> ## Content Index
> Fetch the complete content index at: https://techlore.tech/llms.txt
> Use this file to discover other available public pages before exploring further.

# A Brutal Week for Microsoft Security, Signal Threatens to Leave Canada, And Bitwarden Quietly Shifts Policies
- URL: https://techlore.tech/a-brutal-week-for-microsoft-security-signal-threatens-to-leave-canada-and-bitwarden-quietly-shifts-policies/
- Published: 2026-05-20T21:47:59.000Z
- Updated: 2026-05-20T21:51:09.000Z
- Description: A brutal week of Microsoft vulnerabilities, an npm supply chain attack on 600+ packages, Signal vs Canada, Meta's AI age detection, and Bitwarden worries.
- Author: Henry Fisher
- Tags: Surveillance Report

📰

Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), other [podcast apps](https://pod.link/1507714387), or [RSS](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG)

[Click For All Sources](#action-item-✅)

---

## On Our Radar 🎯

**Microsoft's Worst Week Of 2026**

In one week: an actively exploited Exchange zero-day, the MiniPlasma exploit giving SYSTEM access on fully patched Windows, Pwn2Own exploits for Microsoft Exchange, SharePoint, and Windows 11, a report showing Microsoft's critical vulnerabilities literally doubled year-over-year, and an Azure vulnerability.

Now here's the thing: vulnerabilities happen on **every** operating system. Linux [just finished](https://techlore.tech/three-linux-exploits-palantir-20m-person-database-and-androids-good-bad-week-surveimay-13/) getting hammered the last few weeks. But just like I said then, what actually matters is the response, the history, the way a organization communicates, and the way they prioritize. Linux is fragmented because it's open and community-driven, and that's a known tradeoff for the ecosystem people love. But Microsoft is one centralized company that should know what they're doing. For context, MiniPlasma originated from a Google Project Zero report Microsoft sat on for **six years**. 

To me, it feels like we're watching the duct tape come off from years of neglecting the user experience. All of Microsoft's resources poured into AI features nobody asked (earning them the fitting name, *Microslop*) could have gone toward fixing updates, polishing the user experience, and taking security research seriously. I think Microsoft's pushing their limits on user trust when it's already at a low point.

**What you can do:** If you run Exchange, apply Microsoft's emergency mitigation for the zero-day ASAP. If you're on Windows, stay patched and watch for the MiniPlasma fix. And if you've been considering reducing your Windows footprint on personal devices or your home network, this is a good week to seriously consider experimenting with alternatives (like Linux!)

---

## Bits & Bytes 🤖

**\~ Story 1: Shai-Hulud Wave Compromises 600+ npm Packages**  
A new supply chain attack pushed 639 malicious package versions across 333 npm after hackers compromised a single developer's account. Targets included popular charting and visualization libraries and they were hunting for SSH credentials, database creds, Docker, and vaults.

**Our take:** Most listeners aren't running npm pipelines, but the underlying lesson applies to everyone: every piece of software you install, from anywhere, requires trusting that the published update was actually authorized by the developer. Never forget the amount of trust required when you install something on your system.

**\~ Story 2: Signal Threatens To Pull Out Of Canada**  
Canada's Bill C-22 is looking to force telecoms, ISPs, and messaging services to add surveillance capabilities for police and intelligence services. But Signal's VP said they'd rather leave the country than compromise on privacy. Apple and Meta have also publicly pushed back.

**Our take:** When a company like Meta is publicly opposing your encryption bill, the bill probably has a problem. Canadian politicians are calling this "encryption neutral," but mandating metadata collection on services that currently collect almost nothing is a massive expansion, and metadata can be just as revealing as the messages themselves! And this fight isn't just Canada's, bills that pass in one country set precedent for others. Watch this closely!

**\~ Story 3: Meta To Use AI Visual Analysis To Detect Underage Users**  
Meta is rolling out AI that analyzes user-uploaded photos to estimate age, then auto-restricts accounts it flags as underage.

**Our take:** This is what age verification legislation actually looks like in practice. More surveillance technology, more data collection, more identity verification, applied to everyone to try and solve a problem about kids. The actual issues, like addictive algorithms and exploitative design, keep getting routed around in favor of treating a human problem as a technology problem.

