Researchers warn that fake automated commits pushed malicious GitHub Actions workflows into more than 5,500 repositories, aiming to exfiltrate credentials, CI secrets, keys, and tokens. Developers should audit recent workflow changes, revoke exposed tokens, and enable branch protection and signed commits to reduce tampering risk.
Source: SecurityWeek
TrapDoor Campaign Hits npm, PyPI, and Crates.io With Credential-Stealing Malware
A coordinated cross-ecosystem software supply chain attack dubbed “TrapDoor” spread more than 34 malicious packages across 384 versions to steal developer credentials and secrets. The campaign, active since May 22, 2026, underscores how quickly adversaries can pivot across multiple registries—teams should lock down developer tokens, enforce scoped credentials, and pin trusted package versions.
Source: The Hacker News
Laravel-Lang Packages Poisoned to Exfiltrate CI Secrets
Attackers published malicious tags to popular Laravel-Lang packages within a tight 15-minute window, introducing backdoors designed to siphon CI secrets. Organizations should scrutinize dependency updates during the impacted timeframe, rotate credentials used in builds, and implement SBOM-driven alerting for unexpected package/tag changes.
Source: SecurityWeek
Zero‑Day RCE in KnowledgeDeliver Exploited via ViewState Deserialization
Mandiant detailed active exploitation of KnowledgeDeliver LMS (CVE-2026-5426), where shared ASP.NET machine keys enabled unauthenticated RCE through crafted ViewState payloads. Post-exploitation involved in‑memory BLUEBEAM web shells and Cobalt Strike; defenders should immediately rotate unique machine keys per instance, restrict exposure, and hunt for anomalous w3wp.exe child processes and altered web assets.
Source: GoogleCloud TI
Chinese-Language PhaaS Evolves to Real‑Time MFA Bypass and Wallet Tokenization
Google Threat Intelligence highlights rapid growth of Chinese-language phishing-as-a-service platforms that intercept OTPs in real time via RCS/iMessage and monetize stolen cards by provisioning them into digital wallets. With AI-generated, localized phishing pages eroding signature-based defenses, enterprises should accelerate FIDO2/WebAuthn adoption and banks should tighten risk checks during wallet provisioning.
Source: GoogleCloud TI
Lazarus Deploys Memory‑Only RemotePE RAT Against Finance and Crypto Targets
Fox-IT reports North Korea-linked Lazarus using a multi-stage chain with DPAPILoader and RemotePELoader to deploy a cross‑platform, memory-only RemotePE RAT. The in‑memory tradecraft complicates detection; prioritize EDR with memory scanning, restrict application whitelisting on servers, and monitor for anomalous credential access indicative of DPAPI abuse.
Source: The Hacker News
CISA Adds Drupal Core Flaw to Known Exploited Vulnerabilities Catalog
U.S. CISA has added a Drupal Core vulnerability to its KEV list, signaling confirmed exploitation in the wild and elevating patch urgency. Drupal admins should apply the vendor’s highly critical fixes immediately, inventory exposed instances, and review logs for suspicious parameterized queries or unexpected admin actions.
Source: Security Affairs
You May Also Be Interested In...
Wireshark 4.6.6 patches a vulnerability and 11 bugsAnthropic to expand access to Mythos-class security models
DocketWise discloses data breach affecting 143,000 individuals