The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Internet
Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.
Explore Other Sectors
Internet Threat Reports
JackFix Campaign Exploits Fake Windows Updates to Spread Infostealers in 2025
In late 2025, cybersecurity researchers uncovered a campaign orchestrated by the JackFix group using cloned adult websites as a phishing lure, distributed primarily through malvertising channels. Victims visiting these sites were presented with fake Windows update pop-ups designed to imitate critical security notifications. Unsuspecting users were tricked into executing malicious payloads that installed multiple information stealers, enabling the attackers to exfiltrate credentials, session tokens, and sensitive browser data. This attack illustrates how adversaries exploit popular platforms and social engineering to bypass traditional security controls, posing significant risks to both individuals and enterprises. The incident is particularly significant given the continued adoption of sophisticated phishing techniques and the blending of legitimate web content with highly convincing fraudulent prompts. Enterprises must remain vigilant as such campaigns highlight persistent weaknesses in endpoint protections, user awareness, and lateral movement defenses against infostealers.
8 months ago
Kill Chain
How Phishing-as-a-Service Scams Exploited USPS and E-Z Pass: The Lighthouse Case
In 2025, Google filed a legal complaint against a China-based cybercriminal group alleged to have developed 'Lighthouse' Phishing-as-a-Service (PaaS) kits. These kits empower low-skilled actors to execute widespread smishing (SMS phishing) and e-commerce scams by providing templates, domain setup tools, and fake websites mimicking trusted brands such as USPS and E-Z Pass. Victims are lured via texts about overdue fees or package deliveries, redirecting them to realistic phishing sites that harvest credentials and financial information. The campaign leveraged legitimate ad platforms and payment methods, increasing its reach and credibility. The incident underscores the rising threat and sophistication of PaaS offerings, which lower the barrier for cybercrime and accelerate the proliferation of phishing campaigns. As threat actors streamline attack automation and mimic reputable organizations, enterprises must adapt with real-time detection, segmented network defenses, and stronger authentication measures.
8 months ago
Kill Chain
Cloudflare's 2024 Outage: What Happens When Cloud Control Goes Wrong?
On June 25, 2024, Cloudflare experienced its most significant outage since 2019, following a change to its database access controls that inadvertently propagated across its global network. This technical misconfiguration caused a cascade of failures, disabling the company's control plane and blocking access to thousands of websites and web services worldwide for nearly six hours. The incident was not attributable to cyberattack or malicious activity, but the widespread and prolonged downtime severely impacted Cloudflare's customers and highlighted the fragility of large-scale, cloud-driven infrastructure when faced with operational errors. This outage underscores a growing concern for enterprises reliant on cloud providers, as administrative mistakes and configuration errors have outsized impacts on digital availability. With rapid cloud adoption and increasingly complex infrastructures, businesses must prioritize robust change controls, real-time monitoring, and automated rollback capabilities to mitigate similar risks.
8 months ago
Kill Chain
Cloudflare 2025 Outage: A Wakeup Call for Web Security Resilience
In November 2025, Cloudflare suffered a significant intermittent outage lasting approximately eight hours, which disrupted access for many major websites relying on its services for security and DNS management. The outage was caused by an internal configuration error that expanded a critical feature file, impacting Cloudflare's Bot Management system and resulting in platform instability. Some organizations temporarily bypassed Cloudflare, exposing themselves directly to internet traffic and revealing vulnerabilities previously shielded by Cloudflare's protective layers, such as web application firewall (WAF), bot filtering, and DNS controls. These exposures led to increased malicious probing, raising concerns about previously undetected weaknesses and an overreliance on single-vendor security solutions. The incident highlights the growing operational and security risks of single-vendor dependency, especially as organizations rely more heavily on integrated cloud platforms for web security and availability. Broad industry adoption of zero trust and multi-cloud strategies is now a pressing priority to mitigate similar service disruptions and emergent threats.
