Carding site B1ack’s Stash dumps 4.6 Million stolen cards for free
2026-05-20T14:51:50Z•5f1cd252262ffd48286d5257c7a7f62ccec441553a07b4cc18a1e6f5ad81bbea
CVE-2026-31635cardingdata-breachdrupal-emergency-patchfox-tempestgithub-breachgrafana-token-breachhuawei-zero-dayinterpol-operationlinux-kernellocal-privilege-escalationmalware-signingmena-cybercrimenpm-wormpayment-card-theftshai-huludsignal-account-compromisesupply-chaintelecom-outagetrojanized-extension
What happened
Multiple high-impact cyber incidents reported: B1ack’s Stash released 4.6M stolen payment card records for free; a trojanized VS Code extension allegedly exfiltrated ~3,800 GitHub internal repositories (group TeamPCP claims responsibility); a Linux kernel local privilege escalation (DirtyDecrypt, CVE-2026-31635) has a public PoC; an alleged Huawei zero-day was blamed for Luxembourg’s 2025 nationwide telecom outage. Additional notable items: emergency Drupal security update, Microsoft disruption of the Fox Tempest malware-signing service, Poland moving officials off Signal after account attacks
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 5f1cd252262ffd48286d5257c7a7f62ccec441553a07b4cc18a1e6f5ad81bbea
- Enrichment time
- 2026-05-20T14:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.