ChatGPT share links abused to host fake outage pages to deliver malware
2026-05-29T19:23:31Z•c6b30316dbbda6b35596cac4cb5f356da2180ee6e2c8ccf563e82faaad253b89
CVE-2026-35616DDoS-as-a-ServiceLLM-abuseandroid-ratbotnetdata-breachinfostealermalwarephishingremote-code-executionthreat-actorzero-day
What happened
Multiple active threats and major incidents were reported: threat actors are abusing ChatGPT share links to host fake OpenAI outage pages that push malware disguised as a ChatGPT desktop app; an authentication-bypass in FortiClient EMS (CVE-2026-35616) is being exploited to deliver an undocumented EKZ infostealer; an unpatched Gogs zero-day allows remote code execution on exposed instances; Dutch authorities disrupted a 17 million-device botnet; an Android RAT service (BTMOB) offers custom phishing payloads; the GreyVibe cluster is leveraging ChatGPT/Gemini for AI-generated lures and custommal
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- c6b30316dbbda6b35596cac4cb5f356da2180ee6e2c8ccf563e82faaad253b89
- Enrichment time
- 2026-05-29T19:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.