Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited

2026-05-24T14:51:50Za23401a30f72fe4d81168553ed4e1a5a616ad72e725f334440707da9084cdd0f
ai-agentsai-driven-vuln-discoverycisa-kevcredential-exposureddos-botnetgithub-breachgitlab-19google-api-keyskimwolfnginxnx-consoleproton-passsecrets-managementsupply-chainteampcpvoice-sms-phishingvs-code-extensionwordpress-pluginszero-dayzero-trust

What happened

This weekly roundup highlights several high-impact security developments: a supply‑chain breach traced to a malicious VS Code extension (Nx Console, ~2.2M installs) attributed to threat group TeamPCP that led to GitHub and Grafana Labs intrusions; active exploitation of a critical NGINX vulnerability; and law‑enforcement action against the operator of the KimWolf DDoS botnet (over 1M infected devices). Other notable items: researchers demonstrated low‑cost AI‑driven discovery of WordPress plugin zero‑days (~$20 per exploit); deleted Google API keys can remain valid for up to 23 minutes risking

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
a23401a30f72fe4d81168553ed4e1a5a616ad72e725f334440707da9084cdd0f
Enrichment time
2026-05-24T14:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.