ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
2026-05-30T01:24:07Z•87c48cecf8d0535bdcbbf98c213df180f1bb14f0b93df9f924fb0840d5acd0ca
CVE-2026-27771CVE-2026-39987CVE-2026-45659LLM-agentRCEactive-exploitationchatgphishchatgptcredential-theftmalicious-npmmalicious-nugetphishingprompt-injectionstate-sponsoredsupply-chainsupply-chain-compromise
What happened
The Hacker News roundup describes a surge of high‑severity threats and active exploitation across cloud, developer-supply, and AI surfaces. Notable items include ChatGPhish — a prompt‑injection/phishing technique abusing ChatGPT’s Markdown renderer — and attackers using an LLM agent after exploiting Marimo (CVE-2026-39987) to harvest cloud credentials. Other highlights: a critical Gogs RCE (no CVE), active exploitation of a FortiClient EMS flaw to deploy credential stealers, Gitea unauthenticated private-image disclosure (CVE-2026-27771), and a patched SharePoint RCE (CVE-2026-45659). Multiple
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 87c48cecf8d0535bdcbbf98c213df180f1bb14f0b93df9f924fb0840d5acd0ca
- Enrichment time
- 2026-05-30T01:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.