Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited

2026-05-24T08:51:49Z33a64ac8f1391e38f9301638a8cb6fed6e8f4ba73774cd9f12e34d1d4c8545d8
AI agentsAI-driven vulnerability discoveryCISA KEV nominationDDoS-for-hireGitHub breachGitLab 19.0Google API keysKimWolfMCPNGINXProton PassVS Code extensionWordPress pluginsactive exploitationbotnetcredential exposuresecrets managementsecurity toolingsupply-chainzero trustzero-day market

What happened

Weekly roundup: attackers compromised GitHub’s private repositories using a poisoned VS Code extension (supply‑chain/code‑repo compromise) while a critical NGINX vulnerability is being actively exploited. Researchers demonstrated AI-driven large‑scale vulnerability discovery (reporting a ~$20 per zero‑day pipeline for WordPress plugins), lowering the cost and increasing the speed of exploitable bugs. Operational risks include deleted Google API keys remaining valid for up to 23 minutes, increasing exposure from leaked keys, and ongoing large‑scale DDoS activity tied to the KimWolf botnet (alec

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
33a64ac8f1391e38f9301638a8cb6fed6e8f4ba73774cd9f12e34d1d4c8545d8
Enrichment time
2026-05-24T08:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.