✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Marketing/Advertising/Sales
Breach intelligence, attack campaigns, and threat reports targeting the Marketing/Advertising/Sales sector.
Explore Other Sectors
Marketing/Advertising/Sales Threat Reports
AI Advertising Firm Doublespeed Breached: Over 1,000 Smartphones Compromised in 2025 Attack
In October 2025, AI advertising startup Doublespeed suffered a major security breach when a hacker exploited a vulnerability in the company’s backend systems to gain unauthorized access to its phone farm managing over 1,000 AI-generated social media accounts. The attacker was able to both extract confidential data about undisclosed advertising campaigns and seize remote control of the smartphones used to operate the accounts. This exposure illuminated the company’s covert promotion practices and presented significant risks of both data exfiltration and operational compromise. Despite being notified on October 31, the company had not fully remediated access at the time of reporting, heightening concerns about internal controls and disclosure procedures. The breach underscores growing vulnerabilities in companies that use automation at scale, especially in the context of AI-driven influence operations and digital marketing. It reflects broader industry trends: increasing use of phone farms, sophisticated identity evasion, and regulatory scrutiny around undeclared digital ads, all contributing to a shifting cyber threat landscape.
6 months ago
Kill Chain
GhostPoster Malware Infects 17 Firefox Extensions: Supply Chain Risks Hit 50,000+ Users
In late 2025, cybersecurity researchers discovered a campaign named GhostPoster, which compromised the supply chain of Mozilla Firefox by infiltrating 17 browser add-ons with malicious JavaScript. These extensions, collectively downloaded over 50,000 times, were found to hijack affiliate links, inject tracking scripts, and facilitate click and ad fraud. Threat actors used logo image files within the add-ons to conceal the payload and persist across infected hosts. The extensions were promptly removed from the Mozilla add-ons marketplace upon disclosure, but impacted users may have experienced privacy violations and fraudulent activity. This incident highlights continued escalation in browser extension-based supply chain attacks and the increased sophistication of threat actors at targeting trusted ecosystem channels. With organizations relying on browser tools for productivity, ongoing diligence is required to detect, respond to, and prevent similar infiltrations leveraging obfuscated techniques.
6 months ago
Kill Chain
Sneeit WordPress Plugin Hit by Critical RCE: 2025 Exploitation Wave
In August 2025, a critical remote code execution (RCE) vulnerability (CVE-2025-6389) in the widely used Sneeit Framework WordPress plugin (versions <=8.3) was discovered to be actively exploited in the wild. Attackers leveraged this flaw—scoring 9.8 on CVSS—to gain remote access to vulnerable sites, potentially executing arbitrary code, deploying malware, and further compromising user data or site integrity. The vendor responded by releasing version 8.4 with an urgent security patch, but over 1,700 active installations remain at risk. The Sneeit incident underscores a broader trend of rapid weaponization of WordPress plugin flaws by opportunistic threat actors, intensifying risk for websites lacking prompt patching and robust security controls. As attackers increasingly target web applications and supply chain components, organizations must reinforce visibility, detection, and vulnerability management strategies.
6 months ago
Kill Chain
Critical King Addons Elementor Plugin Flaw Exploited in WordPress Sites (CVE-2025-8489)
In early 2025, attackers began actively exploiting a critical privilege escalation flaw (CVE-2025-8489) in the King Addons for Elementor plugin on WordPress sites. By abusing an insecure registration process, threat actors were able to escalate privileges and gain administrative control over vulnerable sites without authorization. This access could be used to manipulate website content, add malicious backdoors, or exfiltrate sensitive data, impacting website owners' security and reputation. The attacks have been widespread due to the plugin's popularity and ease of exploitation, highlighting the persistent risks present in third-party WordPress extensions. This incident is particularly relevant as it exemplifies an ongoing wave of attacks targeting web application vulnerabilities in widely used CMS platforms. The proliferation of such zero-day exploits magnifies risk for organizations, especially as adversaries move quickly to weaponize flaws before patches are broadly applied.
