Anthropic’s restricted Claude Mythos model may be coming to Claude Code

2026-05-25T19:23:29Z61b3d22ac9a4971d43031891d2d19a365c6a8321b5dbba070cd58236242deee8
CVE-2026-26980MFA bypassMicrosoft 365OAuth device flowauth-token-theftbotnetchromiumclickfraudcomposercredential-stealercrypto-drainer','lucifer-daasdrupalghost-cmsgithub-tagskimwolflaravelphishing-as-a-servicepiracyrceserver-seizuresql-injectionsupply-chaintrend-micro-apex-oneunifi-oszero-day

What happened

Roundup of multiple active security incidents and law‑enforcement actions: the FBI warns of the Kali365 phishing‑as‑a‑service platform abusing the OAuth device‑code flow to steal Microsoft 365 session tokens and bypass MFA; a large campaign is exploiting a critical Ghost CMS SQL injection (CVE-2026-26980) to inject malicious JavaScript in ClickFix flows; Laravel Lang packages were hijacked via GitHub tags to distribute credential‑stealing malware through Composer. Additional items include Trend Micro reporting an Apex One zero‑day in the wild, Drupal SQLi exploitation attempts, Ubiquiti patch‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
61b3d22ac9a4971d43031891d2d19a365c6a8321b5dbba070cd58236242deee8
Enrichment time
2026-05-25T19:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.