CISA Exposes Secrets, Credentials in 'Private' Repo
2026-05-19T20:51:44Z•ad78569cf16d2d4554e4d5a692631d1e9aa59c99a298a52a821995822b468f51
CISACVE-2026-42897ai-agentscisco-sd-wanclaw-chaincredentials-exposurecvss-10dirty-fragexchangefoxconngithubhugging-faceics-otmacos-malwarepcpjackransomwarerubygemsshai-huludshinyhuntersstealersupply-chaintrustfallworm
What happened
Mid-May 2026 Dark Reading roundup highlights multiple high-risk incidents and emerging threat trends: CISA accidentally exposed secrets and credentials in a public GitHub repo named “Private‑CISA”; Microsoft Exchange OWA zero‑day CVE-2026-42897 (XSS) is under active exploitation with no patch available; a CVSS 10.0 Cisco SD‑WAN vulnerability is being exploited in the wild; supply‑chain and self‑propagating malware activity is rising (Shai‑Hulud worm infecting npm/TanStack, malicious RubyGems, Hugging Face tokenizer tampering); new commodity malware and stealers target cloud and endpoints (SHub
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- ad78569cf16d2d4554e4d5a692631d1e9aa59c99a298a52a821995822b468f51
- Enrichment time
- 2026-05-19T20:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.