✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Marketing/Advertising/Sales
Breach intelligence, attack campaigns, and threat reports targeting the Marketing/Advertising/Sales sector.
Explore Other Sectors
Marketing/Advertising/Sales Threat Reports
BdThemes Plugins Supply-Chain Hack Compromises Over 350,000 WordPress Sites
In August 2026, BdThemes, a developer of premium WordPress plugins, experienced a supply-chain attack where a threat actor compromised their infrastructure. The attacker modified a remote JSON feed used by the Biggopti component to display promotional banners in WordPress admin dashboards. By exploiting a cross-site scripting (XSS) vulnerability introduced in March 2026, the malicious code created rogue administrator accounts and installed a webshell for persistent access. This stealthy attack affected over 350,000 active installations, as BdThemes' flagship Element Pack plugin alone had more than 100,000 active installations. The WordPress Plugins team responded by removing the affected plugins from the directory pending a full review. This incident underscores the growing threat of supply-chain attacks targeting widely-used software components. The exploitation of an XSS vulnerability in a promotional banner highlights the need for rigorous security practices in all aspects of software development and distribution. Organizations must remain vigilant, as similar tactics have been observed in other recent attacks, such as those involving the OptinMonster plugin. ([sansec.io](https://sansec.io/research/optinmonster-supply-chain-attack?utm_source=openai))
5 hours ago
Kill Chain
DOUBLECUP's Stealthy Malware Delivery via ClickFix and Steganography
In August 2026, a Russian Loader-as-a-Service (LaaS) named DOUBLECUP was identified utilizing ClickFix lures to embed steganographic PNG images into victims' browser caches. This method facilitated the delivery of CountLoader and a new remote access trojan, DeviceManager. The attack sequence involved dropping a PNG image into the browser cache, extracting hidden content, and executing a second-stage payload that decrypted the final malware using the victim's public IP address as a cryptographic key. DeviceManager employed EtherHiding to resolve its command-and-control infrastructure, communicating over HTTP or DNS tunneling. The DOUBLECUP service, active since June 2026, provided operators with licenses and client agents to create campaigns by embedding code into ClickFix landing pages. Each license included metadata such as the client's IP address, active days, label, and version, allowing multiple campaigns per license. The service also featured a Windows GUI client for configuration updates and command issuance. Campaigns leveraging DOUBLECUP impersonated CRM login pages, including NetSuite, Odoo, HubSpot, and Salesforce, to deliver the loader via embedded iframe elements. This approach led to the execution of ClickFix commands that searched the browser cache for the PNG image, extracted malicious scripts, and launched subsequent payloads. The attack chain concluded with the stager reconstructing and executing the final payload, establishing persistence, and exfiltrating system metadata. The emergence of DOUBLECUP underscores the evolving sophistication of cyber threats, particularly the use of steganography and environmental keying to evade detection. The integration of ClickFix lures with advanced payload delivery mechanisms highlights the need for enhanced security measures and user awareness to mitigate such threats.
6 days ago
Kill Chain
Unveiling the DOUBLECUP ClickFix Malware Attack of August 2026
In August 2026, a Russian loader-as-a-service named DOUBLECUP was identified leveraging ClickFix attacks to embed malicious code within PNG images cached by victims' browsers. This method facilitated the delivery of CountLoader to both Windows and macOS devices, and a new remote access trojan named DeviceManager to Windows systems. The DOUBLECUP service provided clients with tools to create malicious campaigns, handling infrastructure aspects such as hosting steganographic images and managing encryption keys. Attackers used fake CAPTCHA prompts on impersonated login pages to trick users into executing commands that extracted and ran the hidden payloads from the browser cache. This incident underscores the evolving sophistication of malware delivery mechanisms, particularly the use of steganography and social engineering to bypass traditional security measures. The rise of loader-as-a-service platforms like DOUBLECUP highlights the increasing accessibility of advanced attack tools to a broader range of threat actors, necessitating enhanced vigilance and adaptive defense strategies.
