View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

GitHub breached via poisoned VS Code extension

🚨 ACTIVE EXPLOITS & INCIDENTS

  • GitHub breached via poisoned VS Code extension https://www.helpnetsecurity.com/2026/05/24/week-in-review-github-breached-via-poisoned-vs-code-extension-critical-nginx-flaw-exploited/ Help Net Security TeamPCP threat actors successfully compromised GitHub’s internal code repositories by distributing a malicious Visual Studio Code extension. Microsoft has confirmed the breach and launched an investigation. This incident highlights the ongoing risk of supply chain attacks targeting developer tools.

🔓 VULNERABILITIES & CVEs

  • CVE-2026-41054: Missing exit in permission check in haveged could lead to root exploit https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41054 Microsoft MSRC A critical vulnerability in haveged (a Linux entropy daemon) allows privilege escalation due to a missing exit after a permission check. This flaw can be exploited locally to gain root privileges. Immediate patching is advised for affected Linux distributions running haveged.
  • Critical NGINX flaw actively exploited https://www.helpnetsecurity.com/2026/05/24/week-in-review-github-breached-via-poisoned-vs-code-extension-critical-nginx-flaw-exploited/ Help Net Security A severe vulnerability in NGINX web server software is currently being exploited in the wild. Details remain limited, but organizations using NGINX should prioritize monitoring and patching to mitigate potential compromise.

📰 LESSER-KNOWN / UNDER-REPORTED

  • AccLock: Continuous user authentication via heartbeat sensors https://www.helpnetsecurity.com/2026/05/24/week-in-review-github-breached-via-poisoned-vs-code-extension-critical-nginx-flaw-exploited/ Help Net Security Researchers developed AccLock, a novel authentication system that uses heartbeat-induced vibrations from wearable earbud sensors to continuously verify user identity. This emerging biometric approach could impact future endpoint security and MFA strategies.

💼 INDUSTRY NEWS, M&A & DEALS

  • Countdown begins for 4th China International Supply Chain Expo (CISCE) in Beijing, June 22-26 https://www.prnewswire.com/news-releases/debut-du-compte-a-rebours-de-30-jours--la-4e-cisce-ouvrira-ses-portes-a-pekin-le-22-juin-302780752.html PR Newswire Cybersecurity The upcoming CISCE event will showcase key supply chain sectors with a strong focus on cybersecurity innovations and risk management. Security professionals monitoring global supply chain resilience should note this event for emerging trends and partnerships.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check