This month in security with Tony Anscombe – May 2026 edition

2026-05-30T08:51:44Zecb34d581cc05c94917c73ee366af214b2d44440a57e4ee34c7221972deba07f
AI-assisted-exploitsAPTAndroid-malwareApt-activityBTMOBCallPhantomCloud-securityCritical-infrastructureEDR-killersFrostyNeighborGenerative-AIGopherWhisperICSNGatePhishingPromptSpyRansomwareScamsScarCruftSednitSupply-chainTrojanized-appVM-securityWebwormZero-day

What happened

ESET WeLiveSecurity May 2026 roundup and research feed covering rising APT activity and targeted campaigns (GopherWhisper, Webworm, FrostyNeighbor, Sednit, ScarCruft), multiple mobile threats (BTMOB RAT, PromptSpy — first-known Android malware to abuse generative AI, CallPhantom), supply-chain and trojanized apps (NGate in NFC payment app), EDR-killer abuse, and high-impact targeting of critical infrastructure (Polish water treatment). The collection highlights a clear trend: increased abuse of AI/GenAI in both reconnaissance and exploit chains (including reports of a suspected AI-generated 0‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
eset_welivesecurity
Record identifier
ecb34d581cc05c94917c73ee366af214b2d44440a57e4ee34c7221972deba07f
Enrichment time
2026-05-30T08:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.