KongTuke hackers now use Microsoft Teams for corporate breaches

2026-05-14T13:23:31Z6af9e1b751c9fbe265dc60cb89901e17a2c975712c0352add610b8ad740e3bfc
Autopatch bugBSODBitLocker bypassBitLocker recoveryCVE-2026-46300Dell SupportAssistExim RCEFoxconnFragnasiaGreenPlasmaKongTukeLinux kernel privilege escalationMicrosoft TeamsMuddyWater (Seedworm) campaign targeting S Korea electronics','MNitrogen ransomwarePoCWest PharmaceuticalWindows 11YellowKeycritical vulnerabilitydata exfiltrationencryptioninitial access brokerpersistencesocial engineering

What happened

Multiple high-impact security stories: an initial access broker (KongTuke) is now using Microsoft Teams for fast social‑engineering attacks; Dell confirmed its SupportAssist software is causing BSODs; a new Linux kernel privilege‑escalation flaw (Fragnasia/Fragnesia) is tracked as CVE-2026-46300 and is being patched; a critical Exim mailer remote code execution vulnerability was disclosed; Windows BitLocker zero‑days (YellowKey and GreenPlasma) have PoCs released; Foxconn, West Pharmaceutical, and other organizations reported ransomware/data‑exfiltration incidents (Nitrogen, ShinyHunters); and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
6af9e1b751c9fbe265dc60cb89901e17a2c975712c0352add610b8ad740e3bfc
Enrichment time
2026-05-14T13:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.