, disabled over 150,000 Facebook and Instagram accounts linked to sophisticated scam centers operating in Southeast Asia. This coordinated effort, involving authorities from countries including Thailand, the U.S., the U.K., and Singapore, also led to 21 arrests by the Royal Thai Police. The crackdown targeted criminal networks in countries like Cambodia, Myanmar, and Laos, which have been running large-scale scam operations designed to evade detection and cause significant harm to individuals globally. ([about.fb.com](https://about.fb.com/news/2026/03/meta-global-law-enforcement-disrupt-major-southeast-asia-criminal-scam-networks/?utm_source=openai)) This operation underscores the escalating threat posed by industrialized online scams and highlights the necessity for continuous collaboration between tech companies and global law enforcement to protect users from increasingly sophisticated fraudulent activities. ([about.fb.com](https://about.fb.com/news/2026/03/meta-global-law-enforcement-disrupt-major-southeast-asia-criminal-scam-networks/?utm_source=openai))
6 months ago
Kill Chain
KadNap Malware: Over 14,000 Asus Routers Hijacked into Stealth Botnet
In August 2025, cybersecurity researchers identified a new malware strain named KadNap, which primarily targets Asus routers to conscript them into a botnet used for proxying malicious traffic. By March 2026, over 14,000 devices had been infected, with more than 60% located in the United States. KadNap employs a customized version of the Kademlia Distributed Hash Table (DHT) protocol, enabling it to conceal command-and-control (C2) infrastructure within a peer-to-peer network, thereby evading traditional network monitoring and enhancing resilience against detection and disruption efforts. The malware is distributed through a shell script that establishes persistence via cron jobs, downloads a malicious ELF file, and executes it, effectively integrating the compromised device into the botnet. ([thehackernews.com](https://thehackernews.com/2026/03/kadnap-malware-infects-14000-edge.html?utm_source=openai)) The emergence of KadNap underscores a growing trend of sophisticated malware targeting edge networking devices, exploiting their vulnerabilities to build resilient botnets. This incident highlights the critical need for organizations and individuals to secure their network infrastructure, as such compromised devices can be leveraged for various malicious activities, including anonymizing cybercriminal operations and facilitating large-scale attacks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-kadnap-botnet-hijacks-asus-routers-to-fuel-cybercrime-proxy-network/?utm_source=openai))
6 months ago
Kill Chain
UNC4899's $1.5 Billion Cryptocurrency Heist: Lessons for the Industry
In February 2025, the North Korean state-sponsored hacking group UNC4899, also known as TraderTraitor, orchestrated a sophisticated cyberattack resulting in the theft of approximately $1.5 billion from the cryptocurrency exchange Bybit. The attackers compromised a developer's macOS workstation at Safe{Wallet}, a multisignature wallet platform, by deploying a malicious Docker project. This initial breach allowed them to hijack AWS session tokens, bypass multi-factor authentication, and inject malicious JavaScript into Safe{Wallet}'s application. Consequently, they manipulated a routine Ethereum transfer from Bybit's cold wallet to its hot wallet, redirecting the funds to addresses under their control. ([blog.it-expert.net](https://blog.it-expert.net/summaries/The-Feed_2025-03-10.html?utm_source=openai)) This incident underscores the escalating threat posed by state-sponsored cyber actors targeting the cryptocurrency sector. The use of advanced social engineering tactics, exploitation of cloud infrastructure vulnerabilities, and sophisticated supply chain attacks highlight the need for enhanced security measures and vigilance within the industry. ([thehackernews.com](https://thehackernews.com/2025/07/n-korean-hackers-used-job-lures-cloud.html?utm_source=openai))
6 months ago
Kill Chain
UAT-9244's New Malware Threatens South American Telecoms
Since 2024, the China-linked advanced persistent threat actor UAT-9244 has been targeting telecommunication service providers in South America, compromising Windows, Linux, and network-edge devices. The group employs three previously undocumented malware families: TernDoor, a Windows backdoor; PeerTime, a Linux backdoor utilizing the BitTorrent protocol; and BruteEntry, a brute-force scanner that establishes proxy infrastructure. These tools enable UAT-9244 to maintain persistent access, execute remote commands, and expand their network infiltration. This incident underscores the evolving sophistication of state-sponsored cyber threats targeting critical infrastructure. The use of novel malware and advanced techniques highlights the need for enhanced cybersecurity measures and vigilance within the telecommunications sector.
