Police boast of hacking VPN where criminals "believed themselves to be safe"
2026-05-22T20:51:51Z•acc8a36306e8b2d49ae307eefbf1c2e3bbd4fd106ac2d18e568b2852179fd73f
AI-assisted vuln discovery (Mythos/GPT-5.5)BitwardenCISA credentials exposedCanvas outageCheckmarxChromium exploitCopyFailDaemon Tools backdoorGitHub leakLinux vulnerabilityMicrosoft ASP.NET emergency updateTeamPCPVPN compromiseWhatsApp lawsuitWindows 11 BitLocker bypassbug-bounty spamcredential theftcrypto scamelement-dataend-to-end encryptionexploit-code publicationlaw enforcementpost-quantum ransomwaresupply-chain attackzero-day
What happened
A cluster of high-impact security events and trends: law enforcement reportedly hacked a VPN service and arrested its operator; multiple large supply-chain attacks and backdoors (TeamPCP spree, Daemon Tools compromise, targeted hits on Checkmarx/Bitwarden, and a malicious npm package 'element-data') have exposed downstream users; sensitive credentials (including CISA secrets) were found in a public GitHub repo; Google published exploit code for a Chromium flaw before a patch; a zero-day fully defeating default Windows 11 BitLocker protections was disclosed; several severe Linux vulnerabilities
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- acc8a36306e8b2d49ae307eefbf1c2e3bbd4fd106ac2d18e568b2852179fd73f
- Enrichment time
- 2026-05-22T20:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.