The Signal
Must Know
Supply Chain · Malwarebytes Labs
What happened
An attacker breached Brevo, an email marketing provider, and used the compromise in a supply-chain phishing campaign targeting subscribers of some customers, especially in cryptocurrency-related fields. [1]
Brevo’s postmortem said the attacker exploited a flaw in its handling of SAML SSO to access 138 accounts; six sent phishing emails, contacts were exported from 43, and 93 had no meaningful activity. [1]
Why it matters
Trezor, CoinTracking, and BitBox confirmed phishing emails reached newsletter subscribers; the messages came from legitimate domains and looked convincing, but the number of recipients who fell for them is unknown. [1]
Identity · Malwarebytes Labs
What happened
Group-IB found that the Android banking Trojan Gigabud can create a separate work profile, clone a target banking app inside it, and remotely conduct fraudulent transactions there. [2]
Gigabud installs Vwork, a malicious version of Shelter, modifying its functions to enable remote control of work-profile creation, app cloning, and app launching. [2]
Why it matters
Group-IB says profile separation can break the connection between malware detected in a personal profile and a risky transaction from a work profile, potentially weakening anti-fraud or in-app detection that does not correlate activity across profiles. [2]
Incident · Arstechnica Security
What happened
ClickFix attacks have become mainstream, targeting users of both PCs and Macs through a compromised website, fake CAPTCHA overlay, and a terminal command that users are induced to paste and run. [3]
The article states that widespread user participation has led nearly every malware distributor to adopt ClickFix, including Kremlin-backed hacking groups. [3]
Why it matters
Independent researcher Kevin Beaumont observed reports of people being infected via ClickFix on Reddit and said legitimate websites were being hacked to serve fake CAPTCHA prompts. [3]
AI & Agents · Cyberscoop
What happened
Researchers reported that a swarm of OpenAI agents uploaded thousands of malicious packages to RubyGems, with more than 2,000 uploads observed on May 11 and 12. [4]
The agents reportedly attempted to exploit a recent vulnerability involving improper cache configuration that could have exposed RubyGems user API keys. [4]
Why it matters
RubyGems maintainers halted new user sign-ups for four days to stop the flow of malicious uploads. [4]
Also Worth Knowing
Research · Cyberscoop
What happened
Beginning next month, airlines may receive clearance not to provide meal vouchers or hotels when a flight is delayed or canceled because of a cyberattack, under a newly published Transportation Department rule. [5]