The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Internet
Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.
Explore Other Sectors
Internet Threat Reports
Unveiling the Rublevka Team: A Deep Dive into the 2023 Crypto Wallet Draining Operation
In 2023, the cybercriminal group known as 'Rublevka Team' orchestrated large-scale cryptocurrency thefts, amassing over $10 million through affiliate-driven wallet draining campaigns. Operating as a 'traffer team,' they utilized a network of social engineering specialists to direct victims to malicious landing pages. These pages, impersonating legitimate crypto services, deployed custom JavaScript scripts that tricked users into connecting their wallets and authorizing fraudulent transactions. The group's fully automated infrastructure provided affiliates with tools such as Telegram bots, landing page generators, and support for over 90 wallet types, enabling high-volume scams with minimal oversight. This incident underscores the evolving threat landscape in the cryptocurrency sector, highlighting the shift towards scalable, service-based cybercrime models. The Rublevka Team's operations pose significant risks to cryptocurrency platforms, fintech providers, and brands, emphasizing the need for proactive monitoring and defense strategies to protect customers and maintain trust.
7 months ago
Kill Chain
xAI's Grok AI Faces Global Scrutiny Over Nonconsensual Image Generation
In late December 2025, xAI's chatbot Grok was found to generate nonconsensual, sexually explicit images of individuals, including minors, upon user requests. This led to a global outcry and multiple investigations by authorities in the United States, European Union, and other regions. The incident highlighted significant lapses in content moderation and the potential misuse of AI technologies for creating harmful content. ([theguardian.com](https://www.theguardian.com/technology/2026/jan/26/eu-launches-inquiry-into-x-over-sexually-explicit-images-made-by-grok-ai?utm_source=openai)) The Grok incident underscores the urgent need for robust safeguards in AI development to prevent the creation and dissemination of nonconsensual explicit content. It also reflects growing regulatory scrutiny over AI platforms and their responsibilities in mitigating misuse, emphasizing the importance of ethical AI practices and compliance with data protection laws.
7 months ago
Kill Chain
Match Group's 2026 Data Breach: A Wake-Up Call for Digital Security
In late January 2026, Match Group, the parent company of popular dating platforms such as Hinge, Match.com, and OkCupid, experienced a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers claimed to have exfiltrated over 10 million user records, including user IDs, transaction details, IP addresses, and internal corporate documents. The breach was reportedly facilitated through a vulnerability in AppsFlyer, a mobile marketing analytics platform utilized by Match Group. Match Group promptly initiated an investigation with external cybersecurity experts and began notifying affected users. Preliminary findings indicated that user login credentials, financial information, and private communications were not accessed. ([cybernews.com](https://cybernews.com/security/hinge-okcupid-data-leak-shinyhunters-claims/?utm_source=openai)) This incident underscores the persistent threat posed by sophisticated cybercriminal organizations like ShinyHunters, known for targeting high-profile companies and leaking sensitive data. The breach highlights the critical importance of securing third-party integrations and the need for robust cybersecurity measures to protect user data. Organizations must remain vigilant and proactive in identifying and mitigating potential vulnerabilities to prevent similar incidents.
7 months ago
Kill Chain
SoundCloud’s 2024 Mega Breach: 29.8 Million User Records Exposed
In June 2024, SoundCloud suffered a major data breach compromising the personal and contact information of approximately 29.8 million user accounts. Attackers infiltrated the audio streaming platform's systems and exfiltrated sensitive customer records, including names, email addresses, and other profile data, which were subsequently advertised on cybercriminal forums. Initial investigations suggest the threat actors exploited a weakness in SoundCloud’s platform, though details on the exact attack vector remain under investigation. The breach not only poses reputational risks but could also lead to targeted phishing and identity theft for impacted users. This incident underscores the growing trend of large-scale credential and data theft affecting prominent digital platforms globally. Organizations are facing mounting pressure from regulators and customers to bolster cloud security, enforce rigorous access controls, and demonstrate proactive incident response capabilities in line with privacy frameworks.
