GitHub Internal Repos Exposed Through Poisoned VS Code Extension
GitHub says an employee device was compromised through a poisoned VS Code extension, exposing internal repositories and putting developer workstation trust under scrutiny.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
August 24, 2026
GitHub says an employee device was compromised through a poisoned VS Code extension, exposing internal repositories and putting developer workstation trust under scrutiny.
INTERPOL says Operation Ramz led to 201 arrests and the seizure of phishing and malware infrastructure across the MENA region.
SentinelOne says SHub Reaper uses fake macOS security and login prompts to move victims from a trusted-looking page into credential and data theft.
A public MiniPlasma proof-of-concept shows local privilege escalation to SYSTEM on fully patched Windows 11. The risk starts after local execution, so it matters…
Calif says researchers used Anthropic’s Mythos Preview to build a local macOS kernel exploit chain on an M5 Mac in five days. Details are…
ESET says FrostyNeighbor is using fake Ukrtelecom-themed PDF lures, Ukrainian geofencing, JavaScript PicassoLoader, and selective Cobalt Strike delivery against Ukrainian government targets.
Device code phishing uses a real Microsoft login page to authorize an attacker session. Learn 2026 lure red flags, response steps, and Microsoft 365…
Avada Builder patched two WordPress vulnerabilities that could expose server files or database data. Site owners should update to 3.15.3 and review affected access…
Attackers are abusing vulnerable FunnelKit/Funnel Builder installations to inject checkout skimmers into WooCommerce stores. Check External Scripts, unknown WebSocket loaders, and plugin versions.