GitHub Internal Repository Compromise

GitHub detected and contained a compromise on May 18, 2026, involving an employee device infected by a poisoned third-party VS Code extension. The attacker exfiltrated approximately 3,800 GitHub-internal repositories containing proprietary tooling, documentation, and limited customer support excerpts. GitHub immediately isolated the endpoint, removed the malicious extension, rotated critical secrets prioritizing highest-impact credentials, and initiated comprehensive log analysis and infrastructure monitoring.

The company emphasizes there is no evidence of impact to customer-owned repositories, enterprise data, or credentials stored outside GitHub's internal systems. However, because some internal repos contain fragments of customer support interactions, GitHub has committed to notifying affected customers if further impact is confirmed. A fuller technical report will be published upon investigation completion.

Impact Assessment

  • Internal scope only: Exfiltration limited to GitHub-internal repositories; customer code, credentials, and production environments remain unaffected per current forensic analysis

  • Supply chain risk: Compromised internal tooling or documentation could indirectly inform future attacks against GitHub users if leveraged for targeted phishing or exploit development

  • Secret rotation completed: Critical credentials rotated within 24 hours, reducing risk of follow-on exploitation using stolen authentication material

  • Customer notification pending: Limited exposure of support interaction excerpts may trigger targeted notifications if PII or sensitive context is confirmed in exfiltrated data

  • Reputational signal: Incident underscores risks of third-party developer tooling and the importance of strict extension vetting, even for internal use

🤖 AI

Anthropic Releases Glasswing Project Initial Update on AI-Assisted Vulnerability Discovery: Early results show frontier models can identify novel software flaws in open-source projects when given structured testing prompts, though validation and remediation remain human-dependent bottlenecks. Link: https://www.anthropic.com/research/glasswing-initial-update

Cisco Talos Shares Lessons Learned from AI-Generated Incident Response Reporting: Pilot program using LLMs to draft threat intelligence summaries reduced analyst drafting time by 40%, but required strict human review to prevent hallucinated indicators or misattributed TTPs. Link: https://blogs.cisco.com/security/ai-generated-reporting-lessons-learned-from-talos-incident-response

UK AISI Explores Oversight Challenges as AI Systems Grow More Autonomous and Opaque: New blog post examines how model self-improvement, multi-agent coordination, and proprietary training data complicate traditional audit, testing, and accountability frameworks for high-risk deployments. Link: https://www.aisi.gov.uk/blog/will-it-become-harder-to-oversee-ai-systems

ArXiv Preprint Proposes Framework for Evaluating AI Model Robustness Against Adversarial Prompting: Researchers introduce standardized benchmarks for testing LLM resilience to jailbreaks, context poisoning, and output manipulation, aiming to inform procurement and deployment decisions for security-critical applications. Link: https://arxiv.org/abs/2605.18784

💻 Malware and Vulnerabilities

Chinese SMS Blaster Scammers Target Eurovision Attendees in Vienna with Fake Ticket and Accommodation Phishing: Threat actors deployed bulk SMS campaigns impersonating event organizers and travel services, using shortened URLs to harvest payment credentials and personal data from international visitors during the high-profile music competition. Link: https://commsrisk.com/chinese-sms-blaster-scammer-attacks-eurovision-in-vienna/

Google Research Details Web-Based Prompt Injection Attack Vectors Against AI-Powered Browser Agents: New analysis demonstrates how malicious web content can hijack LLM-driven browsing assistants to exfiltrate page content, execute unauthorized actions, or manipulate user decisions, urging developers to implement strict context isolation and user consent workflows. Link: https://blog.google/security/prompt-injections-web/

ESET Researchers Uncover Webworm Malware Using Novel Burrowing Techniques to Evade Detection: The Linux-targeted implant employs process injection, memory-resident payloads, and dynamic configuration loading to maintain persistence while avoiding filesystem-based scanning and behavioral analysis tools. Link: https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/

📈 Breaches and Incidents

GitHub Investigating Unauthorized Access to Internal Repositories Containing Proprietary Tooling and Documentation: The platform confirmed suspicious activity on a limited set of non-production systems, with no evidence of customer code or credential exposure; forensic review and credential rotation underway. Link: https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/

GitHub Internal Leak Raises Questions About Code Exposure Risks for Enterprise Users: Analysis of the incident underscores how compromised internal developer tools can indirectly impact downstream customers through supply chain dependencies, prompting calls for enhanced repository access auditing. Link: https://theravenfile.com/2026/05/20/github-leak-your-code-risk/

Wahlap Arcade Game Maker Suffers Data Leak via Misconfigured WeChat Mini-Program Database: Exposed records include player usernames, device identifiers, and in-app purchase histories for millions of users across Asia; company is notifying affected accounts and implementing access controls. Link: https://cybernews.com/security/wahlap-arcade-game-maker-data-leak-wechat/

