Shai-Hulud worm copycats emerge after source code leak
2026-05-19T08:51:43Z•d748797981b8de398e22f78d2b052b7241f984c0fcbf1bc42913b47c7e2b6cec
7-elevenactive-exploitationaws-s3-misconfigurationcldflt.syscve-2026-42945data-breache-skimmerfunnel-buildergithub-tokengrafanamalwareminiplasmanginxnpmpii-exposureprivilege-escalationpwn2ownshinyhunterssource-code-leaksupply-chaintoken-compromisewindows-zero-daywordpressworm
What happened
Feed of multiple high-impact incidents: the Shai-Hulud worm source code leak spawned fast copycat supply-chain attacks targeting NPM; Grafana confirmed a GitHub token compromise exposing source code; ShinyHunters claim theft of >600k Salesforce/franchisee records from 7‑Eleven; a misconfigured Amazon S3 bucket exposed >1M passports/IDs/selfies from Japanese hotel platform Tabiq. Significant vulnerabilities and active exploitation were reported: critical NGINX flaw CVE-2026-42945 is being actively exploited, a new Windows SYSTEM privilege-escalation zero-day (“MiniPlasma” affecting cldflt.sys)/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- d748797981b8de398e22f78d2b052b7241f984c0fcbf1bc42913b47c7e2b6cec
- Enrichment time
- 2026-05-19T08:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.