'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
2026-06-23T20:51:44Z•8210a0dbc936e730fd7261bb75edf43a964f9c732b86b407e3dd85a5f31eb6ad
ai-data-exfiltrationclipboard-hijackercopilotcordycepscredential-harvestingcrypto-frauddeveloper-workflowdifydifytapfortibleedfortigatefortinetghost-sender','http2-dos','ransomware','inc-ransomware','sprys ngithub-token-leakivantikluemalicious-pull-requestmicrosoft-exchangeoracle-zero-dayprompt-injectionsalesforcesim-swapsocgholishsupply-chaintraffic-distribution-system
What happened
This DarkReading roundup highlights a surge in high-impact attacks and systemic weaknesses: malicious developer-supply-chain tactics (malicious PRs labeled 'Cordyceps'), widespread credential-harvesting campaigns against Fortinet/FortiGate devices (FortiBleed), rapid exploitation of multiple high‑severity flaws (Ivanti, an Oracle zero‑day, active Microsoft Exchange spoofing), and new AI-related data-exfiltration issues (DifyTap, Copilot SearchLeak). Other notable themes include traffic-distribution systems (SocGholish) enabling initial access, targeted app compromises leaking Salesforce data (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 8210a0dbc936e730fd7261bb75edf43a964f9c732b86b407e3dd85a5f31eb6ad
- Enrichment time
- 2026-06-23T20:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.