Grafana confirms GitHub token breach cybercrime group claims the attack

2026-05-19T02:51:42Z365bfe4cdd4fb74a6a344927944196e27c2fca7c380d18f5e84fbb6db31e5869
CISAShinyHuntersactive-exploitationcldflt.syscloud-misconfigurationdata-breache-skimmerexchangefunnel-buildergithub-token-compromiseidentity-exposureknown-exploited-vulnerabilitymalwareminiPlasmanginxpwn2owns3salesforcesource-code-leakwindows-privilege-escalationwordpress

What happened

Multiple high-impact incidents and active exploitations reported: a critical NGINX flaw (CVE-2026-42945) is being actively exploited; CISA added Microsoft Exchange CVE-2026-42897 to its Known Exploited Vulnerabilities catalog; a misconfigured Amazon S3 bucket exposed >1M passports/IDs from the Tabiq hotel platform; ShinyHunters claimed theft of >600k Salesforce and franchisee records from 7‑Eleven; Grafana confirmed a GitHub token compromise that exposed source code (no customer systems reported affected); a new Windows privilege-escalation zero-day dubbed “MiniPlasma” impacts cldflt.sys and復s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
365bfe4cdd4fb74a6a344927944196e27c2fca7c380d18f5e84fbb6db31e5869
Enrichment time
2026-05-19T02:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Grafana confirms GitHub token breach cybercrime group claims the attack · Baitaphish