FBI warns of in-person data theft attacks from extortion gang
2026-05-27T13:23:29Z•cd0538a51bdab4dca6a8658869bd27d563e1d6810da5c9d0b9e6f52d621324c8
MFA-bypassOAuth-abuseactive-exploitationcisaclickfixcybercrimedata-breachfbighost-cmsin-person-theftknowledgedeliverlitespeed-cpanelphishing-as-a-serviceransom-extortionshinyhunterssilent-ransom-groupweb-shellzero-day
What happened
Multiple high-risk incidents and active exploit campaigns were reported across US and global targets: the FBI warned that the Silent Ransom Group (SRG) is conducting in-person data-theft extortion attacks against U.S. law firms; CISA ordered rapid patching of a critical, actively exploited LiteSpeed cPanel user‑end plugin vulnerability; a zero‑day in the KnowledgeDeliver LMS was abused to install the Godzilla web shell; Ghost CMS SQL injection (CVE-2026-26980) is being weaponized in a large ClickFix campaign; and the Kali365 phishing‑as‑a‑service platform is hijacking Microsoft 365 accounts by
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- cd0538a51bdab4dca6a8658869bd27d563e1d6810da5c9d0b9e6f52d621324c8
- Enrichment time
- 2026-05-27T13:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.