Hackers abuse Google ads, Claude.ai chats to push Mac malware
2026-05-10T19:23:31Z•acdf5496325c142b3f4b16d0c8be4a48986a951eb02ac34ed5b1ac84d13d7857
cisaclaude.aidata-breachdirty-fraggeforce-nowgoogle-adshuggingfaceinfostealerivanti-epmmjdownloaderlinux-zero-daylocal-privilege-escalationmac-malwaremalvertisingnvidiapcpjack','clickfix','credential-theft','zara-data-breach','crimEpython-ratransomhouseshinyhunterssite-compromisesource-code-leaksupply-chaintclbankervidar-stealerzero-day
What happened
Multiple active campaigns and breaches reported: attackers are using Google Ads and abused Claude.ai shared chats to deliver Mac malware via malvertising; the JDownloader site was compromised to serve malicious installers (Python RAT for Windows/Linux); a fake OpenAI repo on Hugging Face pushed an infostealer; NVIDIA confirmed a GeForce NOW user-data breach (Armenian users affected); Trellix source-code theft was claimed by RansomHouse; CISA ordered federal fixes for a high-severity Ivanti EPMM zero-day being exploited in the wild; a new Linux local-privilege zero-day (“Dirty Frag”) grantsroot
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- acdf5496325c142b3f4b16d0c8be4a48986a951eb02ac34ed5b1ac84d13d7857
- Enrichment time
- 2026-05-10T19:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.