✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Marketing/Advertising/Sales
Breach intelligence, attack campaigns, and threat reports targeting the Marketing/Advertising/Sales sector.
Explore Other Sectors
Marketing/Advertising/Sales Threat Reports
Dentsu Subsidiary Employee Data Stolen in 2024 Breach: What Enterprises Must Know
In June 2024, a subsidiary of global marketing and PR giant Dentsu experienced a significant data breach in which unidentified threat actors accessed and stole sensitive employee information. The breach reportedly targeted internal personnel data, potentially exposing names, contact information, and other personally identifiable details, though Dentsu has not publicly shared whether client data was affected. The precise entry vector has not been disclosed, but the attack highlights vulnerabilities in east-west traffic inspection and data-in-transit encryption within subsidiary environments. Dentsu's management responded by initiating a comprehensive forensic investigation and notifying affected employees while enhancing internal security protocols. This breach accentuates the growing targeting of large holding companies and their subsidiaries, as attackers increasingly seek weak links in global enterprise ecosystems. With regulatory pressure mounting and privacy violations facing stiffer penalties worldwide, all large organizations must urgently reassess how they secure internal traffic and control access across decentralised operational units.
6 months ago
Kill Chain
YouTube Ghost Network: 2025 Infostealer Botnets Target Users at Scale
In early 2025, a sophisticated malware operation known as the YouTube Ghost Network leveraged compromised accounts and extensive botnets to deliver highly effective infostealer payloads to unsuspecting users. Attackers exploited both social engineering and automated bot infrastructure to distribute malware at scale via malicious YouTube links and hijacked channels, resulting in a threefold increase in infostealer output within months. The campaign focused on harvesting credentials, session tokens, and other sensitive data through obfuscated lures and persistent infiltration tactics, impacting thousands of users globally and raising significant concerns about platform-based threats. This incident underscores the surging trend of infostealer campaigns utilizing social platforms as distribution vectors, challenging traditional detection and response strategies. Escalating reliance on cloud services and digital identities intensifies the risk, making proactive monitoring and policy enforcement critical as adversaries weaponize trusted channels and automation for rapid expansion.
6 months ago
Kill Chain
Dentsu Merkle 2024 Data Breach: What Went Wrong and How to Respond
In June 2024, Japanese advertising conglomerate Dentsu disclosed a cybersecurity breach affecting its U.S.-based subsidiary, Merkle. Unauthorized attackers gained access to internal systems, resulting in the exposure of sensitive employee and client data. The incident was detected after suspicious activity was identified, prompting an immediate investigation and containment measures. While the full extent of the breach is under review, initial reports confirm that personally identifiable information and potentially business-critical records were compromised, highlighting gaps in east-west traffic security and egress controls within corporate IT infrastructure. This incident demonstrates the continuing trend of cyberattacks against major marketing and advertising firms, which are prized for their troves of client data. Organizations are under mounting pressure to modernize east-west traffic security, enforce strict network segmentation, and rapidly detect post-compromise anomaly activity as threat actors increasingly target supply chain partners and professional services firms.
6 months ago
Kill Chain
WordPress Mass Exploitation 2024: The Risks of Outdated Plugin Vulnerabilities
In June 2024, a mass exploitation campaign targeted thousands of WordPress websites worldwide by abusing known critical vulnerabilities in the GutenKit and Hunk Companion plugins. Attackers leveraged outdated versions lacking essential security patches to achieve remote code execution (RCE), enabling full control over affected sites. The campaign's automated exploits installed malicious payloads, manipulated website content, and frequently enabled further lateral movement or data theft. Organizations relying on vulnerable plugins faced significant reputational and operational disruption, with site defacements, malware delivery, and potential customer data exposure as key impacts. The incident highlights the persistent security challenge posed by unpatched plugins in popular web platforms. Amid a surge in mass web exploitation and supply chain attacks against CMS ecosystems, adversaries are rapidly weaponizing public proof-of-concept exploits, putting organizations at immediate risk from even dated vulnerabilities.
