Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt
2026-05-17T13:24:08Z•ca5d700fb78e6034df73409c83e840768cdd62c3685ac1603e81958d2c0e166c
active exploitationauthentication bypassbackdoorcheckout skimmingcisa kevcisco sd-wanclaw chaincode theftdead.lettereximextortionfragnesiagithub tokenkazuarkernel lpelinuxnginxopenclawp2p botnetpraisionai (auth bypass)remote code executionsupply chainturlawooCommercewordpress
What happened
A batch of high‑impact security incidents and actively exploited vulnerabilities was reported, including a Grafana GitHub token compromise that allowed codebase downloads and an extortion attempt (no customer data reported accessed); a critical Funnel Builder WordPress plugin flaw under active exploitation for WooCommerce checkout skimming; and multiple high‑severity product vulnerabilities being actively exploited or added to CISA’s KEV — notably Cisco Catalyst SD‑WAN authentication bypass (CVE‑2026‑20182, CVSS 10.0), Exim BDAT memory‑corruption/possible RCE (CVE‑2026‑45185, “Dead.Letter”, CV
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- ca5d700fb78e6034df73409c83e840768cdd62c3685ac1603e81958d2c0e166c
- Enrichment time
- 2026-05-17T13:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.