Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks

2026-05-28T19:24:09Z235eaa8fdeeb60987b24937afc9e9c6e755146e64e71e283fcf17b4dd8564a81
AI Threat DefenseAI-enabled-attacksAndroid-malwareBTMOBCarnivalChatGPTEdamameFortiClient EMSGeminiGeordieGiteaGoogleGreyVibeMandiantProject LightwellWizagentic-eracontainer-securitydata-breachopen-sourcephishingsupply-chainzero-day

What happened

Multiple SecurityWeek stories highlight rising AI-enabled threat sophistication and several high-impact vulnerabilities and breaches. Russia-linked GreyVibe operators are extensively using ChatGPT, Gemini and other AI to scale and optimize cyberattacks. A critical FortiClient EMS vulnerability was exploited in the wild (Fortinet released hotfixes and urged immediate patching). A Gitea flaw exposed ~30,000 deployments, allowing attackers to pull private container images and exfiltrate source code, credentials and infrastructure secrets. New BTMOB Android malware, distributed via phishing, can实现

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
235eaa8fdeeb60987b24937afc9e9c6e755146e64e71e283fcf17b4dd8564a81
Enrichment time
2026-05-28T19:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.