New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power users"

2026-05-28T13:24:16Zc1bf2dae5ddc93480c32f3d4865538874d74f2d38e8e3913878e93b03ab69438
ai-chatbot-abuseai-ddoscert-incratesiocredential-stealercryptocurrency-targetingcryptojackingghost-cmsgiteaglasswormjinx-0164knowledgedeliverlaravel-langlazarusmacos-malwaremfa-prompt-bombingmuddywaternpmpackagistpatching-guidancepypiremotepesharepointsupply-chain-attacktrapdoor

What happened

A broad set of alerts from The Hacker News covering active exploitation, supply-chain compromises, and AI-related abuse. Highlights include coordinated cross-ecosystem supply chain campaigns (TrapDoor, GlassWorm, Packagist, Laravel-Lang) delivering credential-stealers and Linux/macOS malware; targeted campaigns against cryptocurrency firms using recruiter-themed lures and bespoke macOS malware (JINX-0164); multiple high-severity vulnerabilities being exploited or patched (Ghost CMS, Microsoft SharePoint, Gitea, KnowledgeDeliver LMS); growing AI-assisted threats such as chatbot-driven cryptojam

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
c1bf2dae5ddc93480c32f3d4865538874d74f2d38e8e3913878e93b03ab69438
Enrichment time
2026-05-28T13:24:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.