Grafana confirms GitHub token breach cybercrime group claims the attack
2026-05-19T02:51:42Z•365bfe4cdd4fb74a6a344927944196e27c2fca7c380d18f5e84fbb6db31e5869
CISAShinyHuntersactive-exploitationcldflt.syscloud-misconfigurationdata-breache-skimmerexchangefunnel-buildergithub-token-compromiseidentity-exposureknown-exploited-vulnerabilitymalwareminiPlasmanginxpwn2owns3salesforcesource-code-leakwindows-privilege-escalationwordpress
What happened
Multiple high-impact incidents and active exploitations reported: a critical NGINX flaw (CVE-2026-42945) is being actively exploited; CISA added Microsoft Exchange CVE-2026-42897 to its Known Exploited Vulnerabilities catalog; a misconfigured Amazon S3 bucket exposed >1M passports/IDs from the Tabiq hotel platform; ShinyHunters claimed theft of >600k Salesforce and franchisee records from 7‑Eleven; Grafana confirmed a GitHub token compromise that exposed source code (no customer systems reported affected); a new Windows privilege-escalation zero-day dubbed “MiniPlasma” impacts cldflt.sys and復s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 365bfe4cdd4fb74a6a344927944196e27c2fca7c380d18f5e84fbb6db31e5869
- Enrichment time
- 2026-05-19T02:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.