You do surprise me.exe: An unexpected executable in Hola Browser

2026-06-07T08:51:33Z4a9ad789279bc0384a6b80465871408bd4887b26ba759c5c26c3d665efc09de9
AIAMOSCanvasEDRGartner Magic QuadrantGitHubSMBShinyHuntersVS Code extensionWantToCrycrypto miningendpoint protectionfirewallinfostealermacOSransomwarestudent data compromisesupply chainsynchronized security

What happened

Collection of Sophos threat-research and product news (May–June 2026). Key security items: an unexpected executable bundled with Hola Browser indicating a crypto‑mining/supply‑chain persistence; a malicious VS Code extension that cloned private GitHub repositories (supply‑chain compromise); analysis of the AMOS macOS infostealer operating at scale; WantToCry ransomware performing SMB brute‑force and remote encryption; and fallout from the Canvas data compromise attributed to ShinyHunters. Also includes a writeup on AI‑assisted EDR evasion techniques and several product/market updates (Gartner,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
4a9ad789279bc0384a6b80465871408bd4887b26ba759c5c26c3d665efc09de9
Enrichment time
2026-06-07T08:51:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · You do surprise me.exe: An unexpected executable in Hola Browser · Baitaphish