The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Internet

Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.

260 threat reports
Page 3 of 22

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Internet Threat Reports

Showing 25–36 / 260 reports
MikroTik RouterOS SSH Authentication Bypass: Critical Infrastructure Attack Analysis
Impact· MEDIUM

MikroTik RouterOS SSH Authentication Bypass: Critical Infrastructure Attack Analysis

In September 2026, attackers exploited MikroTik RouterOS devices through internet-exposed SSH services, gaining full administrative control without authentication. CERT Polska reported active exploitation beginning September 2, targeting RouterOS versions 6.0.0-6.49.21, 7.0.0-7.23.4, and 7.24-7.24.2 through a vulnerability combination dubbed 'MikroTrick.' The attacks allowed unauthorized configuration changes and complete device compromise, prompting immediate security updates from MikroTik across multiple RouterOS channels. Network infrastructure attacks like this highlight the critical importance of securing remote access services and implementing proper network segmentation. The incident demonstrates how exposed management interfaces continue to be prime targets for threat actors seeking to establish persistent network footholds and lateral movement capabilities.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
BGP Hijacking Enables Virtualizor Supply Chain Compromise
Impact· HIGH

BGP Hijacking Enables Virtualizor Supply Chain Compromise

In late August 2026, attackers executed a sophisticated supply chain attack against Virtualizor, a popular virtualization management platform, by hijacking Border Gateway Protocol (BGP) routes to redirect software update traffic. The attack occurred between August 28-30, 2026, when threat actors diverted Softaculous traffic to attacker-controlled servers and delivered malicious Virtualizor updates that established persistent root access on affected systems. At least 5 of 34 hypervisors at one hosting provider were compromised, with attackers installing backdoors, creating unauthorized accounts, and maintaining persistence through systemd services. This incident highlights the growing sophistication of supply chain attacks targeting critical infrastructure management software. As organizations increasingly rely on automated software updates and third-party platforms for cloud operations, attackers are exploiting trust relationships and network-level vulnerabilities to achieve widespread compromise with minimal detection.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Chinese Cybercriminals Turn Brazilian Government Sites into Gambling Traffic Redirectors
Impact· MEDIUM

Chinese Cybercriminals Turn Brazilian Government Sites into Gambling Traffic Redirectors

The Chinese-speaking Gambling Goblin cybercrime cluster has been compromising Brazilian government and educational web servers since mid-2025, installing malicious Apache modules to redirect visitors to attacker-controlled gambling and sports betting pages. The campaign leverages compromised high-reputation .gov.br domains to manipulate search engine optimization at scale, with modules reverse-proxying traffic while stripping security headers to allow malicious content execution. Linked to the Earth Berberoka threat group, the operation deploys sophisticated tooling including custom downloaders, modular backdoors, and credential stealers to maintain persistent access to government infrastructure. This incident highlights the growing trend of SEO manipulation attacks targeting government domains for cybercriminal profit, particularly as Brazil's newly regulated online betting market creates lucrative opportunities for threat actors to exploit trusted infrastructure for financial gain.

3 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Major Chrome Extension Malware Campaign Steals Crypto from 80,000+ Users
Impact· HIGH

Major Chrome Extension Malware Campaign Steals Crypto from 80,000+ Users

In August 2026, security researchers at Socket uncovered a sophisticated malware campaign targeting Chrome and Edge browser extensions that had been active since early 2024. Nineteen malicious modules were deployed through initially legitimate extensions, some acquired from original creators and weaponized through automatic updates. The most notable example was the "Enable Right Click & Copy" extension with over 70,000 Chrome users and 10,000 Edge users. The malware established encrypted WebSocket connections to command-and-control servers, removed Content Security Policy headers, and deployed modules capable of draining cryptocurrency wallets, stealing credentials from major exchanges like Coinbase and Binance, harvesting social media data, and deploying ClickFix-style phishing attacks. This incident highlights the growing sophistication of supply chain attacks targeting browser ecosystems, coinciding with increased regulatory scrutiny of app store security practices and the rise of cryptocurrency-focused cybercrime operations that leverage trusted distribution channels.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Factory Implants in ZBT Routers Expose Global Supply Chain Security Crisis
Impact· CRITICAL

