The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Marketing/Advertising/Sales
Breach intelligence, attack campaigns, and threat reports targeting the Marketing/Advertising/Sales sector.
Explore Other Sectors
Marketing/Advertising/Sales Threat Reports
Meta Ads Campaign Delivers StreamRat Android Banking Trojan to 570K+ Users
Between June and July 2026, cybercriminals leveraged Meta advertising platforms to distribute StreamRat, a sophisticated Android banking trojan targeting Spanish-speaking users through fake television streaming campaigns. The malvertising operation reached approximately 570,950 Meta accounts across the European Union, directing victims to download malicious APK files that granted attackers near-complete device control. Once installed, StreamRat could capture keystrokes, steal credentials through overlay attacks, take screenshots, and remotely control infected devices by exploiting Android's Accessibility services and VPN capabilities. This incident highlights the growing threat of malvertising on major social platforms and the evolution of mobile banking trojans that abuse legitimate Android features for malicious purposes, demonstrating how attackers increasingly target mobile users through trusted advertising channels.
3 weeks ago
Kill Chain
Major Chrome Extension Malware Campaign Steals Crypto from 80,000+ Users
In August 2026, security researchers at Socket uncovered a sophisticated malware campaign targeting Chrome and Edge browser extensions that had been active since early 2024. Nineteen malicious modules were deployed through initially legitimate extensions, some acquired from original creators and weaponized through automatic updates. The most notable example was the "Enable Right Click & Copy" extension with over 70,000 Chrome users and 10,000 Edge users. The malware established encrypted WebSocket connections to command-and-control servers, removed Content Security Policy headers, and deployed modules capable of draining cryptocurrency wallets, stealing credentials from major exchanges like Coinbase and Binance, harvesting social media data, and deploying ClickFix-style phishing attacks. This incident highlights the growing sophistication of supply chain attacks targeting browser ecosystems, coinciding with increased regulatory scrutiny of app store security practices and the rise of cryptocurrency-focused cybercrime operations that leverage trusted distribution channels.
3 weeks ago
Kill Chain
Five Critical WordPress Plugin Flaws Enable Complete Site Takeover
In August 2026, security researchers disclosed five critical vulnerabilities affecting popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These flaws, with CVSS scores ranging from 9.8 to 10.0, enable unauthenticated attackers to achieve complete site takeover through authentication bypass, arbitrary file uploads, privilege escalation, and remote code execution. The vulnerabilities collectively affect millions of WordPress installations, allowing attackers to gain administrator access, execute malicious code, and completely compromise websites without requiring initial authentication. These vulnerabilities highlight the ongoing security challenges in the WordPress ecosystem, where third-party plugins and themes continue to be attractive targets for attackers. With WordPress powering over 40% of websites globally, such widespread plugin vulnerabilities represent a significant attack surface that cybercriminals are increasingly exploiting to establish footholds for ransomware deployment and data theft operations.
3 weeks ago
Kill Chain
Critical Zero-Click RCE in Avada WordPress Theme Exposes 1 Million+ Websites
A critical vulnerability chain tracked as CVE-2026-18431 in the popular Avada WordPress theme and Fusion Builder plugin enables unauthenticated attackers to execute arbitrary PHP code through a sophisticated six-step zero-click attack. The flaw, discovered by Wordfence's AI-powered Argus system, affects Avada versions up to 7.16 and Fusion Builder versions up to 3.16, potentially compromising over 1 million websites. The exploit chains together authorization bypass, input validation failures, trust boundary violations, and file handling weaknesses to achieve complete server compromise. ThemeFusion has released patches in versions 7.16.1 and 3.16.1 respectively. This incident highlights the growing sophistication of WordPress theme vulnerabilities and demonstrates how AI-powered security research tools are accelerating both vulnerability discovery and exploitation timelines. The complex multi-step attack chain represents an evolution in web application threats that bypass traditional security controls.
4 weeks ago
Kill Chain
First Android Car Malware Campaign Targets Vehicle Head Units Through Update Compromise
In June 2026, Kaspersky discovered the first documented malware specifically targeting Android-based vehicle head units, marking a significant expansion of cybercriminal operations into automotive systems. The malware, attributed to the MoYu Group behind the BADBOX botnet, infected DoFun-powered head units through compromised legitimate update mechanisms. Attackers weaponized the TWCore system app's MQTT-based update channel to deliver JarService dropper malware, enabling ad fraud and proxy botnet creation. The sophisticated attack chain demonstrates how threat actors are adapting traditional mobile malware techniques for automotive platforms, exploiting SIM-enabled connectivity in modern vehicle infotainment systems. This incident highlights the emerging threat landscape as connected vehicles become mainstream targets, with automotive cybersecurity gaps creating new attack vectors for established cybercriminal groups seeking to monetize vehicle connectivity infrastructure.
1 month ago
Kill Chain
Critical Elementor Pro Vulnerability Exposes 10M+ WordPress Sites to Remote Code Execution
A critical vulnerability (CVE-2026-32475) in Elementor Pro WordPress plugin versions before 4.2.2 allows unauthenticated attackers to upload executable PHP files for remote code execution. The flaw stems from inconsistent file validation logic in the File Upload module, where empty filename entries are handled differently by validation and processing loops. Attackers can exploit this by crafting multipart uploads with empty first entries followed by malicious PHP payloads, bypassing validation and uploading executable files to public directories. With over 10 million WordPress installations using Elementor, this vulnerability poses significant risk to websites using Elementor Pro forms with file upload functionality enabled. This incident highlights the growing trend of supply chain vulnerabilities targeting popular WordPress plugins and website builders. As organizations increasingly rely on third-party components for web development, plugin vulnerabilities have become a primary attack vector for gaining initial access to web infrastructure and conducting broader network compromises.
