Isometric network nodes highlighting critical software vulnerabilities and breaches.

Daily Cybersecurity News - May 20, 2026

Drupal Critical Update to Fix Bug with High Exploitation Risk

Drupal just announced a core security release that drops later today.

The bug sits in Drupal core itself. Attackers could develop exploits within hours of the disclosure.

Every site running current Drupal versions faces exposure.

Threat actors might develop exploits within hours of the update disclosure.

Exploit released for new PinTheft Arch Linux root escalation flaw

A new local root exploit landed for a recently patched flaw in Arch Linux.

PinTheft targets a flaw in the Linux kernel's RDS zerocopy send path. Local attackers use io_uring to overwrite the page cache, corrupting in-memory representations of privileged binaries without modifying the actual files on disk.

Only Arch Linux systems are affected. It requires a user account on the target machine.

Public PoC works on stock installs without extra setup.

Biometrics Diagnoses Bank Details Exposed In Healthcare Breach

NYC Health Hospitals got hit through a third party vendor. Attackers sat in their systems for months.

The compromise exposed biometrics, diagnoses, and bank details for at least 1.8 million people. NYC Health Hospitals disclosed the incident after discovering unauthorized access.

Third party vendor access keeps showing up as a weak spot. This one gave attackers long dwell time without tripping internal controls.

Attacker group and exact initial access vector remain unnamed in the disclosure.

Source: Malwarebytes

Grafana Breach Caused By Missed Token Rotation After TanStack Attack

Grafana Labs got hit through a leftover GitHub token that survived the TanStack npm supply chain attack last week.

Attackers used the token to gain access to the company's internal GitHub repositories, downloading private source code and operational data. Grafana confirmed that the codebase was not altered and no customer production systems or cloud instances were compromised.

Token rotation slipped because teams treated the TanStack incident as contained. One missed step turned a supply chain hit into direct access.

Grafana disclosed the breach four days after the TanStack compromise went public.

GitHub Confirms Breach Of 3800 Repos Via Malicious VSCode Extension

A malicious Visual Studio Code extension installed by one GitHub employee gave attackers access to roughly 3800 internal repositories.

Attackers pushed the bad extension through the official VS Code marketplace. It stole tokens and credentials that let them clone source code from those repos.

This one slipped past GitHub's own security reviews. The attacker turned a trusted developer tool into a supply chain vector that hit the company's own code.

GitHub says it revoked all affected tokens and no customer data was involved.

Stealer Spoofs Google Microsoft Apple Then Backdoors macOS

A new macOS stealer hides behind fake Google, Microsoft, and Apple installers distributed via compromised WeChat and Miro accounts.

The malware arrives through fake application bundles that run AppleScript to download and execute the payload. It targets developers and designers primarily in North America and Europe.

This marks a shift from earlier ClickFix social engineering tactics to native macOS execution. The actor shows comfort with both Windows and macOS tradecraft.

The SHub Reaper cluster has hit over 50 victims so far, with infrastructure reuse across multiple fake installer campaigns.

Source: Dark Reading

Over 320 NPM Packages Hit by Fresh Mini Shai Hulud Supply Chain Attack

A compromised maintainer account let attackers push malicious versions into more than 320 NPM packages under the antv namespace.

They hid a downloader inside the packages that fetches additional payloads from remote servers. The campaign targets developers who install these packages during normal workflows.

The angle here is reuse of an old supply chain trick with fresh infrastructure. Attackers are piggybacking on a trusted namespace rather than building new ones from scratch.

This attack is the second confirmed wave of the Mini Shai-Hulud campaign within twelve days, a broader operation that has been ongoing across the open-source ecosystem since September 2025.

Source: SecurityWeek