GitHub Confirms Breach of 3800 Internal Repos via Poisoned Extension
GitHub confirms TeamPCP exfiltrated 3800 internal repos via a poisoned VS Code extension. No customer data impact found yet as investigation continues.
Read more →Latest cybersecurity news, vulnerabilities, and threat intelligence
GitHub confirms TeamPCP exfiltrated 3800 internal repos via a poisoned VS Code extension. No customer data impact found yet as investigation continues.
Read more →
Microsoft issues emergency mitigation for YellowKey CVE-2026-45585, a BitLocker zero-day bypass requiring only a USB stick and physical access.
Read more →
Nx Console VS Code extension with 2.2M installs hijacked via stolen token. Credential stealer targeted developer secrets and AI assistant configs.
Read more →
Trellix discloses unauthorized access to its source code repository. No evidence of code exploitation found as forensic investigation continues.
Read more →
CVE-2026-31431 Copy Fail lets unprivileged users gain Linux root access with a 732-byte script. CISA mandates patching by May 15.
Read more →
CVE-2026-41940 in cPanel exploited as zero-day, deploying Sorry ransomware across 44,000+ servers. CISA mandates immediate patching.
Read more →
Chinese espionage operation SHADOW-EARTH-053 deploys ShadowPad across eight countries targeting governments, defense, and journalists.
Read more →
Apache patches CVE-2026-23918, a double-free flaw in mod_http2 enabling RCE with two HTTP/2 frames. Immediate upgrade to 2.4.67 urged.
Read more →
Anthropic accidentally leaked Claude Code source code via an npm source map file, exposing unreleased features and internal security mechanisms.
Read more →
BeyondTrust discloses CVE-2026-1731, a critical 9.9 CVSS pre-auth RCE flaw affecting Remote Support and Privileged Remote Access with 11,000 exposed instances.
Read more →