Major Cyber Attacks in May 2026: Fake Invitations, Agent Tesla, BlobPhish, and More
ID: 0288f2a8-59b7-5539-8560-48682c3e50d2
STIX ID: report--0288f2a8-59b7-5539-8560-48682c3e50d2
Feed Name: ANY.RUN's Cybersecurity Blog
May 2026 featured a series of active phishing and fileless campaigns—fake invitations, Agent Tesla attacks, BlobPhish browser-based credential theft, OTP phishing, compromised B2B sites delivering in-memory payloads, and phishing-driven RMM deployment—that targeted finance, procurement, corporate email, and IT users; attackers used injected scripts, PowerShell execution, blob-generated pages, and OTP interception to steal credentials and gain remote access while evading traditional detection, prompting recommendations for sandbox-based analysis and cross-signal SOC detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
