Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt

2026-05-17T13:24:08Zca5d700fb78e6034df73409c83e840768cdd62c3685ac1603e81958d2c0e166c
active exploitationauthentication bypassbackdoorcheckout skimmingcisa kevcisco sd-wanclaw chaincode theftdead.lettereximextortionfragnesiagithub tokenkazuarkernel lpelinuxnginxopenclawp2p botnetpraisionai (auth bypass)remote code executionsupply chainturlawooCommercewordpress

What happened

A batch of high‑impact security incidents and actively exploited vulnerabilities was reported, including a Grafana GitHub token compromise that allowed codebase downloads and an extortion attempt (no customer data reported accessed); a critical Funnel Builder WordPress plugin flaw under active exploitation for WooCommerce checkout skimming; and multiple high‑severity product vulnerabilities being actively exploited or added to CISA’s KEV — notably Cisco Catalyst SD‑WAN authentication bypass (CVE‑2026‑20182, CVSS 10.0), Exim BDAT memory‑corruption/possible RCE (CVE‑2026‑45185, “Dead.Letter”, CV

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ca5d700fb78e6034df73409c83e840768cdd62c3685ac1603e81958d2c0e166c
Enrichment time
2026-05-17T13:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt · Baitaphish