Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
2026-07-10T07:24:06Z•560d984f4f988117ac96061680ada23cd0a02255bcc75fa261fab58361c83b18
ai-agentsai-securitydisable-install-scriptsdisk-wipingdormant-accountsendpoint-evasioneviltokensfake-installersfake-ransomwarefriendly-fireghost-phishingghostapprovalgiga wipergithub-enumerationgoddamn-ransomwaregranular-access-tokenshallu squattinglinux-kernel-privilege-escalation','ghostlock'npm-12oauth-token-compromisepoisonx-driverresidential-proxysupply-chainsymlink-vulnerabilityubiquiti-unifi
What happened
The collection highlights multiple high-risk incidents and emerging attack techniques: attackers are enumerating corporate GitHub orgs using dormant or 'ghost' accounts and compromised OAuth tokens; Microsoft dissected GigaWiper, a modular destructive Windows backdoor that can wipe drives, overwrite the Windows volume, or run fake ransomware; npm v12 ships with install scripts disabled by default and deprecates granular access tokens to reduce supply-chain risk; a new GodDamn ransomware family uses the PoisonX kernel driver to disable endpoint defenses; multiple high-severity/critical flaws (e
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 560d984f4f988117ac96061680ada23cd0a02255bcc75fa261fab58361c83b18
- Enrichment time
- 2026-07-10T07:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.