The Containment Era is here. →Explore

Industry Category

Marketing/Advertising/Sales

Breach intelligence, attack campaigns, and threat reports targeting the Marketing/Advertising/Sales sector.

128 threat reports
Page 7 of 11

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Marketing/Advertising/Sales Threat Reports

Showing 7384 / 128 reports
Instagram's 2026 Private Profile Photo Leak: A Privacy Wake-Up Call
Impact· MEDIUM

Instagram's 2026 Private Profile Photo Leak: A Privacy Wake-Up Call

In October 2025, security researcher Jatin Banga discovered a vulnerability in Instagram's private account feature, where private profile photos and captions were embedded in publicly accessible server responses. This flaw allowed unauthenticated users to access content intended for approved followers. Banga reported the issue to Meta on October 12, 2025, and although Meta initially classified it as a CDN caching problem, the exploit ceased functioning around October 16, 2025. However, Meta later closed the case as 'not applicable,' stating the vulnerability could not be reproduced. This incident underscores the critical importance of rigorous authorization checks in web applications to prevent unauthorized data exposure. Organizations must ensure that private content remains inaccessible to unauthorized users, as such vulnerabilities can lead to significant privacy breaches and erode user trust.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Malicious Chrome Extensions Compromise User Security by Hijacking Affiliate Links and Stealing ChatGPT Tokens
Impact· HIGH

Malicious Chrome Extensions Compromise User Security by Hijacking Affiliate Links and Stealing ChatGPT Tokens

In January 2026, cybersecurity researchers uncovered a series of malicious Google Chrome extensions designed to hijack affiliate links and steal OpenAI ChatGPT authentication tokens. Notably, the 'Amazon Ads Blocker' extension, uploaded by '10Xprofit' on January 19, 2026, claimed to block Amazon ads but covertly injected the developer's affiliate tag into product links, replacing existing ones. This extension was part of a larger cluster targeting e-commerce platforms like AliExpress, Amazon, Best Buy, Shein, Shopify, and Walmart. Additionally, 16 other extensions masquerading as ChatGPT productivity tools were found to exfiltrate ChatGPT session tokens, granting attackers full access to users' conversation histories and associated data. This incident underscores the growing trend of malicious browser extensions exploiting the popularity of AI tools and e-commerce platforms. The deceptive nature of these extensions, often appearing legitimate and even bearing 'Featured' badges, highlights the need for heightened vigilance among users and stricter vetting processes by browser extension stores to prevent such security breaches.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
AI-Powered Android Malware Unleashes New Click-Fraud Wave via Xiaomi App Store
Impact· high

AI-Powered Android Malware Unleashes New Click-Fraud Wave via Xiaomi App Store

In January 2026, cybersecurity researchers at Dr.Web uncovered a sophisticated new Android malware family distributed via Xiaomi’s GetApps, popular third-party APK sites, and messaging platforms like Telegram and Discord. This malware leverages AI-driven image analysis using Google’s TensorFlow.js to identify and autonomously click on hidden browser ads within compromised apps, particularly games, simulating user behavior without obvious signs to victims. The malware is delivered through legitimate-looking apps, which update with malicious payloads post-installation. Impacts include increased battery consumption, higher data charges, and indirect monetization for attackers. This incident exemplifies the evolution of mobile ad fraud TTPs, as attackers increasingly deploy AI/ML for advanced automation and evasion. The trend signals rising risks to mobile advertising integrity and higher scrutiny for app stores’ vetting processes, especially on third-party and OEM-specific app markets.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
North Korean PurpleBravo Fakes Job Interviews to Breach Global Firms: 2026 Incident Analysis
Impact· low

North Korean PurpleBravo Fakes Job Interviews to Breach Global Firms: 2026 Incident Analysis

In January 2026, the North Korean-aligned PurpleBravo threat group orchestrated a sophisticated social engineering campaign targeting more than 3,000 unique IP addresses. The attackers posed as recruiters from leading firms to lure victims, primarily within AI, cryptocurrency, financial services, IT, marketing, and software development, into fake job interviews. Exploiting trust through convincing communications, PurpleBravo gained access to targeted organizations across Europe, South Asia, the Middle East, and Central America, compromising data and exposing confidential operational environments. This campaign underscores the evolution of nation-state social engineering methods, leveraging supply chain trust and exploiting interest in career mobility. As geopolitical tensions rise and attackers continually refine techniques, organizations must double down on identity-centric security and awareness to mitigate evolving social engineering risks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(low)
Read Report
Critical 2026 WordPress ACF Extended Vulnerability Exposes 50,000 Sites to Admin Takeover
Impact· medium

