The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Internet

Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.

260 threat reports
Page 21 of 22

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Internet Threat Reports

Showing 241–252 / 260 reports
Israeli-Linked AI Disinformation Campaign Targets Iran Amid Evin Prison Strike
Impact· high

Israeli-Linked AI Disinformation Campaign Targets Iran Amid Evin Prison Strike

In June 2023, a coordinated network linked to the Israeli government, dubbed PRISONBREAK, used AI-generated deepfake content and social media manipulation to incite unrest in Iran amid escalating regional tensions and real-world airstrikes. Researchers at Citizen Lab and Clemson University uncovered how this sophisticated influence campaign leveraged newly created accounts on X to disseminate doctored videos and imagery—often timed with kinetic events such as an Israeli strike on Tehran’s Evin Prison. The operation successfully tricked news outlets and amassed significant engagement, specifically pushing calls for uprisings against the Iranian government. This incident spotlights the growing use of state-backed AI-enabled disinformation as a tool of hybrid warfare, bridging digital and physical attacks to maximize psychological impact. It exemplifies the broadening threat landscape, where credible-seeming content can intensify volatility and erode trust in open information ecosystems.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
UAT-8099 Hijacks IIS Servers: SEO Fraud and Data Theft Exposed
Impact· high

UAT-8099 Hijacks IIS Servers: SEO Fraud and Data Theft Exposed

In early 2024, the Chinese-language cybercrime group UAT-8099 orchestrated a sophisticated series of attacks targeting Internet Information Services (IIS) web servers belonging to reputable organizations worldwide, including technology firms, telecoms, and universities. Exploiting insecure internet-facing servers with weak file upload controls, the attackers established footholds using open source web shells. They escalated privileges, enabled remote access with OSS reverse proxy tools, and deployed 'BadIIS' implants to perform SEO poisoning, redirecting search engine traffic to fraudulent gambling and scam sites. Simultaneously, the threat actors exfiltrated credentials, configuration files, and certificates, setting the stage for future attacks or data sales on darknet markets. This campaign demonstrates the threat actor's multi-pronged approach, blending fraud and espionage in ways that evade immediate detection. The incident highlights a growing global trend where SEO manipulation and credential theft converge, exposing organizations to operational, reputational, and regulatory risks amidst rising regulatory scrutiny around digital trust and supply chain integrity.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
TOTOLINK X6000R Routers: 2025 Vulnerabilities Uncovered in Edge Devices
Impact· low

TOTOLINK X6000R Routers: 2025 Vulnerabilities Uncovered in Edge Devices

In June 2025, three new critical vulnerabilities (CVE-2025-52905, CVE-2025-52906, CVE-2025-52907) were discovered in TOTOLINK X6000R routers by Palo Alto Networks' Unit 42 researchers. These flaws exposed the devices to remote code execution and unauthorized access, potentially allowing attackers to gain persistent control over affected networks. The vulnerabilities stem from insecure input validation, weak authentication mechanics, and flaws in firmware that could be exploited over the internet. Immediate patching and network segmentation were recommended to prevent exploitation while vendor mitigation efforts commenced. This incident highlights ongoing risks to consumer and small business gateway devices, demonstrating how router vulnerabilities remain a rich attack surface for cyber actors. The event underscores the urgency for continuous vulnerability research, robust patch management, and defense-in-depth to counter the accelerating trend of targeting edge and IoT devices.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Datzbro Android Trojan Exploits Elderly via Facebook Travel Event Scams in 2025
Impact· medium

Datzbro Android Trojan Exploits Elderly via Facebook Travel Event Scams in 2025

In August 2025, cybersecurity researchers discovered a sophisticated Android banking trojan named Datzbro targeting elderly users in Australia. The malware spread through AI-generated Facebook groups promoting travel events for seniors, tricking victims into installing a malicious app under the guise of exclusive event details. Once installed, Datzbro enabled full device takeover, allowing threat actors to intercept credentials, manipulate transactions, and conduct fraudulent activities undetected, resulting in significant financial losses for victims and the potential compromise of sensitive personal data. This incident highlights the growing exploitation of AI-driven social engineering techniques and the increasing focus on vulnerable demographics like the elderly. The convergence of advanced mobile malware and tailored deception campaigns presents escalating risks for global financial institutions and their customer bases.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Interpol Uncovers Major Romance Scam and Sextortion Networks in Africa
Impact· high

