Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
2026-09-26T07:23:59Z•ccb8bf5cfa39f7fea53f8dbc623312c30d829f5237564cd536f18a53a1b26d17
CVE-2026-48842CVE-2026-5430CVE-2026-67279CVE-2026-86060CVE-2026-87902AI-securityAdobe-CommerceAndroid-spywareCI/CD-securityCISA-KEVClickFixGitHub-ActionsMicrosoft-365MikroTikPyPIRoundcubeTerraformWSO2WordPressactive-exploitationcloud-securitycontainer-isolationcredential-theftinformation-stealermacOS-malwaremalwarenpmsoftware-supply-chainvulnerability-managementweb-application-security
What happened
The document aggregates cybersecurity news covering active exploitation of critical vulnerabilities, malware and spyware campaigns, supply-chain compromises, credential theft, cloud and CI/CD security issues, and AI-related security risks. Highest-impact items include actively exploited Roundcube, WordPress, WSO2, Adobe Commerce, and MikroTik flaws; compromise of GitHub Actions and package registries; Android and macOS malware; and large-scale account compromise and cryptocurrency theft.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- ccb8bf5cfa39f7fea53f8dbc623312c30d829f5237564cd536f18a53a1b26d17
- Enrichment time
- 2026-09-26T07:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.