The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Internet
Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.
Explore Other Sectors
Internet Threat Reports
CVE-2026-87886: Acronis cPanel Backup Plugin Under Active Attack
Acronis disclosed that CVE-2026-87886, a high-severity privilege escalation vulnerability in its Backup plugin for cPanel and WHM deployments, has been actively exploited in targeted attacks. The flaw, scoring 7.8 on CVSS, stems from insecure file permissions that allow attackers with low-level access to escalate privileges on vulnerable Linux systems. Successful exploitation enables unauthorized actions and arbitrary code execution, potentially compromising application confidentiality and integrity across web hosting environments. This incident highlights the growing trend of supply chain vulnerabilities targeting managed hosting infrastructure, where a single compromised plugin can provide attackers with elevated access across multiple customer environments. The active exploitation underscores the critical need for immediate patch management in hosting environments where administrative tools create expanded attack surfaces.
1 week ago
Kill Chain
Black Axe Cybercrime Leaders Face US Charges: The Evolution of Romance Scam Operations
Five alleged leaders of the Black Axe cybercrime syndicate were extradited from South Africa to the United States in September 2026 to face wire fraud and money laundering charges. The defendants orchestrated a decade-long internet fraud campaign from 2011 to 2021, using romance scams and advance fee schemes to defraud victims across multiple platforms including social media and dating websites. The operation involved sophisticated social engineering tactics, including threats of publishing compromising materials when victims refused to send money. This case highlights the increasing international cooperation in cybercrime prosecution and the growing threat of transnational organized crime groups leveraging digital platforms for financial fraud at unprecedented scale.
1 week ago
Kill Chain
CVE-2026-87886: Acronis cPanel Backup Plugin Under Active Attack
In September 2026, Acronis disclosed CVE-2026-87886, a high-severity Linux local privilege escalation vulnerability in its backup plugins for cPanel, WebHost Manager (WHM), and Plesk. The vulnerability allows low-privileged attackers to escalate permissions on vulnerable Linux servers without user interaction, potentially enabling access to sensitive data and system disruption. Acronis confirmed active exploitation in limited, targeted attacks against hosting environments, prompting immediate patching recommendations for affected versions. This incident highlights the growing trend of attackers targeting web hosting infrastructure and third-party plugins, which provide attractive attack surfaces due to their privileged access to multiple customer environments and critical business operations.
1 week ago
Kill Chain
Critical LiteSpeed Enterprise Flaw Exposes Shared Hosting Infrastructure to Root Access Attacks
A critical privilege escalation vulnerability in LiteSpeed Web Server Enterprise versions before 6.3.7 allows low-privilege hosting account users to gain root access on shared hosting servers. Disclosed by cPanel on September 14, 2026, the flaw bypasses security controls including CageFS that normally isolate hosting accounts from each other. The vulnerability enables attackers with basic hosting accounts to access or alter other customers' websites and compromise the entire server infrastructure. LiteSpeed released version 6.3.7 on September 11 to address the issue, though specific technical details and CVE assignment remain pending. This represents the third LiteSpeed-related privilege escalation flaw reported since May 2026, highlighting ongoing security challenges in shared hosting environments where multiple customer websites coexist on single servers.
1 week ago
Kill Chain
Black Axe Cybercrime Leaders Extradited: International Crackdown on Romance Scam Network
Five alleged leaders of Black Axe's South African operations were extradited to the United States in December 2024 to face charges related to romance scams and advance fee fraud. The Nigerian nationals, including Cape Town zone founder Perry Osagiede, operated sophisticated financial fraud schemes from 2011-2021, using fake identities to manipulate victims into sending money through fabricated emergencies, business partnerships, and romantic relationships. The group leveraged business entities and compromised victim accounts to launder proceeds, with some cases involving extortion through threats to release sensitive photos. This extradition represents the latest phase of intensified global law enforcement action against Black Axe, a hierarchical cybercrime organization generating billions in annual criminal proceeds across dozens of countries. The coordinated international response demonstrates increasing capability to pursue transnational cybercriminals across jurisdictions and disrupt their financial networks.
1 week ago
Kill Chain
Mass Campaign Exploits Vite CVE-2026-39364 to Steal Cloud Credentials
A mass-scanning campaign targeting internet-exposed Vite development servers exploited CVE-2026-39364, a high-severity vulnerability affecting Vite versions 7.1.0 through 7.3.2 and 8.x before 8.0.5. Attackers used query parameter manipulation to bypass file access controls and steal AWS and Azure cloud credentials, configuration files, and environment variables. F5 detected over 800 attacks and 32,000 events within a month, with attackers primarily using Google Cloud IP ranges from the US, Belgium, and Netherlands for evasion. This campaign highlights the growing threat to exposed development environments and the critical need for proper configuration management and credential protection in cloud-native deployments.
