GitHub says an employee device running a trojanized VS Code extension allowed threat actors to exfiltrate roughly 3,800 internal repositories. The company reports no evidence of customer data exposure and has rotated impacted secrets, but the incident underscores the growing risk from developer-tool supply chains. Organizations should review extension governance, pin versions, and audit credentials tied to Actions, CI, and cloud providers.
Source: Help Net Security
Fresh ‘Mini Shai-Hulud’ wave poisons 320+ npm packages in @antv namespace
A compromised maintainer account was used to publish malicious versions across more than 320 npm packages in Alibaba’s popular @antv ecosystem. The campaign highlights how attacker-controlled releases can bypass developer trust heuristics at scale. Teams should pin dependencies to known-good SHAs, enforce 2FA for maintainers, and add behavioral checks at install/build time.
Source: SecurityWeek
Drupal rushes fix for highly critical core flaw enabling RCE on PostgreSQL-backed sites
Drupal patched CVE-2026-9082, a database abstraction API bug that can allow remote code execution, privilege escalation, or data disclosure—particularly on PostgreSQL configurations. Site owners should update immediately and review logs for anomalous queries or admin actions, as high-profile CMS flaws are often exploited quickly.
Source: The Hacker News
Microsoft issues mitigations for ‘YellowKey’ BitLocker bypass (CVE-2026-45585)
Microsoft published guidance to mitigate a BitLocker security feature bypass that requires physical access but can expose encrypted data. Administrators should prevent the FsTx Auto Recovery Utility from launching in WinRE and enforce TPM+PIN for sensitive devices while awaiting a full patch.
Source: SecurityWeek
Verizon DBIR 2026: Exploit-driven intrusions now top stolen creds for initial access
For the first time in the report’s 19-year history, vulnerability exploitation overtook credential theft as the dominant entry point in breaches. The shift raises the stakes on patch velocity, exposure management, and compensating controls when immediate remediation isn’t possible.
Source: Help Net Security
China-linked Webworm APT expands into Europe with new backdoors
ESET observed Webworm (aka Space Pirates/UAT-8302) targeting government organizations across Belgium, Italy, Poland, Serbia, and Spain in 2025, deploying new backdoors as it broadened beyond Asia. The campaign reinforces the need for hardening of government and critical-sector endpoints and monitoring for atypical C2 patterns.
Source: Help Net Security
FortiGuard: P2PInfect abuses exposed Redis in GKE to enroll, lie dormant, and persist
FortiGuard Labs analyzed P2PInfect compromises in Google Kubernetes Engine, showing how internet-exposed Redis instances enable persistent botnet enrollment and dormant footholds that raise cloud runtime risk. Lock down Redis, remove public exposure, enforce network policies, and continuously scan nodes for unauthorized processes.
Source: Fortinet
You May Also Be Interested In...
Anthropic silently patches Claude code sandbox bypass
Discord migrates all users to end-to-end encryption by default
Microsoft takes down malware-signing service behind ransomware attacks