CNMI Government Email Systems Disrupted by Ransomware-Adjacent Cyberattack: The Commonwealth of the Northern Mariana Islands reported extended outages to official communications and public service portals, with emergency operations continuing via manual workflows during forensic investigation. Link: https://dysruptionhub.com/cnmi-email-cyberattack/

Trump Mobile Website Reportedly Exposing Customer Personal Data via Unsecured API Endpoints: Security researchers identified endpoints returning names, phone numbers, and order details without authentication; site operators have not yet confirmed the vulnerability or timeline for remediation. Link: https://uk.pcmag.com/mobile-phones/165085/trump-mobile-site-reportedly-exposing-customers-private-data

Europol-Led Operation Dismantles Cybercriminal VPN Service Used by Ransomware Actors: "Operation Dark Tunnel" seized infrastructure for a bulletproof hosting provider that enabled threat actors to anonymize C2 traffic, launder payments, and evade takedowns across 12 jurisdictions. Link: https://www.europol.europa.eu/media-press/newsroom/news/cybercriminal-vpn-used-ransomware-actors-dismantled-in-global-crackdown

New Actors Deploy Shai Hulud Clones and TeamPCP Copycats in Ransomware Campaigns: Threat intelligence firms observe derivative variants of known ransomware families adopting similar encryption routines and extortion tactics, suggesting code sharing or recruitment among financially motivated groups. Link: https://www.ox.security/blog/new-actors-deploy-shai-hulud-clones-teampcp-copycats-are-here/

🚨 Threat Intel & Info Sharing

Pro-Kremlin Actors Launch Disinformation Campaign Targeting Armenia's Parliamentary Elections: Coordinated inauthentic behavior across social media platforms amplifies divisive narratives and fabricated news stories aimed at undermining electoral integrity, with infrastructure linked to prior Russian influence operations in the Caucasus region. Link: https://www.euronews.com/my-europe/2026/05/20/pro-kremlin-actors-launch-large-scale-disinformation-campaign-targeting-armenias-elections

CISA Enhances Known Exploited Vulnerabilities Catalog with New Nomination Form for Community Submissions: The updated process enables security researchers and vendors to formally propose CVEs for KEV inclusion, accelerating federal binding operational directive timelines and improving cross-sector vulnerability prioritization. Link: https://www.cisa.gov/news-events/news/cisa-enhances-known-exploited-vulnerabilities-catalog-include-new-nomination-form

SEO Poisoning Campaign Leverages Gemini and Claude Code Impersonation to Distribute Infostealer Malware: Threat actors optimize malicious websites to rank for AI coding assistant queries, serving trojanized "Claude Code" or "Gemini CLI" downloads that harvest credentials, crypto wallets, and browser sessions upon execution. Link: https://blog.eclecticiq.com/seo-poisoning-campaign-leverages-gemini-and-claude-code-impersonation-to-deliver-infostealer

Scammers Abuse Internal Microsoft Account to Send Phishing Spam at Scale: Attackers compromised a legitimate Microsoft service account to bypass email authentication checks, distributing fraudulent invoices and credential-harvesting links to thousands of recipients before detection and revocation. Link: https://techcrunch.com/2026/05/21/scammers-are-abusing-an-internal-microsoft-account-to-send-spam/

UK Government Publishes Cyber Security Sectoral Analysis 2026 Highlighting AI, Supply Chain, and Critical Infrastructure Risks: The annual report synthesizes threat intelligence from 150+ organizations, identifying accelerated AI-enabled attacks, third-party dependency vulnerabilities, and geopolitical cyber operations as top strategic concerns for national resilience. Link: https://www.gov.uk/government/publications/cyber-security-sectoral-analysis-2026/cyber-security-sectoral-analysis-2026

South Korean Regulators Recruit White-Hat Hackers to Test Financial Apps and Trading Systems: The Financial Services Commission launched a bug bounty initiative offering rewards up to ₩100M for critical vulnerabilities in banking, payment, and crypto platforms, aiming to strengthen pre-deployment security validation. Link: http://koreabizwire.com/korean-regulators-recruit-white-hackers-to-test-financial-apps-and-trading-systems/351083?ckattempt=3

Microsoft Disrupts Fox Tempest Cybercrime Service Responsible for $100M+ in Fraud Losses: Coordinated takedown with international partners dismantled infrastructure used to sell phishing kits, credential dumps, and money-mule recruitment tools, while seizing domains and freezing cryptocurrency wallets linked to the operation. Link: https://blogs.microsoft.com/on-the-issues/2026/05/19/disrupting-fox-tempest-a-cybercrime-service/

Indonesian Police Arrest 321 Foreign Nationals in Major Online Gambling and Cyber Fraud Crackdown: Operation targeted transnational syndicates using compromised infrastructure, fake identities, and money-laundering networks to operate illegal betting platforms and romance scams across Southeast Asia. Link: https://www.pbs.org/newshour/world/indonesian-police-arrest-321-foreigners-in-online-gambling-crackdown

Microsoft Warns of New Defender Zero-Days Exploited in Targeted Attacks: Two previously unknown vulnerabilities in Microsoft Defender allow privilege escalation and defense evasion; patches are available but active exploitation observed against high-value enterprise targets. Link: https://www.bleepingcomputer.com/news/security/microsoft-warns-of-new-defender-zero-days-exploited-in-attacks/

Cisco Security Advisory: Critical Flaw in Cloud Services Wire Allows Auth Bypass and Data Exfiltration: CVE-2026-20223 affects CSW deployments; attackers can bypass authentication to access sensitive configuration data and intercept traffic metadata—immediate patching or network isolation recommended. Link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy

Iranian Hackers Use Fake Job Recruitment Sites to Breach Defense and Aerospace Firms: APT actors impersonate HR departments at major contractors, luring employees with fraudulent job offers containing malicious attachments that deploy remote access tools for long-term espionage. Link: https://www.databreachtoday.co.uk/iranian-hackers-using-fake-job-sites-to-breach-defense-firms-a-31762

⚖️ Laws, Policies and Regulations

European Consumer Groups Urge Commission to Act Against Meta, TikTok, and Google Over Misleading Advertisements: Coalition filed formal complaints alleging platforms fail to clearly label sponsored content, enable deceptive influencer marketing, and insufficiently protect minors from manipulative ad targeting under the Digital Services Act. Link: https://www.consumentenbond.nl/nieuws/2026/europese-commissie-moet-ingrijpen-bij-meta-tiktok-en-google-om-misleidende-advertenties

Trump Administration Postpones Executive Order on AI Security Standards Amid Industry Pushback: The delayed directive, which would have mandated rigorous testing and reporting for frontier models, faces criticism over potential innovation constraints and compliance burdens on U.S. AI developers competing globally. Link: https://cyberscoop.com/trump-postpones-executive-order-focused-on-ai-security/

Bank of England, FCA, and HM Treasury Issue Joint Statement on Frontier AI Models and Cyber Resilience: UK financial regulators outline expectations for firms deploying high-capability AI, including model risk governance, third-party dependency assessments, and incident reporting for AI-driven operational failures. Link: https://www.bankofengland.co.uk/news/2026/may/boe-fca-and-hm-treasury-joint-statement-on-frontier-ai-models-and-cyber-resilience

European Commission Marks 10 Years of GDPR with Emphasis on Enforcement, Cross-Border Cooperation, and Emerging Tech Guidance: Anniversary statement highlights €4.3B in fines issued since 2018, ongoing adequacy negotiations with third countries, and new draft guidelines for AI data processing under Article 22 automated decision-making provisions. Link: https://commission.europa.eu/news-and-media/news/ten-years-gdpr-your-data-your-rights-2026-05-22_en

💾 The Privacy Posts

The Call List Is the Compliance Risk

  • ICO enforcement shows unsolicited marketing calls remain a live privacy risk, not a legacy nuisance issue.

  • A Glasgow energy company was fined £160,000 after more than 700,000 calls and over 30 complaints.

  • Consent records, TPS and CTPS screening, caller transparency, and vendor oversight are now core marketing controls.

The UK Information Commissioner’s Office has kept the pressure on direct marketing practices, with Energy Prices Direct Limited fined £160,000 after making more than 700,000 unsolicited marketing calls over a 12-month period. The case is a reminder that outbound calling is not just a sales-channel issue, it is regulated processing of personal data with real enforcement exposure. According to reporting on the ICO action, the company contacted individuals and businesses, including numbers registered with the Telephone Preference Service and Corporate Telephone Preference Service. The ICO also identified weaknesses around purchased marketing data, including situations where the company had not established whether numbers had been screened and could not identify the source of some data.

For privacy teams, the lesson is broader than simply adding better consent wording to a script. UK PECR rules require organisations to screen live marketing call lists against TPS and CTPS unless valid, specific consent applies, and organisations must also maintain their own do-not-call lists. The ICO’s guidance also expects callers to identify themselves, display a number, and stop calling people who object. That means lead generation, affiliates, purchased lists, CRM uploads, and outsourced call centres all need governance, evidence, and audit trails. The practical takeaway is simple: marketing operations should be risk-assessed like any other regulated data processing activity, with documented consent provenance, suppression-list controls, complaint monitoring, and vendor accountability.

Apple App Store Blocked Over $2.2 Billion in Fraudulent Transactions in 2025, Company Reports: Annual transparency data highlights machine learning-driven detection of fake apps, subscription scams, and payment fraud, with human review teams escalating high-risk patterns for manual investigation. Link: https://www.apple.com/newsroom/2026/05/the-app-store-stopped-over-2-point-2-billion-usd-in-fraudulent-transactions-in-2025/

📅 Upcoming Events

If you would like to sponsor any of our future in person or virtual events then please email us on [email protected]

We hope you enjoyed our email briefing! ☕🥮If you want to sponsor our next edition or advertise on our site, drop us an email [email protected].

Thank you for being a part of our newsletter community and you can be part of the community by joining our LinkedIn Group.