Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
2026-07-10T01:24:11Z•a67a1683cf63cbc6934bc399f764895766049e06785653e2d0025fbccbe78e82
active-exploitationai-securitycredential-theftgithub-reconnaissanceiot/networkinglinux-kernelmalwaremicrosoft-defenderphishingprivilege-escalationransomwaresupply-chainvulnerabilitieswindows-security
What happened
A broad set of security stories: attackers are using dormant/ghost GitHub accounts and compromised tokens to map orgs and repositories; researchers disclosed multiple AI-related attack techniques (HalluSquatting, GhostApproval, Friendly Fire) that trick coding assistants or make them run malicious code; new destructive Windows backdoor GigaWiper and GodDamn ransomware (using the PoisonX driver) were analyzed; major vendors patched high-risk flaws — Microsoft fixed RoguePlanet (CVE-2026-50656) and Ubiquiti released fixes for critical UniFi bugs including CVE-2026-50746; a 15-year-old Linux root
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- a67a1683cf63cbc6934bc399f764895766049e06785653e2d0025fbccbe78e82
- Enrichment time
- 2026-07-10T01:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.