CISA Exposes Secrets, Credentials in 'Private' Repo

2026-05-19T20:51:44Zad78569cf16d2d4554e4d5a692631d1e9aa59c99a298a52a821995822b468f51
CISACVE-2026-42897ai-agentscisco-sd-wanclaw-chaincredentials-exposurecvss-10dirty-fragexchangefoxconngithubhugging-faceics-otmacos-malwarepcpjackransomwarerubygemsshai-huludshinyhuntersstealersupply-chaintrustfallworm

What happened

Mid-May 2026 Dark Reading roundup highlights multiple high-risk incidents and emerging threat trends: CISA accidentally exposed secrets and credentials in a public GitHub repo named “Private‑CISA”; Microsoft Exchange OWA zero‑day CVE-2026-42897 (XSS) is under active exploitation with no patch available; a CVSS 10.0 Cisco SD‑WAN vulnerability is being exploited in the wild; supply‑chain and self‑propagating malware activity is rising (Shai‑Hulud worm infecting npm/TanStack, malicious RubyGems, Hugging Face tokenizer tampering); new commodity malware and stealers target cloud and endpoints (SHub

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
ad78569cf16d2d4554e4d5a692631d1e9aa59c99a298a52a821995822b468f51
Enrichment time
2026-05-19T20:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.