A week in security (May 11 – May 17)
2026-05-18T08:51:52Z•9117f4e8d69f9015e15f3782ceb582273149aac2b353002df57d6f193992df41
AI misuseBunCanvasChromeClickFixEdgeInstructureIoTJDownloaderKeitaroNWHStealerPatch TuesdayShinyHuntersYarboad-frauddata breachdeepfakemacOSmalwarephishingprivacyrobotics vulnerabilitiessextortionsupply-chain compromise
What happened
Malwarebytes published a series of May 2026 reports covering multiple high-impact incidents and trends: a supply‑chain compromise of the JDownloader website that served infected installers; a large education data breach and follow‑on defacements/pressure by the ShinyHunters group affecting Instructure/Canvas; attackers abusing the Bun JavaScript runtime to distribute NWHStealer; a ClickFix macOS campaign using fake Claude setup results; vulnerabilities in Yarbo garden robots that could expose Wi‑Fi credentials, cameras, and enable physical harm; widespread AI/deepfake harms including sextortio
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 9117f4e8d69f9015e15f3782ceb582273149aac2b353002df57d6f193992df41
- Enrichment time
- 2026-05-18T08:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.