The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Marketing/Advertising/Sales
Breach intelligence, attack campaigns, and threat reports targeting the Marketing/Advertising/Sales sector.
Explore Other Sectors
Marketing/Advertising/Sales Threat Reports
Salesbleed Attack: How AI Agents Became the New Phishing Vector
The 'Salesbleed' vulnerabilities discovered in September 2026 by Zenity researchers exploit Salesforce Agentforce AI agents to enable sophisticated phishing attacks through trusted internal Slack channels. Attackers inject malicious prompts via Web-to-lead forms, leveraging AI agents' permissions to exfiltrate data and send phishing messages that appear to originate from legitimate employees or IT help desk personnel. This attack chain demonstrates how agentic AI platforms create new attack vectors by combining legitimate business processes with inadequate security controls, particularly around URL filtering and message attribution. This incident highlights the growing security challenges posed by autonomous AI agents in enterprise environments, as organizations rapidly deploy agentic systems without adequate visibility and control mechanisms. The vulnerability underscores the critical need for comprehensive AI governance frameworks as businesses increasingly rely on AI agents with elevated permissions across interconnected cloud platforms.
4 hours ago
Kill Chain
WordPress CVE-2026-87902: Critical RCE Vulnerability Exploited Within Hours
Within hours of WordPress releasing patches for CVE-2026-87902 on September 22, 2026, threat actors began actively exploiting this critical remote code execution vulnerability affecting WordPress sites. The flaw allows unauthenticated attackers to include arbitrary PHP files and achieve RCE when specific preconditions are met, including the presence of page- directories in active themes and readable PHP files like pearcmd.php. Security researchers observed 68 exploitation attempts originating from multiple countries, with attackers deploying web shells and writing malicious PHP files to compromised systems. This incident exemplifies the increasingly rapid weaponization of disclosed vulnerabilities, with attackers now exploiting critical flaws within the same day of patch releases. The WordPress ecosystem's massive attack surface combined with automated exploit frameworks enables threat actors to achieve widespread reconnaissance and compromise attempts at unprecedented speed.
1 day ago
Kill Chain
WordPress Under Siege: CVE-2026-87902 Exploitation Analysis
Threat actors began exploiting CVE-2026-87902, a critical WordPress path traversal vulnerability with a CVSS score of 9.2, within hours of patch release on September 22, 2026. The unauthenticated flaw allows remote code execution through path traversal attacks targeting the get_page_template() function, enabling attackers to include malicious PHP files outside theme directories. Initial reconnaissance activity escalated to active payload delivery within 24 hours, with attackers writing executable shell commands to /tmp directories on vulnerable WordPress installations running versions before 7.1.2. This incident highlights the accelerating weaponization timeline for critical web application vulnerabilities, as attackers now exploit high-severity flaws within hours rather than days or weeks. The widespread nature of WordPress deployments and the unauthenticated attack vector amplify the risk landscape significantly.
1 day ago
Kill Chain
WordPress Comment2Shell: When Anonymous Comments Become Server Backdoors
In September 2026, WordPress patched a critical vulnerability (CVE-2026-93485) dubbed 'Comment2Shell' that allowed anonymous attackers to inject malicious scripts through comments. The flaw exploited a gap in WordPress's comment processing, where line breaks in HTML attributes could bypass sanitization and execute JavaScript when pages loaded. If an administrator viewed a compromised page, the script could leverage their elevated privileges to upload web shells and achieve remote code execution on the server. This vulnerability highlights the evolving sophistication of web application attacks targeting content management systems. As WordPress powers over 40% of websites globally, such zero-click exploits represent a significant threat vector for cybercriminals seeking to compromise web infrastructure at scale.
2 days ago
Kill Chain
WordPress CVE-2026-87902: Critical Unauthenticated RCE Vulnerability Demands Immediate Action
WordPress released an emergency security patch on September 22, 2026, addressing CVE-2026-87902, a critical path traversal vulnerability affecting versions 4.7.0 through 7.1.1. The flaw allows unauthenticated attackers to force WordPress sites to load arbitrary PHP files from outside theme directories through manipulated URL parameters. On servers with specific configurations, particularly those running older PHP versions with register_argc_argv enabled and themes containing page- prefixed directories, this vulnerability can escalate to remote code execution. The vulnerability bypassed WordPress's built-in directory traversal protections in the template selection mechanism. This incident highlights the persistent threat of web application vulnerabilities in widely-deployed platforms, with WordPress powering over 40% of websites globally. The timing coincides with increased scrutiny of supply chain security and the growing sophistication of automated vulnerability exploitation frameworks targeting content management systems.
2 days ago
Kill Chain
WordPress Click2Shell: How a CSRF Flaw Became a Critical RCE Threat
In September 2026, security researcher Paulos Yibelo discovered a critical WordPress Core vulnerability dubbed 'Click2Shell' affecting versions 7.1.0 and earlier. This cross-site request forgery (CSRF) flaw enables pre-authenticated remote code execution by allowing attackers to force-install vulnerable themes from the WordPress catalog and execute arbitrary PHP code during theme preview. The exploit requires a logged-in administrator to visit a crafted URL, making it particularly dangerous via phishing campaigns or existing XSS vulnerabilities. WordPress addressed the flaw in version 7.1.1 by implementing proper input escaping and restricting theme selectors. This vulnerability highlights the growing sophistication of web application attacks targeting content management systems that power over 40% of websites globally. With complete technical details and proof-of-concept exploits now public, organizations face immediate risk from automated exploitation attempts targeting unpatched WordPress installations.
