Fake INTERPOL Ransomware, Claude Sandbox Flaw, Apple Hide My Email Bug Exposed
A wave of cyber incidents this week underscores how attackers continue to exploit trust in familiar brands and trusted infrastructure. Researchers at Bitdefender uncovered a phishing campaign impersonating INTERPOL that targets small businesses across Europe, Asia, the Middle East, and the United States. Victims receive emails claiming to contain evidence of suspicious company activity, with a password-protected archive hosted on Proton Drive that ultimately delivers a custom-built ransomware payload. The strain does not match any known ransomware family, suggesting a purpose-built tool designed to evade signature-based detection. Organizations can mitigate risk by verifying any law enforcement correspondence through official channels and by testing employee credentials with a password checker to ensure stolen credentials aren't already circulating.
In the AI security space, Armadin disclosed an attack chain affecting Anthropic's Claude Cowork sandbox on Windows that allows local attackers to escalate to root execution inside the virtual machine. The exploit leverages two unvalidated parameters in the VM service interface, enabling arbitrary command execution and bypass of network egress filtering. Anthropic declined to classify the issue as a security vulnerability following responsible disclosure on May 29, 2026, arguing it requires pre-existing local code execution. The findings nonetheless highlight how AI agent platforms expand the traditional attack surface well beyond model prompts and training data.
A separate privacy issue surfaced in Apple's Hide My Email service, where researcher Tyler Murphy demonstrated that the service's anonymized aliases can be unmasked to reveal users' real addresses. Murphy reported the flaw to Apple over a year ago and stated it remains unpatched, with 100% success rate in limited volunteer testing. While full technical details are being withheld, the disclosure raises concerns about the reliability of aliasing services marketed as privacy controls. Users relying on Hide My Email should monitor exposure using an email breach checker and run a broader privacy checkup to identify other leaked identifiers.
Rounding out the week, Rubrik Zero Labs identified BeepRAT, a customized build of the open-source DCRat framework distributed through a Chinese phone number management utility bundled in ZIP archives. The .NET payload, named HFY.exe, signals continued operational activity from China-aligned threat actors leveraging commodity RATs for targeted intrusions. Together, these stories reinforce a familiar pattern: ransomware operators abuse trust in institutions, AI platforms inherit sandbox weaknesses, and privacy features fail quietly until someone tests them.