Massive breach spills credentials for thousands of sensitive networks
2026-06-18T08:51:51Z•db5a9c04bd86c9f9669bf0f680b56fea3c2c607a2b03bba644c5122885e4418e
LLM-securityamd-tsmebadhostbotnetcopilotcredentialsdashlanedata-breachexfiltrationlinux-kernelmemory-encryptionnpm-backdoorpackage-malwarepeopleSoftprivilege-escalationsecure-bootsecure-boot-keysstarlettesupply-chaintwo-factor-authuse-after-freezero-day
What happened
A broad set of high-impact incidents and vulnerabilities reported by Ars Technica: a massive credential breach exposing access to thousands of sensitive networks (affecting Oracle, Lenovo, FedEx, a NATO contractor, Fortinet, etc.); a critical PeopleSoft zero-day used to steal gigabytes of data; a critical Copilot/LLM vulnerability (SearchLeak) that allowed attackers to exfiltrate 2FA codes; a widely-used Starlette/"BadHost" flaw endangering millions of AI agents; a Linux kernel use‑after‑free triggered by a single character enabling sandbox escape and root; and multiple supply‑chain/backdoor/"
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- db5a9c04bd86c9f9669bf0f680b56fea3c2c607a2b03bba644c5122885e4418e
- Enrichment time
- 2026-06-18T08:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.