✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Marketing/Advertising/Sales
Breach intelligence, attack campaigns, and threat reports targeting the Marketing/Advertising/Sales sector.
Explore Other Sectors
Marketing/Advertising/Sales Threat Reports
Google's 2025 Gemini AI Initiative: A New Era in Combating Malvertising
In 2025, Google intensified its efforts to combat malvertising by integrating its Gemini AI models into ad detection systems. This initiative led to the blocking or removal of 8.3 billion ads and the suspension of 24.9 million advertiser accounts, including 602 million ads linked to scams. Malvertising campaigns often impersonate legitimate brands to distribute malware or lead users to phishing sites. By leveraging Gemini AI, Google enhanced its ability to analyze vast datasets, including advertiser behavior and campaign patterns, to identify and block malicious ads before they reach users. ([apnews.com](https://apnews.com/article/06d9ef869958555884989e8ec25974be?utm_source=openai)) The urgency of addressing malvertising has grown as cybercriminals increasingly use generative AI to create deceptive ads at scale. Google's proactive measures with Gemini AI have not only improved ad filtering efficiency but also reduced incorrect advertiser suspensions by 80%. This underscores the critical need for advanced AI-driven defenses to maintain the integrity of digital advertising platforms. ([apnews.com](https://apnews.com/article/06d9ef869958555884989e8ec25974be?utm_source=openai))
3 months ago
Kill Chain
Massive WordPress Plugin Supply Chain Attack Compromises Thousands of Websites
In August 2025, a malicious actor acquired the EssentialPlugin suite, comprising over 30 WordPress plugins, and embedded dormant backdoors into their codebase. These backdoors remained inactive until April 2026, when they were activated to inject spam content and redirects into websites using the compromised plugins. This supply chain attack affected thousands of sites, exploiting the trust placed in widely-used plugins to distribute malware. The incident underscores the critical need for vigilance in monitoring third-party software components and the potential risks associated with software supply chain vulnerabilities. As attackers increasingly target trusted software providers to distribute malicious code, organizations must implement robust security measures to detect and mitigate such threats.
3 months ago
Kill Chain
Microsoft and Salesforce Address Critical AI Security Flaws
In April 2026, security researchers identified critical prompt injection vulnerabilities in Microsoft Copilot and Salesforce Agentforce, which could allow attackers to exfiltrate sensitive data. In Microsoft's case, malicious code inserted into SharePoint forms could trigger Copilot to send customer data to unauthorized emails. Similarly, Salesforce's Agentforce was susceptible to prompt injections via public-facing lead forms, enabling unauthorized access to CRM data. Both companies have since patched these vulnerabilities. ([darkreading.com](https://www.darkreading.com/cloud-security/microsoft-salesforce-patch-ai-agent-data-leak-flaws/?utm_source=openai)) This incident underscores the persistent threat of prompt injection attacks in AI systems, highlighting the need for robust input validation and security measures to prevent unauthorized data access and exfiltration.
3 months ago
Kill Chain
Massive Data Breach: 108 Malicious Chrome Extensions Compromise 20,000 Users
In April 2026, cybersecurity researchers uncovered a coordinated campaign involving 108 malicious Google Chrome extensions that compromised approximately 20,000 users. These extensions, published under five fake identities, masqueraded as legitimate tools such as games, translation utilities, and YouTube enhancers. Once installed, they exfiltrated sensitive data, including Google account credentials and Telegram session tokens, to a centralized command-and-control server. Some extensions injected ads and arbitrary JavaScript code into web pages, while others stripped security headers from sites like YouTube and TikTok to facilitate further exploitation. ([gizchina.com](https://www.gizchina.com/malicious-apps/108-fake-chrome-extensions-were-stealing-your-google-and-telegram-data-remove-them-now/?utm_source=openai)) This incident underscores the persistent threat posed by malicious browser extensions and highlights the need for vigilant scrutiny of third-party add-ons. The attackers' ability to infiltrate the official Chrome Web Store and maintain their presence for an extended period raises concerns about the effectiveness of current security measures in detecting and preventing such threats. ([cybernews.com](https://cybernews.com/security/chrome-extensions-flagged-for-stealing-user-data/?utm_source=openai))
3 months ago
Kill Chain
Mirax Android RAT: A New Era of Mobile Malware Threats
In April 2026, a sophisticated Android remote access trojan (RAT) named Mirax was identified targeting Spanish-speaking countries. Distributed through Meta advertisements, Mirax infected over 220,000 devices by masquerading as legitimate streaming applications. Once installed, it granted attackers full control over compromised devices, enabling real-time interaction, keystroke logging, and the deployment of dynamic overlays to steal sensitive information. Notably, Mirax transformed infected devices into residential proxy nodes using the SOCKS5 protocol, allowing cybercriminals to route malicious traffic through victims' IP addresses, thereby evading detection systems and facilitating fraudulent activities. This incident underscores a concerning evolution in mobile malware, where traditional RAT functionalities are augmented with proxy capabilities, expanding the operational scope of cybercriminals. The use of social media platforms for widespread distribution highlights the need for enhanced vigilance and security measures among users and organizations to mitigate such threats.
