Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack

2026-05-06T08:51:54Z16b056e468dad4fb2e54e5c791a6acf9beb43b8d074653991eb8dc596778480a
aspnetbackdoorbitwardencheckmarxcopyfailcredential-theftcritical-infrastructure-attacks','subdomain-takeover','universitdaemon-toolselement-dataemergency-patchiran-linked-actorslinuxmicrosoftopen-source-compromiseopenclawpost-quantumpqcransomwareroot-privilegerouters-compromiserussiasupply-chaintotalrecallubuntu-outagewindows

What happened

A cluster of high-impact incidents across April–May 2026: a month-long supply‑chain compromise backdoored the widely used Daemon Tools disk app; an extremely severe Linux vulnerability dubbed “CopyFail” threatens multi-tenant servers, CI/CD pipelines, containers and Kubernetes; an Ubuntu infrastructure outage impeded coordination around a critical root‑privilege vulnerability; an npm package (element-data) with ~1M monthly downloads exfiltrated credentials; targeted supply‑chain activity singled out security firms (Checkmarx, Bitwarden); OpenClaw and a Windows 11 Recall side‑entrance tool show

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
16b056e468dad4fb2e54e5c791a6acf9beb43b8d074653991eb8dc596778480a
Enrichment time
2026-05-06T08:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.