ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
2026-05-30T07:24:07Z•c9a78477c17542900fdd1390d8377f38184f351f7fed988f9e036c9e6afc8eb1
CERT-InChatGPhishFortiClient EMSGREYVIBEGiteaGlassWormGogsJINX-0164KimsukyLLM-agentMarimoMuddyWaterSharePointactive-exploitationcredential-theftcryptojackingmalicious-npmmalicious-nugetphishingprompt-injectionsupply-chainvulnerability-disclosurezero-day-policy
What happened
A broad roundup of active and newly disclosed threats and vulnerabilities: Permiso Security disclosed “ChatGPhish,” a ChatGPT renderer weakness that trusts Markdown links/images and enables prompt-injection-based phishing; an unknown actor exploited Marimo via CVE-2026-39987 and used an LLM agent for post-compromise credential theft; WithSecure attributed AI-powered campaigns to a Russia-linked group dubbed GREYVIBE; researchers found malicious packages in npm and NuGet (including a Sicoob-themed NuGet stealing PFX and client IDs and an npm package exfiltrating files from Anthropic Claude user
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- c9a78477c17542900fdd1390d8377f38184f351f7fed988f9e036c9e6afc8eb1
- Enrichment time
- 2026-05-30T07:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.