The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Broadcast Media
Breach intelligence, attack campaigns, and threat reports targeting the Broadcast Media sector.
Explore Other Sectors
Broadcast Media Threat Reports
UTA0565 Exploits Chrome-Windows Zero-Day Chain in Sophisticated Campaign Against Asian Governments
In September 2026, Chinese threat actor UTA0565 exploited a zero-day exploit chain targeting Google Chrome and Microsoft Windows vulnerabilities (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to deploy CLEANGULP malware. The attackers used fake websites masquerading as legitimate media organizations and NGOs to target Asian government entities, particularly through phishing campaigns related to Hong Kong activist Chow Hang-tung. The exploit chain allowed attackers to break out of Chrome's sandbox and achieve remote code execution, demonstrating sophisticated coordinated efforts within the Chinese cyber espionage community. This incident highlights the growing sophistication of state-sponsored actors utilizing coordinated zero-day exploit chains and the increasing targeting of government entities through social engineering campaigns tied to geopolitical events.
2 days ago
Kill Chain
Chinese APT Group UTA0565 Weaponizes Chrome and Microsoft Zero-Days in Coordinated Espionage Campaign
In September 2024, Volexity researchers identified UTA0565, a Chinese state-aligned threat group, exploiting a triple-chain of zero-day vulnerabilities in Chrome and Microsoft Windows. The group leveraged CVE-2026-85046, CVE-2026-87491 (Chrome JavaScript engine RCE flaws), and CVE-2026-85880 (Windows ALPC privilege escalation) between September 3-4, before patches were available. UTA0565 deployed sophisticated phishing campaigns targeting Asian government entities with fake websites impersonating legitimate organizations, ultimately delivering the previously undocumented CLEANGULP malware family for espionage operations. This incident represents a concerning trend of coordinated exploit sharing within China's cyber espionage ecosystem, as multiple threat groups including APT31 have weaponized the same vulnerability chains. The sophisticated nature of these attacks and their targeting of government entities highlights the escalating capabilities and coordination among state-sponsored actors in exploiting zero-day vulnerabilities for strategic intelligence collection.
2 days ago
Kill Chain
APT37 Embeds Malware in Load Balancers to Spy on South Korean Industries
A North Korean advanced persistent threat group, likely APT37, conducted sophisticated espionage operations against South Korean media and automotive companies throughout 2025-2026. The attackers compromised HAProxy load balancers to deploy a custom Linux toolkit called 'TED', gaining access to decrypted communications and conducting long-term surveillance operations. The group harvested credentials, modified log files to hide their tracks, and maintained persistent access to target networks for intelligence collection on media sources and manufacturing technology. This incident represents a significant evolution in APT tactics, demonstrating how threat actors are embedding malicious code directly into production infrastructure rather than deploying traditional malware. The targeting of critical industrial sectors and the sophisticated load balancer compromise technique highlight the growing threat to network appliances and the need for enhanced infrastructure security.
1 week ago
Kill Chain
Mass Plex Server Exposure: 36,000 Vulnerable Instances Highlight Critical Patch Management Gaps
In September 2026, over 36,000 Plex Media Server instances remained exposed online and unpatched against critical security vulnerabilities affecting version 1.43.2 and earlier. Plex urgently warned users to upgrade to version 1.43.3, released in May 2026, to address multiple security flaws that lack CVE identifiers for easy tracking. The company took the unusual step of emailing customers directly about the severity of these vulnerabilities. Shadowserver's scanning revealed the massive scale of exposure, with tens of thousands of servers remaining vulnerable to potential exploitation as attackers could reverse-engineer the patches to develop exploits. This incident highlights the persistent challenge of vulnerability management in internet-exposed services, particularly as organizations increasingly rely on media streaming and file sharing platforms that may lack enterprise-grade security controls and patch management processes.
2 weeks ago
Kill Chain
Critical Plex Security Update: Multiple Vulnerabilities Patched in September 2026
In September 2026, Plex urged users to immediately update their Media Server and Desktop applications following the discovery of multiple undisclosed security vulnerabilities. The streaming media service released patches in Plex Media Server version 1.43.3 and Plex Desktop 1.115.0, with CVE identifiers requested for the flaws. While technical details remain undisclosed, this follows a pattern of critical Plex vulnerabilities, including a high-severity authentication bypass flaw (CVE-2025-34158) patched in August 2025 that exposed server owner credentials to any authenticated user. This incident highlights the ongoing security challenges facing media streaming infrastructure, particularly as threat actors increasingly target home and small business servers. With over 360,000 Plex servers exposed to the internet and a history of exploitation including the 2022 LastPass breach chain, these vulnerabilities underscore the critical need for rapid patch deployment and network segmentation.
3 weeks ago
Kill Chain
Ted Backdoor Reveals Critical Gap in Load Balancer Security
In September 2026, North Korean state-sponsored actors deployed a sophisticated backdoor called 'Ted' by compromising HAProxy load balancers at two South Korean organizations in the automotive and media sectors. The attackers replaced legitimate HAProxy binaries with trojanized versions containing embedded malware that intercepted web traffic and served altered pages to selected visitors. The implant operated covertly by handling command-and-control requests without reaching backend servers, erasing traces from connection logs and statistics. The attack toolkit included additional trojans targeting system binaries like sshd and crond, along with a companion remote access trojan called curlRAT that maintained persistent access to compromised systems. This incident highlights the evolving sophistication of supply chain attacks where legitimate infrastructure components are weaponized to establish persistent footholds in critical networks. The attack demonstrates advanced techniques for traffic manipulation and steganographic communication that bypass traditional security controls focused on network perimeter defense.
