The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Marketing/Advertising/Sales
Breach intelligence, attack campaigns, and threat reports targeting the Marketing/Advertising/Sales sector.
Explore Other Sectors
Marketing/Advertising/Sales Threat Reports
Mirax Android RAT: A New Era of Mobile Malware Threats
In April 2026, a sophisticated Android remote access trojan (RAT) named Mirax was identified targeting Spanish-speaking countries. Distributed through Meta advertisements, Mirax infected over 220,000 devices by masquerading as legitimate streaming applications. Once installed, it granted attackers full control over compromised devices, enabling real-time interaction, keystroke logging, and the deployment of dynamic overlays to steal sensitive information. Notably, Mirax transformed infected devices into residential proxy nodes using the SOCKS5 protocol, allowing cybercriminals to route malicious traffic through victims' IP addresses, thereby evading detection systems and facilitating fraudulent activities. This incident underscores a concerning evolution in mobile malware, where traditional RAT functionalities are augmented with proxy capabilities, expanding the operational scope of cybercriminals. The use of social media platforms for widespread distribution highlights the need for enhanced vigilance and security measures among users and organizations to mitigate such threats.
5 months ago
Kill Chain
Unveiling Webloc: The Ad-Based Geolocation Surveillance Tool Used by Law Enforcement
In April 2026, Citizen Lab uncovered that law enforcement agencies in Hungary, El Salvador, and the United States utilized Webloc, an ad-based geolocation surveillance system developed by Cobwebs Technologies and later sold by Penlink. Webloc accesses data from up to 500 million mobile devices worldwide, including device identifiers, location coordinates, and profile data harvested from mobile apps and digital advertising. This system enables authorities to monitor individuals' locations and movements without warrants, raising significant privacy and civil liberties concerns. The revelation underscores the growing use of commercial data for surveillance purposes, highlighting the need for stringent oversight and regulation to protect individual privacy rights.
5 months ago
Kill Chain
Smart Slider 3 Pro Supply Chain Attack: A 2026 Case Study
In April 2026, unknown threat actors compromised Nextend's update infrastructure to distribute a malicious version (3.5.1.35) of the Smart Slider 3 Pro plugin for WordPress and Joomla. This backdoored update, available for approximately six hours on April 7, allowed attackers to create hidden administrator accounts, execute remote commands, and establish multiple persistence mechanisms, leading to unauthorized access and potential data exfiltration on affected websites. The incident underscores the critical risks associated with supply chain attacks, where trusted software distribution channels are exploited to deliver malware. Such attacks bypass traditional security measures, emphasizing the need for enhanced vigilance and monitoring of software update processes to detect and mitigate unauthorized modifications promptly.
5 months ago
Kill Chain
Supply Chain Attack on Smart Slider 3 Pro Compromises Websites in 2026
In April 2026, attackers compromised the update system of the Smart Slider 3 Pro plugin, affecting version 3.5.1.35 for both WordPress and Joomla platforms. This malicious update introduced multiple backdoors, created hidden administrator accounts, and exfiltrated sensitive data from affected websites. The incident underscores the critical importance of securing software supply chains to prevent unauthorized code distribution and maintain the integrity of widely used web applications. This event highlights a growing trend of supply chain attacks targeting popular web plugins, emphasizing the need for vigilant monitoring of software updates and the implementation of robust security measures to detect and prevent unauthorized modifications.
5 months ago
Kill Chain
Critical Security Flaw in Ninja Forms Plugin Puts WordPress Sites at Risk
In early 2026, a critical vulnerability (CVE-2026-0740) was discovered in the Ninja Forms File Uploads plugin for WordPress, affecting versions up to 3.3.26. This flaw allowed unauthenticated attackers to upload arbitrary files, including malicious PHP scripts, leading to potential remote code execution and complete site takeover. The vulnerability stemmed from inadequate validation of file types and extensions during the file upload process. The issue was reported on January 8, 2026, and a full patch was released on March 19, 2026, with version 3.3.27. Despite the availability of a fix, exploitation attempts surged, with over 3,600 attacks blocked in a single day. This incident underscores the critical importance of timely software updates and robust security practices in mitigating emerging threats.
5 months ago
Kill Chain
ComfyUI Cryptomining Botnet Attack 2026
In April 2026, over 1,000 internet-exposed instances of ComfyUI, a popular stable diffusion platform, were targeted in a sophisticated cryptomining botnet campaign. Attackers utilized a custom Python scanner to identify vulnerable ComfyUI deployments, exploiting misconfigurations that allowed remote code execution via custom nodes. Upon successful exploitation, compromised hosts were enlisted into a botnet mining Monero and Conflux cryptocurrencies, managed through a Flask-based command-and-control dashboard. The campaign also employed persistence mechanisms to maintain control over infected systems. This incident underscores the critical need for securing internet-facing applications and services, as attackers continue to exploit misconfigurations and vulnerabilities to deploy cryptomining operations. Organizations must prioritize regular security assessments, implement robust authentication mechanisms, and monitor for unauthorized activities to mitigate such threats.
