One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens
2026-06-03T13:24:14Z•28d02277fed81d13935bd2a4525875070d5bdc628750432a4d26e183b48e28bd
ApacheCISA KEVCloudflareDoSEnvoyGitHub.devHTTP/2 BombIISMiasmaNGINXNTLMv2 leakOAuth token theftOpenAI Codex token theftOracle WebLogicPAN-OS CVE-2026-0257VS CodeWP Maps ProWinRAR CVE-2025-8088Windows search URIactive exploitationcodexui-androidcredential theftnpmphishingsupply chain
What happened
A collection of active security incidents and disclosures: a one-click GitHub.dev/VS Code attack that can steal full GitHub OAuth tokens; an unpatched Windows search: URI issue that can leak NTLMv2 hashes; a newly disclosed HTTP/2 "Bomb" remote DoS impacting NGINX, Apache, IIS, Envoy and Cloudflare; multiple supply-chain campaigns (Miasma against Red Hat npm packages, codexui-android stealing OpenAI Codex tokens); active exploitation of several high-impact flaws (Oracle WebLogic CVE-2024-21182 added to KEV, PAN-OS GlobalProtect CVE-2026-0257, WP Maps Pro critical flaw creating admin accounts);
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 28d02277fed81d13935bd2a4525875070d5bdc628750432a4d26e183b48e28bd
- Enrichment time
- 2026-06-03T13:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.