GitHub and Grafana Labs suffered breaches linked to a compromised VS Code extension, while critical vulnerabilities in NGINX and Microsoft Defender are currently being exploited by active threat actors.
Key Points
- GitHub CISO Alexis Wales confirmed the breach originated from the malicious "Nx Console" VS Code extension, which impacted 2.2 million installations.
- Attackers are actively exploiting a critical NGINX vulnerability (CVE-2026-42945) and two Microsoft Defender flaws (CVE-2026-41091 and CVE-2026-45498).
- The 2026 Verizon Data Breach Investigations Report identifies vulnerability exploitation as the primary method for initial network access, surpassing stolen credentials.
- Microsoft is developing a fix for the "YellowKey" BitLocker bypass (CVE-2026-45585) that allows unauthorized access to encrypted user data.
- Researchers discovered that deleted Google API keys remain functional for up to 23 minutes, posing a significant risk for unauthorized service access.