ChatGPT share links abused to host fake outage pages to deliver malware

2026-05-30T01:23:32Zfff072f7405b8f026347d7884734e6fb174e6c7f63c2772c4aa8755f4bca66dd
23andmeBTMOBCVE-2026-35616DDoSEKZFortiClientGreyVibeai-assisted_luresandroid_malwarebotnetcharterchatgpt_abusechrome_dbsccredential_theftdata_breachddos-as-a-servicefake_fifafraudgogs_zero-dayinfostealermalwarephishingremote_code_executionsocial_engineering

What happened

Multiple active threats and major security developments: attackers are abusing ChatGPT content-share links to host fake OpenAI outage pages that distribute malware disguised as a ChatGPT desktop app; hackers are exploiting an authentication bypass in FortiClient EMS (CVE-2026-35616) to deploy the EKZ credential stealer; an unpatched Gogs zero-day enables remote code execution on exposed instances; and DDoS-as-a-Service and large botnet operations remain significant, with Dutch authorities disrupting a 17-million-device botnet. Other notable items include AI-assisted phishing campaigns by GreyV

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
fff072f7405b8f026347d7884734e6fb174e6c7f63c2772c4aa8755f4bca66dd
Enrichment time
2026-05-30T01:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.