THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Congress Presses CISA After Contractor Exposes GovCloud Keys on GitHub

A CISA contractor unintentionally left highly privileged AWS GovCloud credentials and internal deployment details in a public GitHub repository, forcing the agency into a scramble to invalidate leaked keys. Lawmakers in both chambers are demanding answers as the incident is being called one of the most serious federal data leaks in recent memory, underscoring the systemic risk of hardcoded secrets and mismanaged dev tooling in government environments.

Source: KrebsOnSecurity


Megalodon supply-chain attack poisons 5,500+ GitHub repos in hours

Researchers detailed a rapid campaign that injected malicious GitHub Actions workflows into thousands of repositories to exfiltrate CI secrets and cloud credentials. Tied to a broader wave of open-source compromises, the attack shows how forged bot identities and automated commits can quickly turn developer infrastructure into an exfiltration pipeline.

Source: Ars Technica


FBI warns of Kali365 PhaaS stealing Microsoft 365 OAuth tokens, bypassing MFA

Federal authorities issued an advisory on Kali365, a Telegram-based phishing service that captures legitimate OAuth tokens to access Microsoft 365 tenants without passwords or MFA prompts. The kit lowers the barrier for less-skilled actors by providing AI-generated lures, campaign automation, and dashboards, shifting enterprise risk from credentials to token and consent governance.

Source: RecordedFuture


Drupal Core SQL injection bug under active attack; added to CISA KEV

A critical SQL injection vulnerability in Drupal Core (CVE-2026-9082) is being widely probed and exploited shortly after disclosure. With the flaw now in CISA’s Known Exploited Vulnerabilities catalog, site owners should prioritize patching and review logs for suspicious database activity and unexpected admin actions.

Source: The Hacker News


Cisco patches CVSS 10.0 flaw in Secure Workload APIs

Cisco fixed a maximum-severity vulnerability affecting Secure Workload APIs that could enable critical abuse of the platform. Organizations running Secure Workload should apply updates immediately, audit API access, and verify the service is not unnecessarily exposed to the internet.

Source: SC Media


Update Chrome now: critical bugs enable remote code execution via web content

Google’s latest Chrome release patches multiple critical flaws that attackers can exploit through malicious websites to run arbitrary code. While the separate “Browser Fetch” issue remains unaddressed, enterprises should fast-track this update and enforce restarts to ensure protections are active.

Source: Malwarebytes Blog


Grafana codebase stolen after TanStack supply-chain fallout

Grafana disclosed that attackers accessed its GitHub repositories and stole code after a token compromised in the TanStack incident wasn’t rotated in time. The breach highlights how a single upstream credential compromise can cascade across ecosystems and why rigorous secret rotation and provenance checks are essential in developer pipelines.

Source: SecurityWeek


You May Also Be Interested In...

CISA opens public nomination form to add bugs to the KEV catalog

Deleted Google API keys can remain valid for up to 23 minutes

Global takedown dismantles “First VPN” used by ransomware crews

Cybersecurity — May 23, 2026 | Briefing24