Interpol Uncovers Major Romance Scam and Sextortion Networks in Africa

In June 2024, Interpol coordinated "Operation Contender 3.0" across 14 African countries, arresting 260 individuals involved in cyber-enabled romance scams and sextortion schemes. The operation disrupted 81 cybercrime networks and resulted in the seizure of devices, forged documents, and other cybercrime infrastructure. Authorities uncovered nearly $2.8 million in losses affecting almost 1,500 victims, with Ghana and Senegal among the countries making substantial arrests and asset recoveries. Criminal networks exploited online platforms to deceive victims, using forged identities, stolen images, and blackmail tactics to extort payments or sensitive information. This operation highlights the escalating threat of social engineering attacks and cyber-enabled financial fraud in rapidly digitizing regions. As online interactions increase, so do identity-driven scams, making it critical for organizations and individuals alike to strengthen digital vigilance and invest in layered, resilient cybersecurity controls.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Vane Viper Powers 1 Trillion DNS Queries in 2025 Malvertising Mega-Breach
Impact· high

Vane Viper Powers 1 Trillion DNS Queries in 2025 Malvertising Mega-Breach

In September 2025, the threat actor group known as Vane Viper was revealed to be operating a vast and covert ad fraud and malvertising network, leveraging a staggering one trillion DNS queries to enable malware distribution globally. According to a detailed Infoblox technical report, Vane Viper manipulated core internet infrastructure using shell companies and complex ownership structures to obfuscate responsibility and perpetuate malicious adtech practices. Their operations enabled widespread malvertising campaigns, significantly impacting advertising platforms and exposing users worldwide to illicit downloads and credential theft. This breach underscores a recent surge in the use of advanced DNS tunneling and obfuscation tactics in cybercrime, particularly within ad fraud and malvertising schemes. The incident exemplifies how attackers increasingly exploit foundational internet protocols, challenging traditional detection and defense measures while prompting urgent regulatory attention and industry-wide response.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Webshells Hidden in .well-known Directories: The 2024 Web Application Attack Trend
Impact· medium

Webshells Hidden in .well-known Directories: The 2024 Web Application Attack Trend

In September 2024, cybersecurity researchers observed a surge in malicious actors targeting the .well-known directory on web servers to deploy PHP-based webshells. Attackers exploited this typically-overlooked directory, intended for status and authentication files, as it remains web-accessible but hidden within the Unix filesystem. Logs and honeypot data detailed repeated attempts to probe and establish footholds via .well-known and its subdirectories, such as acme-challenge and pki-validation, with the clear goal of persistent, covert remote control. This technique illustrates an evolving trend in web application attacks, where multistage threats exploit common web standards and overlooked controls. Organizations face heightened risk from such stealthy compromises, underscoring the need for continuous monitoring and adaptive defense in the current threat landscape.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Iframe Security Exposed: The 2025 Rise of Payment Skimmer Attacks
Impact· high

Iframe Security Exposed: The 2025 Rise of Payment Skimmer Attacks

In September 2025, a widespread web application attack exploited payment iframes across major online retailers to deploy advanced payment skimmer malware. Attackers leveraged vulnerabilities in embedded iframe components on e-commerce checkout pages, bypassing client-side security controls and web isolation policies to secretly harvest customer credit card data. The campaign remained undetected for weeks, affecting thousands of transactions globally and prompting emergency mitigation efforts, reputational impact, and regulatory scrutiny for affected organizations. This incident highlights the urgent need for stronger web application and iframe security, as payment skimming through novel overlay techniques continues to surge. Organizations are under increased regulatory pressure to harden PCI compliance and prevent supply chain-driven client-side attacks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Cloudflare Thwarts Record-Breaking 22.2 Tbps DDoS Assault in 2025
Impact· high

