Microsoft discovers new lightweight backdoor that steals cryptocurrency
2026-06-22T08:51:53Z•9f787d3bc3797a6fbc042670d294e1043f09a20abcdba4d9aaf6e35bf8d73f2a
2fa-theftai-securitybackdoorbadhostcopilotcredential-breachcrypto-clipperdata-exfiltrationfedexfortinetlenovolinux-kernel-uaf','use-after-free'malwaremass-breachnato-contractornpm-backdoororaclepeopleSoftred-hatsearchleakstarlettesupply-chaintorusb-spreadzero-day
What happened
A roundup of June 2026 security news: Microsoft spotted a lightweight Crypto Clipper backdoor that spreads via USB and communicates over Tor; an Oracle PeopleSoft 0‑day is being exploited to steal large volumes of data; and a critical supply‑chain flaw (“BadHost”) in the Starlette package imperils millions of AI agents. Other high‑impact incidents include a massive credential spill affecting dozens of sensitive networks (Oracle, Lenovo, FedEx, a NATO contractor, Fortinet), dozens of Red Hat packages backdoored through its NPM channel, and a critical Copilot/SearchLeak issue that exposed 2FA. R
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- 9f787d3bc3797a6fbc042670d294e1043f09a20abcdba4d9aaf6e35bf8d73f2a
- Enrichment time
- 2026-06-22T08:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.