The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Internet

Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.

260 threat reports
Page 17 of 22

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Internet Threat Reports

Showing 193–204 / 260 reports
Inside Vercel’s 2025 React2Shell Race: Supply-Chain RCE and the Open Source Security Wake-up Call
Impact· medium

Inside Vercel’s 2025 React2Shell Race: Supply-Chain RCE and the Open Source Security Wake-up Call

In late 2025, Vercel—maintainers of the popular Next.js framework—faced a critical cybersecurity incident involving the React2Shell vulnerability (CVE-2025-55182). Discovered just after Thanksgiving, this supply-chain flaw in React Server Components enabled unauthenticated remote code execution across multiple frameworks and bundlers in default configurations. A rapid, global response mobilized Vercel, open-source contributors, major cloud providers, and security vendors who coordinated mitigations and validated patches within days. Despite these efforts, over 60 organizations were compromised, with attackers from cybercriminal, ransomware, and nation-state groups exploiting disclosed weaknesses, leading to millions of exploit attempts and sustained attack volumes. The React2Shell episode highlighted the ongoing risks inherent in reliance on open-source components and the urgent need for collaborative, industry-wide response standards. Attackers have rapidly adopted similar techniques, sustaining high exploitation rates and revealing critical gaps in software supply-chain security.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
D-Link Legacy Router Flaw Exploited: CVE-2026-0625 Zero-Day Endangers Networks
Impact· medium

D-Link Legacy Router Flaw Exploited: CVE-2026-0625 Zero-Day Endangers Networks

In early January 2026, a critical security incident involving D-Link legacy DSL routers came to light as attackers actively exploited a command injection vulnerability tracked as CVE-2026-0625. The flaw, caused by improper input sanitization in the dnscfg.cgi endpoint of several out-of-support D-Link DSL gateway models, allowed unauthenticated remote attackers to execute arbitrary shell commands and potentially gain full control over affected devices. Although the exploit was first detected by Shadowserver Foundation honeypots, the method was not previously public, raising the risk of widespread attacks on consumer and small business network infrastructure. Impacted routers—including the DSL-526B, DSL-2640B, DSL-2740R, and DSL-2780B—are end-of-life and will not receive security updates, leaving users exposed unless devices are decommissioned or isolated. This incident highlights the persistent risks associated with legacy, unsupported network hardware across both consumer and SMB environments, particularly as attackers increasingly exploit unpatched, remotely accessible routers. It underscores the urgent importance of retiring end-of-life devices or segmenting critical networks, as well as the need for improved asset management strategies in the face of rising supply-chain and infrastructure vulnerabilities.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Kimwolf Botnet’s 2024 Assault: How Residential Proxies Fueled Widespread Android Device Infections
Impact· medium

Kimwolf Botnet’s 2024 Assault: How Residential Proxies Fueled Widespread Android Device Infections

In 2024, the Kimwolf Android botnet rapidly expanded to over two million infected hosts by exploiting vulnerabilities in residential proxy networks to penetrate internal devices. This botnet, an evolution of Aisuru malware, leverages residential IP addresses to mask malicious activity and facilitate lateral movement inside targeted networks. By abusing these proxies, Kimwolf can bypass perimeter defenses, execute command-and-control operations, and enable wide-scale internal compromise of Android and IoT devices, causing extensive disruption and exposing organizations to data theft, downtime, and potential extortion. Kimwolf highlights a growing threat: attackers are increasingly leveraging residential proxies and internal lateral movement tactics to amplify reach and evade detection. Its success underscores the need for improved egress filtering, network segmentation, and east-west traffic monitoring as threat actors adopt more sophisticated methods to breach internal assets.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Brightspeed Hit by Crimson Collective: Major 2026 Data Breach Exposes Customer PII
Impact· high

Brightspeed Hit by Crimson Collective: Major 2026 Data Breach Exposes Customer PII

In January 2026, Brightspeed, one of the largest fiber broadband providers in the United States, launched an investigation after the Crimson Collective extortion gang claimed to have breached the company’s networks and stolen sensitive data. The group asserted they had accessed personal and account-related information of over 1 million customers, including names, addresses, emails, phone numbers, payment histories, and some payment card details. The threat actors reportedly targeted user account systems and exfiltrated personally identifiable information (PII), subsequently pressuring Brightspeed to respond to their extortion demands by threatening to publish samples of the stolen data. This attack underscores the persistent risk posed by targeted data breaches in the telecom sector, where expansive networks and large customer bases make attractive targets for financially motivated threat actors. The incident further highlights a concerning trend: extortion groups are increasingly leveraging cloud misconfigurations, stolen credentials, and lateral movement within corporate environments to maximize data theft and pressure on organizations.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Kimwolf Botnet Compromises 2 Million+ Android Devices via Exposed ADB in 2026
Impact· high

