GM agrees to $12.75M California settlement over sale of drivers’ data

2026-05-12T01:23:29Z0326949a72820ac470bb460b483a19d88b94e2f003fbb3259ac3d8346a080f66
AI-assisted exploit generationAndroid banking malwareC2CCPA settlementCanvas defacementClaude.aiGeneral MotorsGhostLockGoogle Ads abuseInstructureNVIDIA GeForce NOWTON blockchainTrickMoWindows API abusedata breachextortion messagefile access denialinfostealermalvertisingprivacypython RATransomware techniquesupply-chain compromiseweb admin toolzero-day

What happened

A batch of security incidents and research was reported: a malicious Checkmarx Jenkins plugin on the Jenkins Marketplace distributed an infostealer (supply-chain compromise); the JDownloader website was hacked to replace installers with malicious Windows/Linux packages installing a Python RAT; a fake OpenAI repository on Hugging Face pushed an infostealer; malvertising campaigns abused Google Ads and Claude.ai shared chats to deliver Mac malware; TrickMo Android banking malware added new commands and now uses the TON blockchain for covert C2; a GhostLock proof-of-concept shows how a legitimate

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
0326949a72820ac470bb460b483a19d88b94e2f003fbb3259ac3d8346a080f66
Enrichment time
2026-05-12T01:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.