Latin American Cybercriminals Hoover Up Government Data

2026-05-27T20:51:43Z4b60ba633926644b7116460b85a4c50bb4872bb495a34d92c5c175bede8ac59f
AI BOMsAI-assisted exploit developmentAPI key persistenceCISA exposed secretsCVE-2026-42897Exchange zero‑dayGitHub compromiseGoogle API keysLatin AmericaMegalodonOT/ICS vulnerabilityShai‑HuludSharePoint patchShowboatTeamPCPagentic AI securitybackdoorbrand hijackingdata breachgovernment data leakmalwarerobotics securitysupply‑chain riskunderminr domain frontingzero-day vulnerabilities

What happened

A DarkReading roundup highlights a surge in high-impact incidents and trends: a purported leak of 5.8M Uruguayan citizen records and multiple government-targeting breaches; GitHub-focused campaigns (malicious commits, Megalodon malware and a 4K-internal-repo data theft credited to TeamPCP); widespread worm/backdoor activity (Shai‑Hulud, Showboat); and critical vulnerabilities under active exploitation — notably Microsoft Exchange zero‑day CVE-2026-42897 and a critical unauthenticated command‑injection flaw in an OT robot OS. The feed also calls out emerging risks from AI-assisted exploit dev (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
4b60ba633926644b7116460b85a4c50bb4872bb495a34d92c5c175bede8ac59f
Enrichment time
2026-05-27T20:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.