VS Code zero-day lets hackers steal GitHub tokens in one click
2026-06-03T07:23:29Z•80924e3e8682b344aae65f0b5224a8f9ff90913625944566c8154c25205f1d05
Active Directory discoveryAndroid patchCISACVE-2026-8206ClickFixDashlaneDriveSurgeEDR evasionFakeUpdateGitHub tokensKirkiMiasmaOracle WebLogicVS CodeWeedHackWordPressaccount takeoveractive exploitationbrute-forcecredential theftmalwarenpm compromiseransomwaresupply-chain compromisezero-day
What happened
A BleepingComputer roundup reports multiple active and high-impact security incidents: a VS Code zero-day with exploit code that can steal GitHub authentication tokens via a malicious click; a critical privilege-escalation flaw in the Kirki WordPress plugin (CVE-2026-8206) being actively exploited to take over admin accounts; large-scale malware and supply-chain campaigns (WeedHack infecting >116k Minecraft systems, Red Hat npm package compromise distributing the Miasma credential stealer, and DriveSurge ClickFix/FakeUpdate distribution); and an AI-built ransomware toolkit that automates AD/ED
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 80924e3e8682b344aae65f0b5224a8f9ff90913625944566c8154c25205f1d05
- Enrichment time
- 2026-06-03T07:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.