6 months ago
Kill Chain
2025 WordPress King Addons Breach: Unauthenticated Admin Access & Website Takeover
In December 2025, attackers actively exploited a critical vulnerability (CVE-2025-8489, CVSS 9.8) in the popular King Addons for Elementor WordPress plugin. The flaw allowed unauthenticated individuals to escalate privileges by specifying the 'administrator' user role at registration, instantly granting themselves administrative access. Threat actors leveraged this zero-day to seize complete control of vulnerable sites, install malicious content, and potentially exfiltrate sensitive data or deploy further attacks. Affected organizations risked significant operational disruption, data compromise, reputational harm, and potential compliance violations due to unauthorized admin creation and persistence. This incident highlights the increasing trend of exploiting supply-chain and plugin vulnerabilities in widely used CMS platforms. The rapid weaponization of unauthenticated privilege escalation flaws underscores the need for continuous patch management, threat detection, and segmentation controls to counter evolving web application and identity-focused attack techniques.
6 months ago
Kill Chain
Fake Calendly Invites Target Top Brands to Hijack Business Ad Accounts
In mid-2024, a sophisticated phishing campaign leveraged fake Calendly invitation emails to impersonate established brands such as Unilever, Disney, MasterCard, LVMH, and Uber. The attackers crafted convincing lures to target business users and administrators, aiming to harvest credentials for Google Workspace and Facebook Business accounts. Victims who clicked malicious links were redirected to lookalike phishing pages designed to steal login data, potentially enabling unauthorized access to digital ad campaigns, sensitive corporate data, and financial assets. The tactics combined brand impersonation, social engineering, and business workflow subversion, which heightened trust and success rates for attackers. This incident underscores the growing risks of identity-driven attacks that target business SaaS platforms, as cybercriminals increasingly exploit collaboration tools to penetrate defenses. Such phishing methods continue to evolve, challenging traditional detection and user awareness while putting critical business operations at risk.
6 months ago
Kill Chain
JackFix Campaign Exploits Fake Windows Updates to Spread Infostealers in 2025
In late 2025, cybersecurity researchers uncovered a campaign orchestrated by the JackFix group using cloned adult websites as a phishing lure, distributed primarily through malvertising channels. Victims visiting these sites were presented with fake Windows update pop-ups designed to imitate critical security notifications. Unsuspecting users were tricked into executing malicious payloads that installed multiple information stealers, enabling the attackers to exfiltrate credentials, session tokens, and sensitive browser data. This attack illustrates how adversaries exploit popular platforms and social engineering to bypass traditional security controls, posing significant risks to both individuals and enterprises. The incident is particularly significant given the continued adoption of sophisticated phishing techniques and the blending of legitimate web content with highly convincing fraudulent prompts. Enterprises must remain vigilant as such campaigns highlight persistent weaknesses in endpoint protections, user awareness, and lateral movement defenses against infostealers.
6 months ago
Kill Chain
Salesloft Drift SaaS Breach: How Excessive Trust Unlocked CRM Data
In early 2024, the Salesloft Drift SaaS integration breach unfolded when attackers exploited security weaknesses in the Drift chatbot’s OAuth implementation. Malicious actors obtained chatbot OAuth tokens—intended for secure system integrations—and leveraged these for legitimate API calls against customer CRM environments, such as Salesforce. Because the tokens remained valid and were often granted excessive standing privileges, attackers could exfiltrate sensitive business records, contact information, support data, and even embedded credentials across over 700 organizations, all without immediate detection. This breach underscored a powerful new threat vector involving identity and permissions sprawl in SaaS and AI-driven environments. As organizations increasingly rely on deeply integrated third-party systems with broad and persistent access, similar attacks targeting privileged automation and identity-based authorizations are expected to surge without robust governance and continuous monitoring.
