Cybercriminal Twins Caught After They Forgot to Turn Off Microsoft Teams Recording

2026-05-17T08:52:26Zf6c40104757fd5f875be6348c9bb623a2bef7fe780b2f9abf153dda177f4daec
5G‑dronesCVE-2026-31431CopyFailcanvascritical‑infrastructuredata‑exposurefoxconniphone‑unlockinglinuxmobile‑theftphishingprivacyransomwarerobot‑iotsatcomshinyhunterssupply-chainteams‑recordingvibe‑codedwhatsapp‑incognito

What happened

A roundup of mid‑May 2026 security incidents and trends: a critical Linux local‑privilege/root exploit dubbed CopyFail (CVE-2026-31431) allowing widespread takeover of PCs and servers; major ransomware and extortion activity (Instructure/Canvas/ShinyHunters and a Foxconn outage); supply‑chain attacks hitting OpenAI workers; massive data exposures from low‑code/vibe‑coded apps and leaked screenshots/spyware; mobile‑theft ecosystems that unlock iPhones and enable follow‑on phishing; privacy failures (recorded Microsoft Teams meetings, face recognition at Disneyland) and new AI/privacy features (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
wired_security
Record identifier
f6c40104757fd5f875be6348c9bb623a2bef7fe780b2f9abf153dda177f4daec
Enrichment time
2026-05-17T08:52:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.