logo

GitHub npm supply chain attacks, LiteSpeed RCE, CISA credentials exposed

ID: 49fe5348-40d8-5372-9500-08ce7e40a5d0

STIX ID: report--49fe5348-40d8-5372-9500-08ce7e40a5d0

Feed Name: defend.network – Daily Threat Briefings

Threat Score
90/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

...
...

**Executive Summary:** GitHub and multiple package ecosystems are facing coordinated supply-chain attacks and credential-stealing malware; a critical LiteSpeed cPanel RCE (CVE-2026-48172) and Ghost CMS SQL injection (CVE-2026-26980) are actively exploited, and a CISA contractor publicly exposed AWS GovCloud credentials—urgent patching, credential rotation, and repository/audit actions are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.