72 Followers
18 Following
1.2K Posts
If olive oil comes from olives 🫒 where does baby oil come from? 🤔 🥸
webpagehttps://tomcat-links.surge.sh
Status@tomcat.stateofus.eth

Dutch authorities have dismantled a botnet comprising at least 17 million infected devices, including computers, smartphones, tablets, and IoT devices.

More than 200 servers in the Netherlands supported the operation. Police seized a subset of the infrastructure, and the hosting provider subsequently took the network offline.

Read: https://thehackernews.com/2026/05/dutch-authorities-dismantle-botnet.html

Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices

Dutch authorities dismantled a 17 million-device botnet backed by 200+ servers, disrupting infrastructure used for cybercrime.

The Hacker News

⚠️ Attackers used an LLM agent for post-exploitation after breaching a public Marimo notebook via CVE-2026-39987, a pre-auth RCE flaw affecting versions ≤0.20.4.

The intrusion stole cloud credentials, retrieved an SSH key from AWS Secrets Manager, and exfiltrated a PostgreSQL database via eight SSH sessions in under two minutes.

Full report: https://thehackernews.com/2026/05/attackers-use-llm-agent-for-post.html

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

LLM-driven attackers exploited CVE-2026-39987 on May 10, 2026, to steal credentials and exfiltrate a PostgreSQL database.

The Hacker News

⚠️ A new technique called "ChatGPhish" turns OpenAI’s ChatGPT into a #phishing tool.

No special prompt required... simply summarizing a malicious web page can cause #ChatGPT to display phishing links, fake security alerts, QR codes, and attacker-hosted images in its trusted interface.

Full story: https://thehackernews.com/2026/05/chatgphish-vulnerability-turns-chatgpt.html

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

ChatGPhish exploits ChatGPT Markdown rendering to deliver phishing content from summarized web pages, increasing AI attack surfaces.

The Hacker News

⚠️ Two new #Android NFC relay malware families — DevilNFC and NFCMultiPay — are targeting banking customers in Europe and Latin America.

These tools, developed with possible AI assistance, steal card PINs. DevilNFC even locks victims in a fake interface using Kiosk Mode while relaying card data.

Local threat actors are now building their own tools instead of relying on Chinese MaaS platforms.

Read this story: https://thehackernews.com/2026/05/weekly-recap-linux-flaws-defender-0.html#:~:text=DevilNFC%20and%20NFCMultiPay%20Android%20NFC%20Relay%20Malware

⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos

Supply chain chaos, old bugs, smarter phishing, and botnets everywhere — here’s what broke the internet this week.

The Hacker News

⚠️ Enterprise AI risk is heavily concentrated among a small group of power users and personal accounts.

LayerX Security’s 2026 report shows the top 5% of employees generate 144+ conversations each. Nearly half of all enterprise AI conversations use personal identities. Over 6% contain sensitive data.

Most organizations lack full visibility.

Full report: https://thehackernews.com/2026/05/new-ai-usage-report-enterprise-ai-risk.html

New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power users"

More than 6% of enterprise AI conversations contain sensitive data, with DeepSeek reaching 12.63%, increasing governance risks.

The Hacker News

🚨 Lazarus deployed a new memory-only RAT against crypto and financial organizations.

https://thehackernews.com/2026/05/lazarus-deploys-remotepe-memory-only.html

The RemotePE malware executes entirely in memory with no filesystem artifacts, using DPAPI loaders, ETW patching, and Hell’s Gate techniques to evade detection and maintain stealthy access.

Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms

Lazarus deployed RemotePE against crypto firms using memory-only malware, enabling stealthy long-term financial intrusions.

The Hacker News

🚨 TrapDoor supply chain attack hits npm, PyPI, and Crates-io.

https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html

34 malicious packages across 384 versions were used to steal crypto wallets, SSH keys, cloud credentials, and developer secrets from crypto, DeFi, Solana, and AI environments.

The malware abused npm hooks, Python imports, and Rust build scripts for execution and persistence.

TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

TrapDoor spread 34 malicious packages across npm, PyPI, and Crates.io, stealing developer credentials and enabling persistence.

The Hacker News

Ghostwriter is phishing Ukraine’s government with Prometheus-themed malware lures.

https://thehackernews.com/2026/05/ghostwriter-targets-ukraine-government.html

Compromised-account emails deliver PDF links that lead to ZIP-based JavaScript malware: OYSTERFRESH → OYSTERBLUES/OYSTERSHUCK.

Cobalt Strike is assessed as the final payload.

Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware

Ghostwriter used Prometheus lures since spring 2026 to target Ukraine agencies, enabling malware delivery and data theft.

The Hacker News

🚨 Anthropic’s Claude Mythos Preview found 10,000+ severe software flaws in one month.

https://thehackernews.com/2026/05/claude-mythos-ai-finds-10000-high.html

The AI uncovered high- or critical-severity vulnerabilities across widely used software, including 1,726 confirmed flaws and 1,094 rated high or critical severity.

The findings have already led to 97 patches and 88 advisories.

One flaw, CVE-2026-5194 in WolfSSL, could allow certificate forgery.

Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software

Anthropic uncovered 10,000 vulnerabilities through Project Glasswing, driving urgent patching efforts and stronger cyber defenses.

The Hacker News
Eurojust coordinated investigation shuts down criminal VPN network

A joint investigation by the French and Dutch authorities, supported by Eurojust and Europol, has shut down a large-scale criminal virtual private network (VPN) service. The criminal service, known as First VPN, targeted cybercriminals by offering their services and promising a secure environment to carry out illegal activities such as hacking and ransomware attacks. Thanks to a joint action coordinated at Eurojust on the 19 and 20 May, authorities were able to dismantle critical infrastructure including 33 servers and conduct a search and interview of a suspect in Ukraine.

Eurojust