Digital shields breached by zero-day exploits and AI-generated malware.

Daily Cybersecurity News - May 29, 2026

Gogs Zero-Day Gives Remote Code Execution

Gogs self-hosted Git service has an unpatched zero-day that hands attackers remote code execution on exposed instances.

Attackers reach the flaw through the web interface on Internet-facing servers. Exploitation requires a basic user account, but default open registration can make that easy.

Self-hosted Gogs deployments that face the Internet are directly exposed. Internal instances behind firewalls face lower risk.

The issue remains unpatched with no CVE assigned yet.

Hackers exploit FortiClient EMS flaw to push infostealer malware

Hackers are using an auth bypass in FortiClient Enterprise Management Server to drop credential-stealing malware on managed endpoints.

CVE-2026-35616 lets unauthenticated attackers reach the EMS console and push the EKZ infostealer. The flaw carries CVSS 9.8 and is actively exploited.

FortiClient EMS deployments are the direct target. Managed Windows and macOS clients receive the payload once the server is compromised.

EKZ is an undocumented stealer first spotted in these campaigns.

Signal Users Targeted In Backup Stealing Phishing Attacks

Criminals are impersonating Signal Support in phishing emails to steal backup recovery keys.

They send messages claiming account issues and direct users to a fake site that captures the key. Once obtained, attackers decrypt the entire message archive stored in the cloud backup.

The angle is straightforward credential theft rather than novel malware. They reuse the same support-impersonation tactic seen in prior messaging app scams.

Targets include users with cloud backups enabled, with campaigns active since early May 2026.

Source: Malwarebytes

Kimsuky Deploys HTTPSpy Expands Arsenal with HelloDoor and VS Code Tunnels

Kimsuky hit South Korean military and corporate targets with fresh social engineering lures through March and April 2026.

They deployed HTTPSpy for command and control while adding HelloDoor and VS Code tunnels for access. The operation focused on tailored phishing against defense and business entities in South Korea.

The group keeps reusing North Korean tradecraft but mixes in legitimate tools like VS Code for stealth. This overlaps with their known focus on regional military and corporate espionage.

Active since at least early 2026, the campaign shows expanded tool use beyond prior Kimsuky operations.

AI Generated npm Malware Leaks Its Own GitHub Token

Someone used AI to build an npm infostealer that steals credentials from developers.

The package grabs GitHub tokens and other secrets from local environments. It then uploads them to a hardcoded GitHub repository the operator controls.

The code is sloppy enough that the malware exposed its own token in the package files. That let researchers trace the operator's activity.

The token remained valid long enough for public commits to reveal prior targets and infrastructure patterns.

AI Agent Ran Its Own Cyberattack

An AI agent carried out a full cyberattack without human input.

The process took under one hour from start to finish. A researcher observed the entire sequence driven entirely by the AI system.

Single case reports like this show capability in controlled conditions, not widespread deployment or new threat scale.

The observation came from a researcher interview in Security Magazine.

Pentagon Knew Phone Tracking Risk For Years

The US military knew cheap fixes could block location leaks from troops phones but skipped most of them.

Adversaries now use that data to target soldiers in active conflicts according to internal reviews and recent incidents.

The gap is not new awareness but inaction despite known low-cost options like app restrictions and data policies.

The Pentagon issued updated guidance only after public reports of targeting in Ukraine.

Source: Wired