logo

The Cyber Express Weekly Roundup: Supply Chain Attacks, Mobile Banking Malware, and Expanding Cloud Phishing Campaigns

ID: 0f6a110c-098c-51ac-a0e2-fb6c9b56d237

STIX ID: report--0f6a110c-098c-51ac-a0e2-fb6c9b56d237

Feed Name: The Cyber Express

Threat Score
85/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Ashish Khaitan

...
...

This weekly roundup highlights several high-impact incidents: researchers attribute an LA transit cyberattack to an Iranian-linked group (‘Ababil of Minab’); a critical flaw in the WP Maps Pro plugin allowed unauthenticated full-site takeovers affecting over 15,000 WordPress sites; the OverlayPhantom Android trojan is spreading via fake updates to target 180+ banking and crypto apps across 10 countries; the ‘Megalodon’ supply-chain campaign injected malicious GitHub Actions into some 5,500 repositories within six hours; and the FBI warns of Kali365 phishing-as-a-service that intercepts Microsoft 365 authentication tokens to bypass MFA — together underscoring an attacker focus on trusted platforms to maximize scale and impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.