1 week ago
Kill Chain
How HBO Max's Hijacked Reddit Account Became a Malware Distribution Network
In September 2026, cybercriminals compromised HBO Max's verified Reddit account and launched 108 malicious advertisements over 48 hours, targeting both Windows and macOS users through ClickFix social engineering attacks. The campaign, linked to the broader PasteSwitch operation, tricked victims into executing malicious commands through legitimate system tools like PowerShell and Terminal, bypassing traditional security controls. The attacks distributed information stealers including MacSync and Amatera Stealer, cryptocurrency clippers, and fake wallet applications, demonstrating sophisticated multi-platform targeting capabilities. This incident represents a significant escalation in social media account takeover attacks, where threat actors exploit trusted brand verification to distribute malware at scale. The use of ClickFix techniques shows how attackers are evolving to bypass modern security tools by manipulating users into executing malicious code through legitimate operating system functions.
1 week ago
Kill Chain
3BB Thailand Cyberattack: How Attackers Used MeshCentral Backdoors and Fortinet Exploits
In June 2026, threat actors compromised 3BB, Thailand's largest broadband provider, using a sophisticated attack that leveraged CVE-2024-21762, a critical Fortinet FortiGate SSL-VPN vulnerability. The attackers maintained persistent access through MeshCentral remote management tools configured as hidden backdoors, achieved root-level privileges on internal servers, and targeted RADIUS databases containing subscriber credentials. Hunt.io researchers discovered the ongoing operation through an exposed attacker server containing tools, compromised device lists, and evidence of lateral movement across 3BB's network infrastructure. This incident exemplifies the growing trend of attackers abusing legitimate remote management tools to maintain stealth persistence while exploiting unpatched edge devices for initial access, highlighting critical gaps in network segmentation and credential management practices.
1 week ago
Kill Chain
cPanel SQL Injection Flaw CVE-2026-67401 Enables Complete Server Takeover
cPanel disclosed CVE-2026-67401, a critical SQL injection vulnerability in its EmailTrack functionality that allows authenticated hosting account holders with mail privileges to escalate to root access on entire servers. The flaw affects all supported versions of cPanel and WHM, enabling attackers to create arbitrary files and execute code with administrative privileges. This represents a complete server compromise where attackers can access all hosting accounts, install malware, steal credentials, and pivot into customer networks. cPanel has released patches across multiple release lines including 11.110, 11.134, 11.136, and 11.138. This incident highlights the continuing trend of hosting platform vulnerabilities that enable tenant-to-host escalation attacks. Following similar cPanel flaws disclosed in April, July, and August 2026, hosting providers face increased scrutiny over multi-tenant security boundaries and the cascading impact of single vulnerabilities affecting thousands of customer websites.
2 weeks ago
Kill Chain
DoppelCart Fraud Network Exposes Massive E-Commerce Security Gap
In September 2026, cybersecurity researchers discovered DoppelCart, the largest documented fake e-commerce network comprising over 119,000 fraudulent domains, primarily using the .SHOP TLD. The operation impersonates 44,182 legitimate brands by copying product catalogs and branding, then uses WebSocket connections to steal payment card data, CVV codes, and personal information in real-time during checkout. The network affects 2.72% of all .SHOP domains and significantly surpasses previous operations like BogusBazaar's 75,000 sites, with over 105,000 shops remaining active at discovery. This incident highlights the evolving sophistication of financial fraud networks and their ability to operate at unprecedented scale through automated domain generation and brand impersonation, representing a critical threat to consumer trust and e-commerce security.
2 weeks ago
Kill Chain
StyleSmuggler Zero-Day: How Advanced Backdoors Bypass E-Commerce Security
On September 4, 2026, threat actors began exploiting a zero-day vulnerability dubbed 'StyleSmuggler' affecting all versions of Magento and Adobe Commerce platforms. The attackers leveraged PHP code injection through Magento's template system to generate fake payment failure emails, triggering code execution that deployed a sophisticated Rust-based Linux backdoor. The malware disguises itself as legitimate system processes and establishes persistent command-and-control communication using NTP traffic mimicry to evade detection. With over 160,000 Magento installations worldwide, including 14,000 high-traffic sites, this incident represents a significant supply chain risk. This attack highlights the growing trend of threat actors targeting e-commerce platforms through zero-day exploits, coinciding with increased regulatory scrutiny on supply chain security and the rising sophistication of malware that mimics legitimate network protocols to bypass traditional security controls.
2 weeks ago
Kill Chain
MikroTik SSH Authentication Bypass: Critical RouterOS Vulnerability Demands Immediate Zero Trust Response
In September 2024, MikroTik released an emergency patch for a critical SSH authentication bypass vulnerability affecting RouterOS devices that was already being actively exploited in the wild. The vulnerability allows attackers to completely bypass SSH authentication mechanisms, gaining unauthorized administrative access to network infrastructure devices. Threat actors have been leveraging this flaw to create persistent backdoor accounts on compromised devices, ensuring continued access even after patches are applied. The exploitation campaign has resulted in widespread compromise of MikroTik devices globally, with attackers targeting both enterprise and service provider networks. This incident highlights the critical importance of network infrastructure security and the devastating impact of authentication bypass vulnerabilities on organizational networks and internet infrastructure stability.
2 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports