The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Internet
Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.
Explore Other Sectors
Internet Threat Reports
MikroTik RouterOS SSH Authentication Bypass: Critical Infrastructure Attack Analysis
In September 2026, attackers exploited MikroTik RouterOS devices through internet-exposed SSH services, gaining full administrative control without authentication. CERT Polska reported active exploitation beginning September 2, targeting RouterOS versions 6.0.0-6.49.21, 7.0.0-7.23.4, and 7.24-7.24.2 through a vulnerability combination dubbed 'MikroTrick.' The attacks allowed unauthorized configuration changes and complete device compromise, prompting immediate security updates from MikroTik across multiple RouterOS channels. Network infrastructure attacks like this highlight the critical importance of securing remote access services and implementing proper network segmentation. The incident demonstrates how exposed management interfaces continue to be prime targets for threat actors seeking to establish persistent network footholds and lateral movement capabilities.
2 weeks ago
Kill Chain
BGP Hijacking Enables Virtualizor Supply Chain Compromise
In late August 2026, attackers executed a sophisticated supply chain attack against Virtualizor, a popular virtualization management platform, by hijacking Border Gateway Protocol (BGP) routes to redirect software update traffic. The attack occurred between August 28-30, 2026, when threat actors diverted Softaculous traffic to attacker-controlled servers and delivered malicious Virtualizor updates that established persistent root access on affected systems. At least 5 of 34 hypervisors at one hosting provider were compromised, with attackers installing backdoors, creating unauthorized accounts, and maintaining persistence through systemd services. This incident highlights the growing sophistication of supply chain attacks targeting critical infrastructure management software. As organizations increasingly rely on automated software updates and third-party platforms for cloud operations, attackers are exploiting trust relationships and network-level vulnerabilities to achieve widespread compromise with minimal detection.
3 weeks ago
Kill Chain
Chinese Cybercriminals Turn Brazilian Government Sites into Gambling Traffic Redirectors
The Chinese-speaking Gambling Goblin cybercrime cluster has been compromising Brazilian government and educational web servers since mid-2025, installing malicious Apache modules to redirect visitors to attacker-controlled gambling and sports betting pages. The campaign leverages compromised high-reputation .gov.br domains to manipulate search engine optimization at scale, with modules reverse-proxying traffic while stripping security headers to allow malicious content execution. Linked to the Earth Berberoka threat group, the operation deploys sophisticated tooling including custom downloaders, modular backdoors, and credential stealers to maintain persistent access to government infrastructure. This incident highlights the growing trend of SEO manipulation attacks targeting government domains for cybercriminal profit, particularly as Brazil's newly regulated online betting market creates lucrative opportunities for threat actors to exploit trusted infrastructure for financial gain.
3 weeks ago
Kill Chain
Major Chrome Extension Malware Campaign Steals Crypto from 80,000+ Users
In August 2026, security researchers at Socket uncovered a sophisticated malware campaign targeting Chrome and Edge browser extensions that had been active since early 2024. Nineteen malicious modules were deployed through initially legitimate extensions, some acquired from original creators and weaponized through automatic updates. The most notable example was the "Enable Right Click & Copy" extension with over 70,000 Chrome users and 10,000 Edge users. The malware established encrypted WebSocket connections to command-and-control servers, removed Content Security Policy headers, and deployed modules capable of draining cryptocurrency wallets, stealing credentials from major exchanges like Coinbase and Binance, harvesting social media data, and deploying ClickFix-style phishing attacks. This incident highlights the growing sophistication of supply chain attacks targeting browser ecosystems, coinciding with increased regulatory scrutiny of app store security practices and the rise of cryptocurrency-focused cybercrime operations that leverage trusted distribution channels.
3 weeks ago
Kill Chain
Factory Implants in ZBT Routers Expose Global Supply Chain Security Crisis
In August 2026, VulnCheck disclosed two previously undocumented factory implants, SPEAKINGSTONE and DARKLANTERN, found in firmware for routers manufactured by Shenzhen Zhibotong Electronics (ZBT). Both implants, tracked as CVE-2026-74232 and CVE-2026-74233 with CVSS scores of 9.3-9.8, provide unauthenticated remote attackers with root access to affected devices. SPEAKINGSTONE operates as a surveillance implant that beacons to hardcoded command-and-control servers, while DARKLANTERN listens on UDP port 9992 with ineffective authentication. VulnCheck identified over 200 internet-facing DARKLANTERN instances across 22 countries and received beacons from 392 unique devices when they registered the backup C2 domain. This incident highlights the growing threat of supply chain attacks targeting network infrastructure, particularly as organizations increasingly rely on low-cost networking equipment from overseas manufacturers. The discovery comes amid heightened awareness of nation-state activities targeting critical infrastructure and follows similar findings in Chinese-manufactured networking equipment.
3 weeks ago
Kill Chain
Critical cPanel Domain Parking Vulnerability Enables Root Privilege Escalation
In August 2026, cPanel disclosed CVE-2026-65643, a critical vulnerability in domain parking and addon domain functionality affecting all supported versions of cPanel and WebHost Manager (WHM). The flaw allows authenticated users with domain management privileges to create arbitrary files on the server, leading to code execution as the root user and complete server compromise. cPanel released patches across multiple version branches (11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7) with automatic updates available for servers configured for daily updates. This incident highlights the growing trend of privilege escalation vulnerabilities in shared hosting control panels, which continue to be high-value targets for attackers seeking to compromise multiple websites simultaneously. The vulnerability's impact on shared hosting environments makes it particularly concerning given the widespread deployment of cPanel across the hosting industry.
