WhatsApp says it disrupted new NSO spyware phishing attacks
2026-06-08T19:23:28Z•a56731584507fe90ed005c2b5cc3c754aa6407f3c3e3126b0b2cdfdac625d662
AI support abuseAgentPSDBrickstormC0XMO botnetCISACVE-2026-3300Check PointChinese APT UNC5221DD-WRTEverest Forms ProGogsInstagram account takeoverMetaNSO GroupPlenetQilin ransomwareRCESolarWinds Serv-UUbiquiti UniFidata breach','third-party breach','supply-chain compromise','botphishingremote code executionroot escalationspywarezero-day
What happened
Multiple high-impact security incidents were reported: WhatsApp says it disrupted NSO-linked spear-phishing campaigns delivering spyware; Gogs patched a critical RCE zero-day impacting Internet-facing instances; and a chained set of Ubiquiti UniFi OS vulnerabilities allows unauthenticated root code execution. Other notable events include Check Point tying a VPN zero-day to the Qilin ransomware group, CISA warning active exploitation of a SolarWinds Serv‑U flaw to crash servers, a large Meta/Instagram account‑takeover incident via abuse of Meta’s AI support, and an actively exploited critical漏洞
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- a56731584507fe90ed005c2b5cc3c754aa6407f3c3e3126b0b2cdfdac625d662
- Enrichment time
- 2026-06-08T19:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.