logo

Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited

ID: ab9857bc-3bdb-5382-a072-30049e605233

STIX ID: report--ab9857bc-3bdb-5382-a072-30049e605233

Feed Name: Help Net Security

Threat Score
72/100

Date Published: 2026-05-24

Date Updated: 2026-05-24

Author: Help Net Security

...
...

This weekly roundup highlights numerous active cybersecurity issues: a supply-chain compromise via a malicious VS Code extension linked to TeamPCP affecting popular developer tooling, multiple critical CVEs being actively exploited (including NGINX and Microsoft Defender/BitLocker flaws), ongoing infostealer and malware campaigns, and broader trends such as shrinking vulnerability-to-exploit timelines and AI-related attack surface changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.