Anthropic’s restricted Claude Mythos model may be coming to Claude Code
2026-05-26T01:23:27Z•eb4839e2b25a24fd5febf7c0962551235ea2750675738471a405ee8eda34567a
Apex OneCINEMAGOALCVE-2026-26980Chromium RCEClickFixComposerDrupalGhost CMSKali365KimWolfLaravel LangMFA bypassMicrosoft 365OAuth device codePhaaSSQL injectionUbiquitiUniFi OSbotnetcredential theftlaw enforcementphishingpiracysupply chainzero-day
What happened
Collection of security news covering multiple active and high-impact threats: FBI warns of Kali365 phishing-as-a-service abusing OAuth device code flows to steal Microsoft 365 session tokens and bypass MFA; Ghost CMS critical SQL injection (CVE-2026-26980) is being exploited at scale in ClickFix campaigns; Laravel Lang Composer packages were hijacked via GitHub tags to distribute credential-stealing malware (supply-chain compromise); Trend Micro and others report exploited zero-days (Apex One) and a highly critical Drupal SQLi being actively targeted; Ubiquiti released patches for maximum-sev.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- eb4839e2b25a24fd5febf7c0962551235ea2750675738471a405ee8eda34567a
- Enrichment time
- 2026-05-26T01:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.