Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

2026-09-26T01:24:00Z•4133acb68c9c3aaf146dd585d3615f694dec31b6b5b77a00d4ac86a6057174f9
CVE-2026-48842CVE-2026-5430CVE-2026-67279CVE-2026-86060CVE-2026-87902AI securityAdobe CommerceAndroid spywareCISA KEVClickFixGitHub ActionsMicrosoft 365MikroTikNorth KoreaPyPIRoundcubeTerraformWSO2WordPressactive exploitationcPanelcloud securitycredential theftcryptocurrency theftmacOS malwaremalwarenpmsupply-chain compromisevulnerability

What happened

The feed reports a broad set of September 2026 cybersecurity incidents, led by actively exploited vulnerabilities and supply-chain compromises. High-impact items include pre-authentication SQL injection in Roundcube, critical WSO2 and Adobe Commerce flaws added to CISA KEV, rapid exploitation of WordPress RCE, passwordless MikroTik router takeover, cPanel privilege escalation to root, compromised GitHub Actions and package repositories, ClickFix malware campaigns, Android and macOS spyware, Microsoft 365 account compromise, and a cryptocurrency theft attributed to suspected North Korean actors

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
4133acb68c9c3aaf146dd585d3615f694dec31b6b5b77a00d4ac86a6057174f9
Enrichment time
2026-09-26T01:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.