惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Microsoft Security Blog
Microsoft Security Blog
J
Java Code Geeks
S
SegmentFault 最新的问题
Apple Machine Learning Research
Apple Machine Learning Research
N
Netflix TechBlog - Medium
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园_首页
宝玉的分享
宝玉的分享
Google DeepMind News
Google DeepMind News
B
Blog RSS Feed
Hugging Face - Blog
Hugging Face - Blog
量子位
Blog — PlanetScale
Blog — PlanetScale
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
阮一峰的网络日志
阮一峰的网络日志
D
Docker
罗磊的独立博客
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
云风的 BLOG
云风的 BLOG
IT之家
IT之家
MyScale Blog
MyScale Blog
Microsoft Azure Blog
Microsoft Azure Blog

Latest from TechRadar in Security

Robots are fighting wars and helping to quash riots — China is arming riot police with squads of AI controlled drones and Ukraine wants to man the frontlines with 25,000 robots US security agency still using Mythos despite ban – government using new security tool despite Pentagon's… Struggling to launch Teams? Microsoft recalls update causing failed startup and infinite loading loops –… NIST is cataloging so many vulnerabilities it can only assign severity scores to the highest priority threats How to meaningfully measure the effectiveness of cyber resilience 'We've identified a security incident': Vercel breach confirmed after hackers claim stolen data for sale… How EU organizations can turn sovereign cloud theory into action 'Update immediately': 60,000 WordPress websites at risk after experts discover flaw that allows hackers to… 'They mopped the floor with me and pulled every childish game they could': Disgruntled researcher releases second major Windows zero-day — claims Microsoft 'would ruin my life, and they did' 'As threats evolve, Gemini keeps our defenses one step ahead': Google claims its AI helped it block over 8.3… Cisco tells Webex users to patch critical security flaws immediately, as experts find its Wi-Fi boxes may be filling their disks with undeletable data every day Microsoft experts warn North Korean attackers target macOS users with 'a highly reliable infection chain' to steal passwords, financial data and more — here's how to stay safe Solving the shadow IT crisis in travel Agentic swarms will change how everyone uses AI – but how can organizations deploy them securely? Europol launches Operation PowerOFF — warns 75,000 DDoS users and takes down 53 domains China completes testing on ‘deep-sea electro-hydrostatic actuator’ capable of slicing undersea cables as deep as 3.5 kilometers – new compact subsea vessel testing bridges the ‘last mile’ and could deploy in 2026 Many are still leaving the door open': Security experts warn FIFA World Cup partners could be putting customers at… 'Anyone with $10 could have walked straight through': Report warns this legit-looking software is actually… An ancient Microsoft Excel security flaw could let hackers hijack your entire system, so patch now 'This is not a traditional coding error': Experts flag potentially critical security issues at the heart of Anthropic's MCP, exposes 150 million downloads and thousands of servers to complete takeover Your OpenClaw agents can empty your inbox and leak your data. Here's how to secure them Russia hits European thermal power plant in attempted ‘destructive’ cyberattack – Pro-Kremlin hackers are engaging in ‘riskier and more reckless behavior’ in latest attempt to cripple Western critical infrastructure The war in Iran is reaching cyberspace - here’s how to prepare Millions of hotel goers may have been exposed after hackers steal data and leak it on Telegram 'Every Apple user needs to know about this nasty scam': Fake warnings tell users their iCloud data will be… Dozens of WordPress plugins hijacked to target thousands of sites 'We are currently being extorted' — crypto giant Kraken says it is facing extortion attack, here's… McGraw Hill becomes latest to see its Salesforce data hacked Over 100 Chrome Web Store extensions found stealing user data from thousands of accounts OpenAI reveals its Mythos rival designed for cybersecurity pros
Your marketing stack is an attack surface – is secu...
Mike Schrobo · 2026-04-06 · via Latest from TechRadar in Security

Picture this: an enterprise employee clicks on what appears to be a verified ad from a trusted brand on Google. But the ad is anything but verified – it’s convincingly spoofed and redirects to a scammer-controlled domain.

The real brand has no idea it’s being imitated, security has no record of the breach, and Google’s own reviewers never saw the malicious content. Still, the unaware employee enters the “trusted” environment and hands over their login or downloads compromised software, creating an exploitable leak of unknown origin.

