Red Hat removes tainted packages after software pipeline compromise

2026-06-02T14:51:55Zb01fab2fa1903867539886ff2b1090a9b23ae1e1180a1459600107cddf21ca5a
GitHub compromiseNISTNSA leadershipNVDRed Hatcybersecurity policydata breachdoxinginspector generallaw enforcementopen-sourcepackage compromisesecurity researchsoftware supply chaintainted packagesvulnerability database backlogvulnerability managementzero-day disclosure

What happened

Multiple cybersecurity developments: Red Hat removed 32 tainted packages after a compromised GitHub account pushed malicious code to packages downloaded ~117,000 times per week, indicating a software supply‑chain compromise. Spanish authorities arrested a suspected hacker for large‑scale publication of sensitive personal data belonging to police, prosecutors and cyber officials. An inspector general report found NIST’s National Vulnerability Database backlog roughly doubled (from ~13k to >27k), undermining the NVD’s effectiveness and public trust. Separately, the NSA named new leaders for key,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
b01fab2fa1903867539886ff2b1090a9b23ae1e1180a1459600107cddf21ca5a
Enrichment time
2026-06-02T14:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Red Hat removes tainted packages after software pipeline compromise · Baitaphish