ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
2026-05-29T19:24:12Z•d44b25d756a9f6c150eb678955dc2865fd102814fe1d7acec9d459daaaee2ebc
CERT-In 12-hour patchingCVE-2026-27771CVE-2026-39987CVE-2026-45659ChatGPTChatGPhishClaude/Anthropic data exfiltrationFortiClient EMSGREYVIBEGiteaGlassWorm takedownGogs RCEKimsukyLLM agentMFA prompt bombingMarimoMarkdownMicrosoft SharePointMuddyWaterNuGet supply chainRussian-linkedcredential stealermalicious npmphishingprompt injection
What happened
A batch of security reports from The Hacker News highlights multiple high-impact issues: ChatGPhish, a Permiso Security finding, abuses ChatGPT's trust in Markdown links/images to enable prompt-injection-based phishing; attackers leveraged CVE-2026-39987 to compromise Marimo notebooks and used an LLM agent for post-exploitation; active exploitation campaigns abused a critical FortiClient EMS flaw to distribute credential stealers; a critical Gogs RCE (CVSS 9.4) allows authenticated RCE (no CVE assigned); Gitea disclosure CVE-2026-27771 exposes private container images; Microsoft patched ShareP
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- d44b25d756a9f6c150eb678955dc2865fd102814fe1d7acec9d459daaaee2ebc
- Enrichment time
- 2026-05-29T19:24:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.