Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps
2026-05-19T19:24:13Z•9c47b38135ddf0e9287b9f8e3e70af8d29ec5d95abf3e5170508edaa9d771287
PoCad-fraudandroidci-cd-credentialsdrupalemail-gatewaygithub-actionsheap-overflowlinux-kernellocal-privilege-escalationmalvertisingmfa-bypassmini-shai-huludmobile-malwarenginxnpm-supply-chainoauth-phishingp2p-botnetphishing-as-a-serviceremote-code-executionsupply-chainturlavs-code-extensionweb-cmswoocomerce-skimmer
What happened
The Hacker News roundup (19 May 2026) describes a broad set of active and high-impact threats and disclosures: a large Android ad-fraud/malvertising campaign called “Trapdoor” (455 malicious apps, 183 C2 domains, ~659M daily bid requests); a PoC (DirtyDecrypt / DirtyCBC) for a Linux kernel LPE (CVE-2026-31635); OAuth-consent phishing (EvilTokens) bypassing MFA and compromising Microsoft 365 orgs; an urgent Drupal core security release scheduled for May 20; critical RCE and mail-exfiltration flaws in SEPPMail Secure E-Mail Gateway; a compromised Nx Console VS Code extension delivering a cred‑/s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 9c47b38135ddf0e9287b9f8e3e70af8d29ec5d95abf3e5170508edaa9d771287
- Enrichment time
- 2026-05-19T19:24:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.