8 months ago
Kill Chain
Cloudflare's 2024 Outage: How a Simple Misconfiguration Led to Global Disruption
In June 2024, Cloudflare, a leading cloud services provider, experienced a major global outage initially suspected to be the result of a distributed denial-of-service (DDoS) attack. Further investigation revealed that the real cause was an internal configuration error: a routine permissions update inadvertently triggered a critical software failure within network infrastructure, disrupting access to innumerable customer websites and business services for several hours worldwide. The incident underscored the fragile interplay between automated change management and resiliency of cloud-based operations. This outage is especially timely as organizations accelerate cloud adoption and automation, increasing their susceptibility to operational lapses and accidental misconfigurations. Regulatory bodies and industry frameworks are now sharpening requirements for cloud governance, real-time visibility, and robust change controls to mitigate such risks.
8 months ago
Kill Chain
CISA 2025 Issues Guidance to Mitigate Bulletproof Hosting Provider Risks
In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA), together with the NSA, FBI, Department of Defense Cyber Crime Center, and international partners, released comprehensive guidance to combat risks posed by Bulletproof Hosting Providers (BPHs). BPHs are infrastructure providers that knowingly lease servers and networking resources to cybercriminals, enabling ransomware, phishing, malware distribution, and denial-of-service attacks at scale. The guidance urges Internet Service Providers and network operators to apply blocklists, traffic analysis, intelligence sharing, and stronger vetting to prevent malicious actors from exploiting BPH resources, aiming to bolster the digital resilience of critical infrastructure sectors globally. The ongoing proliferation of cyberattacks leveraging BPH infrastructure underscores the urgency of these recommendations. With threat actors increasingly turning to anonymized, resilient hosting to evade law enforcement and detection, proactive mitigation by ISPs is crucial to limiting damage and strengthening industry-wide cybersecurity defense.
8 months ago
Kill Chain
ImunifyAV RCE Flaw Puts Millions of Linux Websites at Immediate Risk in 2024
In June 2024, a critical remote code execution (RCE) vulnerability was discovered in ImunifyAV, a malware scanner widely deployed on Linux web servers hosting millions of websites globally. Attackers could exploit this unauthenticated flaw to execute arbitrary code on vulnerable servers, potentially gaining full control over hosting environments and compromising customer websites at scale. The flaw threatened the security of hosting providers and their clients, enabling advanced threat actors to launch further attacks, steal data, or deploy additional malware. Immediate patching was required to prevent exploitation in the wild. This incident underscores the increasing risks posed by third-party security tool vulnerabilities, especially in shared and cloud-hosted web environments. Rapid exploitation of newly disclosed software flaws and supply chain attacks continues to rise, highlighting the critical importance of timely patch management and zero trust controls.
8 months ago
Kill Chain
Google Targets Smishing Triad: 2025 Lawsuit Disrupts Phishing-as-a-Service Operations
In November 2025, Google filed a landmark lawsuit in the Southern District of New York targeting the so-called "Smishing Triad," a China-based phishing-as-a-service group responsible for operating the Lighthouse phishing kit. This kit empowers cybercriminals to impersonate over 400 brands and conduct high-volume SMS attacks, luring victims worldwide into divulging payment information and one-time passcodes. Attackers leveraged the compromised data to enroll payment cards in mobile wallets on Apple and Google devices, allowing them to transact and cash out at scale. Google identified over a million victims in 120 countries, with Smishing Triad operators rotating up to 25,000 phishing domains in an eight-day window. The case highlights an increasing sophistication and industrialization of mobile phishing schemes, where threat actors utilize automation, rapid domain turnover, and collaboration across specialized roles. Legal escalation by a major tech company reflects growing efforts to disrupt cross-border cybercrime ecosystems that evade technical and regulatory countermeasures.
