Massive AI investment scam network spans 15,500 domains

2026-05-07T20:52:12Z46f8cc76a25d140fc11144dea6eb0d55494aba38e7e249f57f6027f6a9b5d1a9
ai-scamappsheetbun-runtimecanvaschromecpanelcredential-theftdata-breachdomain-abusefake-captchainfostealerkeitaronwhstealerpatch-managementpaypalphishingprivacyrobloxshinyhuntersthreat-intelvulnerabilityweb-exploitwhatsappworld-cup-scams

What happened

Malwarebytes published multiple high-impact incidents: a massive AI investment scam operation (≈15,500 domains) abused the Keitaro ad‑tracking platform to cloak and selectively expose landing pages; an actively exploited cPanel/WHM bug allows website takeover at scale; ShinyHunters claims a 275M‑user data theft from Instructure Canvas; attackers are packaging NWHStealer via the Bun JavaScript runtime; WhatsApp patched two file‑handling flaws; and Google Chrome is silently writing a 4 GB AI model to user devices. Additional coverage describes wide phishing campaigns (Google AppSheet, hijacked/”

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
46f8cc76a25d140fc11144dea6eb0d55494aba38e7e249f57f6027f6a9b5d1a9
Enrichment time
2026-05-07T20:52:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.