Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited
2026-05-24T08:51:49Z•33a64ac8f1391e38f9301638a8cb6fed6e8f4ba73774cd9f12e34d1d4c8545d8
AI agentsAI-driven vulnerability discoveryCISA KEV nominationDDoS-for-hireGitHub breachGitLab 19.0Google API keysKimWolfMCPNGINXProton PassVS Code extensionWordPress pluginsactive exploitationbotnetcredential exposuresecrets managementsecurity toolingsupply-chainzero trustzero-day market
What happened
Weekly roundup: attackers compromised GitHub’s private repositories using a poisoned VS Code extension (supply‑chain/code‑repo compromise) while a critical NGINX vulnerability is being actively exploited. Researchers demonstrated AI-driven large‑scale vulnerability discovery (reporting a ~$20 per zero‑day pipeline for WordPress plugins), lowering the cost and increasing the speed of exploitable bugs. Operational risks include deleted Google API keys remaining valid for up to 23 minutes, increasing exposure from leaked keys, and ongoing large‑scale DDoS activity tied to the KimWolf botnet (alec
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 33a64ac8f1391e38f9301638a8cb6fed6e8f4ba73774cd9f12e34d1d4c8545d8
- Enrichment time
- 2026-05-24T08:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.