Fake Spotify Premium tutorials on TikTok and Instagram Reels spread malware

2026-06-11T14:51:47Z758c38dbcab768d113e74314793304f78b37a93132b214fb50f01aa2eec4bd7b
CVE-2026-35273Chinese intelligenceGDPRInstagram ReelsOracle PeopleSoftPyPITikTokVidaragentic-AIcloud-insider-threatdomain-seizureespionageinfostealermanaged-securityprivacyprompt-injectionremote-code-executionsocial-media-malwaresupply-chain-compromisezero-day

What happened

This collection highlights multiple active and emerging threats: social-media-driven distribution of the Vidar infostealer via fake Spotify Premium tutorials on TikTok and Instagram Reels; an actively exploited Oracle PeopleSoft zero-day (CVE-2026-35273) enabling unauthenticated remote code execution for affected PeopleTools versions (Oracle issued an out-of-band alert); seizure of 13 domains tied to an alleged Chinese intelligence-gathering operation targeting current and former U.S. government and military personnel; and agentic AI supply-chain/security failures (including a short-lived PyPI

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
758c38dbcab768d113e74314793304f78b37a93132b214fb50f01aa2eec4bd7b
Enrichment time
2026-06-11T14:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.