Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

2026-09-26T07:23:59Z•ccb8bf5cfa39f7fea53f8dbc623312c30d829f5237564cd536f18a53a1b26d17
CVE-2026-48842CVE-2026-5430CVE-2026-67279CVE-2026-86060CVE-2026-87902AI-securityAdobe-CommerceAndroid-spywareCI/CD-securityCISA-KEVClickFixGitHub-ActionsMicrosoft-365MikroTikPyPIRoundcubeTerraformWSO2WordPressactive-exploitationcloud-securitycontainer-isolationcredential-theftinformation-stealermacOS-malwaremalwarenpmsoftware-supply-chainvulnerability-managementweb-application-security

What happened

The document aggregates cybersecurity news covering active exploitation of critical vulnerabilities, malware and spyware campaigns, supply-chain compromises, credential theft, cloud and CI/CD security issues, and AI-related security risks. Highest-impact items include actively exploited Roundcube, WordPress, WSO2, Adobe Commerce, and MikroTik flaws; compromise of GitHub Actions and package registries; Android and macOS malware; and large-scale account compromise and cryptocurrency theft.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ccb8bf5cfa39f7fea53f8dbc623312c30d829f5237564cd536f18a53a1b26d17
Enrichment time
2026-09-26T07:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.