Meet GREYVIBE, the Russia-Linked Hacking Group Using AI to Target Ukraine and Still Making Rookie Mistakes

2026-05-29T20:51:52Z265ad46536fd6b3c989c604a8c3508d80ec06708282b71f0682235faa970aa91
AI-assisted malwareAPTAndroid RATBTMOBCISA-KEVCVE-2026-35616CVE-2026-48172CVE-2026-8398CarnivalFortiClientFox TempestGREYVIBELiteSpeedRussia-linkedUkraineWindows vulnerabilitiescode signing abusedata breachexposed passportszero-day

What happened

This batch covers multiple high-impact incidents: a newly tracked Russia-linked APT dubbed GREYVIBE using AI-assisted malware to target Ukraine; a controversial public dump of six Windows zero-days (three of which are already exploited in the wild); active exploitation of FortiClient EMS (CVE-2026-35616) for unauthenticated RCE; and a critical LiteSpeed cPanel plugin flaw (CVE-2026-48172) added to CISA’s KEV. Other notable items: commercial Android full-device takeover kit BTMOB, a nearly 6M-record Carnival customer data breach, Microsoft/Resecurity disruption of the Fox Tempest code‑signing/“

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
265ad46536fd6b3c989c604a8c3508d80ec06708282b71f0682235faa970aa91
Enrichment time
2026-05-29T20:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.