CEO and Founder of Fraud Blocker.

A recently unearthed scam did just this for years by cloaking fake ads and tricking the internet’s biggest ad platform into serving them. It’s the latest in a growing trend of weaponized ad fraud at scale, a scam that not only drains marketing budgets but also threatens cybersecurity.

Increasingly, the enterprise ad stack is the attack surface and fighting back requires security and marketing teams to address it as one.

Ad fraud at scale is now a security problem

In February, researchers announced the discovery of 1Campaign, a fully managed criminal toolkit for malvertizing, phishing, and credential theft. The cloaking tool tricked Google into approving malicious ads by showing different content to different visitors.

The fraud-as-a-service platform profiled every visitor – based on factors like IP ranges, geographic locations, and behavioral patterns – to determine what they would see next.

Security researchers, ad platform reviewers, and automated scanners were instantly flagged and directed to a harmless white page.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

General users, on the other hand, were funneled wherever the bad actor wanted, using ads convincingly dressed as trusted brands to earn clicks that lead to phishing pages, crypto drainers, and fake software downloads that deliver malware.

This scheme is part of a disturbing pattern. Buoyed by AI, ad fraudsters are technologically equipped to do more with less and attack at scale. This is something we saw last September with malware hiding behind legitimate apps on the Google Play Store and turning user devices into ghost click farms.

Bots are now engaging with ads like humans – pausing on content, simulating scrolling, mimicking viewing behavior – and making detection far more difficult. In turn, marketing is battling corrupted campaign data, inflated click metrics, and the loss of about one in five dollars to ad fraud.

Ad networks are fighting a losing battle

1Campaign is the latest in a line of attacks that sees fraudsters weaponizing ads, outpacing detection, and ultimately threatening security. This is a triple threat with serious consequences across the enterprise. A big reason the scam succeeds is that marketing and security don’t talk to each other.

Security isn’t watching the ad stack and marketing isn’t flagging unusual traffic as a security concern. Bad actors know the two are siloed and exploit the gap in between, silently co-opting trusted brands and opening backdoors that neither team is monitoring.

Worse still, even ad platforms are struggling to keep up. 1Campaign operated undetected for several years by successfully evading traditional detection methods and circumventing the ad review process. In some documented campaigns, the scheme’s success rate at blocking security scanners reached 99%.

Our research reinforces that ad platforms are fighting a losing battle: invalid click rates from independent sources are nearly 50% higher than Google’s reported figures, suggesting plenty of fake clicks still slip through the cracks.

This is the new normal in ad fraud and enterprises that rely solely on platform defenses and disparate departments are leaving both their ad spend and security posture exposed.

Marketing and security must come together

Both sides need to step up and stamp out this threat. For security, this can be achieved by treating unusual ad traffic as a potential threat indicator rather than just a marketing problem. Specifically, watch for signs of credential harvesting.

If employees click through to unexpected domains via ad platforms, this should trigger the same level of scrutiny as phishing emails. Likewise, start including ad infrastructure in endpoint monitoring and incident response protocols, and training employees on the dangers of malvertizing (even if an ad comes from Google).

For marketing, remember that there’s no single source of truth. Platform performance reports are a starting point that can and should be strengthened by behavioral analytics and fraud-scoring systems. Think more holistically and flag unusual traffic spikes, click patterns, and conversion anomalies as potential security events.

Layered, independent verification is the only reliable defense in this threat landscape and it pays dividends. For example, armed with better visibility into real versus fake engagement, marketing teams can more quickly identify invalid clicks and pursue platform refunds with confidence.

For both teams, you’re stronger when you tackle this together.

This kind of collaboration is easier than many realize – establish joint dashboards that correlate ad traffic with security threat indicators, build incident response protocols that include ad stack breaches, and train across departments so each team understands the other’s blind spots.

This is a threat that both teams and wider enterprises need to address. Agentic browsers and prompt injection are on the way, threatening to introduce even more autonomous and legitimate-looking clicks. The time for cross-functional marketing and security defenses is now.

We've featured the best encryption software.

This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro

CEO and Founder of Fraud Blocker.