KongTuke hackers now use Microsoft Teams for corporate breaches
2026-05-14T13:23:31Z•6af9e1b751c9fbe265dc60cb89901e17a2c975712c0352add610b8ad740e3bfc
Autopatch bugBSODBitLocker bypassBitLocker recoveryCVE-2026-46300Dell SupportAssistExim RCEFoxconnFragnasiaGreenPlasmaKongTukeLinux kernel privilege escalationMicrosoft TeamsMuddyWater (Seedworm) campaign targeting S Korea electronics','MNitrogen ransomwarePoCWest PharmaceuticalWindows 11YellowKeycritical vulnerabilitydata exfiltrationencryptioninitial access brokerpersistencesocial engineering
What happened
Multiple high-impact security stories: an initial access broker (KongTuke) is now using Microsoft Teams for fast social‑engineering attacks; Dell confirmed its SupportAssist software is causing BSODs; a new Linux kernel privilege‑escalation flaw (Fragnasia/Fragnesia) is tracked as CVE-2026-46300 and is being patched; a critical Exim mailer remote code execution vulnerability was disclosed; Windows BitLocker zero‑days (YellowKey and GreenPlasma) have PoCs released; Foxconn, West Pharmaceutical, and other organizations reported ransomware/data‑exfiltration incidents (Nitrogen, ShinyHunters); and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 6af9e1b751c9fbe265dc60cb89901e17a2c975712c0352add610b8ad740e3bfc
- Enrichment time
- 2026-05-14T13:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.