Polymarket customers lose $3 million in supply-chain attack

2026-06-26T19:23:30Z67003da5740bcd1298da9db998d1145ad2ea3b5e8063da3f0334dae77a84781d
ai-prompt-injectionbluekitbrowser-in-the-middlecallback-phishingcisco-sd-wancrypto-theftdomain-seizurefraudulent-openai-invitegaslightmacos-malwaremalicious-script-injectionphishingpiracyshop-app-abusesim-swappingsocial-engineeringsupply-chain-attacktelecom-fraudthird-party-breachzero-day

What happened

This collection highlights several active and emerging threats: a supply‑chain attack on Polymarket where a malicious script injected into the frontend via a third‑party vendor led to ~${3}M in customer losses (Polymarket will reimburse affected users); threat actors creating fraudulent OpenAI organization tenants to invite employees and harvest sensitive company data via chats/projects; Mandiant disclosures on in‑the‑wild exploitation of a Cisco SD‑WAN zero‑day (CVE‑2026‑20245) to create rogue root accounts; and new macOS malware (“Gaslight”) that hides prompt‑injection strings and embeds dec

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
67003da5740bcd1298da9db998d1145ad2ea3b5e8063da3f0334dae77a84781d
Enrichment time
2026-06-26T19:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.