Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited
2026-05-24T14:51:50Z•a23401a30f72fe4d81168553ed4e1a5a616ad72e725f334440707da9084cdd0f
ai-agentsai-driven-vuln-discoverycisa-kevcredential-exposureddos-botnetgithub-breachgitlab-19google-api-keyskimwolfnginxnx-consoleproton-passsecrets-managementsupply-chainteampcpvoice-sms-phishingvs-code-extensionwordpress-pluginszero-dayzero-trust
What happened
This weekly roundup highlights several high-impact security developments: a supply‑chain breach traced to a malicious VS Code extension (Nx Console, ~2.2M installs) attributed to threat group TeamPCP that led to GitHub and Grafana Labs intrusions; active exploitation of a critical NGINX vulnerability; and law‑enforcement action against the operator of the KimWolf DDoS botnet (over 1M infected devices). Other notable items: researchers demonstrated low‑cost AI‑driven discovery of WordPress plugin zero‑days (~$20 per exploit); deleted Google API keys can remain valid for up to 23 minutes risking
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- a23401a30f72fe4d81168553ed4e1a5a616ad72e725f334440707da9084cdd0f
- Enrichment time
- 2026-05-24T14:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.