To gain root access at this company, all an intruder had to do was ask nicely

2026-05-14T07:24:00Z296749250c0cae865d3a171d9eb97486cd8b911456319697ec471da3b107b4e0
ai-securitycredential-theftdata-breachinsider-threatjenkins-compromiselinuxllm-riskmalwaremicrosoftnpmpatchingprivilege-escalationpublic-exploitransomwareroot-exploitsocial-engineeringsupply-chainsupply-chain-poisoningvishingweak-hasheswormzero-day

What happened

A roundup of mid‑May 2026 security news: a successful social‑engineering campaign let an intruder obtain root by manipulating IT staff; multiple publicly disclosed Linux kernel/userland flaws (CopyFail, Dirty Frag) with reliable root exploits and limited/no patches; active exploitation and widespread ransomware/data‑theft incidents (Foxconn, ShinyHunters, TeamPCP); a high‑volume Patch Tuesday from Microsoft (30 critical CVEs); a fast supply‑chain compromise of TanStack npm packages pushing credential‑theft and wiper payloads; malware authors open‑sourcing a worm (Shai‑Hulud); credential thefts

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
296749250c0cae865d3a171d9eb97486cd8b911456319697ec471da3b107b4e0
Enrichment time
2026-05-14T07:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.