Massive AI investment scam network spans 15,500 domains
2026-05-07T20:52:12Z•46f8cc76a25d140fc11144dea6eb0d55494aba38e7e249f57f6027f6a9b5d1a9
ai-scamappsheetbun-runtimecanvaschromecpanelcredential-theftdata-breachdomain-abusefake-captchainfostealerkeitaronwhstealerpatch-managementpaypalphishingprivacyrobloxshinyhuntersthreat-intelvulnerabilityweb-exploitwhatsappworld-cup-scams
What happened
Malwarebytes published multiple high-impact incidents: a massive AI investment scam operation (≈15,500 domains) abused the Keitaro ad‑tracking platform to cloak and selectively expose landing pages; an actively exploited cPanel/WHM bug allows website takeover at scale; ShinyHunters claims a 275M‑user data theft from Instructure Canvas; attackers are packaging NWHStealer via the Bun JavaScript runtime; WhatsApp patched two file‑handling flaws; and Google Chrome is silently writing a 4 GB AI model to user devices. Additional coverage describes wide phishing campaigns (Google AppSheet, hijacked/”
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 46f8cc76a25d140fc11144dea6eb0d55494aba38e7e249f57f6027f6a9b5d1a9
- Enrichment time
- 2026-05-07T20:52:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.