Company CEO flooded file share with smut, called for help after he deleted it
2026-05-28T07:23:57Z•89efc4d2ce7196007f5b8d2b7e37c5b16193eb3d41447db452482b11149c803e
ai-securitycode-signingcredential-exposuredrupalgithublinux-kernelnginxnpmransomwaresandbox-escapesecret-managementsocial-engineeringsupply-chainvs-code-extensionvulnerability-disclosure
What happened
This batch of security stories highlights a sharp uptick in supply‑chain and developer‑targeted attacks (poisoned npm packages, Megalodon repo poisonings, poisoned VS Code extensions, TanStack/GitHub incidents), widespread credential and secret exposure (open repos with keys/tokens, Google API keys usable after deletion), and fast‑moving exploit activity against disclosed vulnerabilities (NGINX Rift being probed/exploited days after disclosure, critical Drupal core fixes, Cisco Secure Workload admin flaw, a Linux kernel privilege bug). AI is a recurring theme — both as an attack/automation en‐
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 89efc4d2ce7196007f5b8d2b7e37c5b16193eb3d41447db452482b11149c803e
- Enrichment time
- 2026-05-28T07:23:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.