Grafana confirms GitHub token breach cybercrime group claims the attack

2026-05-18T20:51:44Z4e243c998b10f260ec06fabfb004a789dbe9e158b6d560c584dcdc8a403c76b7
CVE-2026-41940CVE-2026-42897CVE-2026-42945Funnel BuilderGitHub token compromiseMicrosoft ExchangeMiniPlasmaNGINXPII exposurePwn2OwnS3ShinyHuntersWindows zero-dayWordPressactive exploitationcldflt.syscloud misconfigurationdata breache-skimmerextortionmalware newsletterpassport leakprivilege escalation

What happened

Multiple high-impact security incidents and active exploitations were reported: Grafana confirmed a GitHub token compromise that exposed source code (no customer systems or data reported affected) after an extortion group claimed theft; 7‑Eleven disclosed a breach after ShinyHunters claimed theft of >600k Salesforce records and franchisee PII; a misconfigured Amazon S3 bucket in the Tabiq hotel check-in system exposed over 1 million passports, IDs and selfie verification photos; researcher Chaotic Eclipse published a MiniPlasma Windows local privilege escalation zero-day (cldflt.sys) that can升

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
4e243c998b10f260ec06fabfb004a789dbe9e158b6d560c584dcdc8a403c76b7
Enrichment time
2026-05-18T20:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Grafana confirms GitHub token breach cybercrime group claims the attack · Baitaphish