8 months ago
Kill Chain
Cloudflare Top Domain Rankings Compromised by Aisuru Botnet in 2025
In October 2025, Cloudflare faced an unprecedented attack by the Aisuru botnet, a rapidly scaling network of compromised IoT devices. The botnet leveraged its vast fleet to overwhelm Cloudflare's public DNS resolver (1.1.1.1) with massive volumes of automated queries, propelling its malicious command-and-control domains to the top ranks of Cloudflare's most-queried website list. This manipulation triggered widespread concern over data integrity and brand confusion, as Aisuru domains temporarily displaced legitimate top domains like Google and Apple. In response, Cloudflare resorted to redacting and eventually removing suspicious domains from its ranking list, highlighting significant security gaps in popular trust datasets. This incident underscores the mounting risk posed by large IoT botnets to critical internet infrastructure, including DNS reliability and reputation-based services. It reveals how attackers exploit both technical and social trust mechanisms, with potential downstream effects on security decisions that leverage third-party domain rankings.
8 months ago
Kill Chain
Arrest of 764 Group Leader Signals Crackdown on Online Child Exploitation and Extremism
In December 2023, Baron Cain Martin, alleged leader of the violent extremist group 764, was arrested in Tucson, Arizona, following an extensive federal investigation. Unsealed in June 2024, the indictment charges Martin with 29 counts, including producing and distributing child sexual abuse material (CSAM), cyberstalking, conspiracy to commit wire fraud, animal cruelty, and providing material support to terrorists. Federal law enforcement alleges that Martin not only led the illicit collective but also created detailed guides for grooming and exploiting minors. The operation exploited online anonymity, targeting vulnerable young individuals across the globe. At least nine victims, primarily minors, have been identified, with the group's activities linked to broader networks such as The Com. The Martin case spotlights alarming trends in cyber-enabled abuse and violent extremism, highlighting law enforcement’s ongoing efforts to dismantle depraved online collectives. The prosecution’s severity underscores rising societal and regulatory pressure to address digital child exploitation, encrypted criminal coordination, and psychologically manipulative methods used by such groups.
8 months ago
Kill Chain
Critical 2025 Raisecomm Authentication Bypass: Root Access Risk to ICS Networks
In October 2025, a critical remote authentication bypass vulnerability (CVE-2025-11534) was publicly disclosed in Raisecomm RAX701-GC series network equipment, allowing unauthenticated attackers to establish SSH sessions and gain root shell access without providing valid credentials. Discovered and reported by security researchers from runZero, this exploit poses an elevated risk to infrastructure sectors relying on these devices globally, as affected firmware versions remain susceptible with exploits achievable at low complexity and no prior privileges. Business and operational impacts include full remote compromise, lateral movement potential, and the ability for attackers to implant persistent threats or disrupt essential communications and IT operations. The incident is especially pressing now, indicating a rising trend in targeting embedded and edge devices in critical environments via misconfigurations or software flaws. As attackers expand their focus to accessible infrastructure, organizations face increasing pressure to implement robust access controls, proactive segmentation, and defense-in-depth strategies to safeguard operational networks.
8 months ago
Kill Chain
Aisuru Botnet’s 2025 Shift: From DDoS Disruptor to Proxy Powerhouse
In mid-2025, the Aisuru botnet—already infamous for record-shattering distributed denial-of-service (DDoS) attacks—shifted tactics, repurposing hundreds of thousands of compromised Internet of Things (IoT) devices to fuel residential proxy networks. Initially detected in August 2024, Aisuru rapidly infected over 700,000 vulnerable routers and cameras, enabling DDoS attacks reaching up to 30 terabits per second. As global internet providers struggled to mitigate these waves, Aisuru’s operators began renting bot-infected devices as residential proxies, granting cybercriminals more effective means to anonymize web scraping, credential stuffing, and data harvesting operations. This incident marks a significant escalation in how botnets are monetized, as botnet-powered residential proxies become a key enabler for content scraping—especially by AI firms seeking vast datasets. The pivot highlights a rising convergence between traditional cybercrime and emerging AI-driven abuse, challenging defenders to address both volumetric attack trends and subtle, persistent data exfiltration.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports