Hackers abuse Google ads for GoDaddy ManageWP login phishing
2026-05-07T01:23:30Z•6cc5df59f57c86833c32ed11f1ad393bc97ce7d0543f2adf7d5c71377adf772a
backdoorchaos-ransomwareciscocredential-theft','instructure-data-breach','vimeo-breach','kochcrossworkdaemon-toolsdenial-of-servicegodaddygoogle-adslinux-malwaremanagewpmuddywaternetwork-services-orchestratornodejspalo-alto-networkspan-osphishingquasar-linuxransomwareremote-code-executionrootkitsandbox-escapesupply-chain-attackvm2zero-day
What happened
A batch of BleepingComputer security reports (May 5–6, 2026) highlights multiple high-impact incidents: a Google Ads phishing campaign targeting ManageWP/GoDaddy credentials; a critical vm2 Node.js sandbox escape allowing host code execution; an actively exploited Palo Alto Networks PAN-OS User‑ID Authentication Portal zero‑day; a Cisco Crosswork/NSO denial‑of‑service requiring manual reboots; and a DAEMON Tools supply‑chain trojanized installer delivering a backdoor. Other notable stories cover MuddyWater using Chaos ransomware as a decoy, a new Quasar Linux implant targeting developers, a 8,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 6cc5df59f57c86833c32ed11f1ad393bc97ce7d0543f2adf7d5c71377adf772a
- Enrichment time
- 2026-05-07T01:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.