30,000 Facebook Accounts Hacked via Google AppSheet Phishing Campaign
2026-05-02T01:24:10Z•ca964dfd225e2f20fb5c811ac65b157577420c48cef8a58a7226944bd060276a
active-exploitationappsheetaptcredential-theftgithubgo-moduleslocal-privilege-escalationnpmphishingpypiransomwarercerubygemssqlisso-abusesupply-chainvishingvulnerabilitieswiper
What happened
A batch of high-impact cybersecurity incidents and disclosures: a Vietnamese-linked AppSheet phishing relay (AccountDumpling) that compromised ~30,000 Facebook accounts; rapid SaaS-targeted extortion using vishing and SSO abuse by criminal clusters (Cordial Spider, Snarky Spider); multiple supply-chain compromises (malicious Ruby gems, Go modules, PyTorch Lightning, SAP-related npm packages); new backdoors and distribution tricks (DEEP#DOOR, EtherRAT GitHub facades); and numerous critical vulnerabilities and active exploits (Linux LPE "Copy Fail", LiteLLM SQLi, GitHub push-to-RCE, Hugging Face
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- ca964dfd225e2f20fb5c811ac65b157577420c48cef8a58a7226944bd060276a
- Enrichment time
- 2026-05-02T01:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.