ChatGPT share links abused to host fake outage pages to deliver malware
2026-05-30T07:23:31Z•d151a91d0d184c7ed5fcfab854028418cced4ccdb641b06f4352643377162bee
ai-assisted-attacksandroid-ratbotnetcredential-stealerdata-breachddos-as-a-servicefake-websitesforticlientgogsinfostealermalware-distributionphishingremote-code-executionvulnerability-exploitzero-day
What happened
Multiple active threats and incidents reported: attackers are abusing ChatGPT share links to host fake outage pages that distribute malware disguised as a ChatGPT desktop app; FortiClient EMS is being actively exploited via an authentication bypass (CVE-2026-35616) to deploy an undocumented credential stealer (EKZ); an unpatched Gogs zero‑day allows remote code execution on internet‑facing instances; and a massive 17‑million‑device botnet was disrupted by Dutch authorities. Other notable activity includes expansion of DDoS-as-a-Service platforms, AI-powered social‑engineering campaigns (GreyV
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- d151a91d0d184c7ed5fcfab854028418cced4ccdb641b06f4352643377162bee
- Enrichment time
- 2026-05-30T07:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.