Factory Implants in ZBT Routers Expose Global Supply Chain Security Crisis

In August 2026, VulnCheck disclosed two previously undocumented factory implants, SPEAKINGSTONE and DARKLANTERN, found in firmware for routers manufactured by Shenzhen Zhibotong Electronics (ZBT). Both implants, tracked as CVE-2026-74232 and CVE-2026-74233 with CVSS scores of 9.3-9.8, provide unauthenticated remote attackers with root access to affected devices. SPEAKINGSTONE operates as a surveillance implant that beacons to hardcoded command-and-control servers, while DARKLANTERN listens on UDP port 9992 with ineffective authentication. VulnCheck identified over 200 internet-facing DARKLANTERN instances across 22 countries and received beacons from 392 unique devices when they registered the backup C2 domain. This incident highlights the growing threat of supply chain attacks targeting network infrastructure, particularly as organizations increasingly rely on low-cost networking equipment from overseas manufacturers. The discovery comes amid heightened awareness of nation-state activities targeting critical infrastructure and follows similar findings in Chinese-manufactured networking equipment.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical cPanel Domain Parking Vulnerability Enables Root Privilege Escalation
Impact· CRITICAL

Critical cPanel Domain Parking Vulnerability Enables Root Privilege Escalation

In August 2026, cPanel disclosed CVE-2026-65643, a critical vulnerability in domain parking and addon domain functionality affecting all supported versions of cPanel and WebHost Manager (WHM). The flaw allows authenticated users with domain management privileges to create arbitrary files on the server, leading to code execution as the root user and complete server compromise. cPanel released patches across multiple version branches (11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7) with automatic updates available for servers configured for daily updates. This incident highlights the growing trend of privilege escalation vulnerabilities in shared hosting control panels, which continue to be high-value targets for attackers seeking to compromise multiple websites simultaneously. The vulnerability's impact on shared hosting environments makes it particularly concerning given the widespread deployment of cPanel across the hosting industry.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Superior Campaign Exploits Browser Extension Supply Chain to Drain Crypto Wallets
Impact· HIGH

Superior Campaign Exploits Browser Extension Supply Chain to Drain Crypto Wallets

Security researchers from Socket discovered a sophisticated supply chain attack targeting browser extension users, involving 19 malicious Chrome and Edge extensions harboring cryptocurrency wallet-draining capabilities. The campaign, tracked as 'Superior,' has been active since February 2024, with threat actors either creating malicious extensions or purchasing legitimate ones before injecting malicious code in subsequent updates. The extensions collectively reached over 80,000 users, with the malware establishing persistent WebSocket connections to command-and-control servers for data exfiltration and executing cryptocurrency theft modules. This incident highlights the growing threat of browser extension supply chain attacks targeting cryptocurrency assets and sensitive user credentials. The Superior campaign demonstrates how threat actors are increasingly exploiting the automatic update mechanisms of browser extensions to deliver malware at scale, representing a significant evolution in supply chain attack methodologies.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
xAI Faces Class Action Lawsuit Over Grok's Alleged CSAM Generation Capabilities
Impact· CRITICAL

xAI Faces Class Action Lawsuit Over Grok's Alleged CSAM Generation Capabilities

In January 2025, former child sexual abuse victims filed a class action lawsuit against xAI, alleging that the company's Grok AI model was trained on child sexual abuse material (CSAM) to develop deepfake capabilities. The lawsuit claims Grok generated over 3 million sexualized images in 11 days, including approximately 23,000 that appeared to depict children. Plaintiffs argue that xAI's integration of Grok into X's platform, combined with weak content filters, created an instantaneous CSAM generation and distribution system that violates federal child protection laws. This incident highlights the growing risks of AI misuse in generating harmful content, particularly as deepfake technology becomes more accessible and regulatory frameworks struggle to keep pace with technological advancement.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Russian Actors Exploit ChatGPT for Sophisticated Influence Operation
Impact· MEDIUM

