Cyber security developments for Saturday the 30th of May 2026 covering articles added to the BlueTeamSec community on infosec.pub. Today we have 11 articles to cover. All attribution is by the article authors. All article analysis is automated.
WithSecure are tracking GREYVIBE, a Russia-nexus espionage group that's been systematically using ChatGPT, Google Gemini, and other generative AI tools since August 2025 to speed up their attacks on Ukrainian military and government targets. They're using AI across the full attack lifecycle β phishing content, fake websites, CAPTCHA pages β essentially outsourcing the grunt work to language models.
A 39-year-old Albanian national known as 'Venom' has been arrested in Athens and extradited to France after selling VenomRAT malware at least 36 times between 2021 and 2025 through a malware-as-a-service operation. Worth noting this was a joint effort involving Australian authorities, the FBI, and Greek cybercrime units β shows cross-jurisdictional cooperation can still land these operators.
The NSA has released Zero Trust Implementation Guidelines β a phased framework covering discovery and implementation organised around the usual pillars of least privilege, continuous verification, and granular access. This is strategic guidance for organisations planning the transition rather than anything incident-driven.
A Romanian national, Catalin Dragomir, has been sentenced to 56 months for operating as an initial access broker β he gained unauthorised access to an Oregon state government network and others, then tried to sell that access with stolen personal data as proof of compromise. Total losses across victims exceeded a quarter of a million dollars.
Law firm Wiley Rein is facing a class action after Chinese government-affiliated hackers maintained access to Microsoft 365 email accounts for nearly 12 months β July 2024 to June 2025 β via phishing. The breach exposed sensitive client data including social security numbers and financial records, with victims not notified until March this year.
Dutch police and the NCSC have dismantled a botnet comprising at least 17 million infected devices globally β computers, routers, IoT kit β seizing 200 command-and-control servers hosted in the Netherlands. The infrastructure was being used for the usual buffet of attacks, fraud, spam, and DDoS operations.
Carnegie Mellon have disclosed nine critical vulnerabilities in Casdoor versions 2.362.0 and earlier β authentication bypass, account takeover, privilege escalation β stemming from broken SAML assertion validation, MFA bypass in social login flows, and poor token management. No patch available yet from the development team.
And another vulnerability disclosure, this one from Adversa AI β they've found 'SymJack', an architectural flaw in six major AI coding agents including Claude Code, Gemini CLI, and GitHub Copilot CLI. Attackers can use symlink redirection to bypass human approval prompts and achieve remote code execution, particularly nasty in CI/CD environments running in auto-approval mode.
Researchers have developed FROST, a browser-based side-channel attack that uses the Origin Private File System API to fingerprint user activity by measuring SSD latency contention. Works on Chrome, Firefox, and Safari across Linux and macOS, allowing malicious sites to determine which sites you visit and which applications you launch β no permissions needed. Can also exfiltrate data at nearly 900 bits per second.
Sonatype have uncovered a campaign of 176 malicious npm packages exploiting dependency confusion β attackers published packages with version 99.99.99 to supersede legitimate internal dependencies, then used post-install scripts to exfiltrate credentials, environment variables, and CI/CD secrets from developer systems and build pipelines.
And finally, Florian Roth has built a custom benchmark for evaluating large language models on their ability to triage THOR forensic scanner findings. It measures critical miss rate, threat capture rate, and false review load β basically testing whether an LLM can make high-stakes security decisions in SOC environments, which general-purpose benchmarks don't really cover. Useful if you're looking to deploy LLMs for alert triage.
That concludes today's briefing.