Police seize “First VPN” service used in ransomware, data theft attacks
2026-05-21T13:23:32Z•c932a3c0e72482bdba8d4c13109b3ae2651bf33ec2e03749d944214c4f5c1db4
Arch-LinuxBitLockerChromaDBFastAPIGitHubGrafanaMFA-bypassMicrosoft-DefenderPinTheftSonicWallTanStackVPN-takedownVSCode-extensionYellowKeybrute-forcedata-theftinfostealerlaw-enforcementnpmprivilege-escalationransomwaresupply-chaintoken-rotationunauthenticated-RCE','code-signing-abuse','Microsoft-Artifact-Sizero-day
What happened
A BleepingComputer digest covering multiple high-impact incidents: international law enforcement seized “First VPN,” a VPN service linked to ransomware and data-theft operations; Microsoft released patches and mitigations for actively exploited Defender zero-days and a BitLocker “YellowKey” issue; GitHub and multiple orgs were impacted by a TanStack npm supply-chain compromise and a malicious VS Code extension that exposed ~3,800 internal repos (also causing a Grafana breach after a missed token rotation); SonicWall Gen6 SSL‑VPN appliances had MFA bypasses due to incomplete patching; Ukrainian
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- c932a3c0e72482bdba8d4c13109b3ae2651bf33ec2e03749d944214c4f5c1db4
- Enrichment time
- 2026-05-21T13:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.