3 months ago
Kill Chain
Unveiling Webloc: The Ad-Based Geolocation Surveillance Tool Used by Law Enforcement
In April 2026, Citizen Lab uncovered that law enforcement agencies in Hungary, El Salvador, and the United States utilized Webloc, an ad-based geolocation surveillance system developed by Cobwebs Technologies and later sold by Penlink. Webloc accesses data from up to 500 million mobile devices worldwide, including device identifiers, location coordinates, and profile data harvested from mobile apps and digital advertising. This system enables authorities to monitor individuals' locations and movements without warrants, raising significant privacy and civil liberties concerns. The revelation underscores the growing use of commercial data for surveillance purposes, highlighting the need for stringent oversight and regulation to protect individual privacy rights.
3 months ago
Kill Chain
Smart Slider 3 Pro Supply Chain Attack: A 2026 Case Study
In April 2026, unknown threat actors compromised Nextend's update infrastructure to distribute a malicious version (3.5.1.35) of the Smart Slider 3 Pro plugin for WordPress and Joomla. This backdoored update, available for approximately six hours on April 7, allowed attackers to create hidden administrator accounts, execute remote commands, and establish multiple persistence mechanisms, leading to unauthorized access and potential data exfiltration on affected websites. The incident underscores the critical risks associated with supply chain attacks, where trusted software distribution channels are exploited to deliver malware. Such attacks bypass traditional security measures, emphasizing the need for enhanced vigilance and monitoring of software update processes to detect and mitigate unauthorized modifications promptly.
3 months ago
Kill Chain
Supply Chain Attack on Smart Slider 3 Pro Compromises Websites in 2026
In April 2026, attackers compromised the update system of the Smart Slider 3 Pro plugin, affecting version 3.5.1.35 for both WordPress and Joomla platforms. This malicious update introduced multiple backdoors, created hidden administrator accounts, and exfiltrated sensitive data from affected websites. The incident underscores the critical importance of securing software supply chains to prevent unauthorized code distribution and maintain the integrity of widely used web applications. This event highlights a growing trend of supply chain attacks targeting popular web plugins, emphasizing the need for vigilant monitoring of software updates and the implementation of robust security measures to detect and prevent unauthorized modifications.
3 months ago
Kill Chain
Critical Security Flaw in Ninja Forms Plugin Puts WordPress Sites at Risk
In early 2026, a critical vulnerability (CVE-2026-0740) was discovered in the Ninja Forms File Uploads plugin for WordPress, affecting versions up to 3.3.26. This flaw allowed unauthenticated attackers to upload arbitrary files, including malicious PHP scripts, leading to potential remote code execution and complete site takeover. The vulnerability stemmed from inadequate validation of file types and extensions during the file upload process. The issue was reported on January 8, 2026, and a full patch was released on March 19, 2026, with version 3.3.27. Despite the availability of a fix, exploitation attempts surged, with over 3,600 attacks blocked in a single day. This incident underscores the critical importance of timely software updates and robust security practices in mitigating emerging threats.
3 months ago
Kill Chain
ComfyUI Cryptomining Botnet Attack 2026
In April 2026, over 1,000 internet-exposed instances of ComfyUI, a popular stable diffusion platform, were targeted in a sophisticated cryptomining botnet campaign. Attackers utilized a custom Python scanner to identify vulnerable ComfyUI deployments, exploiting misconfigurations that allowed remote code execution via custom nodes. Upon successful exploitation, compromised hosts were enlisted into a botnet mining Monero and Conflux cryptocurrencies, managed through a Flask-based command-and-control dashboard. The campaign also employed persistence mechanisms to maintain control over infected systems. This incident underscores the critical need for securing internet-facing applications and services, as attackers continue to exploit misconfigurations and vulnerabilities to deploy cryptomining operations. Organizations must prioritize regular security assessments, implement robust authentication mechanisms, and monitor for unauthorized activities to mitigate such threats.
3 months ago
Kill Chain
LinkedIn's 2026 Browser Extension Scanning: A Privacy Wake-Up Call
In April 2026, reports emerged that LinkedIn was injecting hidden JavaScript into user sessions to scan for over 6,000 installed Chrome extensions and collect detailed device data. This practice, termed 'BrowserGate,' raised significant privacy concerns as it linked extension data to identifiable user profiles, potentially exposing sensitive personal and corporate information. LinkedIn acknowledged the scanning but stated it was intended to detect extensions that violate their terms of service by scraping data without consent. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/linkedin-secretly-scans-for-6-000-plus-chrome-extensions-collects-data/?utm_source=openai)) This incident underscores the growing scrutiny over corporate data collection practices and the balance between platform security and user privacy. It highlights the need for transparency in how user data is gathered and utilized, especially as similar fingerprinting techniques have been employed by other companies in the past. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/linkedin-secretly-scans-for-6-000-plus-chrome-extensions-collects-data/?utm_source=openai))
3 months ago
Kill Chain
Critical Vulnerability in Smart Slider 3 Plugin Affects 500K WordPress Sites
In March 2026, a critical vulnerability (CVE-2026-3098) was discovered in the Smart Slider 3 WordPress plugin, affecting versions up to 3.5.1.33. This flaw allows authenticated users, including those with minimal access like subscribers, to read arbitrary files on the server, including sensitive files such as wp-config.php. Exploitation of this vulnerability could lead to unauthorized access to database credentials and potential full site compromise. The issue arises from missing capability checks in the plugin's AJAX export actions, enabling any authenticated user to invoke them without proper validation. This incident underscores the persistent risks associated with plugin vulnerabilities in the WordPress ecosystem. With over 500,000 websites still running vulnerable versions of Smart Slider 3, it highlights the critical need for timely updates and robust security practices to mitigate potential exploits.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports