Zombie user account let hackers control the city’s water
2026-05-21T07:24:01Z•cb0317d24f89b0bfc10674239b5ed40e057e06acba387b64aae54fdba8a83803
ai-sandbox-vulnerabilityanthropic-mythoscookie-theftdouble-canvas-breachdrupal-critical-patchexposed-credentialsgithub-exfiltrationillegal-code-signinglinux-kernel-privilege-escalationmacos-stealermicrosoft-cvesnginx-riftno-public-cvenpmopenai-compromisepatch-tuesdaypoisoned-vscode-extensionprivileged-accountransomwareshai-huludsupply-chain-attacktanstackwater-utility-hackzombie-account
What happened
A run of high-impact incidents and trends across infrastructure, supply chains, and AI security dominated The Register’s recent reporting: an unchanged ‘zombie’ user account let attackers control a city water system; multiple supply-chain compromises (poisoned VS Code extensions, npm cache-poisoning and the Shai‑Hulud worm, TanStack incident) led to credential theft and repo code exfiltration; Microsoft disrupted an illegal code‑signing operation used by ransomware gangs; and several orgs — including a US cyber‑defense agency and Grafana — inadvertently exposed sensitive credentials or had Git
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- cb0317d24f89b0bfc10674239b5ed40e057e06acba387b64aae54fdba8a83803
- Enrichment time
- 2026-05-21T07:24:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.