ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

29/05/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant’s implicit trust in Markdown links and images to trigger prompt injections and

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

29/05/2026 0 Comments 0 tags

An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network

New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks

29/05/2026 0 Comments 0 tags

A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities since at least August 2025. GREYVIBE, per WithSecure, is assessed

What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks

29/05/2026 0 Comments 0 tags

Shadow AI used to mean employees pasting things they shouldn’t into ChatGPT. It now means something bigger: employees building full applications with AI, wiring them into production systems, and publishing

Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets

29/05/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil’s largest cooperative financial systems, to siphon client IDs and

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

29/05/2026 0 Comments 0 tags

The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean military and corporate entities through

Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code

28/05/2026 0 Comments 0 tags

A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user to execute arbitrary code under certain conditions. The security flaw,

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

28/05/2026 0 Comments 0 tags

Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver credential-stealing malware. “The campaign abused trusted endpoint management infrastructure to

ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More

28/05/2026 0 Comments 0 tags

Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled social-engineering bait, and

Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

28/05/2026 0 Comments 0 tags

Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings and give affected vendors an opportunity to better understand the