Microsoft discovers new lightweight backdoor that steals cryptocurrency

2026-06-22T08:51:53Z9f787d3bc3797a6fbc042670d294e1043f09a20abcdba4d9aaf6e35bf8d73f2a
2fa-theftai-securitybackdoorbadhostcopilotcredential-breachcrypto-clipperdata-exfiltrationfedexfortinetlenovolinux-kernel-uaf','use-after-free'malwaremass-breachnato-contractornpm-backdoororaclepeopleSoftred-hatsearchleakstarlettesupply-chaintorusb-spreadzero-day

What happened

A roundup of June 2026 security news: Microsoft spotted a lightweight Crypto Clipper backdoor that spreads via USB and communicates over Tor; an Oracle PeopleSoft 0‑day is being exploited to steal large volumes of data; and a critical supply‑chain flaw (“BadHost”) in the Starlette package imperils millions of AI agents. Other high‑impact incidents include a massive credential spill affecting dozens of sensitive networks (Oracle, Lenovo, FedEx, a NATO contractor, Fortinet), dozens of Red Hat packages backdoored through its NPM channel, and a critical Copilot/SearchLeak issue that exposed 2FA. R

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
9f787d3bc3797a6fbc042670d294e1043f09a20abcdba4d9aaf6e35bf8d73f2a
Enrichment time
2026-06-22T08:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.