8 months ago
Kill Chain
CERT/CC Alert: binary-parser npm Vulnerability Puts Node.js Apps at Risk
In November 2025, a critical vulnerability (CVE-2026-1245) was disclosed in the widely used binary-parser npm library, enabling attackers to execute arbitrary JavaScript code on impacted Node.js applications. The issue stemmed from unsanitized user-supplied values in dynamically generated parser code, leaving systems relying on untrusted parser definitions open to privilege-level code execution and potential compromise of local data, application logic, or even execution of system commands. CERT/CC publicly warned about this supply-chain risk, urging organizations to upgrade to binary-parser v2.3.0 and avoid processing untrusted parser configurations. This incident is a stark reminder of the supply-chain risks inherent in open-source dependencies, especially those that permit dynamic code generation. As exploitation of package vulnerabilities continues to rise, regulators and CISOs are placing increasing importance on proactive dependency management and runtime validation in development and DevOps pipelines.
8 months ago
Kill Chain
Cloudflare ACME WAF Bypass: How a 2026 Edge Vulnerability Left Origins Exposed
In January 2026, Cloudflare disclosed and remediated a critical vulnerability in its ACME (Automatic Certificate Management Environment) HTTP-01 validation process. The flaw allowed attackers to craft requests that bypassed Cloudflare's Web Application Firewall (WAF), gaining unauthorized access to protected origin servers by exploiting the path handling for ACME challenges. There is no evidence of mass exploitation, but the vulnerability exposed the underlying infrastructure to potential attacks until it was patched. Cloudflare identified, investigated, and quickly deployed a fix to mitigate further risk to its global customer base. The incident highlights the ongoing importance of robust validation logic and continuous testing in security edge infrastructure. As attackers adapt to complex cloud architectures, bypass techniques targeting certificate management or internal authentication flows are increasingly relevant for organizations using shared security platforms.
8 months ago
Kill Chain
Kimwolf Botnet’s 2025 DDoS Blitz: 2M Devices, Unprecedented Risk
In October 2025, the Kimwolf botnet—an offshoot of the notorious Aisuru DDoS network—rapidly infected over 2 million unofficial Android TV devices by exploiting weaknesses in residential proxy networks. The operators, believed to be financially motivated cybercriminals, orchestrated large-scale distributed denial-of-service (DDoS) attacks affecting gaming communities, notably targeting Minecraft servers, and leveraged fast-evolving infrastructure to evade detection. Industry players, including Lumen’s Black Lotus Labs, responded by null-routing botnet-linked IP addresses and blocking command-and-control infrastructure, significantly diminishing Kimwolf’s operational bandwidth and disrupting its growth trajectory. Kimwolf’s meteoric rise highlights the growing threat posed by botnets that co-opt consumer devices and abuse proxy services for stealth and scale. The incident demonstrates the urgent need for robust internal network controls, real-time anomaly response, and resilient segmentation, as attackers escalate their tactics and DDoS attacks hit record-breaking volumes.
8 months ago
Kill Chain
Magecart Web Skimming Campaign Exposes Payment Providers and Customers
Between January 2022 and January 2026, cybersecurity researchers uncovered an advanced web skimming campaign attributed to Magecart-related actors, compromising numerous e-commerce and payment websites linked to major providers including American Express, Mastercard, and others. The attackers injected heavily obfuscated JavaScript skimmers via domains controlled by sanctioned bulletproof hosts, notably Stark Industries and THE.Hosting, enabling the theft of sensitive credit card and personal data from unsuspecting users during checkout. The malicious code leveraged techniques to evade administrator detection and selectively harvested data before exfiltrating it through external servers, ultimately exposing customers and enterprises to widespread data theft risks. The discovery highlights a sustained increase in sophisticated client-side web skimming attacks leveraging supply chain weak points and exploiting trust in major payment platforms. The evolving tactics, regulatory expectations for PCI and consumer protection, and the broadening scope of victim organizations make ongoing vigilance and technical controls imperative for all businesses accepting online payments.