Kimwolf Botnet Compromises 2 Million+ Android Devices via Exposed ADB in 2026

In early 2026, the Kimwolf botnet orchestrated one of the largest Android targeting campaigns to date, infecting over 2 million devices. Attackers exploited exposed Android Debug Bridge (ADB) interfaces and abused residential proxy networks to establish persistent control and monetize the compromised devices. Synthient researchers revealed that Kimwolf operators maintained access for lateral movement, facilitated app installations, sold network bandwidth, and weaponized infected endpoints for DDoS attacks. The attack chain emphasized exploiting weak or default security configurations on Android devices, allowing broad propagation and quick monetization at scale. The Kimwolf botnet illustrates the evolving risk landscape for mobile endpoints and the increasing use of cloud or residential proxy infrastructure by cybercriminals. Given the speed and scale of infection, this case underscores the urgent need for stronger defense-in-depth strategies and highlights regulatory scrutiny on IoT and mobile security postures.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
RondoDox Botnet Leverages React2Shell to Breach Next.js Servers
Impact· high

RondoDox Botnet Leverages React2Shell to Breach Next.js Servers

In early 2024, the RondoDox botnet launched widespread attacks targeting exposed Next.js servers by exploiting a vulnerability known as React2Shell. The threat actors leveraged this exploit to install cryptomining malware, enroll compromised enterprise and IoT devices into their botnet, and facilitate lateral movement across affected networks. The campaign demonstrates advanced threat sophistication, including rapid deployment of botnet payloads and persistent communication over encrypted channels, resulting in operational disruption and the risk of sensitive data exposure for impacted organizations. This incident underscores an uptick in supply chain and application-layer attacks, particularly on modern frameworks like Next.js. With attackers automating exploitation of recently disclosed vulnerabilities, organizations must prioritize patch management and adopt Zero Trust controls to defend against evolving botnet campaigns.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
SmarterMail 2025: Critical Pre-Auth File Upload Flaw Threatens Global Email Servers
Impact· low

SmarterMail 2025: Critical Pre-Auth File Upload Flaw Threatens Global Email Servers

In December 2025, Singapore's Cyber Security Agency (CSA) issued an alert concerning a critical pre-authentication vulnerability (CVE-2025-52691) in SmarterTools SmarterMail email servers. The flaw allows unauthenticated remote attackers to upload arbitrary files to any location on the server, leveraging an unvalidated GUID parameter for path traversal via the '/api/upload' endpoint. An attacker could exploit this for remote code execution, potentially resulting in full compromise of the server, with malicious files executed under system privileges. Although no in-the-wild exploitation has been confirmed, more than 16,000 vulnerable public-facing servers were identified globally. This incident underscores growing risks from exposed infrastructure and rapid exploitation of high-severity application flaws. With threat actors increasingly targeting business-critical communication platforms, organizations face mounting pressure to quickly remediate vulnerabilities and bolster segmentation and detection capabilities in line with zero trust frameworks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Evasive Panda APT Uses DNS Poisoning for Prolonged Espionage: 2022–2024 Campaign
Impact· medium

Evasive Panda APT Uses DNS Poisoning for Prolonged Espionage: 2022–2024 Campaign

Between November 2022 and November 2024, the China-linked Evasive Panda APT group conducted a sophisticated cyber espionage campaign targeting entities in Türkiye, China, and India. The attackers leveraged DNS poisoning techniques to redirect requests for popular software updates (such as SohuVA and Tencent QQ) to attacker-controlled infrastructure. Through adversary-in-the-middle attacks, victims received trojanized loaders, which proceeded to fetch and decrypt highly targeted MgBot backdoors. The attack chain involved supply chain and AitM vectors, advanced encryption and obfuscation methods, and allowed persistent compromise and broad data theft, including keylogging and credential exfiltration. This campaign highlights the growing sophistication of APT operations exploiting core network infrastructure such as DNS to evade perimeter defenses. The increased prevalence of similar DNS-manipulation campaigns and targeted malware delivery emphasizes the urgent need for robust segmentation, encrypted traffic, and thorough network and endpoint visibility.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Evasive Panda: APT Delivers MgBot via DNS Poisoning in Asia (2022–2024)
Impact· medium

