GitHub Confirms Breach, 4K Internal Repos Stolen

2026-05-20T20:52:00Z2ca6b329560ae5d1ae22ddbc9660346aff744fdbffcb9ec489cde7f45c21c3a1
CVE-2026-42897TeamPCPcisco-sd-wancredentials-exposuredata-breachexchange-zero-daygithubmacOS-malwareopenclawot-securitypatchingroboticssecrets-managementshai-huludsoftware-supply-chainsource-code-leakvulnerability-management

What happened

GitHub confirmed a data breach in which threat actor TeamPCP claims to have stolen roughly 4,000 internal repositories — raising high risk of exposed source code, credentials, and other sensitive artifacts that could fuel supply-chain attacks. Related coverage in the feed highlights additional active threats and vulnerabilities: a Microsoft Exchange zero-day (CVE-2026-42897) under attack, a critical OT robot OS command-injection flaw, a CVSS 10.0 Cisco SD‑WAN bug being exploited in the wild, and multiple malware and agent-framework issues (macOS backdoors, OpenClaw/Claw Chain flaws, Shai‑Hulud

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
2ca6b329560ae5d1ae22ddbc9660346aff744fdbffcb9ec489cde7f45c21c3a1
Enrichment time
2026-05-20T20:52:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.