Carding site B1ack’s Stash dumps 4.6 Million stolen cards for free

2026-05-20T14:51:50Z5f1cd252262ffd48286d5257c7a7f62ccec441553a07b4cc18a1e6f5ad81bbea
CVE-2026-31635cardingdata-breachdrupal-emergency-patchfox-tempestgithub-breachgrafana-token-breachhuawei-zero-dayinterpol-operationlinux-kernellocal-privilege-escalationmalware-signingmena-cybercrimenpm-wormpayment-card-theftshai-huludsignal-account-compromisesupply-chaintelecom-outagetrojanized-extension

What happened

Multiple high-impact cyber incidents reported: B1ack’s Stash released 4.6M stolen payment card records for free; a trojanized VS Code extension allegedly exfiltrated ~3,800 GitHub internal repositories (group TeamPCP claims responsibility); a Linux kernel local privilege escalation (DirtyDecrypt, CVE-2026-31635) has a public PoC; an alleged Huawei zero-day was blamed for Luxembourg’s 2025 nationwide telecom outage. Additional notable items: emergency Drupal security update, Microsoft disruption of the Fox Tempest malware-signing service, Poland moving officials off Signal after account attacks

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
5f1cd252262ffd48286d5257c7a7f62ccec441553a07b4cc18a1e6f5ad81bbea
Enrichment time
2026-05-20T14:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.