supply-chain Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows A sophisticated cyberattack, dubbed Megalodon, has targeted over 5,500 GitHub repositories using malicious CI/CD workflows. The attacker leveraged throwaway accounts and forged author identities to exfiltrate sensitive d… The Hacker News · May 22, 2026 Critical IRILci/cdgithubsupply chain
threat-intel GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos GitHub experienced a breach originating from an employee device compromised by a poisoned Microsoft Visual Studio Code extension. The attacker exfiltrated over 3,800 internal repositories, facilitated by the threat actor… The Hacker News · May 20, 2026 High USILIRsupply chaincredential theftinfostealer
threat-intel Real-World ICS Security Tales From the Trenches This article details real-world incidents involving industrial control systems (ICS) security vulnerabilities, highlighting the challenges of securing OT environments beyond traditional IT security practices. Two separat… SecurityWeek · May 20, 2026 High IRUSicsotlateral movement
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-05-17, (Mon, May 18th) The TeamPCP supply chain campaign intensified significantly on May 17th, 2026, marked by the confirmed compromise of a Checkmarx Jenkins plugin and the emergence of a new Mini Shai-Hulud worm. This campaign targeted npm… SANS Internet Storm Center · May 18, 2026 Critical CVE-2026-45321CVE-2025-29927CVE-2025-55182GBILIRsupply-chainnpmpypi
threat-intel Fuel Tank Breaches Expand Scope of Iran's Cyber Offensive This article reports on a cyber offensive by Iran targeting fuel tank systems in the United States, exploiting insecure automatic tank gauge (ATG) systems exposed online. The attacks, which involved manipulating displaye… Dark Reading · May 18, 2026 High USIRcyberattackcritical infrastructuregeopolitics
threat-intel Why geopolitical turmoil is a gift for scammers, and how to stay safe Geopolitical turmoil is being exploited by scammers to increase the success of their fraudulent schemes. The article details a range of scams – from fake charities and romance fraud to investment scams and sensational fa… WeLiveSecurity · May 15, 2026 Medium IRMIscamsfraudcybercrime
threat-intel From Stuxnet to ChatGPT: 20 News Events That Shaped Cyber This Dark Reading article reflects on key cybersecurity events from the past two decades, highlighting the evolution of cyber threats and their impact on businesses and critical infrastructure. The piece emphasizes how a… Dark Reading · May 6, 2026 High CVE-2017-0144CVE-2021-44228IRUSISindustrial control systemsnation-state actorsair gap
threat-intel Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) This report from Palo Alto Unit 42 details a significant escalation of cyber risk originating from Iran following a 47-day internet outage. Iranian threat actors, identified as CL-STA-1128 (Cyber Av3ngers), are now aggre… Palo Alto Unit 42 · Apr 17, 2026 High USIRILoticsphishing
threat-intel ‘CanisterWorm’ Springs Wiper Attack Targeting Iran A financially motivated cybercrime group, TeamPCP, is deploying a wiper attack targeting Iran, leveraging a self-propagating worm that exploits vulnerabilities in cloud services like Azure and AWS. The group gained initi… Krebs on Security · Mar 23, 2026 High IRcloud securitysupply chain attackwiper