A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets
2026-05-23T07:23:57Z•77457a126365f3b79fc94d0e4276ea80c2e24600fe6a0b2d193943671b97352d
ai-securityapi-keysciscocode-signingcredential-exposurecryptocurrency-theftdata-exfiltrationdrupalgithubincident-responselinux-kernelmalwarenginxnpmprivilege-escalationstealersupply-chainvscode-extensionvulnerability
What happened
A cluster of high-risk incidents and active exploitation dominated the feed: large-scale supply-chain poisonings (Megalodon, Shai‑Hulud) and poisoned npm/GitHub/VS Code extensions led to codebase compromises and malware spread; multiple Linux kernel privilege escalation flaws (including public exploit code) and an nginx 'Rift' flaw are being actively probed/exploited; a critically urgent Drupal core patch and a Cisco Secure Workload admin API bug risk tenant-crossing data/config access. Significant credential and secrets exposure events were reported (open GitHub repo from a US cyber‑defense‑f
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 77457a126365f3b79fc94d0e4276ea80c2e24600fe6a0b2d193943671b97352d
- Enrichment time
- 2026-05-23T07:23:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.