Validated Containment Architectures are here. →Explore

Industry Category

Marketing/Advertising/Sales

Breach intelligence, attack campaigns, and threat reports targeting the Marketing/Advertising/Sales sector.

136 threat reports
Page 1 of 12

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Marketing/Advertising/Sales Threat Reports

Showing 112 / 136 reports
BdThemes Plugins Supply-Chain Hack Compromises Over 350,000 WordPress Sites
Impact· CRITICAL

BdThemes Plugins Supply-Chain Hack Compromises Over 350,000 WordPress Sites

In August 2026, BdThemes, a developer of premium WordPress plugins, experienced a supply-chain attack where a threat actor compromised their infrastructure. The attacker modified a remote JSON feed used by the Biggopti component to display promotional banners in WordPress admin dashboards. By exploiting a cross-site scripting (XSS) vulnerability introduced in March 2026, the malicious code created rogue administrator accounts and installed a webshell for persistent access. This stealthy attack affected over 350,000 active installations, as BdThemes' flagship Element Pack plugin alone had more than 100,000 active installations. The WordPress Plugins team responded by removing the affected plugins from the directory pending a full review. This incident underscores the growing threat of supply-chain attacks targeting widely-used software components. The exploitation of an XSS vulnerability in a promotional banner highlights the need for rigorous security practices in all aspects of software development and distribution. Organizations must remain vigilant, as similar tactics have been observed in other recent attacks, such as those involving the OptinMonster plugin. ([sansec.io](https://sansec.io/research/optinmonster-supply-chain-attack?utm_source=openai))

5 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
DOUBLECUP's Stealthy Malware Delivery via ClickFix and Steganography
Impact· HIGH

DOUBLECUP's Stealthy Malware Delivery via ClickFix and Steganography

In August 2026, a Russian Loader-as-a-Service (LaaS) named DOUBLECUP was identified utilizing ClickFix lures to embed steganographic PNG images into victims' browser caches. This method facilitated the delivery of CountLoader and a new remote access trojan, DeviceManager. The attack sequence involved dropping a PNG image into the browser cache, extracting hidden content, and executing a second-stage payload that decrypted the final malware using the victim's public IP address as a cryptographic key. DeviceManager employed EtherHiding to resolve its command-and-control infrastructure, communicating over HTTP or DNS tunneling. The DOUBLECUP service, active since June 2026, provided operators with licenses and client agents to create campaigns by embedding code into ClickFix landing pages. Each license included metadata such as the client's IP address, active days, label, and version, allowing multiple campaigns per license. The service also featured a Windows GUI client for configuration updates and command issuance. Campaigns leveraging DOUBLECUP impersonated CRM login pages, including NetSuite, Odoo, HubSpot, and Salesforce, to deliver the loader via embedded iframe elements. This approach led to the execution of ClickFix commands that searched the browser cache for the PNG image, extracted malicious scripts, and launched subsequent payloads. The attack chain concluded with the stager reconstructing and executing the final payload, establishing persistence, and exfiltrating system metadata. The emergence of DOUBLECUP underscores the evolving sophistication of cyber threats, particularly the use of steganography and environmental keying to evade detection. The integration of ClickFix lures with advanced payload delivery mechanisms highlights the need for enhanced security measures and user awareness to mitigate such threats.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Unveiling the DOUBLECUP ClickFix Malware Attack of August 2026
Impact· HIGH

Unveiling the DOUBLECUP ClickFix Malware Attack of August 2026

In August 2026, a Russian loader-as-a-service named DOUBLECUP was identified leveraging ClickFix attacks to embed malicious code within PNG images cached by victims' browsers. This method facilitated the delivery of CountLoader to both Windows and macOS devices, and a new remote access trojan named DeviceManager to Windows systems. The DOUBLECUP service provided clients with tools to create malicious campaigns, handling infrastructure aspects such as hosting steganographic images and managing encryption keys. Attackers used fake CAPTCHA prompts on impersonated login pages to trick users into executing commands that extracted and ran the hidden payloads from the browser cache. This incident underscores the evolving sophistication of malware delivery mechanisms, particularly the use of steganography and social engineering to bypass traditional security measures. The rise of loader-as-a-service platforms like DOUBLECUP highlights the increasing accessibility of advanced attack tools to a broader range of threat actors, necessitating enhanced vigilance and adaptive defense strategies.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Adform JavaScript Supply Chain Attack Diverts Cryptocurrency Transactions
Impact· MEDIUM