6 months ago
Kill Chain
YouTube Malware Network: Over 3,000 Malicious Videos Unleashed in 2025 Campaign
In 2025, a coordinated cybercriminal network leveraged YouTube to distribute malware by uploading over 3,000 malicious videos disguised as legitimate content. The actors abused the platform’s trusted reputation and sophisticated SEO tactics to trick users into downloading harmful payloads linked from these videos. First detected in 2021, the operation escalated throughout 2025, with the volume of malicious uploads tripling and impacting thousands of unsuspecting viewers worldwide. The campaign has demonstrated the persistent risk posed by seemingly trustworthy public platforms being subverted for large-scale malware distribution, resulting in significant data compromise and potential financial losses for both individuals and organizations. This incident reflects a broader trend where threat actors exploit popular social media and video platforms to evade conventional perimeter defenses and reach wider audiences. The proliferation of such tactics underscores the urgent need for organizations and users to increase vigilance and adopt security controls that emphasize east-west traffic security, anomaly detection, and robust egress monitoring.
6 months ago
Kill Chain
Spear-Phishers Impersonate Tesla & Red Bull Recruiters in Targeted Job Scam (2024)
In early 2024, cyber attackers launched a coordinated spear-phishing campaign targeting social media influencers and digital marketing professionals by impersonating talent recruiters from popular brands such as Tesla and Red Bull. The threat actors distributed convincing fake job offers via email and LinkedIn, luring victims to share personal information, credentials, and résumé files. The adversaries’ primary objectives were data theft and potential follow-up attacks leveraging stolen credentials and information, causing reputational damage and exposing a sensitive subset of professionals. This incident highlights the growing use of sophisticated social engineering tactics against targeted individuals in the digital marketing and influencer space. Similar attacks have proliferated across industries, underlining the urgent need for heightened workforce awareness, advanced email security, and robust identity controls.
6 months ago
Kill Chain
ICTBroadcast RCE Vulnerability: Hackers Gain Remote Shell Access via Cookie Exploit in 2025
In October 2025, a critical remote code execution vulnerability (CVE-2025-2611, CVSS 9.3) in ICTBroadcast's autodialer platform was actively exploited by threat actors. By leveraging improper input validation in the application's session cookie handler, attackers achieved unauthenticated remote shell access to internet-exposed servers. This exploit enabled malicious actors to execute arbitrary system commands, potentially compromising sensitive data and business operations for organizations using ICTBroadcast. The incident required immediate patching and forensic investigation to contain the breach and restore normal operations. This breach highlights the persistent risk posed by zero-day vulnerabilities in widely used communications software, especially as remote access vector attacks surge. It underscores the strategic shift among attackers toward supply chain and software-specific exploits, which remain difficult to rapidly mitigate across diverse deployment environments.
6 months ago
Kill Chain
Adobe AEM 2025 Breach: CISA Flags Critical Application Flaw Under Active Attack
In June 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) raised alarms about a critical misconfiguration vulnerability (CVE-2025-54253) impacting Adobe Experience Manager (AEM). This flaw, assigned a CVSS score of 10.0, allows remote unauthenticated attackers to achieve arbitrary code execution on vulnerable AEM instances. Active exploitation was confirmed as attackers leveraged the bug to gain foothold, escalate privileges, and deploy malware on targeted organizations, potentially exposing sensitive data and compromising internal operations. The incident highlights the risks of unpatched enterprise software within digital supply chains and data-driven organizations. The AEM vulnerability is currently notable due to increased exploitation by multiple threat actors, coinciding with a larger trend of critical zero-day application flaws being used in advanced persistent attacks. Regulatory agencies and security experts underscore the urgency for patching exposed business applications given the frequency and sophistication of exploitation campaigns in 2025.
