ChatGPT share links abused to host fake outage pages to deliver malware
2026-05-30T13:23:29Z•d3976db16910d07cea1e55ac7e0b923ba5a6a7d6872d56dbd818458ae10108f5
CVE-2026-35616ai-generated-luresandroid-rat-btmobanthropic-mythosbotnet-takedownchatgpt-abusecredential-theftdata-breachddos-as-a-servicefifa-fraudforticlient-emsgogs-zero-daymalware-distributionphishingremote-code-executionsession-cookie-protectionsocial-engineering
What happened
Multiple active threats and notable security developments were reported: threat actors abused ChatGPT share links to host fake outage pages that distribute malware, and AI-powered lures (GreyVibe) and an Android RAT (BTMOB) are being used in targeted campaigns. Researchers and authorities disclosed high-impact incidents: active exploitation of FortiClient EMS authentication bypass (CVE-2026-35616) to deploy an infostealer, an unpatched Gogs zero-day enabling remote code execution, and a massive 17 million–device botnet disrupted by Dutch authorities. Other items include growing DDoS-as-a‑서비스,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- d3976db16910d07cea1e55ac7e0b923ba5a6a7d6872d56dbd818458ae10108f5
- Enrichment time
- 2026-05-30T13:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.