logo

GitHub discloses breach of 3,800 internal code repositories.

ID: afac15c9-290f-5f3a-9ec7-c96ab16b655e

STIX ID: report--afac15c9-290f-5f3a-9ec7-c96ab16b655e

Feed Name: The CyberWire

Threat Score
75/100

Date Published: 2026-05-23

Date Updated: 2026-05-23

...
...

This report summarizes multiple security incidents: GitHub confirmed a supply-chain compromise via a Trojanized VS Code extension that reportedly affected ~3,800 internal repositories (TeamPCP claimed responsibility and is selling the data); a CISA contractor accidentally exposed AWS GovCloud credentials on a public GitHub repo; researchers published a macOS kernel privilege-escalation exploit for Apple M5 hardware (developed with AI assistance) with details withheld while Apple patches; and coordinated international law-enforcement actions disrupted cybercrime infrastructure (Operation Ramz, takedown of First VPN, and disruption of Fox Tempest).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.