A week in security (May 4 – May 10)

2026-05-11T08:51:55Z81f4d3012e3b97b339e063fede8ad9ded883253b507c9497b7eaa0c1eaa9330e
active-exploitationai-investment-scamai-modelsbrowser-securitybuncanvaschromecpaneldata-breachdomain-abuseedgefacebook-phishingfraudincident-responseinfostealerkeitaronwhstealerphishingplaintext-passwordsransomware/defacementroblox-account-theftshinyhuntersvulnerabilitywhatsapp

What happened

This set of Malwarebytes posts (May 4–10, 2026) highlights multiple high-impact incidents and trends: a claimed large-scale Canvas data breach (ShinyHunters, ~275M records) and related login-portal defacements; an actively exploited cPanel/WHM vulnerability enabling site takeover; WhatsApp patched two flaws that could allow delivery of malicious/disguised files; browser security concerns (Microsoft Edge loading saved plaintext passwords into memory; Google Chrome silently downloading a 4GB AI model and reinstalling it); attackers repurposing the Bun JavaScript runtime to distribute NWHStealer;

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
81f4d3012e3b97b339e063fede8ad9ded883253b507c9497b7eaa0c1eaa9330e
Enrichment time
2026-05-11T08:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · A week in security (May 4 – May 10) · Baitaphish