5 months ago
Kill Chain
LinkedIn's 2026 Browser Extension Scanning: A Privacy Wake-Up Call
In April 2026, reports emerged that LinkedIn was injecting hidden JavaScript into user sessions to scan for over 6,000 installed Chrome extensions and collect detailed device data. This practice, termed 'BrowserGate,' raised significant privacy concerns as it linked extension data to identifiable user profiles, potentially exposing sensitive personal and corporate information. LinkedIn acknowledged the scanning but stated it was intended to detect extensions that violate their terms of service by scraping data without consent. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/linkedin-secretly-scans-for-6-000-plus-chrome-extensions-collects-data/?utm_source=openai)) This incident underscores the growing scrutiny over corporate data collection practices and the balance between platform security and user privacy. It highlights the need for transparency in how user data is gathered and utilized, especially as similar fingerprinting techniques have been employed by other companies in the past. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/linkedin-secretly-scans-for-6-000-plus-chrome-extensions-collects-data/?utm_source=openai))
5 months ago
Kill Chain
Critical Vulnerability in Smart Slider 3 Plugin Affects 500K WordPress Sites
In March 2026, a critical vulnerability (CVE-2026-3098) was discovered in the Smart Slider 3 WordPress plugin, affecting versions up to 3.5.1.33. This flaw allows authenticated users, including those with minimal access like subscribers, to read arbitrary files on the server, including sensitive files such as wp-config.php. Exploitation of this vulnerability could lead to unauthorized access to database credentials and potential full site compromise. The issue arises from missing capability checks in the plugin's AJAX export actions, enabling any authenticated user to invoke them without proper validation. This incident underscores the persistent risks associated with plugin vulnerabilities in the WordPress ecosystem. With over 500,000 websites still running vulnerable versions of Smart Slider 3, it highlights the critical need for timely updates and robust security practices to mitigate potential exploits.
6 months ago
Kill Chain
TikTok Business Accounts Compromised in 2026 AiTM Phishing Attack
In March 2026, TikTok for Business accounts were targeted by adversary-in-the-middle (AiTM) phishing attacks. Cybercriminals employed sophisticated techniques to intercept user credentials and session cookies, effectively bypassing multi-factor authentication (MFA) measures. This allowed unauthorized access to business accounts, which were then exploited for malicious activities such as distributing malware and conducting fraudulent advertising campaigns. The attackers utilized deceptive emails and messages, directing users to counterfeit login pages that closely mimicked TikTok's official interface, thereby harvesting sensitive information. This incident underscores a growing trend in cyber threats where attackers leverage AiTM tactics to circumvent traditional security protocols, including MFA. The increasing prevalence of such sophisticated phishing methods highlights the need for organizations to adopt advanced security measures and continuous monitoring to protect against evolving cyber threats.
6 months ago
Kill Chain
Phishing Campaign Targets TikTok Business Accounts in 2026
In March 2026, a sophisticated phishing campaign targeted TikTok for Business accounts, exploiting their extensive reach and credibility. Attackers employed Cloudflare-hosted phishing pages, registered via NiceNIC, to impersonate TikTok's business services. Victims were lured through legitimate Google Storage URLs, which redirected them to malicious sites after bypassing security bots using Cloudflare Turnstile checks. These sites mimicked TikTok's 'Schedule a Call' pages, prompting users to enter business email addresses and login credentials. The attackers utilized reverse proxy techniques to capture credentials and session cookies, effectively bypassing two-factor authentication and enabling unauthorized access to accounts. This incident underscores the evolving tactics of cybercriminals in targeting high-profile business accounts for malicious activities. The campaign's sophistication, including the use of legitimate services to mask malicious intent and the ability to circumvent multi-factor authentication, highlights the need for enhanced vigilance and security measures among businesses utilizing social media platforms for marketing and outreach.
6 months ago
Kill Chain
AppsFlyer Web SDK Hijacked: A 2026 Supply Chain Attack Analysis
In March 2026, the AppsFlyer Web SDK, utilized by over 100,000 applications for marketing analytics, was compromised in a supply chain attack. Malicious JavaScript code was injected into the SDK, enabling attackers to intercept and replace cryptocurrency wallet addresses entered by users on affected websites, diverting funds to attacker-controlled wallets. The attack targeted major cryptocurrencies, including Bitcoin, Ethereum, Solana, Ripple, and TRON, potentially impacting a vast number of end users. The incident underscores the critical vulnerabilities inherent in widely deployed third-party SDKs and the significant risks they pose to downstream applications and their users. Organizations relying on such SDKs must implement rigorous security measures and maintain vigilant monitoring to detect and mitigate potential compromises promptly.
6 months ago
Kill Chain
Critical SQL Injection Vulnerability in Elementor Ally Plugin Puts Over 250,000 WordPress Sites at Risk
In March 2026, a critical SQL injection vulnerability (CVE-2026-2313) was discovered in the Ally – Web Accessibility & Usability plugin for WordPress, affecting versions up to 4.0.3. This flaw allows unauthenticated attackers to inject malicious SQL queries via the URL path, potentially leading to unauthorized access to sensitive database information. The vulnerability arises from insufficient escaping of user-supplied URL parameters in the `get_global_remediations()` method, which are directly concatenated into SQL JOIN clauses without proper sanitization. Exploitation is possible when the plugin is connected to an Elementor account with the Remediation module active. Despite the release of a patched version (4.1.0) on February 23, 2026, data indicates that only about 36% of the affected websites have updated, leaving over 250,000 sites vulnerable. This incident underscores the persistent threat posed by SQL injection vulnerabilities in web applications, emphasizing the need for developers to implement robust input validation and sanitization practices. Website administrators are urged to promptly update plugins and maintain regular security audits to mitigate such risks.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports