Meet GREYVIBE, the Russia-Linked Hacking Group Using AI to Target Ukraine and Still Making Rookie Mistakes
2026-05-29T20:51:52Z•265ad46536fd6b3c989c604a8c3508d80ec06708282b71f0682235faa970aa91
AI-assisted malwareAPTAndroid RATBTMOBCISA-KEVCVE-2026-35616CVE-2026-48172CVE-2026-8398CarnivalFortiClientFox TempestGREYVIBELiteSpeedRussia-linkedUkraineWindows vulnerabilitiescode signing abusedata breachexposed passportszero-day
What happened
This batch covers multiple high-impact incidents: a newly tracked Russia-linked APT dubbed GREYVIBE using AI-assisted malware to target Ukraine; a controversial public dump of six Windows zero-days (three of which are already exploited in the wild); active exploitation of FortiClient EMS (CVE-2026-35616) for unauthenticated RCE; and a critical LiteSpeed cPanel plugin flaw (CVE-2026-48172) added to CISA’s KEV. Other notable items: commercial Android full-device takeover kit BTMOB, a nearly 6M-record Carnival customer data breach, Microsoft/Resecurity disruption of the Fox Tempest code‑signing/“
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 265ad46536fd6b3c989c604a8c3508d80ec06708282b71f0682235faa970aa91
- Enrichment time
- 2026-05-29T20:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.