AUTO-UPDATED

Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited

GitHub and Grafana Labs suffered breaches linked to a compromised VS Code extension, while critical vulnerabilities in NGINX and Microsoft Defender are currently being exploited by active threat actors.

Key Points

  • GitHub CISO Alexis Wales confirmed the breach originated from the malicious "Nx Console" VS Code extension, which impacted 2.2 million installations.
  • Attackers are actively exploiting a critical NGINX vulnerability (CVE-2026-42945) and two Microsoft Defender flaws (CVE-2026-41091 and CVE-2026-45498).
  • The 2026 Verizon Data Breach Investigations Report identifies vulnerability exploitation as the primary method for initial network access, surpassing stolen credentials.
  • Microsoft is developing a fix for the "YellowKey" BitLocker bypass (CVE-2026-45585) that allows unauthorized access to encrypted user data.
  • Researchers discovered that deleted Google API keys remain functional for up to 23 minutes, posing a significant risk for unauthorized service access.

Why it Matters

The rapid shift toward automated exploitation has narrowed the window for organizations to patch critical vulnerabilities to mere hours. These incidents highlight a growing trend where supply chain compromises and identity-based attacks are increasingly used to bypass traditional security perimeters.
Help Net Security Published by Help Net Security
Read original