Anthropic’s restricted Claude Mythos model may be coming to Claude Code
2026-05-25T19:23:29Z•61b3d22ac9a4971d43031891d2d19a365c6a8321b5dbba070cd58236242deee8
CVE-2026-26980MFA bypassMicrosoft 365OAuth device flowauth-token-theftbotnetchromiumclickfraudcomposercredential-stealercrypto-drainer','lucifer-daasdrupalghost-cmsgithub-tagskimwolflaravelphishing-as-a-servicepiracyrceserver-seizuresql-injectionsupply-chaintrend-micro-apex-oneunifi-oszero-day
What happened
Roundup of multiple active security incidents and law‑enforcement actions: the FBI warns of the Kali365 phishing‑as‑a‑service platform abusing the OAuth device‑code flow to steal Microsoft 365 session tokens and bypass MFA; a large campaign is exploiting a critical Ghost CMS SQL injection (CVE-2026-26980) to inject malicious JavaScript in ClickFix flows; Laravel Lang packages were hijacked via GitHub tags to distribute credential‑stealing malware through Composer. Additional items include Trend Micro reporting an Apex One zero‑day in the wild, Drupal SQLi exploitation attempts, Ubiquiti patch‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 61b3d22ac9a4971d43031891d2d19a365c6a8321b5dbba070cd58236242deee8
- Enrichment time
- 2026-05-25T19:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.