3 weeks ago
Kill Chain
Plex Issues Urgent Security Warning: Multiple Critical Vulnerabilities Require Immediate Patching
In September 2026, Plex issued an urgent security advisory warning users to immediately update their media servers and desktop clients to patch multiple critical vulnerabilities affecting Plex Media Server v1.43.2 and earlier. The company released patched versions (Media Server 1.43.3 and Desktop 1.115.0) and took the unusual step of emailing customers directly about the severity of these flaws, though specific CVE details were not yet published. This follows Plex's history of serious security incidents, including a 2025 credential theft vulnerability (CVE-2025-34158) and a 2022 data breach that compromised user credentials and personal information. This incident highlights the growing trend of threat actors targeting popular media streaming platforms and home entertainment systems as attack vectors for lateral movement into personal and corporate networks, particularly as remote work continues to blur the lines between home and business environments.
3 weeks ago
Kill Chain
Serbian Student Activists Targeted by Pegasus Zero-Click Spyware Campaign
In December 2025 through January 2026, NSO Group's Pegasus spyware infected the iPhone of a Serbian student protest movement member using a zero-click iMessage exploit. The attack was part of a broader surveillance campaign targeting at least 14 Serbian activists, opposition politicians, and student leaders coinciding with March 2026 local elections. Citizen Lab and SHARE Foundation confirmed the infection, while a separate incident involved NoviSpy Android malware deployed during police detention of another student activist. This incident highlights the escalating use of commercial spyware against civil society, particularly as authoritarian governments increasingly weaponize surveillance technology to suppress political dissent and monitor opposition movements ahead of critical elections.
3 weeks ago
Kill Chain
Critical Unpatched Kaltura mwEmbed Vulnerabilities Expose Video Platforms to Remote Attacks
Two critical unpatched vulnerabilities in Kaltura's HTML5 video player library (CVE-2026-19913 and CVE-2026-19912) allow remote, unauthenticated attackers to read arbitrary files and execute code on affected servers. The flaws stem from unsafe deserialization in the mwEmbedLoader.php endpoint, affecting both individual customer installations and Kaltura's shared multi-tenant CDN infrastructure. With CVSS scores of 9.1 and 10.0 respectively, these vulnerabilities require only network access to exploit, with no authentication needed. CERT/CC reported being unable to coordinate with Kaltura for patches, leaving administrators to implement workarounds. This incident highlights the growing risk of unpatched vulnerabilities in widely-deployed media platforms and the challenges of coordinating disclosures with unresponsive vendors, particularly as video streaming infrastructure becomes increasingly critical to business operations.
1 month ago
Kill Chain
UAT-10147 Cybercrime Group Weaponizes AI for Massive Server Attack Campaign
In August 2026, cybersecurity researchers disclosed details of UAT-10147, a Chinese-speaking cybercrime group leveraging AI-powered tools to conduct large-scale attacks against Windows and Linux web servers globally. The threat actor deployed artificial intelligence frameworks including PentestGPT, DeepAudit, and custom AI-generated Python scripts to automate vulnerability exploitation, reconnaissance, and payload generation across approximately 170,000 target URLs. UAT-10147 exploited known vulnerabilities to establish initial access, then deployed the cross-platform SPECTRE implant featuring advanced EDR bypass capabilities and Linux rootkit functionality, primarily targeting education, media, technology, and gaming sectors in Brazil, Bolivia, China, Canada, and Vietnam for SEO fraud and data theft operations. This incident represents a significant evolution in cybercrime operations, demonstrating how threat actors are integrating AI capabilities to scale attacks and enhance operational efficiency. The emergence of AI-driven offensive frameworks marks a critical shift in the threat landscape, enabling lower-skilled actors to conduct sophisticated attacks while highlighting the urgent need for organizations to strengthen their security postures against automated exploitation campaigns.
1 month ago
Kill Chain
Critical 'PixelSmash' Vulnerability in FFmpeg's MagicYUV Decoder (CVE-2026-8461)
In June 2026, a critical vulnerability known as 'PixelSmash' (CVE-2026-8461) was identified in FFmpeg's MagicYUV decoder, affecting versions prior to 8.1.2. This heap out-of-bounds write flaw allows attackers to execute arbitrary code or cause denial-of-service conditions by tricking users into opening malicious AVI, MKV, or MOV files. Applications utilizing FFmpeg's libavcodec, such as Jellyfin, Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio, are susceptible. Exploitation for remote code execution is feasible if Address Space Layout Randomization (ASLR) is disabled or bypassed. The widespread use of FFmpeg across various media applications amplifies the risk, highlighting the importance of prompt updates to mitigate potential attacks. This incident underscores the critical need for rigorous supply chain security practices and timely patch management to protect against emerging vulnerabilities.
3 months ago
Kill Chain
FIFA 2026 World Cup Broadcast Vulnerability Exposed
In June 2026, an ethical hacker known as "BobDaHacker" identified a critical access control vulnerability within FIFA's Microsoft Entra environment. By registering as a football agent, the hacker gained unauthorized access to FIFA's internal systems, including the live production hub for World Cup broadcasts. This flaw allowed potential manipulation of global television streams, match management systems, and other critical platforms. The vulnerability was promptly reported and subsequently addressed by FIFA. This incident underscores the pressing need for robust server-side authorization mechanisms, especially in high-profile events like the FIFA World Cup. The exposure of such critical systems highlights the importance of comprehensive security measures to prevent unauthorized access and potential disruptions on a global scale.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports