Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack
2026-05-06T08:51:54Z•16b056e468dad4fb2e54e5c791a6acf9beb43b8d074653991eb8dc596778480a
aspnetbackdoorbitwardencheckmarxcopyfailcredential-theftcritical-infrastructure-attacks','subdomain-takeover','universitdaemon-toolselement-dataemergency-patchiran-linked-actorslinuxmicrosoftopen-source-compromiseopenclawpost-quantumpqcransomwareroot-privilegerouters-compromiserussiasupply-chaintotalrecallubuntu-outagewindows
What happened
A cluster of high-impact incidents across April–May 2026: a month-long supply‑chain compromise backdoored the widely used Daemon Tools disk app; an extremely severe Linux vulnerability dubbed “CopyFail” threatens multi-tenant servers, CI/CD pipelines, containers and Kubernetes; an Ubuntu infrastructure outage impeded coordination around a critical root‑privilege vulnerability; an npm package (element-data) with ~1M monthly downloads exfiltrated credentials; targeted supply‑chain activity singled out security firms (Checkmarx, Bitwarden); OpenClaw and a Windows 11 Recall side‑entrance tool show
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- 16b056e468dad4fb2e54e5c791a6acf9beb43b8d074653991eb8dc596778480a
- Enrichment time
- 2026-05-06T08:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.