Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

2026-07-10T01:24:11Za67a1683cf63cbc6934bc399f764895766049e06785653e2d0025fbccbe78e82
active-exploitationai-securitycredential-theftgithub-reconnaissanceiot/networkinglinux-kernelmalwaremicrosoft-defenderphishingprivilege-escalationransomwaresupply-chainvulnerabilitieswindows-security

What happened

A broad set of security stories: attackers are using dormant/ghost GitHub accounts and compromised tokens to map orgs and repositories; researchers disclosed multiple AI-related attack techniques (HalluSquatting, GhostApproval, Friendly Fire) that trick coding assistants or make them run malicious code; new destructive Windows backdoor GigaWiper and GodDamn ransomware (using the PoisonX driver) were analyzed; major vendors patched high-risk flaws — Microsoft fixed RoguePlanet (CVE-2026-50656) and Ubiquiti released fixes for critical UniFi bugs including CVE-2026-50746; a 15-year-old Linux root

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
a67a1683cf63cbc6934bc399f764895766049e06785653e2d0025fbccbe78e82
Enrichment time
2026-07-10T01:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.