6 months ago
Kill Chain
The Rising Threat of Compromised cPanel Credentials in Cybercrime Markets
In March 2025, a cybercriminal known as "miya" advertised for sale compromised SSH, cPanel, Mail, and WebHost Manager (WHM) credentials belonging to a Canadian car dealership on a dark web forum, pricing the access at $400. These credentials provided potential attackers with privileged access to the dealership's critical systems, including remote command-line server control via SSH, administrative capabilities through WHM and cPanel, and access to sensitive communications via the mail server. The breach underscored the escalating cybersecurity risks faced by automotive retailers, who increasingly rely on interconnected digital systems to manage sales, customer data, and backend infrastructure. ([cyberpress.org](https://cyberpress.org/cybercriminal-miya-stolen/?utm_source=openai)) This incident highlights a broader trend of cybercriminals targeting cPanel and other site management credentials to facilitate unauthorized access to web servers and associated services. The sale of such credentials on underground forums has become increasingly common, with prices ranging from $3 to $5, depending on the target and level of access provided. ([documents.trendmicro.com](https://documents.trendmicro.com/assets/wp/wp-north-american-underground.pdf?utm_source=openai))
6 months ago
Kill Chain
Kimwolf Botnet's 2026 Rampage: A Wake-Up Call for IoT Security
In late 2025, the Kimwolf botnet emerged as a significant cybersecurity threat, infecting over 2 million Android devices worldwide, primarily targeting off-brand smart TVs and set-top boxes. Exploiting vulnerabilities in residential proxy networks and exposed Android Debug Bridge (ADB) services, Kimwolf transformed these devices into nodes for large-scale distributed denial-of-service (DDoS) attacks. Notably, in November 2025, the botnet launched a record-setting DDoS attack peaking at 31.4 terabits per second, underscoring its unprecedented scale and impact. ([thehackernews.com](https://thehackernews.com/2026/02/aisurukimwolf-botnet-launches-record.html?utm_source=openai)) The rapid proliferation and sophistication of Kimwolf highlight the escalating threat posed by botnets leveraging IoT devices. This incident underscores the urgent need for enhanced security measures in consumer electronics and the importance of proactive defense strategies to mitigate the risks associated with large-scale botnet attacks.
6 months ago
Kill Chain
Iran's 2026 Internet Blackout: A New Era of Digital Repression
In January 2026, the Iranian government imposed a comprehensive internet blackout amid escalating nationwide protests. This shutdown disrupted all forms of digital communication, including mobile networks, landlines, and even satellite services like Starlink. The blackout aimed to suppress the coordination of protests and conceal human rights violations. Concurrently, Iran implemented a two-tiered internet system, granting unrestricted access to government officials and loyalists via 'white SIM cards,' while the general populace faced severe restrictions. This strategy effectively isolated citizens, preventing both internal coordination and external information dissemination. The incident underscores a growing trend among authoritarian regimes to leverage internet control as a tool for social suppression. The international community has condemned these actions, emphasizing the need for global efforts to uphold internet freedom and human rights.
6 months ago
Kill Chain
Critical Unauthenticated RCE Vulnerability in Juniper Networks PTX Series Routers
In February 2026, Juniper Networks disclosed a critical vulnerability (CVE-2026-21902) in its Junos OS Evolved operating system running on PTX Series routers. This flaw, stemming from incorrect permission assignments in the On-Box Anomaly Detection framework, allows unauthenticated, network-based attackers to execute code with root privileges. The vulnerability affects Junos OS Evolved versions prior to 25.4R1-S1-EVO and 25.4R2-EVO, potentially leading to full device compromise. The exposure of such a critical service over externally accessible ports underscores the importance of rigorous access controls and timely patch management. Organizations relying on PTX Series routers should prioritize applying the provided patches or implementing recommended mitigations to prevent potential exploitation.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports