The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Marketing/Advertising/Sales
Breach intelligence, attack campaigns, and threat reports targeting the Marketing/Advertising/Sales sector.
Explore Other Sectors
Marketing/Advertising/Sales Threat Reports
Unveiling Trapdoor: The 2026 Android Ad Fraud Scheme
In May 2026, cybersecurity researchers uncovered 'Trapdoor,' a sophisticated ad fraud and malvertising operation targeting Android users. The scheme involved 455 malicious apps and 183 command-and-control domains, creating a self-sustaining cycle of fraud. Users unknowingly downloaded utility-style apps, which then initiated malvertising campaigns, coercing them into installing additional malicious apps. These secondary apps launched hidden WebViews, loaded threat actor-controlled HTML5 domains, and requested ads, leading to 659 million daily bid requests and over 24 million app downloads, primarily affecting users in the U.S. ([thehackernews.com](https://thehackernews.com/2026/05/trapdoor-android-ad-fraud-scheme-hit.html?utm_source=openai)) This incident highlights the evolving tactics of cybercriminals who blend legitimate tools with malicious intent, emphasizing the need for continuous vigilance and advanced detection mechanisms to protect users from such deceptive schemes.
4 months ago
Kill Chain
Critical Vulnerability in Funnel Builder Plugin Leads to Credit Card Theft
In May 2026, a critical vulnerability in the Funnel Builder plugin for WordPress was actively exploited to inject malicious JavaScript into WooCommerce checkout pages. This flaw, present in versions prior to 3.15.0.3, allowed unauthenticated attackers to modify the plugin's global settings via an unprotected checkout endpoint, leading to the execution of malicious code on checkout pages. The injected code facilitated a payment card skimmer that stole sensitive customer information, including credit card numbers, CVVs, billing addresses, and other personal data. FunnelKit addressed the vulnerability by releasing version 3.15.0.3, urging users to update immediately and review their settings for any unauthorized scripts. This incident underscores the persistent threat posed by vulnerabilities in widely-used plugins, emphasizing the need for regular updates and vigilant monitoring of third-party components in web applications. The exploitation of such vulnerabilities can lead to significant data breaches, financial loss, and reputational damage for businesses, highlighting the critical importance of proactive cybersecurity measures.
4 months ago
Kill Chain
Critical Authentication Bypass Vulnerability in Burst Statistics WordPress Plugin (CVE-2026-8181)
In May 2026, a critical authentication bypass vulnerability, CVE-2026-8181, was discovered in the Burst Statistics WordPress plugin, affecting versions 3.4.0 and 3.4.1. This flaw allowed unauthenticated attackers to impersonate administrator accounts by exploiting improper handling of authentication functions, potentially leading to full site compromise. The vulnerability was actively exploited shortly after disclosure, with over 7,400 attacks recorded within 24 hours. This incident underscores the persistent threat posed by vulnerabilities in widely used WordPress plugins. It highlights the importance of prompt patching and vigilant monitoring, as attackers rapidly exploit such flaws to gain unauthorized access and control over websites.
4 months ago
Kill Chain
Cybercriminals Exploit Google Ads and Claude.ai to Target Mac Users
In May 2026, attackers exploited Google Ads and legitimate Claude.ai shared chats to distribute malware targeting macOS users. By searching for 'Claude mac download,' users encountered sponsored search results that appeared to link to the official Claude.ai website but redirected them to malicious instructions. These instructions guided users to execute terminal commands that downloaded and ran malware on their systems, leading to unauthorized access and potential data exfiltration. This incident underscores a growing trend where cybercriminals leverage trusted platforms and search engine advertisements to disseminate malware. The use of legitimate AI-generated content to host malicious instructions highlights the evolving sophistication of social engineering tactics, emphasizing the need for heightened vigilance and robust security measures among users and organizations.
4 months ago
Kill Chain
Massive Phishing Campaign Exploits Google AppSheet to Hack 30,000 Facebook Accounts
In May 2026, a Vietnamese-linked cyber operation, dubbed 'AccountDumpling' by Guardio, exploited Google's AppSheet platform to distribute phishing emails impersonating Meta Support. These emails targeted Facebook Business account owners, urging them to submit appeals to avoid account deletion. The phishing campaign successfully compromised approximately 30,000 Facebook accounts, which were subsequently sold through illicit channels. The attackers utilized AppSheet's legitimate 'noreply@appsheet.com' email address to bypass spam filters, enhancing the credibility of their fraudulent messages. This incident underscores a growing trend where cybercriminals leverage trusted platforms to execute sophisticated phishing attacks. The exploitation of legitimate services like Google AppSheet highlights the need for enhanced vigilance and adaptive security measures to counteract evolving threat vectors.
4 months ago
Kill Chain
Massive WordPress Plugin Backdoor Exposes Thousands of Sites in 2026
In April 2026, a significant supply chain attack compromised over 30 WordPress plugins, collectively known as the 'Essential Plugin' portfolio. An individual operating under the alias 'Kris' purchased these plugins in early 2025 and injected a PHP deserialization backdoor during subsequent updates. This backdoor remained dormant for eight months before activation, allowing the attacker to inject spam content and potentially execute arbitrary code on over 20,000 active WordPress sites. The attack underscores the vulnerabilities inherent in plugin ecosystems, where ownership changes can introduce malicious code without immediate detection. This incident highlights a growing trend in supply chain attacks targeting widely used software components. The strategy of purchasing and compromising trusted plugins poses a significant threat to website security, emphasizing the need for rigorous vetting processes and continuous monitoring of third-party software integrations.
