logo

GitHub, npm, and Drupal under attack: supply-chain threats and active CVE exploitation

ID: 5582ec39-4a97-5532-9df4-ced430816ffa

STIX ID: report--5582ec39-4a97-5532-9df4-ced430816ffa

Feed Name: defend.network – Daily Threat Briefings

Threat Score
90/100

Date Published: 2026-05-24

Date Updated: 2026-05-24

...
...

This briefing warns of high-severity, actively exploited incidents: a public GitHub leak exposed AWS GovCloud and CISA credentials, Drupal and LiteSpeed vulnerabilities are being exploited in the wild, and supply-chain compromises of Laravel-Lang and Packagist packages delivered credential-stealing malware; immediate actions include credential rotation, patching affected software, auditing dependencies and logs, and enforcing stronger GitHub controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.