Microsoft discovers new lightweight backdoor that steals cryptocurrency
2026-06-20T20:51:46Z•4b90d2f4d91cff6c9d74f6199dbea2e1df6d63917fde4fdfbe6e1e9926e4421b
2fa-theftamdbackdoorbeatsbydrebreachcopilotcredential-leakcrypto-clipperdata-thefteavesdropping-vulnkey-rotationlinux-kernelmalwarenpmoraclepeopleSoftred-hat-backdoor','starlette','badhost','open-source-vuln','botnsearchleaksecure-bootsupply-chaintortsmeusb-propagationuse-after-freezero-day
What happened
A collection of Ars Technica security stories (June 2026) covering multiple high-impact incidents: Microsoft spotted a lightweight Crypto Clipper backdoor that spreads via USB and talks over Tor; a PeopleSoft zero‑day is being exploited to steal gigabytes of data from hundreds of organizations; a massive breach leaked credentials tied to many sensitive networks (Oracle, Lenovo, FedEx, a NATO contractor, Fortinet); a critical Copilot/"SearchLeak" vulnerability enabled theft of 2FA codes; Apple patched a high‑severity eavesdropping flaw affecting Beats Studio Buds; a single‑character use‑after‑f
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- 4b90d2f4d91cff6c9d74f6199dbea2e1df6d63917fde4fdfbe6e1e9926e4421b
- Enrichment time
- 2026-06-20T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.