1 week ago
Kill Chain
Adform JavaScript Supply Chain Attack Diverts Cryptocurrency Transactions
In July 2026, attackers compromised Adform's JavaScript file, 'trackpoint-async.js', injecting malicious code that intercepted and replaced cryptocurrency wallet addresses on websites utilizing Adform's services. This supply chain attack enabled the adversaries to divert funds by substituting legitimate wallet addresses with those under their control. Adform detected the breach on July 27, 2026, promptly removed the malicious code, notified affected clients, and reported the incident to authorities. Users who visited impacted sites and copied Bitcoin, Ethereum, or Tron addresses on that date risked pasting altered addresses, potentially leading to unauthorized fund transfers. This incident underscores the escalating threat of supply chain attacks targeting widely-used third-party services to exploit end-users. The attack's sophistication, involving real-time interception and modification of sensitive data, highlights the critical need for organizations to implement robust monitoring and validation mechanisms for third-party scripts and to educate users on verifying transaction details to prevent financial losses.
1 week ago
Kill Chain
Critical Authorization Flaw in Adobe Campaign Classic: CVE-2026-48449
In August 2026, Adobe disclosed a critical vulnerability (CVE-2026-48449) in its Campaign Classic platform, rated with a CVSS score of 10.0. This flaw, stemming from incorrect authorization, allows attackers to execute arbitrary code without user interaction, potentially compromising systems running affected versions. Additionally, a high-severity SQL injection vulnerability (CVE-2026-48448) was identified, enabling unauthorized file reads. Adobe has released updates to address these issues and recommends immediate application to mitigate risks. The disclosure underscores the persistent threat posed by authorization and input validation vulnerabilities in enterprise software. Organizations are urged to prioritize patch management and conduct regular security assessments to prevent exploitation of such critical flaws.
1 week ago
Kill Chain
Adform's 2026 Supply-Chain Breach: A Wake-Up Call for Ad Tech Security
In July 2026, Adform, a leading European online advertising firm, experienced a supply-chain attack where its JavaScript tracking script, 'trackpoint-async.js', was compromised. This malicious code, embedded in numerous client websites, monitored users' clipboards for cryptocurrency wallet addresses and replaced them with attacker-controlled addresses, leading to unauthorized redirection of cryptocurrency transactions. The breach was identified by security researcher Kevin Beaumont, who noted that the malicious script also transmitted user data to an attacker-controlled server. This incident underscores the escalating threat of supply-chain attacks, particularly in the ad tech industry, where third-party scripts are widely utilized. The ability of attackers to infiltrate trusted platforms and distribute malicious code highlights the need for enhanced security measures and vigilance in monitoring third-party integrations to prevent similar breaches.
1 week ago
Kill Chain
Malware-Infested Android TV Boxes Exploit Users' Broadband for Ad Fraud
In July 2026, cybersecurity researchers uncovered a large-scale operation involving inexpensive Android TV boxes preloaded with malware. These devices, primarily identified as the H96_MAX_V11 model, were found to mimic popular smartphone brands like Samsung and Huawei to conduct ad fraud by clicking on ads hosted on operator-controlled websites. Additionally, when connected to an HDMI signal, these boxes transformed into SOCKS5 proxy nodes, routing third-party traffic through the owners' broadband connections without their knowledge. The operation, dubbed 'Fuyao,' was attributed to Zhejiang Fengwo IoT Technology Co., Ltd., a Chinese company established in 2019. This incident underscores the escalating threat posed by supply chain compromises in consumer electronics. The integration of sophisticated malware into devices at the manufacturing stage highlights the need for stringent security measures and thorough vetting of hardware sources. As cybercriminals continue to exploit such vulnerabilities, it is imperative for consumers and businesses to remain vigilant and prioritize security in their purchasing decisions.
