Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps

2026-05-19T19:24:13Z9c47b38135ddf0e9287b9f8e3e70af8d29ec5d95abf3e5170508edaa9d771287
PoCad-fraudandroidci-cd-credentialsdrupalemail-gatewaygithub-actionsheap-overflowlinux-kernellocal-privilege-escalationmalvertisingmfa-bypassmini-shai-huludmobile-malwarenginxnpm-supply-chainoauth-phishingp2p-botnetphishing-as-a-serviceremote-code-executionsupply-chainturlavs-code-extensionweb-cmswoocomerce-skimmer

What happened

The Hacker News roundup (19 May 2026) describes a broad set of active and high-impact threats and disclosures: a large Android ad-fraud/malvertising campaign called “Trapdoor” (455 malicious apps, 183 C2 domains, ~659M daily bid requests); a PoC (DirtyDecrypt / DirtyCBC) for a Linux kernel LPE (CVE-2026-31635); OAuth-consent phishing (EvilTokens) bypassing MFA and compromising Microsoft 365 orgs; an urgent Drupal core security release scheduled for May 20; critical RCE and mail-exfiltration flaws in SEPPMail Secure E-Mail Gateway; a compromised Nx Console VS Code extension delivering a cred‑/s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
9c47b38135ddf0e9287b9f8e3e70af8d29ec5d95abf3e5170508edaa9d771287
Enrichment time
2026-05-19T19:24:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.