Cybersecurity News | Daily Recap [09 May 2026]

Cybersecurity News | Daily Recap [09 May 2026]
Daily Recap, Fake OpenAI repositories on Hugging Face pushed an infostealer, while the TCLBANKER banking trojan spread through WhatsApp and Outlook alongside fake call-history apps that reportedly amassed 7.3 million Play Store downloads before stealing payments; PamDOORa also emerged as a new Linux backdoor. In other headlines, cPanel and WHM released fixes for three vulnerabilities, Braintrust urged API key rotation after a breach, NVIDIA confirmed a GeForce NOW breach affecting Armenian users, and ShinyHunters claimed a second attack against Instructure. #HuggingFace #OpenAI #Infostealer #TCLBANKER #WhatsApp #Outlook #PlayStore #PamDOORa #Linux #cPanel #WHM #Braintrust #NVIDIA #GeForceNOW #Armenian #ShinyHunters #Instructure #APIKey

Malware & Apps

  • A fake OpenAI repository on Hugging Face delivered an infostealer, while the TCLBANKER banking trojan spread via WhatsApp and Outlook worms, and fake call-history apps racked up 7.3 million Play Store downloads before stealing payments – OpenAI Repo, TCLBANKER, Fake Apps
  • A new PamDOORa Linux backdoor surfaced alongside other threat updates, including a train-hacker arrest and the latest CISA leadership race – PamDOORa

Vulnerabilities & Breaches

  • cPanel and WHM released fixes for 3 new vulnerabilities, urging immediate patching – cPanel Fixes
  • Braintrust disclosed a data breach and prompted API key rotation, while NVIDIA confirmed a GeForce NOW breach affecting Armenian users – Braintrust Breach, NVIDIA Breach
  • ShinyHunters claimed a second attack against Instructure, extending its campaign of high-profile compromises – ShinyHunters Attack

Critical Infrastructure & Government

  • Poland’s security agency reported ICS breaches at 5 water treatment plants, highlighting risks to essential services – Water Breaches
  • A Virginia man was found guilty of deleting 96 government databases, underscoring insider-damage concerns – Gov Databases
  • Sen. Schumer pressed the DHS for a plan to coordinate AI cyber efforts with state and local governments amid growing policy pressure – AI Coordination

Law Enforcement & Policy

  • The Kingdom Market administrator received a 16-year sentence as authorities continued to target dark-web marketplaces – Kingdom Market
  • GM agreed to pay over $12 million in a California privacy settlement tied to driver-data handling – GM Settlement

Cybersecurity News | Daily Recap – hendryadrian.com