Exploits and vulnerabilities in Q1 2026
2026-05-07T20:52:00Z•96364bf5bbe22fbe89b4791767e97dbd74c90d71bc04186c00859c9858874760
APTBECabcdooramazon-sesc2-frameworksclipbankercryptostealerexploitsfakewalletindustrial-automationiosjanelaratmalwareoceanlotusphantomrpcphishingprivilege-escalationpyPIq1-2026rpcsilver-foxsupply-chainvalleyratvulnerabilitieszichatbot
What happened
Kaspersky Securelist (Apr–May 2026) published multiple threat reports covering (1) a Q1 2026 vulnerabilities and exploits roundup and C2-framework usage in APTs; (2) OceanLotus supply‑chain abuse via malicious PyPI wheel packages delivering ZiChatBot targeting Windows and Linux; (3) a new Windows RPC privilege‑escalation issue dubbed PhantomRPC; (4) Silver Fox campaigns distributing ValleyRAT and a new ABCDoor backdoor via tax‑notification lures; (5) Amazon SES being abused to bypass email defenses in phishing/BEC campaigns; (6) FakeWallet iOS crypto‑stealers on the App Store; and (7) regional
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 96364bf5bbe22fbe89b4791767e97dbd74c90d71bc04186c00859c9858874760
- Enrichment time
- 2026-05-07T20:52:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.