WhatsApp phishing attack uses fake business docs to hack PCs

2026-06-23T07:23:29Zc80d6dc1bd11a1d4465ddeec59a9cbbdcba06fb5ec56aa343ec82baa59b7bdbc
BlueNoroffDoSEmbyFFmpegFortiBleedFortiGateJaredFromSubwayJellyfinKodiMEV botMastra AINextcloudOBS StudioPixelSmashRCESapphire SleetVBScriptWhatsAppcredential harvestingcrypto theftmalwarenpm compromise","Klue","OAuth breach","Icarus","Gravity SMTP","Vphishingremote accesssupply chain

What happened

A collection of BleepingComputer security reports (19–22 Jun 2026) covering multiple active threats and major incidents: WhatsApp phishing distributing VBScript to gain remote access; a $15M theft from the JaredFromSubway MEV bot via manipulated trading-opportunity logic; a newly disclosed FFmpeg “PixelSmash” flaw that can lead to RCE or DoS in many media apps (Jellyfin, Kodi, Emby, Nextcloud, PhotoPrism, OBS); the FortiBleed campaign using custom FortiGate sniffers to harvest credentials; Microsoft fixes for an AutoGen Studio chain (“AutoJack”) enabling code execution via a malicious webpage;

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
c80d6dc1bd11a1d4465ddeec59a9cbbdcba06fb5ec56aa343ec82baa59b7bdbc
Enrichment time
2026-06-23T07:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.