Evasive Panda: APT Delivers MgBot via DNS Poisoning in Asia (2022–2024)

Between November 2022 and November 2024, the Evasive Panda APT group executed a sophisticated campaign targeting victims primarily in Türkiye, China, and India. Leveraging adversary-in-the-middle (AitM) techniques and DNS poisoning, the attackers delivered a unique MgBot malware implant through fake software updates and stealthy loaders. The operation employed hybrid encryption, memory injection in signed executables, and evaded traditional defenses to maintain long-term persistence. Multiple new and legacy C2 infrastructures enabled sustained access while attackers tailored payloads based on the victim’s OS. This incident showcases the ongoing evolution of nation-state threat actors, utilizing advanced evasion, supply chain impersonation, and DNS manipulation to bypass security controls. It reflects a broader surge in attacks exploiting trust in software supply chains and underlines the need for continuously adaptive security strategies as actor sophistication grows.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Coupang Suffers Massive 2024 Data Breach: 33.7 Million Users Impacted by Credential Abuse
Impact· high

Coupang Suffers Massive 2024 Data Breach: 33.7 Million Users Impacted by Credential Abuse

In early 2024, Coupang, one of South Korea’s largest e-commerce platforms, suffered a data breach that went undetected for nearly five months, compromising the personal information of approximately 33.7 million users. The attacker, suspected to have leveraged compromised insider credentials, gained unauthorized access to databases containing user details including names, email addresses, and contact information. The breach highlights an extended dwell time during which the threat actor potentially exfiltrated significant data without detection, raising concerns over Coupang’s monitoring and response capabilities. Business impacts include reputational damage, regulatory scrutiny, and increased risk of fraud targeting affected users. This incident is highly relevant as it demonstrates the growing threat of credential and insider abuse, long dwell times, and the necessity for more rigorous data protection practices as regulatory pressure around personal data intensifies worldwide.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
AI Advertising Firm Doublespeed Breached: Over 1,000 Smartphones Compromised in 2025 Attack
Impact· medium

AI Advertising Firm Doublespeed Breached: Over 1,000 Smartphones Compromised in 2025 Attack

In October 2025, AI advertising startup Doublespeed suffered a major security breach when a hacker exploited a vulnerability in the company’s backend systems to gain unauthorized access to its phone farm managing over 1,000 AI-generated social media accounts. The attacker was able to both extract confidential data about undisclosed advertising campaigns and seize remote control of the smartphones used to operate the accounts. This exposure illuminated the company’s covert promotion practices and presented significant risks of both data exfiltration and operational compromise. Despite being notified on October 31, the company had not fully remediated access at the time of reporting, heightening concerns about internal controls and disclosure procedures. The breach underscores growing vulnerabilities in companies that use automation at scale, especially in the context of AI-driven influence operations and digital marketing. It reflects broader industry trends: increasing use of phone farms, sophisticated identity evasion, and regulatory scrutiny around undeclared digital ads, all contributing to a shifting cyber threat landscape.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
React2Shell: How Diverse Exploit Techniques Targeted React Server Components in 2023
Impact· medium

React2Shell: How Diverse Exploit Techniques Targeted React Server Components in 2023

In December 2023, ongoing exploit attempts targeting React Server Components were observed, with attackers leveraging a variant known as 'React2Shell.' The threat actors sent crafted HTTP POST requests containing custom headers and malicious payloads exploiting web application vulnerabilities to execute arbitrary shell commands on compromised systems. Attackers expanded their reach by diversifying target endpoints (e.g., /, /api, /app) as previously vulnerable systems dwindled. The payloads enabled remote code execution, posing a risk of full system compromise and lateral movement across victim networks. The direct business impact includes potential data breach, operational disruptions, compliance failures, and reputational harm for affected organizations. This incident highlights evolving web application exploitation tactics, including the constant adaptation of attackers as defenses improve. The surge in diverse exploit attempts against publicly exposed development components like React reflects broader trends in both sophistication and frequency of web-based threats, stressing the imperative for proactive threat detection and rapid patch management.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports