ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

2026-05-30T01:24:07Z87c48cecf8d0535bdcbbf98c213df180f1bb14f0b93df9f924fb0840d5acd0ca
CVE-2026-27771CVE-2026-39987CVE-2026-45659LLM-agentRCEactive-exploitationchatgphishchatgptcredential-theftmalicious-npmmalicious-nugetphishingprompt-injectionstate-sponsoredsupply-chainsupply-chain-compromise

What happened

The Hacker News roundup describes a surge of high‑severity threats and active exploitation across cloud, developer-supply, and AI surfaces. Notable items include ChatGPhish — a prompt‑injection/phishing technique abusing ChatGPT’s Markdown renderer — and attackers using an LLM agent after exploiting Marimo (CVE-2026-39987) to harvest cloud credentials. Other highlights: a critical Gogs RCE (no CVE), active exploitation of a FortiClient EMS flaw to deploy credential stealers, Gitea unauthenticated private-image disclosure (CVE-2026-27771), and a patched SharePoint RCE (CVE-2026-45659). Multiple

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
87c48cecf8d0535bdcbbf98c213df180f1bb14f0b93df9f924fb0840d5acd0ca
Enrichment time
2026-05-30T01:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.