The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Marketing/Advertising/Sales
Breach intelligence, attack campaigns, and threat reports targeting the Marketing/Advertising/Sales sector.
Explore Other Sectors
Marketing/Advertising/Sales Threat Reports
Supply Chain Attack Compromises Admin Menu Editor Pro Plugin, Backdoors 1,500+ WordPress Sites
In September 2026, threat actors compromised the Admin Menu Editor Pro WordPress plugin distribution infrastructure, affecting over 1,500 websites across 230+ customers. The attackers gained root-level access to adminmenueditor.com and injected malicious code into plugin versions 2.35 and 2.36, creating backdoor access through hidden user accounts and web shells. The compromise lasted approximately seven hours before detection, with the malicious payload (wp-user-consent.php) establishing persistent access on victim sites. Developer Janis Elsts took the distribution site offline and recommended customers restore from pre-September 14 backups to ensure complete remediation. This incident highlights the growing sophistication of supply chain attacks targeting WordPress ecosystems, where attackers increasingly focus on plugin distribution networks to achieve mass compromise. With WordPress powering over 40% of websites globally, such attacks represent a critical threat vector that organizations must address through enhanced vendor security assessments and plugin management practices.
1 week ago
Kill Chain
How a Malicious Twitch Extension Stole 30,000 Users' OAuth Tokens
In September 2026, security researchers discovered that the 'Twitch Enhanced Viewer | JeetBot' browser extension, installed by over 30,000 users across Chrome and Firefox stores, was secretly harvesting users' OAuth authentication tokens. The extension, marketed as a legitimate Twitch enhancement tool for ad-blocking and quality improvements, redirected users' streaming requests through Russian-operated proxy servers while embedding authentication credentials in URL parameters, making them easily accessible in server logs. This supply-chain attack demonstrates the persistent risk of malicious browser extensions infiltrating official app stores despite security reviews. This incident highlights the growing trend of credential theft through seemingly legitimate browser extensions, coinciding with increased regulatory scrutiny of third-party software supply chains and the need for enhanced OAuth token security practices.
1 week ago
Kill Chain
JeetBot Extension Compromises 31,000 Twitch Users in Massive OAuth Token Theft
In September 2026, a malicious Twitch browser extension called 'Twitch Enhanced Viewer | JeetBot' was discovered exposing OAuth tokens from nearly 31,000 users across Chrome and Firefox platforms. The extension, developed by HISHIMIRO/jeetbot.cc and operated by Cyprus-based developer Aleksandr Popov, routed users' authenticated Twitch sessions through operator-controlled proxy servers while claiming to provide ad-free viewing and region-unlocked content. The OAuth tokens were transmitted in cleartext as URL query parameters, enabling unauthorized access to users' chat, private messages, and account settings. Interestingly, the token forwarding mechanism excluded a hardcoded list of ten Russian streamer channels with large followings. This incident highlights the growing threat of supply chain attacks targeting browser extensions and the critical importance of OAuth token security in modern web applications. As streaming platforms and social media continue to expand globally, malicious actors are increasingly exploiting trusted software distribution channels to harvest user credentials at scale.
1 week ago
Kill Chain
Google Play Early Access Exploited: How Thousands of Deceptive Apps Bypassed Security
In September 2026, cybersecurity researchers discovered threat actors systematically abusing Google Play's Early Access program to distribute thousands of deceptive Android applications. These malicious apps promised financial rewards, casino winnings, and premium content while exploiting the program's feature that prevents user reviews and ratings. Notable examples included fake casino games and a Grand Theft Auto imitator called "Vice Streets: Open World" with over 1 million downloads. The attackers promoted these apps through social media platforms using AI-generated celebrity deepfakes, ultimately generating revenue through excessive advertising while never delivering promised payouts to users. This incident highlights the growing sophistication of mobile malware campaigns that exploit legitimate platform features to bypass traditional security mechanisms. The abuse of Early Access programs represents an emerging trend where attackers leverage regulatory gaps and user trust mechanisms to distribute deceptive applications at scale.
2 weeks ago
Kill Chain
Grindr's £26 Million Settlement Exposes Critical Gaps in Dating App Data Privacy
In September 2026, Grindr agreed to pay £26 million ($35.1 million) to settle a U.K. class action lawsuit involving over 10,000 users whose sensitive personal data, including HIV status, was shared with third-party advertising companies Apptimize and Localytics between 2018-2020. The incident, originally exposed by Norwegian research group SINTEF in April 2018, occurred while Grindr was owned by Chinese gaming company Kunlun, before its 2020 acquisition by San Vicente Acquisition LLC. The settlement covers historical data practices that violated U.K. privacy laws through unauthorized sharing of location data, sexual orientation, and medical information for commercial advertising purposes. This incident highlights the ongoing regulatory scrutiny of data privacy violations in dating apps and social platforms, particularly as GDPR enforcement intensifies and class action lawsuits become more prevalent in addressing historical privacy breaches involving sensitive personal information.
2 weeks ago
Kill Chain
BengalSEO Campaign Weaponizes Search Results for MayaBot Distribution
The BengalSEO campaign represents a sophisticated search engine optimization poisoning operation that has been active since 2015, targeting Bing search results to deliver MayaBot malware and facilitate tech support scams. Operating from Rajasthan, India, the threat actors behind this campaign manipulate search engine results to redirect victims to malicious websites, where they deploy malware or engage in fraudulent technical support schemes. The campaign demonstrates the evolution of SEO poisoning techniques and their effectiveness in reaching unsuspecting users through legitimate search queries. This incident highlights the growing sophistication of search engine manipulation attacks and their integration with traditional malware distribution methods. As organizations increasingly rely on digital visibility and search engine optimization, the weaponization of these same techniques by threat actors represents a significant shift in attack vectors that security teams must address.
