WhatsApp phishing attack uses fake business docs to hack PCs
2026-06-23T01:23:29Z•2f8802e41a772411c74b097fd9721c72e50be43f083748594d6b8ea0e4d4c539
bluenoroffcredential-theftdata-breachdosdriver-licenseffmpegfortibleedfortinetgravity-smtp-pluginicaruskluemastranpmoauthphishingpixelsmashrceremote-accesssapphire-sleetsniffersupply-chaintexasvbscriptwhatsappwordpress
What happened
The collection highlights a broad surge in active threats across messaging phishing, supply-chain, credential-theft, and infrastructure compromise. Notable incidents include a WhatsApp phishing campaign delivering VBScript to gain remote access; the FortiBleed campaign using custom sniffers to harvest FortiGate credentials; a newly disclosed FFmpeg 'PixelSmash' flaw enabling potential RCE/DoS in widely used multimedia stacks; a Mastra AI npm supply-chain compromise attributed to North Korean actor Sapphire Sleet/BlueNoroff; the Klue OAuth breach and related Icarus extortion claims; a large Tex
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 2f8802e41a772411c74b097fd9721c72e50be43f083748594d6b8ea0e4d4c539
- Enrichment time
- 2026-06-23T01:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.