Critical 2026 WordPress ACF Extended Vulnerability Exposes 50,000 Sites to Admin Takeover

In January 2026, a critical privilege escalation vulnerability (CVE-2025-14533) was discovered in the ACF Extended plugin for WordPress, which is active on over 100,000 sites. The flaw enables unauthenticated, remote attackers to create or update user accounts with arbitrary roles, including administrator, by abusing weak form restrictions in plugin versions 0.9.2.1 and earlier. Although the vulnerability requires sites to use specific forms with a role field, compromise enables full site takeover and administrative control. The issue was responsibly disclosed in December 2025 and patched four days later, but nearly half of the installed base reportedly remained exposed at the time of reporting. This incident accentuates the persistent risk posed by third-party plugin vulnerabilities in WordPress ecosystems and the widespread targeting of such platforms by malicious actors. With large-scale enumeration and exploitation of plugin flaws on the rise, organizations should prioritize rapid patching and robust privilege segmentation to reduce their exposure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Researchers Hijack StealC Malware Operators: 2026's XSS-Driven Counterattack
Impact· medium

Researchers Hijack StealC Malware Operators: 2026's XSS-Driven Counterattack

In January 2026, cybersecurity researchers uncovered and exploited a cross-site scripting (XSS) vulnerability in the web administration panel of the infamous StealC infostealer malware. By leveraging this flaw, the researchers were able to hijack malware operator sessions, collect hardware and geographic fingerprints, observe live threat actor activities, and even seize control of the attackers' own administration panels. One notable instance involved tracking a StealC affiliate operating as 'YouTubeTA', who stole credentials via malicious YouTube links that resulted in over 5,000 compromised devices and the theft of nearly 390,000 passwords and 30 million cookies. The research highlights critical operational risks inherent in the malware-as-a-service (MaaS) model, particularly as platforms surge in popularity and complexity. This incident is especially relevant as the MaaS cybercrime landscape continues to expand, driving rapid adoption of infostealer toolkits like StealC. Security teams must remain vigilant to emerging attacker tradecraft and vulnerabilities, as both operators and defenders look to exploit weaknesses in rival infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Modular DS WordPress Plugin Flaw Grants Attackers Admin Access in Widespread 2026 Breach
Impact· medium

Modular DS WordPress Plugin Flaw Grants Attackers Admin Access in Widespread 2026 Breach

In January 2026, a critical authentication bypass vulnerability (CVE-2026-23550) was discovered and exploited in the Modular DS WordPress plugin. With over 40,000 installations, the plugin allowed central management of multiple WordPress sites. The flaw enabled unauthenticated attackers to remotely access admin-level privileges by exploiting flawed logic in the plugin’s direct request mode, resulting in privileged access without cryptographic checks. Attackers were able to select or auto-enroll themselves as site administrators, exposing affected sites to full compromise and potential downstream attacks. A patch was quickly released in version 2.5.2, closing the immediate vulnerability. This incident stands out as attackers increasingly target plugin ecosystems in widely-used CMS platforms, exploiting software supply chain vectors for rapid, broad impact. The case illustrates the urgency for continuous code review and rapid patch management in response to emergent threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Browser-in-Browser Phishing Surge: Facebook Credential Thefts Expose New Risks in 2024
Impact· medium

Browser-in-Browser Phishing Surge: Facebook Credential Thefts Expose New Risks in 2024

