Red Hat removes tainted packages after software pipeline compromise
2026-06-02T14:51:55Z•b01fab2fa1903867539886ff2b1090a9b23ae1e1180a1459600107cddf21ca5a
GitHub compromiseNISTNSA leadershipNVDRed Hatcybersecurity policydata breachdoxinginspector generallaw enforcementopen-sourcepackage compromisesecurity researchsoftware supply chaintainted packagesvulnerability database backlogvulnerability managementzero-day disclosure
What happened
Multiple cybersecurity developments: Red Hat removed 32 tainted packages after a compromised GitHub account pushed malicious code to packages downloaded ~117,000 times per week, indicating a software supply‑chain compromise. Spanish authorities arrested a suspected hacker for large‑scale publication of sensitive personal data belonging to police, prosecutors and cyber officials. An inspector general report found NIST’s National Vulnerability Database backlog roughly doubled (from ~13k to >27k), undermining the NVD’s effectiveness and public trust. Separately, the NSA named new leaders for key,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- b01fab2fa1903867539886ff2b1090a9b23ae1e1180a1459600107cddf21ca5a
- Enrichment time
- 2026-06-02T14:51:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.