Police seize “First VPN” service used in ransomware, data theft attacks

2026-05-21T13:23:32Zc932a3c0e72482bdba8d4c13109b3ae2651bf33ec2e03749d944214c4f5c1db4
Arch-LinuxBitLockerChromaDBFastAPIGitHubGrafanaMFA-bypassMicrosoft-DefenderPinTheftSonicWallTanStackVPN-takedownVSCode-extensionYellowKeybrute-forcedata-theftinfostealerlaw-enforcementnpmprivilege-escalationransomwaresupply-chaintoken-rotationunauthenticated-RCE','code-signing-abuse','Microsoft-Artifact-Sizero-day

What happened

A BleepingComputer digest covering multiple high-impact incidents: international law enforcement seized “First VPN,” a VPN service linked to ransomware and data-theft operations; Microsoft released patches and mitigations for actively exploited Defender zero-days and a BitLocker “YellowKey” issue; GitHub and multiple orgs were impacted by a TanStack npm supply-chain compromise and a malicious VS Code extension that exposed ~3,800 internal repos (also causing a Grafana breach after a missed token rotation); SonicWall Gen6 SSL‑VPN appliances had MFA bypasses due to incomplete patching; Ukrainian

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
c932a3c0e72482bdba8d4c13109b3ae2651bf33ec2e03749d944214c4f5c1db4
Enrichment time
2026-05-21T13:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Police seize “First VPN” service used in ransomware, data theft attacks · Baitaphish