Hundreds of Leaked GitHub App Keys Still Authenticate

2026-09-23T20:52:06Z•f509616383b6fc9b7e3d2abbff99b0f36e990d853f49e45ad2d35a9dc3e9fd73
AI-securityAndroidCisco-ISEGitHubOAuth-tokensWindowsWooCommerceWordPressactive-exploitationbotnetcloud-identitycredential-leakcritical-infrastructurecybersecurity-newsdata-breachdeepfakemalwarenetwork-segmentationnpmphishingransomwaresocial-engineeringsupply-chain-securitytrusted-publishingwebshell

What happened

A cybersecurity news feed covering active exploitation, credential and token exposure, ransomware, malware campaigns, supply-chain abuse, AI-enabled attacks, data breaches, phishing, and defensive guidance. Key items include leaked GitHub App keys still authenticating, active exploitation of a critical Cisco ISE flaw, WooCommerce exploitation to deploy PHP webshells, Android and Windows malware, ransomware targeting manufacturing and retail, and attacks abusing trusted publishing and cloud identity tokens.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
f509616383b6fc9b7e3d2abbff99b0f36e990d853f49e45ad2d35a9dc3e9fd73
Enrichment time
2026-09-23T20:52:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hundreds of Leaked GitHub App Keys Still Authenticate · Baitaphish