6 months ago
Kill Chain
Hundreds of Salesforce Customers Impacted: Gainsight Supply Chain Attack by ShinyHunters
In June 2024, Salesforce customers experienced a significant supply chain breach after a third-party vendor, Gainsight, was compromised in an ongoing campaign traced to the ShinyHunters/UNC6240 threat group. Attackers exploited OAuth application connections between Gainsight and Salesforce, potentially impacting over 200 customer instances and exposing sensitive business data. Salesforce responded promptly by revoking access tokens to block further unauthorized entry but confirmed that no vulnerabilities existed within its core platform. The incident echoes a previous attack wave against Salesloft Drift integrations targeting Salesforce users within the same threat cluster, highlighting persistent exploitation of third-party SaaS application connections. The breach underscores mounting risks associated with SaaS supply chain integrations and highlights a shift in attacker tactics toward abusing trusted app connectors. As enterprises continue to expand reliance on cloud-based business platforms and third-party vendors, such attacks increase the urgency for rigorous vendor risk management, least-privilege access policies, and enhanced anomaly detection.
6 months ago
Kill Chain
2024 Salesloft-Drift Supply Chain Breach: AWS Credential Exposure and Cloud Security Lessons
In early 2024, a sophisticated supply chain attack targeted the Salesloft and Drift integration, leading to the compromise of AWS credentials and unauthorized access to cloud environments. Threat actors exploited weaknesses in the integration pipeline, leveraging exposed secrets to move laterally and access sensitive customer data before the breach became public. Red Canary detected anomalous cloud activity tied to this attack, providing early detection prior to broad public awareness and response, thereby helping to mitigate further impact. This incident is significant as it demonstrates the growing frequency and sophistication of supply chain attacks within SaaS and cloud services, especially those exploiting secret leaks and third-party application integrations. The breach highlights the need for heightened vigilance, identity and credential protection, and advanced threat detection capabilities in the cloud ecosystem.
6 months ago
Kill Chain
WordPress Sites Under Siege: Critical Post SMTP Plugin Flaw Exposes 400,000+ Websites
In June 2024, a critical vulnerability was discovered in the Post SMTP mailer plugin for WordPress, widely used by over 400,000 sites. This flaw allows unauthenticated attackers to reset admin accounts and take full control of affected websites. Threat actors have already exploited the vulnerability by leveraging malicious password reset links, leading to complete site compromise, potential data theft, and abuse of compromised infrastructure for further attacks. The vulnerability prompted emergency patching and urgent advisories from both the plugin authors and security firms. This incident underscores the persistent threat posed by plugin vulnerabilities in the WordPress ecosystem, which remains a popular target for cybercriminals due to its vast user base. The surge in attacks exploiting supply chain and third-party plugin weaknesses highlights the need for rapid vulnerability management and robust security controls for web applications.
6 months ago
Kill Chain
WordPress Post SMTP Plugin Exploited in Mass Admin Account Hijacks (2024)
In early June 2024, cybersecurity researchers identified that a critical vulnerability in the Post SMTP WordPress plugin was being actively exploited by threat actors. This vulnerability allowed attackers to hijack administrator accounts across more than 400,000 affected WordPress sites, enabling complete site control and potentially permitting installation of malicious payloads. Attackers gained initial access through the plugin's weak nonce verification, escalating privileges to compromise sites, deploy backdoors, and exfiltrate sensitive data. The incident demonstrates how widespread web application vulnerabilities can be rapidly weaponized, putting enterprises and small businesses alike at risk of data loss, defacement, or further compromise. The Post SMTP exploitation highlights a recent surge in attacks leveraging zero-day or unpatched CMS plugins on large scales, reflecting attackers’ growing focus on supply chain and SaaS-adjacent targets. As organizations increasingly depend on third-party tools and platforms, maintaining rapid patch cycles and comprehensive visibility into software components is more critical than ever.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports