Two new extortion crews are speedrunning the Scattered Spider playbook
2026-04-30T20:51:46Z•d43380c19ccc9bf90b294366af83ca2450d96752b4cc2011c5024c0738fe0300
AI-driven vulnerability discoveryAnthropicCordial SpiderCrowdStrikeHafniumMythosSSO phishingSaaS compromiseScattered SpiderSilk TyphoonSnarky Spidercritical infrastructuredata centersextortiongeofence surveillanceprivacy finesregulatory oversightstudent data breachvoice phishingvulnerability disclosure
What happened
Multiple CyberScoop items highlight elevated cyber risk: CrowdStrike reports two Com‑affiliated extortion crews (Cordial Spider and Snarky Spider) are rapidly compromising SaaS environments using voice phishing and fake SSO pages to steal data for extortion, echoing the Scattered Spider playbook. Separately, Anthropic’s Mythos AI reportedly discovered thousands of previously unknown software vulnerabilities, raising concerns about accelerated automated vulnerability discovery and potential weaponization. Policy and governance issues surfaced — Congress is debating treating data centers as a独st
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cyberscoop
- Record identifier
- d43380c19ccc9bf90b294366af83ca2450d96752b4cc2011c5024c0738fe0300
- Enrichment time
- 2026-04-30T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.