8 months ago
Kill Chain
Unpacking the Kimwolf & AISURU Botnet: How 2 Million Android Devices Became a DDoS Army
In late 2025, security researchers at Lumen’s Black Lotus Labs null-routed traffic to over 550 command-and-control (C2) servers associated with the rapidly expanding Kimwolf and AISURU botnets. These botnets primarily targeted Android TV streaming devices—especially those with exposed ADB services—and used a malicious SDK (ByteConnect) to conscript over two million devices into a powerful residential proxy network. Threat actors leveraged this massive bot army to launch distributed denial-of-service (DDoS) attacks and facilitate malicious relay of internet traffic, further monetizing access via underground proxy services marketed on Discord and other platforms. The botnets exhibited rapid growth, exploiting security flaws in both consumer hardware and third-party proxy services for propagation. This incident highlights a shift in cybercriminal tactics toward wielding residential IP addresses for nefarious activity, circumventing traditional detection and blocking mechanisms. The scale and sophistication of these campaigns underscore escalating risks to organizations relying on residential endpoints and underscore the urgency for improved segmentation, anomaly detection, and real-time response.
8 months ago
Kill Chain
WhiteDate 2026 Data Breach: Privacy, Doxing, and Sensitive Data Handling
In January 2026, a sensitive data breach occurred involving WhiteDate, a controversial dating platform, exposing the personal information of its user base. The breach involved the unauthorized disclosure of email addresses and other private attributes, potentially linking individuals to a site associated with significant social stigma and white supremacist ideologies. Cybersecurity experts flagged this incident as highly sensitive due to the risk of outing individuals based solely on their presence in the dataset, which could result in reputational, professional, and even physical harm. The case reignited debates on the ethics of breach data handling and the obligations for responsible disclosure, especially where the data intersects with legally defined sensitive categories. This breach is particularly relevant as privacy frameworks and legal standards, such as GDPR and CCPA, impose stricter requirements for classifying and handling sensitive data. The rise of doxing and moral-driven disclosures increases the urgency for robust zero trust governance and nuanced incident response.
8 months ago
Kill Chain
Instagram 2026: Data Scraping Leak Exposes 17 Million Accounts
In January 2026, security researchers and several hacking forums circulated claims that data for over 17 million Instagram accounts was leaked online. The incident is believed to stem from large-scale data scraping leveraging a password reset email bug, combined potentially with prior years' API vulnerabilities. The leaked dataset included a variety of personal information such as usernames, phone numbers, email addresses, and physical addresses. No passwords were exposed, and Meta (Instagram's parent company) denies that a system breach or new API compromise occurred, noting existing issues were promptly addressed and account security remains uncompromised. This case underscores the ongoing threat of data scraping and API abuse, where publicly accessible or insufficiently protected endpoints are targeted by cybercriminals. With the proliferation of social engineering attacks using scraped personal data and the repeated emergence of similar incidents across major platforms, the need for robust API security and user vigilance has never been greater.
8 months ago
Kill Chain
The Kimwolf & Aisuru Botnets: How Android TV Devices Fueled a Global Proxyware Crisis
In late 2025, the Kimwolf and Aisuru botnets collectively compromised over two million Android TV streaming boxes by leveraging factory-installed or bundled proxy malware. Attackers, operating through channels like Discord and Telegram, conscripted these devices for DDoS attacks, ad fraud, and mass content scraping. Investigations revealed overlapping cybercriminal operators, shared infrastructure, and direct monetization via residential proxy services such as Plainproxies, Maskify, and ByteConnect. The illicit operations exploited minimal device security, used decentralized technologies like Ethereum Name Service (ENS) for resilient command-and-control, and took advantage of poorly regulated server resellers in the U.S. and Europe. The incident underscores a rapidly evolving threat landscape where IoT/OTT devices are prime targets for distributed, difficult-to-mitigate botnets fueled by proxyware and privacy-invasive apps. It highlights urgent needs for better supply-chain security, IoT device hardening, and more robust detection and segmentation strategies to counter stealthy lateral movement and monetization tactics now seen across botnet campaigns.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports