Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach

2026-05-21T19:23:58Za7f7961c8e6ecc3b00bac07509d60120b6defadf9f792da9fc2088e5f77fc0ba
ai-sandboxcode-signingcredentials-leakdata-breachgithub-exfiltrationindustrial-control-systemskernelnginxnpmnpm-malwarepatchesprivilege-escalationransomwaresupply-chainvulnerability

What happened

A roundup of mid‑May 2026 security stories: multiple high‑impact vulnerabilities and urgent patches (Drupal critical fixes, 30+ Microsoft critical CVEs, Linux kernel privilege‑escalation and NGINX 'Rift' activity), several supply‑chain compromises and malware incidents (TanStack/npm poisonings, Shai‑Hulud worm, poisoned VS Code extension, open‑sourced worm code), widespread credential exposures (46k plaintext Myspace93 passwords, exposed GitHub repo with keys/tokens, agency repo left open), abuse of code‑signing to mask ransomware, and several operational/security failures (zombie user account

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
a7f7961c8e6ecc3b00bac07509d60120b6defadf9f792da9fc2088e5f77fc0ba
Enrichment time
2026-05-21T19:23:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.