Ukraine identifies infostealer operator tied to 28,000 stolen accounts
2026-05-21T01:23:38Z•0579b102e79ad346bbdd9af61ac0b48d153ca52c2223aa52e31184683a45fa37
arch-linuxartifact-signingbitlockerchromadbcritical-updatedrupalgithub-breachgrafanainfostealermalwaremalware-signingmfa-bypassmicrosoftmsaas (malware-signing-as-a-service)pintheftprivilege-escalationransomwarercesonicwalltanstacktoken-rotationvpnvscode-malicious-extensionyellowkeyzero-day
What happened
BleepingComputer roundup (19–20 May 2026) covering multiple high-impact security incidents: an 18-year-old in Ukraine tied to an infostealer operation stealing ~28,000 accounts; SonicWall Gen6 SSL‑VPN deployments where incomplete patching enabled credential brute‑force and MFA bypasses used in ransomware intrusions; a Grafana breach caused by a missed GitHub workflow token rotation after the TanStack npm supply‑chain attack; and a confirmed GitHub internal‑repo compromise via a malicious VS Code extension affecting ~3,800 repos. Also reported: a max‑severity ChromaDB/FastAPI RCE allowing unaut
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 0579b102e79ad346bbdd9af61ac0b48d153ca52c2223aa52e31184683a45fa37
- Enrichment time
- 2026-05-21T01:23:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.