Hackers abuse Google ads for GoDaddy ManageWP login phishing

2026-05-07T01:23:30Z6cc5df59f57c86833c32ed11f1ad393bc97ce7d0543f2adf7d5c71377adf772a
backdoorchaos-ransomwareciscocredential-theft','instructure-data-breach','vimeo-breach','kochcrossworkdaemon-toolsdenial-of-servicegodaddygoogle-adslinux-malwaremanagewpmuddywaternetwork-services-orchestratornodejspalo-alto-networkspan-osphishingquasar-linuxransomwareremote-code-executionrootkitsandbox-escapesupply-chain-attackvm2zero-day

What happened

A batch of BleepingComputer security reports (May 5–6, 2026) highlights multiple high-impact incidents: a Google Ads phishing campaign targeting ManageWP/GoDaddy credentials; a critical vm2 Node.js sandbox escape allowing host code execution; an actively exploited Palo Alto Networks PAN-OS User‑ID Authentication Portal zero‑day; a Cisco Crosswork/NSO denial‑of‑service requiring manual reboots; and a DAEMON Tools supply‑chain trojanized installer delivering a backdoor. Other notable stories cover MuddyWater using Chaos ransomware as a decoy, a new Quasar Linux implant targeting developers, a 8,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
6cc5df59f57c86833c32ed11f1ad393bc97ce7d0543f2adf7d5c71377adf772a
Enrichment time
2026-05-07T01:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.