Adform JavaScript Supply Chain Attack Diverts Cryptocurrency Transactions

In July 2026, attackers compromised Adform's JavaScript file, 'trackpoint-async.js', injecting malicious code that intercepted and replaced cryptocurrency wallet addresses on websites utilizing Adform's services. This supply chain attack enabled the adversaries to divert funds by substituting legitimate wallet addresses with those under their control. Adform detected the breach on July 27, 2026, promptly removed the malicious code, notified affected clients, and reported the incident to authorities. Users who visited impacted sites and copied Bitcoin, Ethereum, or Tron addresses on that date risked pasting altered addresses, potentially leading to unauthorized fund transfers. This incident underscores the escalating threat of supply chain attacks targeting widely-used third-party services to exploit end-users. The attack's sophistication, involving real-time interception and modification of sensitive data, highlights the critical need for organizations to implement robust monitoring and validation mechanisms for third-party scripts and to educate users on verifying transaction details to prevent financial losses.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Authorization Flaw in Adobe Campaign Classic: CVE-2026-48449
Impact· CRITICAL

Critical Authorization Flaw in Adobe Campaign Classic: CVE-2026-48449

In August 2026, Adobe disclosed a critical vulnerability (CVE-2026-48449) in its Campaign Classic platform, rated with a CVSS score of 10.0. This flaw, stemming from incorrect authorization, allows attackers to execute arbitrary code without user interaction, potentially compromising systems running affected versions. Additionally, a high-severity SQL injection vulnerability (CVE-2026-48448) was identified, enabling unauthorized file reads. Adobe has released updates to address these issues and recommends immediate application to mitigate risks. The disclosure underscores the persistent threat posed by authorization and input validation vulnerabilities in enterprise software. Organizations are urged to prioritize patch management and conduct regular security assessments to prevent exploitation of such critical flaws.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Adform's 2026 Supply-Chain Breach: A Wake-Up Call for Ad Tech Security
Impact· MEDIUM

Adform's 2026 Supply-Chain Breach: A Wake-Up Call for Ad Tech Security

In July 2026, Adform, a leading European online advertising firm, experienced a supply-chain attack where its JavaScript tracking script, 'trackpoint-async.js', was compromised. This malicious code, embedded in numerous client websites, monitored users' clipboards for cryptocurrency wallet addresses and replaced them with attacker-controlled addresses, leading to unauthorized redirection of cryptocurrency transactions. The breach was identified by security researcher Kevin Beaumont, who noted that the malicious script also transmitted user data to an attacker-controlled server. This incident underscores the escalating threat of supply-chain attacks, particularly in the ad tech industry, where third-party scripts are widely utilized. The ability of attackers to infiltrate trusted platforms and distribute malicious code highlights the need for enhanced security measures and vigilance in monitoring third-party integrations to prevent similar breaches.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Malware-Infested Android TV Boxes Exploit Users' Broadband for Ad Fraud
Impact· MEDIUM

Malware-Infested Android TV Boxes Exploit Users' Broadband for Ad Fraud

In July 2026, cybersecurity researchers uncovered a large-scale operation involving inexpensive Android TV boxes preloaded with malware. These devices, primarily identified as the H96_MAX_V11 model, were found to mimic popular smartphone brands like Samsung and Huawei to conduct ad fraud by clicking on ads hosted on operator-controlled websites. Additionally, when connected to an HDMI signal, these boxes transformed into SOCKS5 proxy nodes, routing third-party traffic through the owners' broadband connections without their knowledge. The operation, dubbed 'Fuyao,' was attributed to Zhejiang Fengwo IoT Technology Co., Ltd., a Chinese company established in 2019. This incident underscores the escalating threat posed by supply chain compromises in consumer electronics. The integration of sophisticated malware into devices at the manufacturing stage highlights the need for stringent security measures and thorough vetting of hardware sources. As cybercriminals continue to exploit such vulnerabilities, it is imperative for consumers and businesses to remain vigilant and prioritize security in their purchasing decisions.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
H96 TV Streaming Devices Exploited for Ad Fraud in 2026
Impact· MEDIUM