In early 2024, cybercriminals dramatically escalated the use of the 'browser-in-browser' (BitB) attack technique to steal Facebook login credentials. This method mimics a legitimate browser popup within the user's real window, tricking individuals into entering their login details on phishing sites that look identical to authentic Facebook authentication dialogs. Attackers lure victims through targeted ads, social engineering, and cleverly crafted phishing emails. The impact includes widespread account compromise, enabling follow-on fraud, spam campaigns, and potential data exfiltration from the compromised users' profiles. Facebook, along with the wider cybersecurity community, is warning users and rolling out alerts in response, but overall threat exposure remains high. The BitB phishing approach reflects a concerning trend of attackers using more advanced visual deceptions to bypass user awareness and established security controls. Its prevalence highlights a widening capability gap in traditional anti-phishing technologies, reinforcing the need for robust anomaly response and continuous education amid shifting adversary tactics.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
n8n npm Supply Chain Attack: OAuth Tokens Stolen via Malicious Community Nodes
Impact· medium

n8n npm Supply Chain Attack: OAuth Tokens Stolen via Malicious Community Nodes

In early January 2026, threat actors targeted the n8n workflow automation ecosystem by publishing eight malicious npm packages that mimicked legitimate integrations. These packages prompted unsuspecting users to connect OAuth-protected services like Google Ads, Stripe, and Salesforce. Once installed as community nodes, the malware exfiltrated encrypted OAuth tokens from the n8n credential store by decrypting them with n8n's own master key and sending them to attacker-controlled servers. The campaign exploited developer trust in community packages and highlighted a dangerous new avenue for credential theft at scale. This incident reflects the increasing sophistication and frequency of supply chain attacks, particularly against workflow automation tools that centralize sensitive credentials. With open-source ecosystems growing rapidly, businesses face heightened urgency to scrutinize third-party integrations and adopt least-privilege, zero trust security practices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Instagram 2026: Data Scraping Leak Exposes 17 Million Accounts
Impact· medium

Instagram 2026: Data Scraping Leak Exposes 17 Million Accounts

In January 2026, security researchers and several hacking forums circulated claims that data for over 17 million Instagram accounts was leaked online. The incident is believed to stem from large-scale data scraping leveraging a password reset email bug, combined potentially with prior years' API vulnerabilities. The leaked dataset included a variety of personal information such as usernames, phone numbers, email addresses, and physical addresses. No passwords were exposed, and Meta (Instagram's parent company) denies that a system breach or new API compromise occurred, noting existing issues were promptly addressed and account security remains uncompromised. This case underscores the ongoing threat of data scraping and API abuse, where publicly accessible or insufficiently protected endpoints are targeted by cybercriminals. With the proliferation of social engineering attacks using scraped personal data and the repeated emergence of similar incidents across major platforms, the need for robust API security and user vigilance has never been greater.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
DoJ Takes Down Fraud Domain Powering $14.6M Account Takeover Scheme
Impact· high

DoJ Takes Down Fraud Domain Powering $14.6M Account Takeover Scheme

In December 2025, the U.S. Department of Justice (DoJ), working with international partners, seized the domain web3adspanels[.]org at the heart of a large-scale bank account takeover scheme. The criminal group exploited fraudulent search ads to trick users into accessing spoofed bank login portals, harvesting credentials through malicious site components. These stolen credentials enabled attackers to infiltrate legitimate banking sites, drain victim accounts, and inflict confirmed losses of $14.6 million across 19 U.S. victims, including two companies. The backend database hosted by the seized domain contained thousands of login credentials and operated through November 2025. This incident is part of a broader surge in credential-based financial fraud, leveraging sophisticated phishing infrastructure and real-time abuse of search advertising. With attackers refining techniques to bypass user suspicion, enforcement agencies are increasing pressure on such online infrastructure in response to rising losses and evolving digital fraud tactics.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Nomani Scam Exposes AI Deepfake Threats to Social Media in 2025
Impact· high

Nomani Scam Exposes AI Deepfake Threats to Social Media in 2025

In 2025, the Nomani investment scam surged by 62%, leveraging sophisticated AI-based deepfake advertisements across major social media platforms including Facebook and YouTube. The scheme utilized convincing fake endorsements and manipulated video content to lure unsuspecting individuals into fraudulent investment schemes. Security firm ESET recorded over 64,000 unique URLs distributing the fraudulent campaign, indicating an expansion both in scale and reach. The attackers exploited trust in familiar faces, rapidly spreading the scam and leading to substantial financial losses and reputational risks for victims and targeted brands. This incident highlights the growing threat of AI-enabled social engineering, with deepfakes enabling unprecedented scale and believability. As identity manipulation technologies proliferate, organizations and regulators face increased pressure to combat fraud, educate users, and adapt security controls to counter the evolving landscape of digital deception.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports