You do surprise me.exe: An unexpected executable in Hola Browser
2026-06-07T08:51:33Z•4a9ad789279bc0384a6b80465871408bd4887b26ba759c5c26c3d665efc09de9
AIAMOSCanvasEDRGartner Magic QuadrantGitHubSMBShinyHuntersVS Code extensionWantToCrycrypto miningendpoint protectionfirewallinfostealermacOSransomwarestudent data compromisesupply chainsynchronized security
What happened
Collection of Sophos threat-research and product news (May–June 2026). Key security items: an unexpected executable bundled with Hola Browser indicating a crypto‑mining/supply‑chain persistence; a malicious VS Code extension that cloned private GitHub repositories (supply‑chain compromise); analysis of the AMOS macOS infostealer operating at scale; WantToCry ransomware performing SMB brute‑force and remote encryption; and fallout from the Canvas data compromise attributed to ShinyHunters. Also includes a writeup on AI‑assisted EDR evasion techniques and several product/market updates (Gartner,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 4a9ad789279bc0384a6b80465871408bd4887b26ba759c5c26c3d665efc09de9
- Enrichment time
- 2026-06-07T08:51:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.