3 days ago
Kill Chain
WordPress Click2Shell Vulnerability: How a Simple Link Click Leads to Server Compromise
WordPress patched a critical vulnerability called Click2Shell in September 2026 that allows attackers to force automatic theme installation through specially crafted URLs. The flaw exploits differences in how WordPress.org directory and administrator browsers parse the same link, enabling attackers to trigger theme installations when logged-in administrators click malicious links. When chained with secondary vulnerabilities in installed themes, the attack escalates to remote code execution with a CVSS score of 9.6. The vulnerability affects WordPress versions 6.0 through 7.1.0, with fixes released in version 7.1.1 across all supported branches back to 4.7. This incident highlights the growing trend of attackers targeting content management system vulnerabilities that can be chained together for maximum impact, particularly as WordPress powers over 40% of websites globally and remains a high-value target.
6 days ago
Kill Chain
Gyazo Breach Exposes 23.6 Million Users: Server Vulnerability Leads to Massive Data Theft
On September 11, 2026, attackers exploited a server vulnerability in Gyazo's image-sharing platform to steal 23.6 million user records and 490 million image metadata entries. The breach exposed names, email addresses, password hashes, session IDs, and private image metadata including EXIF location data and OCR-extracted text. Gyazo detected the intrusion on September 12 and took the platform offline for maintenance, but the damage was already done with attackers potentially accessing private images and sensitive user information. This incident highlights the growing trend of attackers targeting cloud-based media platforms and the critical importance of server hardening as organizations increasingly rely on image-sharing services for business communications and collaboration.
6 days ago
Kill Chain
Brevo Supply-Chain Attack Exposes CDN Security Gaps Through ClickFix Campaign
In September 2026, attackers compromised Brevo's Cloudflare API key and deployed malicious Workers that injected ClickFix scripts into the company's websites and customer-embedded JavaScript components for approximately 5.5 hours. The attack affected brevo.com, sendinblue.com, and customer sites using Brevo forms, conversation widgets, and SDK loaders, potentially impacting up to 100,000 websites. Victims were presented with fake Cloudflare verification pages prompting them to execute malicious commands, while WordPress administrators faced additional risks through backdoor plugin installations that created persistent access points with hardcoded authentication bypasses. This incident highlights the growing sophistication of supply-chain attacks targeting content delivery networks and the increasing prevalence of ClickFix social engineering tactics that exploit user trust in legitimate cloud services to distribute malware at scale.
1 week ago
Kill Chain
Gyazo Breach Exposes Critical Gaps in Upload Security and Data Protection
In September 2026, Japanese image-sharing service Gyazo suffered a critical security breach that exposed 23.62 million user records and 490 million image metadata records. Attackers exploited a vulnerability in Gyazo's image upload server to execute arbitrary commands and access the company's database, compromising email addresses, password hashes, and sensitive image metadata including IDs that could be used to view private images without authorization. The breach primarily affected data from January 2019 or earlier, with Helpfeel temporarily disabling access to some images and forcing all users to reset their passwords. This incident highlights the growing threat to cloud-based content platforms and demonstrates how legacy vulnerabilities in upload systems can lead to massive data exposure. With increasing regulatory scrutiny on data protection and the rise of AI-driven attacks targeting user-generated content platforms, organizations must prioritize securing file upload mechanisms and implementing comprehensive data loss prevention strategies.
1 week ago
Kill Chain
Critical WordPress Plugin Flaw Enables Mass Web Shell Deployment Campaign
Threat actors are actively exploiting CVE-2026-27540, a critical vulnerability in the WooCommerce Wholesale Lead Capture WordPress plugin with over 6,000 installations. The flaw allows unauthenticated attackers to upload arbitrary PHP files through missing file type validation in the wwlc_file_upload_handler AJAX action. Wordfence has blocked over 100,000 exploit attempts since June 2026, with attackers successfully deploying web shells that enable remote code execution and complete site takeover. The vulnerability affects all plugin versions up to 2.0.3.1 and demonstrates how supply chain weaknesses in popular plugins can create widespread attack surfaces. This incident reflects the growing threat to WordPress ecosystems as attackers increasingly target plugin vulnerabilities to achieve mass compromise across thousands of websites simultaneously, highlighting the urgent need for better third-party component security.
1 week ago
Kill Chain
WordPress Under Fire: CVE-2026-27540 Plugin Flaw Enables Mass Webshell Attacks
In September 2026, security researchers identified active exploitation of CVE-2026-27540, a critical vulnerability in the WooCommerce Wholesale Lead Capture WordPress plugin. The flaw allows unauthenticated attackers to upload PHP webshells through an exposed AJAX action, enabling complete site compromise. Wordfence reported blocking over 100,000 exploitation attempts, with attack spikes occurring between June and August 2026. The vulnerability affects versions 2.0.3.1 and older of the premium plugin, which was patched in version 2.0.3.2 released in February 2026. This incident highlights the ongoing threat landscape targeting WordPress ecosystems, where third-party plugin vulnerabilities continue to provide attack vectors for cybercriminals seeking to establish persistent access to websites for malicious purposes including data theft and further payload deployment.
1 week ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports