Legacy Windows Tool MSHTA Fuels Surge in Silent Malware Attacks
2026-05-19T13:24:09Z•5eae9d8201a59d6e16a41c10ea06b8f79cceeff83447d33504e73f2d3d986956
7-elevenCVE-2026-8153backdoorchro m a dbcredit-card-theftdata-leakdirtydecrypthealthcare-breachlinux-kernellocal-privilege-escalationlolbinmalwaremshtaopenclawoperation-ramzos-command-injectionphishingremote-code-executionsandbox-escapeshinyhuntersunauthenticated-rceuniversal-robots
What happened
A SecurityWeek feed highlights multiple active threats and vulnerabilities: attackers are increasingly abusing the legacy Windows MSHTA utility (LOLBIN) to deliver stealers, loaders and persistent malware via phishing and fake downloads; an unpatched ChromaDB flaw allows unauthenticated remote code execution and sensitive-data leakage; B1ack’s Stash released ~4.6M stolen credit cards for free; PoC was published for the DirtyDecrypt Linux kernel flaw enabling local privilege escalation to root; CVE-2026-8153 (Universal Robots PolyScope 5) is a critical OS command injection affecting industrial-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 5eae9d8201a59d6e16a41c10ea06b8f79cceeff83447d33504e73f2d3d986956
- Enrichment time
- 2026-05-19T13:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.