6 months ago
Kill Chain
131 Chrome Extensions Hijack WhatsApp Web: The 2025 Brazilian Spam Campaign
In October 2025, a coordinated cyberattack was uncovered where 131 malicious Chrome browser extensions—clones of a popular WhatsApp Web automation tool—were used to hijack users’ sessions and launch an automated spam campaign targeting Brazilian users. Researchers from security company Socket found that these plugins, sharing an identical codebase and infrastructure, infected over 20,000 users by enticing them to install seemingly legitimate add-ons, enabling attackers to take control of browser sessions, inject spam messages, and exfiltrate private data at scale. The incident underscores the risks associated with browser extension supply chain threats, exposing enterprises and individuals to large-scale account compromise and privacy breaches. This breach is particularly significant as it demonstrates the adaptability and persistence of threat actors in abusing browser supply routes and leveraging rebranded extensions to evade traditional security controls. The campaign’s targeting of WhatsApp Web also signals a shift toward exploiting widely-used communication channels for coordinated spam and fraud, spotlighting the critical need for proactive browser extension vetting and user awareness.
6 months ago
Kill Chain
TikTok-Delivered Infostealer: ClickFix Campaign Compromises Credentials
In October 2025, a widespread campaign leveraged TikTok videos masquerading as free activation guides for popular software titles—including Windows, Adobe products, and Spotify—to distribute information-stealing malware. Attackers used "ClickFix" social engineering to instruct viewers to run obfuscated PowerShell commands, delivering the Aura Stealer infostealer and an additional payload via Cloudflare-hosted executables. The attack enabled threat actors to harvest browser credentials, authentication cookies, and wallet data from victims, leading to high risk of account compromise and data theft. Infection occurred after users were tricked into executing single-line commands under the guise of software activation or fixes. This incident highlights the increasing weaponization of social media platforms as initial access vectors for malware and demonstrates the growing sophistication of infostealer campaigns. The trend underscores the urgent need for organizations to address social engineering risks and update awareness programs as attackers rapidly innovate their distribution methods.
6 months ago
Kill Chain
MANGO Data Breach 2024: Third-Party Vendor Incident Exposes Customer Data
In April 2024, Spanish fashion retailer MANGO reported that a data breach exposed customer personal information after one of its marketing vendors was compromised. The incident came to light when MANGO began notifying affected customers, stating that data such as names, contact details, and potentially other identifiers had been accessed without authorization. The intrusion was possible due to attackers breaching the marketing service provider’s environment, reflecting a concerning third-party risk. MANGO responded by collaborating with the vendor, investigating the incident, notifying authorities, and reinforcing security controls. This breach underscores a growing trend in supply-chain attacks where threat actors exploit weaker security in trusted partners. It highlights the urgent need for stringent vendor management, robust segmentation, and continuous monitoring, especially as regulatory focus intensifies on safeguarding consumer data throughout the supply chain.
6 months ago
Kill Chain
Hackers Exploit Auth Bypass in Service Finder WordPress Theme (CVE-2025-5947)
In the autumn of 2025, a critical authentication bypass vulnerability (CVE-2025-5947) was discovered and actively exploited in the Service Finder WordPress theme, affecting versions 6.0 and older. Attackers leveraged improper validation in the 'service_finder_switch_back()' function, allowing them to impersonate any user—including administrators—simply by sending HTTP requests with a crafted cookie or query parameter. The flaw enabled threat actors to gain full administrative control over thousands of websites, with over 13,800 exploitation attempts recorded by Wordfence since August 1. Attackers could then create or modify site content, add malicious code, or export sensitive data undetected, putting site owners and users at risk. This breach is particularly relevant as it illustrates the continued targeting of WordPress ecosystems with privilege escalation exploits, highlighting growing risks from vulnerable third-party themes and plugins. It underscores the urgency of rapid patching, improved logging, and continuous monitoring to defend against evolving web application threats.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports