Latin American Cybercriminals Hoover Up Government Data
2026-05-27T20:51:43Z•4b60ba633926644b7116460b85a4c50bb4872bb495a34d92c5c175bede8ac59f
AI BOMsAI-assisted exploit developmentAPI key persistenceCISA exposed secretsCVE-2026-42897Exchange zero‑dayGitHub compromiseGoogle API keysLatin AmericaMegalodonOT/ICS vulnerabilityShai‑HuludSharePoint patchShowboatTeamPCPagentic AI securitybackdoorbrand hijackingdata breachgovernment data leakmalwarerobotics securitysupply‑chain riskunderminr domain frontingzero-day vulnerabilities
What happened
A DarkReading roundup highlights a surge in high-impact incidents and trends: a purported leak of 5.8M Uruguayan citizen records and multiple government-targeting breaches; GitHub-focused campaigns (malicious commits, Megalodon malware and a 4K-internal-repo data theft credited to TeamPCP); widespread worm/backdoor activity (Shai‑Hulud, Showboat); and critical vulnerabilities under active exploitation — notably Microsoft Exchange zero‑day CVE-2026-42897 and a critical unauthenticated command‑injection flaw in an OT robot OS. The feed also calls out emerging risks from AI-assisted exploit dev (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 4b60ba633926644b7116460b85a4c50bb4872bb495a34d92c5c175bede8ac59f
- Enrichment time
- 2026-05-27T20:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.