Ukraine identifies infostealer operator tied to 28,000 stolen accounts

2026-05-21T01:23:38Z0579b102e79ad346bbdd9af61ac0b48d153ca52c2223aa52e31184683a45fa37
arch-linuxartifact-signingbitlockerchromadbcritical-updatedrupalgithub-breachgrafanainfostealermalwaremalware-signingmfa-bypassmicrosoftmsaas (malware-signing-as-a-service)pintheftprivilege-escalationransomwarercesonicwalltanstacktoken-rotationvpnvscode-malicious-extensionyellowkeyzero-day

What happened

BleepingComputer roundup (19–20 May 2026) covering multiple high-impact security incidents: an 18-year-old in Ukraine tied to an infostealer operation stealing ~28,000 accounts; SonicWall Gen6 SSL‑VPN deployments where incomplete patching enabled credential brute‑force and MFA bypasses used in ransomware intrusions; a Grafana breach caused by a missed GitHub workflow token rotation after the TanStack npm supply‑chain attack; and a confirmed GitHub internal‑repo compromise via a malicious VS Code extension affecting ~3,800 repos. Also reported: a max‑severity ChromaDB/FastAPI RCE allowing unaut

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
0579b102e79ad346bbdd9af61ac0b48d153ca52c2223aa52e31184683a45fa37
Enrichment time
2026-05-21T01:23:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Ukraine identifies infostealer operator tied to 28,000 stolen accounts · Baitaphish