1 week ago
Kill Chain
H96 TV Streaming Devices Exploited for Ad Fraud in 2026
In July 2026, security researchers uncovered that H96 TV streaming devices were being exploited to conduct large-scale ad fraud. These devices, manufactured by Zhejiang Fengwo IoT Technology Ltd, were found to spoof themselves as mobile phones, clicking on ads hosted on AI-generated websites operated by the Fengwo Group. This operation not only defrauded online merchants and advertising networks but also compromised user privacy by collecting hardware information and installed apps from tens of thousands of devices globally. This incident highlights the growing trend of cybercriminals leveraging Internet of Things (IoT) devices for fraudulent activities. As IoT adoption increases, the potential attack surface expands, necessitating enhanced security measures and consumer awareness to mitigate such threats.
1 week ago
Kill Chain
SourTrade Malvertising Campaign: A New Era of Browser-Based Threats
In July 2026, a sophisticated malvertising campaign named SourTrade was identified, targeting retail traders and cryptocurrency investors across 12 countries. Active since late 2024, the attackers impersonated reputable platforms like TradingView, Solana, and Luno to lure victims. Instead of delivering a static malicious file, the campaign utilized the victims' browsers to assemble unique Windows executables in memory, leveraging a legitimate Bun runtime. This method effectively evaded traditional security detections by ensuring no complete malware existed on the network. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/?utm_source=openai)) The SourTrade operation underscores a significant evolution in malvertising tactics, highlighting the increasing sophistication of threat actors in circumventing security measures. This incident serves as a critical reminder for organizations to enhance their cybersecurity defenses, particularly against advanced browser-based threats. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/?utm_source=openai))
2 weeks ago
Kill Chain
Vatican's 'Click to Pray' App Data Breach: A Wake-Up Call for API Security
In July 2026, the Vatican's official prayer application, 'Click to Pray,' experienced a significant data breach exposing the personal information of over 700,000 global users. The breach was due to an insecure direct object reference (IDOR) vulnerability in the app's API, allowing unauthorized access to user data, including names, email addresses, and country of origin. This incident underscores the critical need for robust access controls and regular security assessments in applications handling sensitive personal information. The prevalence of IDOR vulnerabilities highlights the importance of implementing comprehensive authorization checks to prevent unauthorized data access.
2 weeks ago
Kill Chain
European Banks' Data Exposure Through Tracking Pixels
In July 2026, research revealed that several European financial institutions inadvertently transmitted sensitive customer data to third-party advertising and analytics platforms via tracking pixels embedded in their websites. This data leakage occurred even before users provided consent, and in some cases, continued despite users rejecting tracking technologies. The exposed information included personally identifiable details such as email addresses, phone numbers, and financial data, raising significant compliance, security, and privacy concerns. This incident underscores the critical need for organizations to rigorously monitor and control third-party code execution on their platforms. The misuse of tracking technologies without proper consent not only violates data protection regulations like GDPR but also erodes customer trust. Financial institutions must implement robust runtime controls and ensure that consent mechanisms are effectively enforced to prevent unauthorized data sharing.
2 weeks ago
Kill Chain
Critical wp2shell WordPress Flaws Exploited to Install Webshells
In July 2026, a critical vulnerability chain known as "wp2shell" (CVE-2026-63030 and CVE-2026-60137) was discovered in WordPress Core, allowing unauthenticated remote code execution. Attackers exploited these flaws to deploy persistent webshells and install malicious plugins on vulnerable servers. The exploit leverages the WordPress REST API's batch-processing feature, enabling code execution without authentication. WordPress addressed the issue in versions 7.0.2, 6.9.5, and 6.8.6, prompting automatic security updates for supported installations. The rapid emergence of proof-of-concept exploits and active exploitation underscores the urgency for organizations to update their WordPress installations promptly. This incident highlights the critical need for timely patch management and vigilant monitoring of web applications to prevent unauthorized access and potential data breaches.
2 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports