PinTheft: Another Linux Privilege Escalation, Another Working Exploit, This Time Targeting Arch

2026-05-21T02:51:42Z8b463d17b6d142bd36f9658958308aeff5a18e0004624f58cdac93af14b3f734
Arch LinuxB1ack's StashBitLockerCVE-2026-31635CVE-2026-45585DirtyDecryptFox TempestGitHub breachHuawei zero-dayLPEMicrosoft takedownPinTheftRDS subsystemYellowKeycardingexfiltrationkernellinuxlocal privilege escalationmalware-signing-as-a-servicemitigationpayment card theftsupply chaintelecom outage (Luxembourg)trojanized VS Code extension

What happened

Multiple high-impact security stories: new Linux local privilege escalation (LPE) vulnerabilities are being actively exploited and weaponized—PinTheft (RDS subsystem, exploit available) and DirtyDecrypt (CVE-2026-31635, public PoC) —with Arch Linux users flagged at particular risk. Microsoft released mitigations (no patch) for the YellowKey BitLocker bypass (CVE-2026-45585). Significant operational incidents: a trojanized VS Code extension led to exfiltration of ~3,800 GitHub internal repositories; carding forum B1ack’s Stash dumped ~4.6M stolen payment card records for free; Microsoft dismant

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
8b463d17b6d142bd36f9658958308aeff5a18e0004624f58cdac93af14b3f734
Enrichment time
2026-05-21T02:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · PinTheft: Another Linux Privilege Escalation, Another Working Exploit, This Time Targeting Arch · Baitaphish