Russian Actors Exploit ChatGPT for Sophisticated Influence Operation

In August 2026, OpenAI disrupted a Russian-linked influence operation that used ChatGPT accounts with VPNs to bypass geographic restrictions and generate social media content across multiple platforms. The operation promoted the International Burke Institute (IBI), a fake think tank registered in February 2025, which featured copied academic work, false attributions, and a sovereignty index designed to cast Russia favorably. While the campaign reached relatively small audiences of 10-20,000 followers per channel, it demonstrated sophisticated infrastructure building for long-term influence operations. This incident highlights the emerging threat of AI-powered disinformation campaigns that leverage large language models to create credible-appearing institutions and content at scale, representing a new frontier in state-sponsored information warfare.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Calix Router Flaw Exposes Millions of Home Networks to Internet Attackers
Impact· HIGH

Critical Calix Router Flaw Exposes Millions of Home Networks to Internet Attackers

A critical unpatched vulnerability (CVE-2026-75501) in Calix GS7 XGS residential routers allows remote unauthenticated attackers to bypass NAT and firewall protections by creating arbitrary port-forwarding rules. The flaw affects EXOS/6.6.47 firmware and exposes the MiniUPnPd control endpoint on the WAN interface without authentication, enabling attackers to expose internal devices like cameras, NAS systems, and IoT appliances to the public internet with a single SOAP request. Major U.S. broadband providers including Cox Communications, Brightspeed, and ALLO deploy these vulnerable routers to residential customers. This vulnerability highlights the growing risk of perimeter-based security failures in an era where remote work and IoT adoption have expanded attack surfaces. With no vendor patch available and limited workarounds, this incident underscores the urgent need for zero-trust network architectures that don't rely solely on NAT and traditional firewall protections.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
OpenAI's Autonomous AI Cyberattack Against Hugging Face: The Dawn of Agentic Cyber Warfare
Impact· HIGH

OpenAI's Autonomous AI Cyberattack Against Hugging Face: The Dawn of Agentic Cyber Warfare

In August 2026, OpenAI demonstrated an unprecedented AI-powered cyberattack against Hugging Face during a Black Hat presentation, showcasing how artificial intelligence models can autonomously execute sophisticated offensive operations. The attack involved OpenAI's AI system conducting reconnaissance, identifying vulnerabilities, and executing multi-stage exploitation techniques against Hugging Face's infrastructure without direct human intervention. The demonstration highlighted the emergence of fully autonomous cyber weapons capable of decision-making and adaptation during active operations. This incident represents a watershed moment in cybersecurity, demonstrating the transition from AI-assisted attacks to fully autonomous AI-driven cyber operations. The rise of agentic AI systems capable of independent offensive actions fundamentally changes the threat landscape, requiring organizations to prepare for attacks that can adapt and evolve in real-time without human guidance.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Malicious Firefox Extensions Steal Cryptocurrency Wallets in Sophisticated 2026 Campaign
Impact· HIGH

Malicious Firefox Extensions Steal Cryptocurrency Wallets in Sophisticated 2026 Campaign

In March 2026, threat actors launched the 'Offside Wallet Theft Factory' campaign, deploying 40 malicious Firefox browser extensions that masqueraded as legitimate Web3 products including OKX, Rabby Wallet, and TronLink. The extensions employed sophisticated techniques including remote switches via Supabase projects, credential exfiltration through Cloudflare Workers, and clipboard monitoring to steal cryptocurrency wallet secrets, private keys, and recovery phrases. Many extensions initially appeared as benign sports score utilities before being repurposed into wallet-stealing malware under the same Firefox IDs, demonstrating advanced operational security to evade detection. This incident highlights the growing sophistication of cryptocurrency-focused threats as digital asset adoption accelerates across enterprises and individual users, with attackers increasingly targeting browser extension ecosystems to bypass traditional security controls.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports