Webinar: The hidden bottlenecks in network incident response
2026-05-19T13:23:31Z•d203032acbfaa3147a3dcad1ece481d7a0a71be87ed8b7e5af5c04efcbe4011f
AppleScript spoofingDirtyDecryptGrafanaKB5089549Linux rxgkMicrosoft 365 account takeoverMiniPlasmaSHubShai-HuludTycoon2FAWindows Updatebackdoorbotnet','P2P' (note: normalized)device-code phishingexploitinfostealermacOSnpmpatch failuresphishingprivilege escalationsource-code theftstolen tokensupply-chainzero-day
What happened
Multiple high-impact security stories: a proof-of-concept for the Windows privilege-escalation zero-day “MiniPlasma” that yields SYSTEM on fully patched hosts has been released; a recently patched Linux local privilege escalation (DirtyDecrypt) in the rxgk module now has an exploit PoC; Microsoft confirmed install/patch failures for several Windows updates (including KB5089549 and January 2026 optional previews) affecting restricted networks and some Windows 11 systems; active malware and supply‑chain activity includes the leaked Shai‑Hulud infostealer being used to push malicious npm packages
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- d203032acbfaa3147a3dcad1ece481d7a0a71be87ed8b7e5af5c04efcbe4011f
- Enrichment time
- 2026-05-19T13:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.