Police boast of hacking VPN where criminals "believed themselves to be safe"
2026-05-24T08:51:46Z•67e9619b2d4e38cca0d69165e4141ea5defe910e591fa0151fcf037bb8362dea
TeamPCPbitlocker zero-daybug-bounty ai noisecanvas outagechromium exploit disclosurecisa credentials leakcopyfaildaemon-toolsdaemon-tools backdooreducation-platform attackelement-data malware package theft-of-credentials,subdomain hijfend-to-end encryptionexploit-publish-before-patchgithub secretsgpt-5.5kernel buglaw-enforcement hackinglinux vulnerabilitiesmythos aiopen-source poisoningsupply-chain attackubuntu outagevpn compromisewhatsapp encryption lawsuitwindows 11
What happened
Mid-May 2026 Ars Technica security roundup: law enforcement reportedly hacked a VPN service used by criminals; Texas AG sued Meta over alleged WhatsApp encryption shortcomings; an active supply-chain campaign (TeamPCP) is poisoning open-source projects and backdooring widely used apps (Daemon Tools); Google published exploit code for a long-reported Chromium bug; CISA left secret credentials in a public GitHub repo; a zero-day bypass defeats default Windows 11 BitLocker protections; multiple severe Linux vulnerabilities (including CopyFail) and other urgent kernel/infra bugs prompted rapid-pul
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- 67e9619b2d4e38cca0d69165e4141ea5defe910e591fa0151fcf037bb8362dea
- Enrichment time
- 2026-05-24T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.