Hundreds of Leaked GitHub App Keys Still Authenticate
2026-09-23T20:52:06Z•f509616383b6fc9b7e3d2abbff99b0f36e990d853f49e45ad2d35a9dc3e9fd73
AI-securityAndroidCisco-ISEGitHubOAuth-tokensWindowsWooCommerceWordPressactive-exploitationbotnetcloud-identitycredential-leakcritical-infrastructurecybersecurity-newsdata-breachdeepfakemalwarenetwork-segmentationnpmphishingransomwaresocial-engineeringsupply-chain-securitytrusted-publishingwebshell
What happened
A cybersecurity news feed covering active exploitation, credential and token exposure, ransomware, malware campaigns, supply-chain abuse, AI-enabled attacks, data breaches, phishing, and defensive guidance. Key items include leaked GitHub App keys still authenticating, active exploitation of a critical Cisco ISE flaw, WooCommerce exploitation to deploy PHP webshells, Android and Windows malware, ransomware targeting manufacturing and retail, and attacks abusing trusted publishing and cloud identity tokens.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- f509616383b6fc9b7e3d2abbff99b0f36e990d853f49e45ad2d35a9dc3e9fd73
- Enrichment time
- 2026-09-23T20:52:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.