Microsoft discovers new lightweight backdoor that steals cryptocurrency

2026-06-20T08:51:52Za9aae4fbcb92ba1e10c422d9688c6a0edbf34be6fe79811dadb50fa234891c21
2fa-theftamd-tsmebackdoorbadhostbeats-studio-budsbotnetcopilotcredential-theftcrypto-clipperdata-breacheavesdroppinglinux-kernelmalwarenpm-backdooropen-source-vulnerabilitypeopleSoftred-hatresidential-proxysecure-bootstarlettesupply-chain-compromisetorusb-propagationuse-after-freezero-day

What happened

A cluster of high-impact security stories: Microsoft uncovered a lightweight Crypto Clipper backdoor that self-propagates over USB and communicates via Tor to steal cryptocurrency; a massive breach leaked credentials for thousands of sensitive networks (including Oracle, Lenovo, FedEx, a NATO contractor, and Fortinet); and a PeopleSoft zero-day is being exploited to exfiltrate gigabytes of data. Other major items include a critical vulnerability in the Starlette package ("BadHost") putting millions of AI agents at risk, a Linux kernel use‑after‑free triggered by a single character enabling SAN

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
a9aae4fbcb92ba1e10c422d9688c6a0edbf34be6fe79811dadb50fa234891c21
Enrichment time
2026-06-20T08:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Microsoft discovers new lightweight backdoor that steals cryptocurrency · Baitaphish