America’s top cyber defense agency is under fire after a researcher found plaintext passwords, tokens, and other secrets left in a public GitHub repository for months. Lawmakers on Capitol Hill are pressing CISA for an explanation and remediation steps, underscoring how even security agencies can fall victim to basic secret-sprawl and poor repo hygiene. Organizations should revisit controls for secret scanning, repository access, and automated key rotation.
Source: CyberScoop
GitHub confirms breach of 3,800 internal repos via poisoned VS Code extension
GitHub said a threat actor accessed roughly 3,800 internal repositories after an employee installed a trojanized Visual Studio Code extension, a technique linked to the TeamPCP campaign. The company reports no evidence of customer data impact beyond its internal code, but the incident highlights escalating risks from supply chain abuse of developer tools and extensions.
Source: SecurityWeek
Ongoing “Mini Shai-Hulud” software supply chain attacks compromise popular open-source packages
Researchers are tracking a broad, ongoing campaign compromising dozens of open-source packages and developer ecosystems to steal credentials and plant backdoors. The Mini Shai-Hulud activity spans NPM and related software supply chains, demonstrating how one compromised maintainer or extension can fan out into mass developer exposure.
Source: TechCrunch
Microsoft disrupts Fox Tempest: malware-signing-as-a-service used by ransomware gangs
Microsoft unsealed a legal action and technical operation against “Fox Tempest,” a service that mass-produced trusted code signatures for criminals to slip malware past defenses. The platform allegedly helped multiple groups, including ransomware operators, by abusing legitimate signing channels and short-lived certificates—an attack vector defenders should explicitly monitor and policy-restrict.
Source: Microsoft Security Blog
Drupal issues highly critical core security update; exploits expected rapidly
Drupal maintainers warned that attackers could develop exploits within hours or days for a new highly critical core vulnerability, releasing emergency fixes across supported branches. Site owners should prioritize immediate patching, review WAF and IPS rules, and prepare rollback plans given the likelihood of automated exploitation.
Source: SecurityWeek
DirtyDecrypt Linux kernel LPE: PoC released for CVE-2026-31635
A proof-of-concept exploit is now public for a recently patched Linux kernel flaw that enables local privilege escalation to root. Although fixes landed in April, the release of working exploit code raises the urgency for enterprises to accelerate kernel updates, validate mitigation coverage, and monitor for suspicious post-exploitation behaviors.
Source: SecurityWeek
Huawei zero-day tied to 2025 nationwide telecom outage in Luxembourg
Investigators say a previously undisclosed Huawei router vulnerability triggered last year’s hours-long crash of Luxembourg’s landline, 4G/5G, and emergency services. While the flaw has not been publicly acknowledged, the episode underscores cascading risks from single-vendor dependencies in critical infrastructure and the need for diversified supply chains, rigorous third-party risk assessments, and rapid patch-to-production pipelines.
Source: Recorded Future News
You May Also Be Interested In... - Verizon DBIR 2026: Vulnerability exploitation overtakes credential theft as top breach vector - Discord enables end-to-end encryption for voice and video calls - New macOS infostealer ‘Reaper’ impersonates Apple, Microsoft, and Google