Anthropic’s restricted Claude Mythos model may be coming to Claude Code

2026-05-26T01:23:27Zeb4839e2b25a24fd5febf7c0962551235ea2750675738471a405ee8eda34567a
Apex OneCINEMAGOALCVE-2026-26980Chromium RCEClickFixComposerDrupalGhost CMSKali365KimWolfLaravel LangMFA bypassMicrosoft 365OAuth device codePhaaSSQL injectionUbiquitiUniFi OSbotnetcredential theftlaw enforcementphishingpiracysupply chainzero-day

What happened

Collection of security news covering multiple active and high-impact threats: FBI warns of Kali365 phishing-as-a-service abusing OAuth device code flows to steal Microsoft 365 session tokens and bypass MFA; Ghost CMS critical SQL injection (CVE-2026-26980) is being exploited at scale in ClickFix campaigns; Laravel Lang Composer packages were hijacked via GitHub tags to distribute credential-stealing malware (supply-chain compromise); Trend Micro and others report exploited zero-days (Apex One) and a highly critical Drupal SQLi being actively targeted; Ubiquiti released patches for maximum-sev.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
eb4839e2b25a24fd5febf7c0962551235ea2750675738471a405ee8eda34567a
Enrichment time
2026-05-26T01:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.