Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

2026-07-10T07:24:06Z560d984f4f988117ac96061680ada23cd0a02255bcc75fa261fab58361c83b18
ai-agentsai-securitydisable-install-scriptsdisk-wipingdormant-accountsendpoint-evasioneviltokensfake-installersfake-ransomwarefriendly-fireghost-phishingghostapprovalgiga wipergithub-enumerationgoddamn-ransomwaregranular-access-tokenshallu squattinglinux-kernel-privilege-escalation','ghostlock'npm-12oauth-token-compromisepoisonx-driverresidential-proxysupply-chainsymlink-vulnerabilityubiquiti-unifi

What happened

The collection highlights multiple high-risk incidents and emerging attack techniques: attackers are enumerating corporate GitHub orgs using dormant or 'ghost' accounts and compromised OAuth tokens; Microsoft dissected GigaWiper, a modular destructive Windows backdoor that can wipe drives, overwrite the Windows volume, or run fake ransomware; npm v12 ships with install scripts disabled by default and deprecates granular access tokens to reduce supply-chain risk; a new GodDamn ransomware family uses the PoisonX kernel driver to disable endpoint defenses; multiple high-severity/critical flaws (e

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
560d984f4f988117ac96061680ada23cd0a02255bcc75fa261fab58361c83b18
Enrichment time
2026-07-10T07:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.