CISA credential leak raises alarms, and Capitol Hill demands answers
2026-05-20T14:51:43Z•3913104927744515694066879285ba77a9151438e47c4a232d90cec7068b594e
backdoorcanvas-breachci-cdcisacredential-leakexploitfox-tempestftcgithubidentity-governanceinterpolmicrosoftmini-shai-huludnpmoperation-ramzpatch-managementphishingransomwaresaas-securitysoftware-signing-abusesupply-chaintake-it-down-acttoken-theftverizon-dbir-2026vulnerabilities
What happened
A batch of CyberScoop stories highlights multiple high‑risk incidents and systemic gaps: a significant CISA credential leak published on GitHub — characterized by researchers as one of the worst seen and drawing Congressional scrutiny; Verizon’s DBIR showing exploited vulnerabilities became the leading breach entry point amid poor remediation; a renewed wave of supply‑chain malware (Mini Shai‑Hulud) compromising hundreds of npm packages, stealing publishing tokens, installing OS‑level backdoors and persisting in developer tools/CI; Microsoft’s disruption of the Fox Tempest service that abusedソ
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cyberscoop
- Record identifier
- 3913104927744515694066879285ba77a9151438e47c4a232d90cec7068b594e
- Enrichment time
- 2026-05-20T14:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.