H96 TV Streaming Devices Exploited for Ad Fraud in 2026

In July 2026, security researchers uncovered that H96 TV streaming devices were being exploited to conduct large-scale ad fraud. These devices, manufactured by Zhejiang Fengwo IoT Technology Ltd, were found to spoof themselves as mobile phones, clicking on ads hosted on AI-generated websites operated by the Fengwo Group. This operation not only defrauded online merchants and advertising networks but also compromised user privacy by collecting hardware information and installed apps from tens of thousands of devices globally. This incident highlights the growing trend of cybercriminals leveraging Internet of Things (IoT) devices for fraudulent activities. As IoT adoption increases, the potential attack surface expands, necessitating enhanced security measures and consumer awareness to mitigate such threats.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
SourTrade Malvertising Campaign: A New Era of Browser-Based Threats
Impact· HIGH

SourTrade Malvertising Campaign: A New Era of Browser-Based Threats

In July 2026, a sophisticated malvertising campaign named SourTrade was identified, targeting retail traders and cryptocurrency investors across 12 countries. Active since late 2024, the attackers impersonated reputable platforms like TradingView, Solana, and Luno to lure victims. Instead of delivering a static malicious file, the campaign utilized the victims' browsers to assemble unique Windows executables in memory, leveraging a legitimate Bun runtime. This method effectively evaded traditional security detections by ensuring no complete malware existed on the network. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/?utm_source=openai)) The SourTrade operation underscores a significant evolution in malvertising tactics, highlighting the increasing sophistication of threat actors in circumventing security measures. This incident serves as a critical reminder for organizations to enhance their cybersecurity defenses, particularly against advanced browser-based threats. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/?utm_source=openai))

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Vatican's 'Click to Pray' App Data Breach: A Wake-Up Call for API Security
Impact· HIGH

Vatican's 'Click to Pray' App Data Breach: A Wake-Up Call for API Security

In July 2026, the Vatican's official prayer application, 'Click to Pray,' experienced a significant data breach exposing the personal information of over 700,000 global users. The breach was due to an insecure direct object reference (IDOR) vulnerability in the app's API, allowing unauthorized access to user data, including names, email addresses, and country of origin. This incident underscores the critical need for robust access controls and regular security assessments in applications handling sensitive personal information. The prevalence of IDOR vulnerabilities highlights the importance of implementing comprehensive authorization checks to prevent unauthorized data access.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
European Banks' Data Exposure Through Tracking Pixels
Impact· HIGH

European Banks' Data Exposure Through Tracking Pixels

In July 2026, research revealed that several European financial institutions inadvertently transmitted sensitive customer data to third-party advertising and analytics platforms via tracking pixels embedded in their websites. This data leakage occurred even before users provided consent, and in some cases, continued despite users rejecting tracking technologies. The exposed information included personally identifiable details such as email addresses, phone numbers, and financial data, raising significant compliance, security, and privacy concerns. This incident underscores the critical need for organizations to rigorously monitor and control third-party code execution on their platforms. The misuse of tracking technologies without proper consent not only violates data protection regulations like GDPR but also erodes customer trust. Financial institutions must implement robust runtime controls and ensure that consent mechanisms are effectively enforced to prevent unauthorized data sharing.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical wp2shell WordPress Flaws Exploited to Install Webshells
Impact· CRITICAL

Critical wp2shell WordPress Flaws Exploited to Install Webshells

In July 2026, a critical vulnerability chain known as "wp2shell" (CVE-2026-63030 and CVE-2026-60137) was discovered in WordPress Core, allowing unauthenticated remote code execution. Attackers exploited these flaws to deploy persistent webshells and install malicious plugins on vulnerable servers. The exploit leverages the WordPress REST API's batch-processing feature, enabling code execution without authentication. WordPress addressed the issue in versions 7.0.2, 6.9.5, and 6.8.6, prompting automatic security updates for supported installations. The rapid emergence of proof-of-concept exploits and active exploitation underscores the urgency for organizations to update their WordPress installations promptly. This incident highlights the critical need for timely patch management and vigilant monitoring of web applications to prevent unauthorized access and potential data breaches.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports