Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach
2026-05-21T19:23:58Z•a7f7961c8e6ecc3b00bac07509d60120b6defadf9f792da9fc2088e5f77fc0ba
ai-sandboxcode-signingcredentials-leakdata-breachgithub-exfiltrationindustrial-control-systemskernelnginxnpmnpm-malwarepatchesprivilege-escalationransomwaresupply-chainvulnerability
What happened
A roundup of mid‑May 2026 security stories: multiple high‑impact vulnerabilities and urgent patches (Drupal critical fixes, 30+ Microsoft critical CVEs, Linux kernel privilege‑escalation and NGINX 'Rift' activity), several supply‑chain compromises and malware incidents (TanStack/npm poisonings, Shai‑Hulud worm, poisoned VS Code extension, open‑sourced worm code), widespread credential exposures (46k plaintext Myspace93 passwords, exposed GitHub repo with keys/tokens, agency repo left open), abuse of code‑signing to mask ransomware, and several operational/security failures (zombie user account
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- a7f7961c8e6ecc3b00bac07509d60120b6defadf9f792da9fc2088e5f77fc0ba
- Enrichment time
- 2026-05-21T19:23:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.