Cloudflare Thwarts Record-Breaking 22.2 Tbps DDoS Assault in 2025

In September 2025, Cloudflare successfully mitigated a record-breaking Distributed Denial-of-Service (DDoS) attack that peaked at 22.2 Tbps and 10.6 billion packets per second. Orchestrated over just 40 seconds, the massive volumetric attack overwhelmed network infrastructure, pushing the limits of firewalls, routers, and load balancers. Prior research links recent large-scale DDoS campaigns—including those hitting Cloudflare—to the AISURU botnet, which leveraged a sudden increase in infected devices globally, stemming in part from exploited router firmware vulnerabilities. Business impact was minimized due to Cloudflare’s rapid mitigation, but the attack underscores the ever-increasing scale and sophistication of DDoS threats. Record-breaking DDoS attacks are climbing in frequency and intensity, with attackers exploiting IoT vulnerabilities and leveraging formidable botnets. This surge highlights the urgent need for resilient, scalable mitigation strategies, and amplifies ongoing regulatory and industry pressure to strengthen defenses against large-scale infrastructure threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Operation Rewrite: Chinese SEO Poisoning Surges in 2024, Compromising Trusted Web Servers
Impact· low

Operation Rewrite: Chinese SEO Poisoning Surges in 2024, Compromising Trusted Web Servers

In early 2024, security researchers identified 'Operation Rewrite,' a sophisticated SEO poisoning campaign linked to a suspected Chinese threat actor. The attackers compromised numerous legitimate web servers, injecting malicious content designed to boost the search ranking of infected sites for financial gain. Unsuspecting users were redirected from popular search results to websites hosting malware or phishing content. The campaign leveraged legitimate server infrastructure to evade traditional detection, complicating mitigation and exposing visitors to potential credential theft, malware infections, and broader data compromise. The attackers’ tactics allowed them to rapidly spread harmful payloads while remaining concealed among normal web traffic. This incident underscores a sharp increase in SEO poisoning and supply chain abuse, as adversaries prioritize techniques that abuse trust in widely visited websites and search engines. With web browsing essential to daily business operations, organizations face mounting risks from threats that bypass perimeter defenses by posing as reputable content.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
SystemBC Malware: How Infected VPS Systems Became a Global Proxy Highway (2025)
Impact· medium

SystemBC Malware: How Infected VPS Systems Became a Global Proxy Highway (2025)

In September 2025, security researchers from Lumen Technology’s Black Lotus Labs uncovered a significant increase in the activity of the SystemBC proxy botnet, which compromised an average of 1,500 commercial virtual private servers (VPS) daily by exploiting unpatched and critically vulnerable systems. SystemBC enabled threat actors, including ransomware gangs and criminal proxy networks, to route malicious traffic through infected VPS infrastructures, obscuring command-and-control activity and facilitating large-scale cyberattacks, such as WordPress brute-forcing and malware distribution. Impacted servers often had dozens of security flaws, with infection lifespans exceeding a month and some systems exhibiting over 100 vulnerabilities. The prevalence of SystemBC underscores a growing shift away from traditional residential botnets toward high-bandwidth, stable VPS resources easily abused due to lax patching. The incident amplifies urgent concerns around lateral movement, proxy abuse, and the need for robust network segmentation and real-time anomaly detection as attackers leverage compromised enterprise-grade infrastructure for persistent threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Dshield Honeypot Exposes IoT Botnet Worm Using Default Credentials in 2024
Impact· high

Dshield Honeypot Exposes IoT Botnet Worm Using Default Credentials in 2024

In September 2024, analysis of a Dshield honeypot deployed on AWS revealed a campaign targeting internet-exposed systems with IoT-focused botnet malware. Attackers attempted to upload shell scripts and architecture-specific binaries using known default credentials and exploited weak or unchanged passwords, particularly on Raspberry Pi and IoT devices. The payloads, often delivered over unencrypted FTP and SSH methods, led to the installation of UNIX_PIMINE.A malware, which achieves persistence, removes competing malware, and connects to IRC-based command-and-control channels, highlighting an active botnet spreading via automated credential stuffing and remote file uploads. This incident underscores a persistent threat: legacy systems and embedded devices with default or weak credentials remain a prime target for botnets. With continued rises in IoT deployments and exposed services, automated malware propagation using basic scripts and known default logins is resurging, driving renewed regulatory scrutiny and best-practice emphasis for credential management and east-west traffic security.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports