A CISA contractor unintentionally left highly privileged AWS GovCloud credentials and internal deployment details in a public GitHub repository, forcing the agency into a scramble to invalidate leaked keys. Lawmakers in both chambers are demanding answers as the incident is being called one of the most serious federal data leaks in recent memory, underscoring the systemic risk of hardcoded secrets and mismanaged dev tooling in government environments.
Source: KrebsOnSecurity
Megalodon supply-chain attack poisons 5,500+ GitHub repos in hours
Researchers detailed a rapid campaign that injected malicious GitHub Actions workflows into thousands of repositories to exfiltrate CI secrets and cloud credentials. Tied to a broader wave of open-source compromises, the attack shows how forged bot identities and automated commits can quickly turn developer infrastructure into an exfiltration pipeline.
Source: Ars Technica
FBI warns of Kali365 PhaaS stealing Microsoft 365 OAuth tokens, bypassing MFA
Federal authorities issued an advisory on Kali365, a Telegram-based phishing service that captures legitimate OAuth tokens to access Microsoft 365 tenants without passwords or MFA prompts. The kit lowers the barrier for less-skilled actors by providing AI-generated lures, campaign automation, and dashboards, shifting enterprise risk from credentials to token and consent governance.
Source: RecordedFuture
Drupal Core SQL injection bug under active attack; added to CISA KEV
A critical SQL injection vulnerability in Drupal Core (CVE-2026-9082) is being widely probed and exploited shortly after disclosure. With the flaw now in CISA’s Known Exploited Vulnerabilities catalog, site owners should prioritize patching and review logs for suspicious database activity and unexpected admin actions.
Source: The Hacker News
Cisco patches CVSS 10.0 flaw in Secure Workload APIs
Cisco fixed a maximum-severity vulnerability affecting Secure Workload APIs that could enable critical abuse of the platform. Organizations running Secure Workload should apply updates immediately, audit API access, and verify the service is not unnecessarily exposed to the internet.
Source: SC Media
Update Chrome now: critical bugs enable remote code execution via web content
Google’s latest Chrome release patches multiple critical flaws that attackers can exploit through malicious websites to run arbitrary code. While the separate “Browser Fetch” issue remains unaddressed, enterprises should fast-track this update and enforce restarts to ensure protections are active.
Source: Malwarebytes Blog
Grafana codebase stolen after TanStack supply-chain fallout
Grafana disclosed that attackers accessed its GitHub repositories and stole code after a token compromised in the TanStack incident wasn’t rotated in time. The breach highlights how a single upstream credential compromise can cascade across ecosystems and why rigorous secret rotation and provenance checks are essential in developer pipelines.
Source: SecurityWeek
You May Also Be Interested In...
CISA opens public nomination form to add bugs to the KEV catalog
Deleted Google API keys can remain valid for up to 23 minutes
Global takedown dismantles “First VPN” used by ransomware crews