**\~ Story 4: Bitwarden Is Quietly Changing, And People Are Worried** Bitwarden's longtime CEO and CFO have both stepped down. The company removed "Always Free" from their prominent password manager messaging. Nothing has changed about the product yet, but it's hard to ignore.

**Our take:** Nothing concrete has happened, and we shouldn't rush to speculation. But these are exactly the kinds of signals worth tracking. Bitwarden's free tier has been the entry point for a huge number of people who get into password management for the first time! If that erodes, we lose a critical onramp into the whole category. 

---

## This Week on Techlore 📺

This week we had some fun content. I shared some thoughts on doomerism takes I saw on a viral YouTube video and how we can tackle the hopelessness:

[Why Even Smart People Think Privacy Is Dead“Privacy is dead, lol.” “You’re naive to still care.” If you’ve seen those comments under every privacy story, you’ve witnessed an engineered hopelessness (digital resignation) with a clear designer and a measurable cost. In this video, I break down who built it, why it’s a lie, and the simple, free![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-09c6fcab10182e9db54629ba2c825c15a4baf6b381c83dd339f0b4024b36e9a1.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/v4-2-61584174e26a3a101f41d9ddb99092403ae9459d529e07f9d0cd585d4f388b3c.png)](https://techlore.tech/why-even-smart-people-think-privacy-is-dead/)

We were also SUPER excited to have on Naomi Brockwell to discuss her Surveillance Accountability Act and how we all can fight for a better digital internet:

[Naomi Brockwell on Digital Privacy Legislation, the Third Party Doctrine, and Fighting the Surveillance State with The Surveillance Accountability ActTechlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260516-NAOMI-INTERVIEW-thumbnail-v1-1-34ea8beef33d746acfe331e2a322e063ee4f3c7401e6e4f2ad15c5afdc98aa00.jpg)](https://techlore.tech/naomi-brockwell-on-digital-privacy-legislation-the-third-party-doctrine-and-fighting-the-surveillance-state-with-the-surveillance-accountability-act-2/)

And finally, I put out a quick review taking a look at a 'dumb' screen from TRMNL for those who are curious about the focused device:

[TRMNL: A Screen That Doesn’t Want Your AttentionE-ink displays that promise ambient, distraction-free information sound great in theory. TRMNL delivers on the concept, with open firmware & open hardware, but the reality of living with it is more nuanced. Here are my thoughts! Watch on Techlore.TV for an ad-free, surveillance-free viewing experience![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/v8-1-2e4ba314b0d899f8149c17f78eeac0b9ba8884bba78205ded1e65c19d287f769.png)](https://techlore.tech/trmnl-a-screen-that-doesnt-want-your-attention/)

---

## Action Item ✅

Very simple, if you're using any Microsoft services: Get them up-to-date and keep following for changes in the upcoming weeks!

#### This Week's Sources

****Highlight: A Week Of Microsoft Vulnerabilities**

- <https://www.forbes.com/sites/daveywinder/2026/05/18/microsoft-exchange-active-0-day-exploit-enable-emergency-mitigation-now/>
- <https://www.bleepingcomputer.com/news/microsoft/new-windows-miniplasma-zero-day-exploit-gives-system-access-poc-released/>
- <https://www.bleepingcomputer.com/news/security/windows-11-and-microsoft-edge-hacked-on-first-day-of-pwn2own-berlin-2026/>
- <https://www.bleepingcomputer.com/news/security/hackers-earn-1-298-250-for-47-zero-days-at-pwn2own-berlin-2026/>
- <https://www.bleepingcomputer.com/news/security/critical-microsoft-vulnerabilities-doubled-from-exposure-to-escalation/>
- <https://www.bleepingcomputer.com/news/security/microsoft-rejects-critical-azure-vulnerability-report-no-cve-issued/>
- <https://www.bleepingcomputer.com/news/microsoft/microsoft-edge-to-stop-loading-cleartext-passwords-in-memory-on-startup/>

****Story 1: Shai-Hulud Wave Compromises 600 npm Packages**

- <https://www.bleepingcomputer.com/news/security/new-shai-hulud-malware-wave-compromises-600-npm-packages/>
- <https://techcrunch.com/2026/05/19/hackers-have-compromised-dozens-of-popular-open-source-packages-in-an-ongoing-supply-chain-attack/>

****Story 2: Signal Threatens To Pull Out Of Canada Over Lawful Access Bill**

- <https://archive.is/20260514002009/https://www.theglobeandmail.com/politics/article-signal-warns-it-would-pull-out-of-canada-if-made-to-comply-with-lawful/>

****Story 3: Meta To Use AI Visual Analysis To Detect Underage Users**

- <https://tuta.com/blog/meta-ai-analyses-pictures-detect-underage-users>

****Story 4: Bitwarden Is Quietly Changing And People Are Worried**

- <https://it.slashdot.org/story/26/05/15/1858235/bitwarden-scrubs-always-free-and-inclusion-values-from-its-website>

****The Defense Bulletin**

****Data Breaches**

- <https://techcrunch.com/2026/05/18/nyc-health-and-hospitals-says-hackers-stole-medical-data-and-fingerprints-during-breach-affecting-at-least-1-8-million-people/>
- <https://techcrunch.com/2026/05/15/a-hotel-check-in-system-left-a-million-passports-and-drivers-licenses-open-for-anyone-to-see/>
- <https://www.bleepingcomputer.com/news/security/7-eleven-confirms-data-breach-claimed-by-the-shinyhunters-gang/>
- <https://www.bleepingcomputer.com/news/security/west-pharmaceutical-says-hackers-stole-data-encrypted-systems/>
- <https://techcrunch.com/2026/05/18/open-source-tool-maker-grafana-labs-says-hackers-stole-its-code-refuses-to-pay-ransom/>
- <https://arstechnica.com/information-technology/2026/05/in-stunning-display-of-stupid-secret-cisa-credentials-found-in-public-github-repo/>

****Threats**

- <https://www.bleepingcomputer.com/news/security/hackers-exploit-auth-bypass-flaw-in-burst-statistics-wordpress-plugin/>
- <https://www.bleepingcomputer.com/news/security/funnel-builder-wordpress-plugin-bug-exploited-to-steal-credit-cards/>
- <https://www.bleepingcomputer.com/news/security/avada-builder-wordpress-plugin-flaws-allow-site-credential-theft/>
- <https://alternativeto.net/news/2026/5/wii-u-emulator-cemu-2-6-for-linux-was-compromised-by-a-russian-threat-actor-for-a-week/>
- <https://www.bleepingcomputer.com/news/security/18-year-old-nginx-vulnerability-allows-dos-potential-rce/>
- <https://www.wired.com/story/your-iphone-gets-stolen-then-the-hacking-begins/>
- <https://www.bleepingcomputer.com/news/security/interpol-operation-ramz-seizes-53-malware-phishing-servers/>
- <https://news.slashdot.org/story/26/05/18/1952255/fbi-wants-to-buy-nationwide-access-to-license-plate-readers>
- <https://apple.slashdot.org/story/26/05/16/1643203/anthropics-mythos-helped-build-a-working-macos-exploit-in-five-days>
- <https://www.bleepingcomputer.com/news/security/shub-macos-infostealer-variant-spoofs-apple-security-updates/>
- <https://mysk.blog/2026/05/19/cve-2026-28910/>

****FOSS+ Updates**

- <https://fsfe.org/news/2026/news-20260519-01.en.html>
- <https://blog.torproject.org/new-release-tor-browser-15014/>
- <https://blog.mozilla.org/en/firefox/more-control-firefox/>
- <https://blog.mozilla.org/en/firefox/ai-controls-firefox-mobile/>
- <https://blog.mozilla.org/en/firefox/shake-to-summarize-expansion/>
- <https://alternativeto.net/news/2026/5/discord-finally-rolls-out-end-to-end-encryption-by-default-for-all-voice-and-video-calls/>
- <https://linux.slashdot.org/story/26/05/19/0056247/microsoft-surprises-with-its-first-server-linux-distribution-azure-linux-40>
- <https://rockylinux.org/news/2026-05-14-introducing-security-repository>
- <https://alternativeto.net/news/2026/5/organic-maps-brings-transit-line-highlights-cleaner-bookmark-labels-and-more-legible-map/>