1 month ago
Kill Chain
Critical Elementor Pro Vulnerability Exposes WordPress Sites to Unauthenticated Remote Code Execution
A critical vulnerability (CVE-2026-32475) in Elementor Pro WordPress plugin allowed unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution. The flaw, scoring 9.0 CVSS, exploited discrepancies in file validation logic within the Forms module's File Upload field. Attackers could bypass extension blocklists by submitting dual file parts, enabling PHP script uploads to public directories. This affected all plugin versions up to 4.2.1, impacting websites with common form configurations like job applications and support tickets. This incident highlights the growing threat landscape targeting WordPress ecosystems, coinciding with large-scale operations like StopAndProtect that weaponize compromised WordPress sites for malware distribution and command-and-control infrastructure.
1 month ago
Kill Chain
StopAndProtect 2026: A Wake-Up Call for Cybersecurity
In mid-2026, cybersecurity researchers identified a global cybercrime operation named 'StopAndProtect' that exploited nearly 2,000 compromised WordPress websites to distribute malware and steal data. The attackers utilized a multifaceted toolkit, including ransomware, worms, and credential stealers, to infiltrate systems via social engineering tactics like fake CAPTCHA prompts. These compromised sites served as command-and-control servers, facilitating malware deployment and data exfiltration. The operation's reliance on outdated WordPress installations underscores the critical need for regular software updates and robust security practices. This incident highlights the escalating sophistication of ransomware campaigns and the increasing use of legitimate platforms as attack vectors. Organizations must prioritize comprehensive cybersecurity measures, including timely software updates, employee training on social engineering tactics, and adherence to frameworks like NIST's Ransomware Risk Management Profile to mitigate such threats.
1 month ago
Kill Chain
Critical Vulnerability in Forminator WordPress Plugin (CVE-2026-15748) Puts Sites at Risk
In August 2026, a critical vulnerability (CVE-2026-15748) was identified in the Forminator Forms WordPress plugin, affecting over 600,000 active installations. This flaw allowed unauthenticated attackers to upload arbitrary files, including executable PHP scripts, leading to potential remote code execution and complete site compromise. The issue stemmed from insufficient file type validation in the 'handle_file_upload()' function, particularly when forms contained both a File Upload field and a Select field. The vulnerability was addressed in version 1.56.2, released on July 31, 2026. This incident underscores the persistent risks associated with web application vulnerabilities, especially in widely used plugins. It highlights the importance of regular security assessments and prompt updates to mitigate potential exploits that can lead to significant operational disruptions and data breaches.
1 month ago
Kill Chain
CTM360's 'RecruitTrap' Campaign Unveils Sophisticated Phishing Tactics
In August 2026, CTM360 uncovered a large-scale phishing campaign named 'RecruitTrap,' involving over 3,000 malicious URLs designed to steal Google and Facebook credentials. The attackers impersonated recruiters from more than 50 organizations across 14 sectors, primarily targeting marketing professionals. Victims received unsolicited emails or meeting invitations leading to counterfeit interview scheduling pages. These pages employed Browser-in-the-Browser (BitB) techniques to display fake authentication pop-ups, tricking users into entering their credentials and multi-factor authentication codes, which were then relayed to the attackers in real time. This incident highlights the increasing sophistication of phishing attacks, particularly those leveraging BitB techniques to bypass traditional security measures. The focus on marketing professionals underscores the strategic targeting of roles with access to sensitive corporate resources, emphasizing the need for heightened vigilance and advanced security protocols to protect against such evolving threats.
1 month ago
Kill Chain
BdThemes Supply Chain Attack: A New Vector in WordPress Plugin Compromises
In August 2026, a sophisticated supply chain attack targeted BdThemes, a WordPress plugin vendor, compromising multiple plugins without altering their source code. Attackers exploited a cross-site scripting (XSS) vulnerability in the Biggopti component, which fetched promotional banners via a JSON API. By poisoning the JSON data stream, they injected malicious scripts that executed within the WordPress admin dashboard, leading to the creation of rogue administrator accounts and deployment of web shells. This breach affected plugins with over 100,000 active installations, prompting WordPress to temporarily disable their downloads. This incident underscores the evolving nature of supply chain attacks, where adversaries manipulate external data sources to compromise systems without direct code modifications. It highlights the critical need for organizations to scrutinize all components of their software supply chain, including third-party APIs and data streams, to mitigate such vulnerabilities.
1 month ago
Kill Chain
BdThemes Plugins Supply-Chain Hack Compromises Over 350,000 WordPress Sites
In August 2026, BdThemes, a developer of premium WordPress plugins, experienced a supply-chain attack where a threat actor compromised their infrastructure. The attacker modified a remote JSON feed used by the Biggopti component to display promotional banners in WordPress admin dashboards. By exploiting a cross-site scripting (XSS) vulnerability introduced in March 2026, the malicious code created rogue administrator accounts and installed a webshell for persistent access. This stealthy attack affected over 350,000 active installations, as BdThemes' flagship Element Pack plugin alone had more than 100,000 active installations. The WordPress Plugins team responded by removing the affected plugins from the directory pending a full review. This incident underscores the growing threat of supply-chain attacks targeting widely-used software components. The exploitation of an XSS vulnerability in a promotional banner highlights the need for rigorous security practices in all aspects of software development and distribution. Organizations must remain vigilant, as similar tactics have been observed in other recent attacks, such as those involving the OptinMonster plugin. ([sansec.io](https://sansec.io/research/optinmonster-supply-chain-attack?utm_source=openai))
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports