Related Threat Clusters
-
Microsoft's MDASH AI System Discovers 16 Windows Vulnerabilities
Microsoft's newly developed MDASH (Multi-Model Agentic Scanning Harness) identified 16 vulnerabilities in Windows, including four critical remote code execution (RCE) flaws. The vulnerabilities were found in key…
33 articles · Updated May 13, 2026 -
77 Counterfeit Open VSX Extensions Harvest Developer Data
Between July 26 and August 1, 2026, 77 counterfeit extensions were discovered on the Open VSX marketplace, impersonating legitimate tools and harvesting sensitive developer information. These extensions, linked to a…
10 articles · Updated August 4, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1484 articles · Updated February 9, 2026 -
Azure DevOps MCP Server Vulnerability Enables AI Agent Hijacking
A critical vulnerability in Microsoft Azure DevOps Model Context Protocol (MCP) server has been identified, allowing attackers to perform indirect prompt injection attacks. By embedding invisible HTML in pull request…
3 articles · Updated July 22, 2026 -
Fake OpenClaw Installer Targets Crypto Wallets and Password Managers
A new malware campaign is exploiting a fake OpenClaw installer to deploy the Hologram infostealer framework, which is designed to harvest credentials from over 250 crypto wallet and password manager browser extensions.…
3 articles · Updated May 11, 2026 -
Accenture Confirms Data Breach Involving 35GB of Stolen Source Code
Accenture has confirmed a data breach involving the theft of approximately 35 GB of sensitive data, including source code, RSA keys, SSH keys, and Azure access tokens. The breach was claimed by a hacker known as '888',…
18 articles · Updated July 7, 2026 -
Version Control Systems Targeted in Supply Chain Attacks
Recent cybersecurity incidents have highlighted the vulnerabilities of Version Control Systems (VCS) like GitHub, GitLab, Bitbucket, and Azure DevOps. Attackers are exploiting these platforms as both targets and…
2 articles · Updated August 28, 2026 -
Open-source CI/CD Abuse Detector Launches to Combat Credential Theft
The CI/CD Abuse Detector is an open-source tool designed to identify suspicious changes in CI/CD pipelines. It utilizes a large language model to analyze modifications in workflows on platforms like GitHub Actions,…
2 articles · Updated June 15, 2026 -
Shai-Hulud Malware Infects npm Packages, Compromising Thousands of Repositories
A new wave of the Shai-Hulud malware has compromised nearly 500 npm packages, affecting over 26,000 GitHub repositories. This self-replicating worm, which targets developers' credentials and secrets, has been linked to…
43 articles · Updated November 29, 2025 -
Golden Pull Requests Enhance Open Source Security Remediation
Sonatype introduces Golden Pull Requests to automate the remediation of open source vulnerabilities. This method streamlines the traditional manual process of addressing security issues in software dependencies. By…
2 articles · Updated March 23, 2026
Recent Intelligence Reports
- Version Control DFIR: GitHub, GitLab, Bitbucket, and Azure DevOps Detection & Incident ... — Securityarsenal · August 28, 2026
- Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps — Wiz · August 27, 2026
- New research — www.manifold.security · August 6, 2026
- 77 Open VSX extensions found harvesting developer info — Bleepingcomputer · August 4, 2026
- Announcing the Launch of TurboPentest, an Affordable Self — Markets.Businessinsider · July 25, 2026
- Azure DevOps MCP server vulnerability allows AI agent hijacking via hidden comments — Feeds.4Sysops · July 22, 2026
- Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data — Cybersecuritynews · July 22, 2026
- Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents — Thehackernews · July 22, 2026