4 months ago
Kill Chain
Unveiling the 2026 Fake CAPTCHA IRSF Scam
In April 2026, cybersecurity researchers uncovered a sophisticated telecommunications fraud campaign leveraging fake CAPTCHA verifications to deceive users into sending international SMS messages. This scheme, active since at least June 2020, exploits social engineering tactics and browser vulnerabilities to generate illicit revenue through International Revenue Share Fraud (IRSF). Victims, believing they are completing standard CAPTCHA tests, unknowingly send multiple SMS messages to premium-rate international numbers, incurring significant charges on their mobile bills. This incident highlights the evolving nature of cyber threats, where attackers combine traditional social engineering with technical exploitation to achieve financial gain. The use of familiar web elements like CAPTCHAs in fraudulent schemes underscores the need for heightened user awareness and robust security measures to detect and prevent such deceptive practices.
5 months ago
Kill Chain
Critical Vulnerability in Breeze Cache WordPress Plugin (CVE-2026-3844)
In April 2026, a critical vulnerability (CVE-2026-3844) was discovered in the Breeze Cache WordPress plugin, affecting versions up to 2.4.4. This flaw allows unauthenticated attackers to upload arbitrary files via the 'fetch_gravatar_from_remote' function, potentially leading to remote code execution and full site compromise. The issue is exploitable only when the 'Host Files Locally - Gravatars' feature is enabled, which is disabled by default. Cloudways, the plugin's developer, released version 2.4.5 to address this vulnerability. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hackers-exploit-file-upload-bug-in-breeze-cache-wordpress-plugin/?utm_source=openai)) The active exploitation of this vulnerability underscores the persistent targeting of WordPress plugins by threat actors. Website administrators are urged to promptly update to the latest plugin version or disable the affected feature to mitigate risks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hackers-exploit-file-upload-bug-in-breeze-cache-wordpress-plugin/?utm_source=openai))
5 months ago
Kill Chain
Google's 2025 Gemini AI Initiative: A New Era in Combating Malvertising
In 2025, Google intensified its efforts to combat malvertising by integrating its Gemini AI models into ad detection systems. This initiative led to the blocking or removal of 8.3 billion ads and the suspension of 24.9 million advertiser accounts, including 602 million ads linked to scams. Malvertising campaigns often impersonate legitimate brands to distribute malware or lead users to phishing sites. By leveraging Gemini AI, Google enhanced its ability to analyze vast datasets, including advertiser behavior and campaign patterns, to identify and block malicious ads before they reach users. ([apnews.com](https://apnews.com/article/06d9ef869958555884989e8ec25974be?utm_source=openai)) The urgency of addressing malvertising has grown as cybercriminals increasingly use generative AI to create deceptive ads at scale. Google's proactive measures with Gemini AI have not only improved ad filtering efficiency but also reduced incorrect advertiser suspensions by 80%. This underscores the critical need for advanced AI-driven defenses to maintain the integrity of digital advertising platforms. ([apnews.com](https://apnews.com/article/06d9ef869958555884989e8ec25974be?utm_source=openai))
5 months ago
Kill Chain
Massive WordPress Plugin Supply Chain Attack Compromises Thousands of Websites
In August 2025, a malicious actor acquired the EssentialPlugin suite, comprising over 30 WordPress plugins, and embedded dormant backdoors into their codebase. These backdoors remained inactive until April 2026, when they were activated to inject spam content and redirects into websites using the compromised plugins. This supply chain attack affected thousands of sites, exploiting the trust placed in widely-used plugins to distribute malware. The incident underscores the critical need for vigilance in monitoring third-party software components and the potential risks associated with software supply chain vulnerabilities. As attackers increasingly target trusted software providers to distribute malicious code, organizations must implement robust security measures to detect and mitigate such threats.
5 months ago
Kill Chain
Microsoft and Salesforce Address Critical AI Security Flaws
In April 2026, security researchers identified critical prompt injection vulnerabilities in Microsoft Copilot and Salesforce Agentforce, which could allow attackers to exfiltrate sensitive data. In Microsoft's case, malicious code inserted into SharePoint forms could trigger Copilot to send customer data to unauthorized emails. Similarly, Salesforce's Agentforce was susceptible to prompt injections via public-facing lead forms, enabling unauthorized access to CRM data. Both companies have since patched these vulnerabilities. ([darkreading.com](https://www.darkreading.com/cloud-security/microsoft-salesforce-patch-ai-agent-data-leak-flaws/?utm_source=openai)) This incident underscores the persistent threat of prompt injection attacks in AI systems, highlighting the need for robust input validation and security measures to prevent unauthorized data access and exfiltration.
5 months ago
Kill Chain
Massive Data Breach: 108 Malicious Chrome Extensions Compromise 20,000 Users
In April 2026, cybersecurity researchers uncovered a coordinated campaign involving 108 malicious Google Chrome extensions that compromised approximately 20,000 users. These extensions, published under five fake identities, masqueraded as legitimate tools such as games, translation utilities, and YouTube enhancers. Once installed, they exfiltrated sensitive data, including Google account credentials and Telegram session tokens, to a centralized command-and-control server. Some extensions injected ads and arbitrary JavaScript code into web pages, while others stripped security headers from sites like YouTube and TikTok to facilitate further exploitation. ([gizchina.com](https://www.gizchina.com/malicious-apps/108-fake-chrome-extensions-were-stealing-your-google-and-telegram-data-remove-them-now/?utm_source=openai)) This incident underscores the persistent threat posed by malicious browser extensions and highlights the need for vigilant scrutiny of third-party add-ons. The attackers' ability to infiltrate the official Chrome Web Store and maintain their presence for an extended period raises concerns about the effectiveness of current security measures in detecting and preventing such threats. ([cybernews.com](https://cybernews.com/security/chrome-extensions-flagged-for-stealing-user-data/?utm_source=openai))
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports