Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

2026-09-25T19:23:59Z•5c11a7feb6169dd2a4ca32242ef4f91f0f6fc49943485caca1480a43c5f1c730
CVE-2026-48842CVE-2026-5430CVE-2026-67279CVE-2026-86060CVE-2026-87902AndroidClickFixGitHub ActionsMicrosoft 365MikroTikPyPIRoundcubeTerraformWindowsWordPressactive exploitationcPanelcloud securitycontainer escapecredential theftcryptocurrency theftinformation stealermacOSmalwarenpmphishingsupply chain compromisevulnerabilityweb application securityzero-day

What happened

The feed highlights multiple active or high-impact cybersecurity threats, including exploitation of critical vulnerabilities in Roundcube, WordPress, WSO2, Adobe Commerce/Magento, MikroTik RouterOS, and cPanel; supply-chain compromises affecting GitHub Actions, npm, PyPI, and Terraform providers; and malware campaigns targeting macOS, Windows, Android, and cryptocurrency assets. Several incidents involve credential theft, ransomware-like code execution, cloud or container data exposure, account takeover, and ClickFix social engineering. The most urgent items are actively exploited pre-auth and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
5c11a7feb6169dd2a4ca32242ef4f91f0f6fc49943485caca1480a43c5f1c730
Enrichment time
2026-09-25T19:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.