Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed

2026-06-10T20:51:42Zb94d0d11e9fc4907b6d165177c0e3854108d96f6926614c7bfb6488b035db448
AI securityBitLockerDashlaneLinux kernelMetaStarletteWindows 11backdoorbotnetchatbotcredential theftexploitmalwarenpmopen-sourcepassword managersupply chainuse-after-freevulnerabilityzero-day

What happened

Recent Ars Technica security coverage highlights a surge of high-impact vulnerabilities and supply-chain attacks: multiple zero-days (including a Windows 11 BitLocker bypass and Microsoft-patched 0-day), a severe Linux kernel use-after-free triggered by a single character, a critical remote-execution/backdoor flaw in widely used open-source packages (Starlette/"BadHost"), and widespread backdoored NPM/Red Hat packages. The feed also documents large-scale credential-stealing package incidents, stolen encrypted password vaults from Dashlane, exploitation of Meta AI support chatbot to hijack high

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
b94d0d11e9fc4907b6d165177c0e3854108d96f6926614c7bfb6488b035db448
Enrichment time
2026-06-10T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.