Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
2026-09-25T19:23:59Z•5c11a7feb6169dd2a4ca32242ef4f91f0f6fc49943485caca1480a43c5f1c730
CVE-2026-48842CVE-2026-5430CVE-2026-67279CVE-2026-86060CVE-2026-87902AndroidClickFixGitHub ActionsMicrosoft 365MikroTikPyPIRoundcubeTerraformWindowsWordPressactive exploitationcPanelcloud securitycontainer escapecredential theftcryptocurrency theftinformation stealermacOSmalwarenpmphishingsupply chain compromisevulnerabilityweb application securityzero-day
What happened
The feed highlights multiple active or high-impact cybersecurity threats, including exploitation of critical vulnerabilities in Roundcube, WordPress, WSO2, Adobe Commerce/Magento, MikroTik RouterOS, and cPanel; supply-chain compromises affecting GitHub Actions, npm, PyPI, and Terraform providers; and malware campaigns targeting macOS, Windows, Android, and cryptocurrency assets. Several incidents involve credential theft, ransomware-like code execution, cloud or container data exposure, account takeover, and ClickFix social engineering. The most urgent items are actively exploited pre-auth and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 5c11a7feb6169dd2a4ca32242ef4f91f0f6fc49943485caca1480a43c5f1c730
- Enrichment time
- 2026-09-25T19:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.