🚨 ACTIVE EXPLOITS & INCIDENTS
- GitHub breached via poisoned VS Code extension https://www.helpnetsecurity.com/2026/05/24/week-in-review-github-breached-via-poisoned-vs-code-extension-critical-nginx-flaw-exploited/
Help Net SecurityTeamPCP threat actors successfully compromised GitHub’s internal code repositories by distributing a malicious Visual Studio Code extension. Microsoft has confirmed the breach and launched an investigation. This incident highlights the ongoing risk of supply chain attacks targeting developer tools.
🔓 VULNERABILITIES & CVEs
- CVE-2026-41054: Missing exit in permission check in haveged could lead to root exploit https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41054
Microsoft MSRCA critical vulnerability in haveged (a Linux entropy daemon) allows privilege escalation due to a missing exit after a permission check. This flaw can be exploited locally to gain root privileges. Immediate patching is advised for affected Linux distributions running haveged. - Critical NGINX flaw actively exploited https://www.helpnetsecurity.com/2026/05/24/week-in-review-github-breached-via-poisoned-vs-code-extension-critical-nginx-flaw-exploited/
Help Net SecurityA severe vulnerability in NGINX web server software is currently being exploited in the wild. Details remain limited, but organizations using NGINX should prioritize monitoring and patching to mitigate potential compromise.
📰 LESSER-KNOWN / UNDER-REPORTED
- AccLock: Continuous user authentication via heartbeat sensors https://www.helpnetsecurity.com/2026/05/24/week-in-review-github-breached-via-poisoned-vs-code-extension-critical-nginx-flaw-exploited/
Help Net SecurityResearchers developed AccLock, a novel authentication system that uses heartbeat-induced vibrations from wearable earbud sensors to continuously verify user identity. This emerging biometric approach could impact future endpoint security and MFA strategies.
💼 INDUSTRY NEWS, M&A & DEALS
- Countdown begins for 4th China International Supply Chain Expo (CISCE) in Beijing, June 22-26 https://www.prnewswire.com/news-releases/debut-du-compte-a-rebours-de-30-jours--la-4e-cisce-ouvrira-ses-portes-a-pekin-le-22-juin-302780752.html
PR Newswire CybersecurityThe upcoming CISCE event will showcase key supply chain sectors with a strong focus on cybersecurity innovations and risk management. Security professionals monitoring global supply chain resilience should note this event for emerging trends and partnerships.