3 weeks ago
Kill Chain
Superior Campaign Exploits Browser Extension Supply Chain to Drain Crypto Wallets
Security researchers from Socket discovered a sophisticated supply chain attack targeting browser extension users, involving 19 malicious Chrome and Edge extensions harboring cryptocurrency wallet-draining capabilities. The campaign, tracked as 'Superior,' has been active since February 2024, with threat actors either creating malicious extensions or purchasing legitimate ones before injecting malicious code in subsequent updates. The extensions collectively reached over 80,000 users, with the malware establishing persistent WebSocket connections to command-and-control servers for data exfiltration and executing cryptocurrency theft modules. This incident highlights the growing threat of browser extension supply chain attacks targeting cryptocurrency assets and sensitive user credentials. The Superior campaign demonstrates how threat actors are increasingly exploiting the automatic update mechanisms of browser extensions to deliver malware at scale, representing a significant evolution in supply chain attack methodologies.
3 weeks ago
Kill Chain
xAI Faces Class Action Lawsuit Over Grok's Alleged CSAM Generation Capabilities
In January 2025, former child sexual abuse victims filed a class action lawsuit against xAI, alleging that the company's Grok AI model was trained on child sexual abuse material (CSAM) to develop deepfake capabilities. The lawsuit claims Grok generated over 3 million sexualized images in 11 days, including approximately 23,000 that appeared to depict children. Plaintiffs argue that xAI's integration of Grok into X's platform, combined with weak content filters, created an instantaneous CSAM generation and distribution system that violates federal child protection laws. This incident highlights the growing risks of AI misuse in generating harmful content, particularly as deepfake technology becomes more accessible and regulatory frameworks struggle to keep pace with technological advancement.
3 weeks ago
Kill Chain
Russian Actors Exploit ChatGPT for Sophisticated Influence Operation
In August 2026, OpenAI disrupted a Russian-linked influence operation that used ChatGPT accounts with VPNs to bypass geographic restrictions and generate social media content across multiple platforms. The operation promoted the International Burke Institute (IBI), a fake think tank registered in February 2025, which featured copied academic work, false attributions, and a sovereignty index designed to cast Russia favorably. While the campaign reached relatively small audiences of 10-20,000 followers per channel, it demonstrated sophisticated infrastructure building for long-term influence operations. This incident highlights the emerging threat of AI-powered disinformation campaigns that leverage large language models to create credible-appearing institutions and content at scale, representing a new frontier in state-sponsored information warfare.
4 weeks ago
Kill Chain
Critical Calix Router Flaw Exposes Millions of Home Networks to Internet Attackers
A critical unpatched vulnerability (CVE-2026-75501) in Calix GS7 XGS residential routers allows remote unauthenticated attackers to bypass NAT and firewall protections by creating arbitrary port-forwarding rules. The flaw affects EXOS/6.6.47 firmware and exposes the MiniUPnPd control endpoint on the WAN interface without authentication, enabling attackers to expose internal devices like cameras, NAS systems, and IoT appliances to the public internet with a single SOAP request. Major U.S. broadband providers including Cox Communications, Brightspeed, and ALLO deploy these vulnerable routers to residential customers. This vulnerability highlights the growing risk of perimeter-based security failures in an era where remote work and IoT adoption have expanded attack surfaces. With no vendor patch available and limited workarounds, this incident underscores the urgent need for zero-trust network architectures that don't rely solely on NAT and traditional firewall protections.
1 month ago
Kill Chain
OpenAI's Autonomous AI Cyberattack Against Hugging Face: The Dawn of Agentic Cyber Warfare
In August 2026, OpenAI demonstrated an unprecedented AI-powered cyberattack against Hugging Face during a Black Hat presentation, showcasing how artificial intelligence models can autonomously execute sophisticated offensive operations. The attack involved OpenAI's AI system conducting reconnaissance, identifying vulnerabilities, and executing multi-stage exploitation techniques against Hugging Face's infrastructure without direct human intervention. The demonstration highlighted the emergence of fully autonomous cyber weapons capable of decision-making and adaptation during active operations. This incident represents a watershed moment in cybersecurity, demonstrating the transition from AI-assisted attacks to fully autonomous AI-driven cyber operations. The rise of agentic AI systems capable of independent offensive actions fundamentally changes the threat landscape, requiring organizations to prepare for attacks that can adapt and evolve in real-time without human guidance.
1 month ago
Kill Chain
Malicious Firefox Extensions Steal Cryptocurrency Wallets in Sophisticated 2026 Campaign
In March 2026, threat actors launched the 'Offside Wallet Theft Factory' campaign, deploying 40 malicious Firefox browser extensions that masqueraded as legitimate Web3 products including OKX, Rabby Wallet, and TronLink. The extensions employed sophisticated techniques including remote switches via Supabase projects, credential exfiltration through Cloudflare Workers, and clipboard monitoring to steal cryptocurrency wallet secrets, private keys, and recovery phrases. Many extensions initially appeared as benign sports score utilities before being repurposed into wallet-stealing malware under the same Firefox IDs, demonstrating advanced operational security to evade detection. This incident highlights the growing sophistication of cryptocurrency-focused threats as digital asset adoption accelerates across enterprises and individual users, with attackers increasingly targeting browser extension ecosystems to bypass traditional security controls.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports