Hackers abuse Google ads, Claude.ai chats to push Mac malware

2026-05-10T19:23:31Zacdf5496325c142b3f4b16d0c8be4a48986a951eb02ac34ed5b1ac84d13d7857
cisaclaude.aidata-breachdirty-fraggeforce-nowgoogle-adshuggingfaceinfostealerivanti-epmmjdownloaderlinux-zero-daylocal-privilege-escalationmac-malwaremalvertisingnvidiapcpjack','clickfix','credential-theft','zara-data-breach','crimEpython-ratransomhouseshinyhunterssite-compromisesource-code-leaksupply-chaintclbankervidar-stealerzero-day

What happened

Multiple active campaigns and breaches reported: attackers are using Google Ads and abused Claude.ai shared chats to deliver Mac malware via malvertising; the JDownloader site was compromised to serve malicious installers (Python RAT for Windows/Linux); a fake OpenAI repo on Hugging Face pushed an infostealer; NVIDIA confirmed a GeForce NOW user-data breach (Armenian users affected); Trellix source-code theft was claimed by RansomHouse; CISA ordered federal fixes for a high-severity Ivanti EPMM zero-day being exploited in the wild; a new Linux local-privilege zero-day (“Dirty Frag”) grantsroot

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
acdf5496325c142b3f4b16d0c8be4a48986a951eb02ac34ed5b1ac84d13d7857
Enrichment time
2026-05-10T19:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.