The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Publishing Industry
Breach intelligence, attack campaigns, and threat reports targeting the Publishing Industry sector.
Explore Other Sectors
Publishing Industry Threat Reports
Psychedelic Stealer Targets Ukraine Through Fake Cloudflare ClickFix Campaign
In September 2026, threat actors compromised legitimate Ukrainian business websites to inject fake Cloudflare verification pages as part of a ClickFix campaign distributing Psychedelic Stealer malware. The attack targeted various Ukrainian businesses including healthcare facilities, retailers, and manufacturers, using social engineering to trick victims into executing malicious MSI installers that harvested browser credentials, cryptocurrency wallets, and account tokens. Arctic Wolf Labs documented 557 views with 426 clicks across the campaign, primarily targeting Ukrainian users but also affecting victims in the US, Poland, Germany, Canada, and the Netherlands. This incident highlights the growing sophistication of information stealer campaigns that exploit trusted brand impersonation and legitimate website compromise to bypass security controls. The emergence of new stealer families like Psychedelic, combined with advanced evasion techniques and modular malware ecosystems, represents an escalating threat to credential security and highlights the urgent need for enhanced egress filtering and behavioral monitoring capabilities.
7 hours ago
Kill Chain
WordPress Click2Shell Vulnerability: How a Simple Link Click Leads to Server Compromise
WordPress patched a critical vulnerability called Click2Shell in September 2026 that allows attackers to force automatic theme installation through specially crafted URLs. The flaw exploits differences in how WordPress.org directory and administrator browsers parse the same link, enabling attackers to trigger theme installations when logged-in administrators click malicious links. When chained with secondary vulnerabilities in installed themes, the attack escalates to remote code execution with a CVSS score of 9.6. The vulnerability affects WordPress versions 6.0 through 7.1.0, with fixes released in version 7.1.1 across all supported branches back to 4.7. This incident highlights the growing trend of attackers targeting content management system vulnerabilities that can be chained together for maximum impact, particularly as WordPress powers over 40% of websites globally and remains a high-value target.
6 days ago
Kill Chain
wp2shell: Critical WordPress Core Vulnerability Exposes Sites to Unauthenticated RCE
In July 2026, a critical vulnerability known as 'wp2shell' was discovered in WordPress core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. This flaw allowed unauthenticated remote code execution (RCE) via anonymous HTTP requests, making even default installations without plugins susceptible. The vulnerability was identified by Adam Kues of Searchlight Cyber and reported through WordPress's HackerOne program. In response, WordPress released emergency security updates—versions 6.9.5 and 7.0.2—on July 17, 2026, and initiated forced auto-updates to mitigate the risk. ([thehackernews.com](https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html?utm_source=openai)) The 'wp2shell' incident underscores the persistent threat of unauthenticated RCE vulnerabilities in widely used platforms. It highlights the critical importance of timely software updates and proactive security measures to protect against emerging exploits targeting core system functionalities.
2 months ago
Kill Chain
McGraw-Hill's 2026 Data Breach: Lessons in Third-Party Platform Security
In April 2026, McGraw-Hill, a leading education company, experienced a data breach due to a misconfiguration in its Salesforce environment. The cybercriminal group ShinyHunters exploited this vulnerability to access internal data. McGraw-Hill confirmed that the breach did not affect its Salesforce accounts, customer databases, or internal systems, and that the exposed data was limited and non-sensitive. However, ShinyHunters claimed to possess 45 million Salesforce records containing personally identifiable information (PII), contradicting the company's statement. The group threatened to leak the stolen data by April 14 unless a ransom was paid. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/mcgraw-hill-confirms-data-breach-following-extortion-threat/?utm_source=openai)) This incident underscores the critical importance of securing third-party platforms and configurations. Misconfigurations in widely used services like Salesforce can serve as entry points for threat actors, leading to significant data breaches and extortion attempts. Organizations must prioritize regular audits and robust security measures to protect sensitive information.
5 months ago
Kill Chain
Kyowon 2026 Ransomware Attack: Lessons from a Massive Data Breach
In January 2026, Kyowon Group, a major South Korean conglomerate specializing in education and consumer services, suffered a disruptive ransomware attack impacting approximately 600 out of 800 servers. The attack resulted in significant operational outages and the confirmed exfiltration of internal data, with the potential exposure of information tied to over 9.6 million registered user accounts. While the full scope of compromised customer data is under investigation, Kyowon immediately notified authorities and began working with security experts to contain the breach and restore services. No ransomware group has publicly claimed responsibility as of now. This incident highlights an ongoing trend of large-scale cyberattacks against major South Korean enterprises, with mounting pressure from regulatory bodies to improve cyber resilience. The Kyowon case exemplifies how attackers are increasingly targeting critical service infrastructure and customer databases for extortion, making robust endpoint protection and incident response capabilities more essential than ever.
8 months ago
Kill Chain
Condé Nast 2024 Breach: Hacker Leaks 2.3M WIRED Subscriber Records
In March 2024, a hacker claimed to have breached Condé Nast's systems, exfiltrating and leaking a database containing over 2.3 million subscriber records from WIRED. The attacker published samples of the data on a known cybercrime forum, alleging access to databases belonging to other major Condé Nast brands and threatening to release up to 40 million more records. The exposed data reportedly included names, email addresses, postal codes, company names, and subscription specifics but did not involve payment card information. The breach highlights ongoing risks associated with third-party access, inadequate segmentation, and insufficient detection controls in the media sector. This incident underscores the growing trend of targeting high-profile media companies for large-scale data theft, aligning with broader increases in B2C sector breaches and information theft campaigns. Increased regulatory scrutiny and investor attention on data security make robust segmentation, encrypted transit, and rapid anomaly detection particularly relevant.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports