ChatGPT share links abused to host fake outage pages to deliver malware

2026-05-29T19:23:31Zc6b30316dbbda6b35596cac4cb5f356da2180ee6e2c8ccf563e82faaad253b89
CVE-2026-35616DDoS-as-a-ServiceLLM-abuseandroid-ratbotnetdata-breachinfostealermalwarephishingremote-code-executionthreat-actorzero-day

What happened

Multiple active threats and major incidents were reported: threat actors are abusing ChatGPT share links to host fake OpenAI outage pages that push malware disguised as a ChatGPT desktop app; an authentication-bypass in FortiClient EMS (CVE-2026-35616) is being exploited to deliver an undocumented EKZ infostealer; an unpatched Gogs zero-day allows remote code execution on exposed instances; Dutch authorities disrupted a 17 million-device botnet; an Android RAT service (BTMOB) offers custom phishing payloads; the GreyVibe cluster is leveraging ChatGPT/Gemini for AI-generated lures and custommal

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
c6b30316dbbda6b35596cac4cb5f356da2180ee6e2c8ccf563e82faaad253b89
Enrichment time
2026-05-29T19:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ChatGPT share links abused to host fake outage pages to deliver malware · Baitaphish