2 weeks ago
Kill Chain
JSCeal Malware: Advanced Session Hijacking Bypasses Google Authentication
JSCeal, a sophisticated compiled V8 JavaScript malware, has been actively targeting cryptocurrency traders since late 2024 through malvertising campaigns on Facebook and Google. The malware uses fake TradingView installers distributed via counterfeit trading sites to harvest credentials, steal browser data, and conduct session replay attacks that bypass Google authentication using stolen cookies. Check Point Research revealed that JSCeal employs advanced obfuscation techniques including RC4-protected strings and control-flow flattening, while maintaining surveillance capabilities through keylogging and screenshot capture. The threat actors behind JSCeal, linked to WEEVILPROXY and MeadowLocust clusters, have expanded their operations across 12 countries in 25 languages, primarily targeting Asia Pacific and Latin America regions. This incident highlights the growing sophistication of browser-based malware campaigns that exploit legitimate advertising platforms to distribute advanced credential harvesting tools, representing a significant escalation in session hijacking techniques that can bypass modern authentication mechanisms.
2 weeks ago
Kill Chain
Mass WordPress Plugin Exploitation: 440,000 Attacks Target Critical RCE Flaws
In July-August 2026, threat actors launched widespread exploitation campaigns targeting critical remote code execution vulnerabilities in two popular WordPress plugins: Super Forms (CVE-2026-14894, CVSS 9.8) and Elementor Pro (CVE-2026-32475, CVSS 9.0-9.8). Both flaws allow unauthenticated attackers to upload malicious PHP files through missing file type validation, enabling complete site takeover. Wordfence blocked over 440,000 exploit attempts across both vulnerabilities, with attackers deploying web shells like "Mushr00w_upl.php" to establish persistent access and exfiltrate data. The mass exploitation demonstrates the continued threat to web applications through plugin vulnerabilities. These attacks highlight the accelerating pace of WordPress plugin exploitation in 2026, as threat actors increasingly target content management systems to gain initial access for broader campaigns including ransomware deployment and data theft operations.
3 weeks ago
Kill Chain
ASCII Smuggling Crosses Over: How AI Attack Techniques Are Transforming Phishing
In February 2026, Microsoft researchers identified a large-scale phishing campaign that repurposed ASCII smuggling techniques originally developed for AI prompt injection attacks. The attackers used invisible Unicode tag characters (U+E0000-U+E007F) to split financial lure words like 'funding' within phishing emails, evading traditional email security filters that rely on keyword detection. The campaign peaked at over 2.3 million messages daily and operated through legitimate email marketing infrastructure, demonstrating how AI-era attack techniques are crossing over into traditional threat vectors. This incident highlights the evolving sophistication of phishing attacks as threat actors adapt cutting-edge evasion techniques originally designed for AI systems to bypass conventional email security defenses. The crossover represents a significant shift in the threat landscape where AI security research methods are being weaponized for traditional cybercrime.
3 weeks ago
Kill Chain
Critical Elementor Pro Vulnerability Enables WordPress Site Takeovers
In September 2026, threat actors began actively exploiting CVE-2026-32475, a critical vulnerability in the Elementor Pro WordPress plugin with over 6 million installations. The flaw allows attackers to bypass file upload validation by submitting an empty file as the first array element and a malicious PHP file as the second, enabling arbitrary code execution on vulnerable WordPress sites. Wordfence recorded nearly 200,000 exploitation attempts within days of the August 19 patch release, with attackers successfully deploying webshells to the /wp-content/uploads/elementor/forms/ directory for remote command execution. This incident highlights the persistent risk of web application vulnerabilities in popular content management systems, particularly when exploitation begins immediately after patch availability. The rapid weaponization demonstrates sophisticated threat actor capabilities in identifying and exploiting plugin vulnerabilities that affect millions of websites worldwide.
3 weeks ago
Kill Chain
Russian Cybercriminal Charged in Massive Freelancer Phishing Campaign
Between June 2016 and November 2017, Russian national Searzhudin Tamirlanovich Aktulaev conducted a large-scale phishing campaign targeting freelance workers through a California-based employment platform. Using 255 fake accounts, Aktulaev sent malicious Excel attachments to 80,000 freelancers, deploying TVRAT and DarkVNC malware to gain remote access to victim systems. The malware enabled theft of e-commerce credentials and personally identifiable information, with half of all victims located in the United States. Aktulaev was arrested in Cyprus in May 2025 and extradited to face federal charges. This case demonstrates the persistent threat of credential theft operations targeting gig economy workers and the growing sophistication of Russian cybercriminals exploiting legitimate platforms for large-scale data harvesting campaigns.
3 weeks ago
Kill Chain
Critical WordPress Plugin Vulnerability Exposes 5 Million Sites to Complete Takeover
A critical SQL injection vulnerability (CVE-2026-19949) in the All-in-One WP Migration and Backup WordPress plugin exposed over 5 million websites to complete takeover attacks. Security researcher Jack Taylor discovered the second-order SQL injection flaw that allows unauthenticated attackers to plant malicious code through WordPress trackbacks, which executes when administrators perform routine backup operations. The vulnerability enables attackers to expose the plugin's secret import key and upload malicious archives containing executable code, potentially leading to full website compromise. While ServMask patched the issue in version 7.110 on August 20, 2026, approximately 3.25 million sites remain vulnerable as only 35% of users have updated. This incident highlights the growing trend of supply chain attacks targeting widely-used WordPress plugins, emphasizing the critical need for organizations to maintain rigorous plugin update procedures and implement comprehensive application security controls.
3 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports