The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Internet
Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.
Explore Other Sectors
Internet Threat Reports
SoundCloud 2024 Breach Exposes Member Data and VPN Vulnerabilities
In June 2024, SoundCloud experienced a significant security breach where threat actors compromised their infrastructure, resulting in outages and disruption of VPN connectivity. The attackers exfiltrated a database containing users' email addresses and profile information, exposing sensitive member data. The attack led to service interruptions that impacted both staff operations and user access, highlighting vulnerabilities in SoundCloud’s VPN and internal data security protocols. Subsequent investigations revealed that unencrypted network traffic and insufficient segmentation allowed the attackers to move laterally and extract confidential data. This incident exemplifies the growing trend of targeting cloud-based media platforms using sophisticated techniques, including exploiting VPN weaknesses and lateral movement within corporate networks. With regulatory scrutiny increasing around customer data privacy and the persistent rise in credential-driven breaches, organizations face mounting pressure to strengthen east-west security and encrypted network controls.
8 months ago
Kill Chain
Parked Domains Weaponized: Inside the 2025 Typosquatting Malvertising Surge
In late 2025, security researchers uncovered that over 90% of parked domains—unused, expired, or misspelled web addresses—were actively redirecting visitors to malicious destinations, including scams, malware, and deceptive subscription offers. Utilizing techniques like device fingerprinting, IP geolocation, and chained redirects, threat actors profited by manipulating the domain parking ecosystem, turning innocuous navigation mistakes into vectors for malware delivery and fraud. The campaign targeted high-profile brands and government offices, often bypassing detection by profiling user access (e.g., residential IPs or VPN use), with some domains weaponized for business email compromise. This incident highlights an alarming shift: parked and typo domains are now a primary malvertising risk, not a minor threat. As domain registration and ad platform policies evolve, attackers rapidly adapt, exploiting weaknesses in digital trust and endpoint security. Organizations must broaden threat detection and policy enforcement to address direct navigation attacks and affiliate-driven malvertising.
8 months ago
Kill Chain
ShinyHunters Extort PornHub: 2024 Analytics Breach Exposes Premium Member Data
In June 2024, adult content platform PornHub became the target of a significant data breach when the ShinyHunters extortion group claimed to have stolen search and viewing history data linked to the site’s Premium members. Attackers reportedly exploited Mixpanel analytics integrations to exfiltrate sensitive user data, including logs of user activity, then threatened public release unless a ransom was paid. PornHub’s operations and brand reputation face heightened scrutiny, especially given the highly sensitive nature of the data involved, with many users fearing exposure and potential blackmail. This incident underscores the ongoing threats facing organizations that handle sensitive personal data, especially as extortion groups increasingly target user activity logs for leverage. Regulatory and reputational risks are amplified by attackers’ focus on analytics platforms, and similar tactics are expected to proliferate across other high-traffic digital properties in 2024.
8 months ago
Kill Chain
PayPal Subscriptions Abused for Advanced Phishing Campaigns in 2024
In mid-2024, cybercriminals exploited PayPal’s legitimate ‘Subscriptions’ billing feature to send authentic-looking emails with fraudulent purchase notifications. By inserting malicious information into the Customer Service URL field, attackers leveraged PayPal’s trusted platform to bypass spam filters, tricking recipients into believing they had initiated a costly subscription. Victims, startled by these official-looking emails, contacted the provided phone numbers, which connected them to threat actors conducting social engineering attacks, potentially resulting in credential theft or financial loss. This incident highlights a growing trend of attackers abusing trusted platforms and supply chain features to execute highly persuasive phishing campaigns. Increased reliance on platform-generated transactional emails, coupled with social engineering, presents new security and compliance challenges for organizations and consumers alike.
8 months ago
Kill Chain
React2Shell Exploit Wave Exposes Web App Security Gaps in 2025
In December 2025, the critical React2Shell (CVE-2025-55182) vulnerability was actively exploited following its public disclosure. Attackers leveraged unsafe deserialization in React Server Components, impacting frameworks including React and Next.js. Proof-of-concept exploits rapidly spread online, with some functional variants enabling remote code execution. Exploit activity was observed from China-nexus threat groups and opportunistic cybercriminals, resulting in widespread targeting of vulnerable systems with cryptominers, infostealers, and webshells. Security vendors and threat researchers noted that while many PoC attacks were ineffective, validated exploits—some featuring advanced WAF bypasses and in-memory payloads—posed serious risks to organizations relying on web application frameworks. The incident highlights the increasing sophistication of attackers in quickly adapting and bypassing newly deployed defenses such as WAF rules. As automated scanning and exploit release cycles accelerate, enterprises face mounting challenges in promptly identifying, patching, and defending against RCE vulnerabilities across their web application infrastructure.
8 months ago
Kill Chain
Cloudflare 2024 Outage: Why Network Resilience and Redundancy Matter More Than Ever
On June 20, 2024, Cloudflare, a major internet infrastructure and security provider, suffered a widespread service outage that disrupted access to thousands of websites and web services globally. The event was characterized by persistent 500 Internal Server Error messages for end users. Cloudflare initiated an internal investigation, ultimately attributing the incident to a critical infrastructure failure rather than a cyberattack or external threat. Throughout the outage, web-facing businesses, SaaS providers, and end-users experienced degraded network performance, extended downtime, and impact to brand trust, illustrating the magnitude of hyperscaler dependencies. The Cloudflare outage highlights the increasing risks associated with concentration of critical internet services and underscores the urgency for organizations to bolster resilience strategies. In an era of heightened service interdependencies and upticks in both incidents and attacks targeting fundamental service providers, outage preparedness and robust incident response planning are more essential than ever.
8 months ago
Kill Chain
How Sophisticated Attackers Exploited the 2025 React2Shell Zero-Day
In June 2025, a critical remote code execution vulnerability named React2Shell (CVE-2025-55182) was exploited in the wild against organizations using React Server Components. Within hours of the public disclosure and patch release, Chinese state-linked groups such as UNC5174 (CL-STA-1015), Earth Lamia, and Jackpot Panda, alongside opportunistic cybercriminals, began mass scanning and targeting exposed systems. The threat actors successfully deployed malware (notably Snowlight and Vshell), established persistent access, conducted credential theft, and attempted to extract Amazon Web Services configuration and credential files. Over 30 organizations across industries suffered breaches, including documented impact on customer cloud environments. This campaign demonstrates the increasing speed and coordination of attackers exploiting newly public vulnerabilities, especially in widely deployed frameworks like React and Next.js. The incident underscores the necessity of rapid patching, improved east-west traffic security, and continuous threat detection, as adversaries quickly weaponize disclosures for initial access and persistent footholds.
8 months ago
Kill Chain
Cloudflare’s 2024 Outage: Lessons from the React2Shell RCE Emergency
In June 2024, Cloudflare experienced a significant outage after emergency patching efforts to address an actively exploited remote code execution (RCE) vulnerability in the React framework, dubbed "React2Shell." The incident unfolded as threat actors began leveraging the vulnerability to attempt unauthorized code execution on internet-facing workloads, prompting Cloudflare to rush critical security mitigations. While the attack itself targeted exploitation routes via React, it was the swift application of mitigations—rather than a direct breach—which triggered widespread downtime, temporarily impacting Cloudflare's global network operations and customer accessibility. This incident underscores the increasing speed and aggression of active exploitation cycles, particularly for zero-day vulnerabilities in widely used frameworks. As attacker sophistication grows and organizations race to patch critical flaws, operational disruptions and collateral damage are becoming more frequent in the ongoing effort to balance security with business continuity.
8 months ago
Kill Chain
Cloudflare Defeats Record 29.7 Tbps DDoS Attack Attributable to AISURU Botnet
In December 2025, Cloudflare successfully detected and mitigated the largest recorded distributed denial-of-service (DDoS) attack, peaking at 29.7 terabits per second. The attack was orchestrated by the AISURU botnet, leveraging up to four million infected hosts to launch a hyper-volumetric assault. The malicious traffic targeted Cloudflare’s infrastructure, testing the limits of web security and putting critical online services at risk of disruption during the 69-second onslaught. This incident illustrates the increasing scale and sophistication of botnet-driven DDoS attacks, forcing organizations to reassess their mitigation strategies. The AISURU attack underscores a troubling trend in the growth of for-hire botnets and record-breaking DDoS volumes seen in 2025. These evolving threats continue to challenge traditional perimeter defenses, making advanced detection, automated response, and robust network segmentation more critical than ever.
8 months ago
Kill Chain
Critical React Flaw Puts Cloud Supply Chains at Immediate Risk
In June 2024, multiple severe vulnerabilities (CVSS 10.0) were discovered in the React JavaScript library, widely used by more than a third of cloud service providers. The flaws, which have been assigned two CVEs, could enable supply-chain attacks by allowing attackers to execute unauthorized code through compromised package updates or dependencies. If exploited, these vulnerabilities may lead to credential theft, lateral movement, and unauthorized access to sensitive cloud workloads, severely impacting the confidentiality and integrity of customer data. Cloud providers were urged to apply emergency patches and audit their environments for suspicious activity. This incident exemplifies the increasing risk posed by software supply-chain vulnerabilities, particularly as critical open-source components underpin cloud and enterprise infrastructures. The speed and scale of exploitation have raised concerns with regulators and CISOs, highlighting escalating threats to core cloud services and compliance programs.
8 months ago
Kill Chain
Critical Supply Chain React Vulnerability Puts Major Web Apps at Risk
In June 2025, a critical deserialization vulnerability (CVE-2025-55182) was discovered in React Server Components, an open-source project underpinning a vast ecosystem of web frameworks. The flaw, initially reported by security researcher Lachlan Davidson, allowed unauthenticated attackers to execute remote code in default configurations of major frameworks—most notably Next.js—and impacted about 39% of cloud environments using vulnerable packages. Meta, Vercel, and affected project maintainers issued emergency patches, with no exploitation observed before public disclosure, but technical details were widely circulated, causing industry-wide urgency for remediation. This incident demonstrates the growing risks associated with open-source supply chain dependencies and highlights how a single upstream vulnerability can propagate rapidly across major SaaS platforms and developer environments. The ease of exploitation and prevalence of the affected components elevate concerns about lateral movement, credential exposure, and long-tail risk in environments slow to update or lacking robust software composition analysis.
8 months ago
Kill Chain
ShadowV2 Botnet Turns AWS Outage into Opportunity: 2024 IoT and Hybrid Cloud Attacks Surge
In June 2024, a new botnet malware known as ShadowV2 emerged, leveraging Mirai source code to target IoT devices, particularly from D-Link and TP-Link, exploiting known vulnerabilities for large-scale infection. Security researchers observed the malware operators using the widespread AWS outage as an opportunity to test command and control resilience, evade detection, and enhance lateral spread across hybrid and cloud networks. Initial access occurred via unpatched vulnerabilities in internet-facing devices, leading to rapid compromise and recruitment of thousands of endpoints, posing heightened risks to corporate and critical infrastructure systems. Detection was challenged by the use of encrypted and east-west traffic, with attackers adapting quickly to shifting network topologies. This incident highlights the increasing sophistication of IoT-focused botnets and their opportunistic exploitation of cloud service disruptions. Organizations with hybrid or cloud-connected assets are strongly urged to reassess east-west traffic controls, segmentation, and anomaly detection, as automated threats now more readily exploit both vulnerable devices and network instability.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports