We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
🚨 WARNING: The official JDownloader website was compromised earlier this week to distribute malicious Windows and Linux installers that deployed Python-based malware on infected systems.
The supply chain attack impacted users who downloaded installers from the site between May 6 and May 7 via the “Download Alternative Installer” links on Windows or the Linux shell installer.
What happened:
🔴Attackers breached the JDownloader site via an unpatched security flaw.
🔴Attackers then modified JDownloader download links to point to malicious payloads
🔴The Windows malware deployed a heavily obfuscated Python-based RAT framework
@thomasklemenc found that the Windows malware deployed a Python RAT that can execute attacker-supplied Python code remotely.
BleepingComputer's analysis of the Linux installer also revealed injected code that downloaded additional malware, installed a SUID-root launcher, and disguised the payload as /usr/libexec/upowerd.
Here is the list of every school district, college, and university impacted by the ShinyHunter's Canvas compromise. It is nearly indeed over 9,000 schools because it includes entire school districts.
Here is a list of every place currently impacted:
https://t.co/E9wCXYGczw
🚨 BREAKING: Hackers are now exploiting the cPanel authentication bypass flaw (CVE-2026-41940) to deploy "Sorry" ransomware on compromised websites.
Numerous sources say attacks began Thursday, with threat actors breaching servers and deploying a Go-based Linux encryptor that appends the .sorry extension to files.
What the ransomware does:
🔴 Encrypts files and appends the ".sorry" extension.
🔴 Protects the encryption key with an embedded RSA-2048 public key
🔴 Drops a README.md ransom note in every folder
🔴 Uses a fixed Tox ID for ransom negotiations
Victims are being instructed to contact the attacker via Tox to pay for decryption.
This is not related to the older 2018 HiddenTear ".sorry" ransomware. This is a new, Linux-targeting encryptor tied directly to active cPanel exploitation.
If you're running cPanel or WHM, patch immediately.
CVE-2026-31431 a/k/a CopyFail
> Linux LPE
> Description sounds like AI slop
> Exploit is legit
> Impacts every Linux kernel from 2017 - Now
> Proof-of-concept released
> It's Wednesday?
https://t.co/FXgjWW7lOV
BREAKING: You checked the weather this morning.
And you just told a surveillance company where you sleep.
Meet #Webloc, used by ICE, cops & foreign govs to track 500m+ phones.
No warrant required.
Our latest @citizenlab investigation + how to protect yourself 🧵/1
I built https://t.co/R1jAMUfNTv — a free public database for American citizens who deserve safer communities.
You can track which judges released defendants who then got rearrested, skipped court, or violated their release conditions. All public records. All free.
I started with Orange County FL and will be expanding to all 67 Florida counties and eventually every state in the country. This first batch of info is from 2024 and since public reports are released in March/April for the previous year, data is behind. But I wanted to see if this is plausible. After adding 2024,I'll add 2025 and then figure out how to get real-time-data uploaded.
It's in beta — would love to know what you think 👇
Numbers don't lie, but criminals do.
https://t.co/DfTcJ6XMYn
@bennyjohnson@jockowillink@GrantCardone@LauraLoomer@nickshirleyy@j_fishback
🚨JUST IN🚨The Defense Criminal Investigative Service (DCIS), FBI Anchorage, and international partners disrupted four of the world’s largest Internet of Things (IoT) botnets that together were responsible for millions of infected devices and hundreds of thousands of DDoS attacks worldwide. 🔗https://t.co/SzcMSDAUdD
@USAO_AK | @DoD_IG
‼️New Instagram Vulnerability Exposes Private Posts to Anyone
A vulnerability in Instagram’s server-side logic allowed unauthenticated users to access private posts by sending GET requests with specific mobile headers.
The flaw exposed direct CDN links to private media and captions for about 28% of tested accounts. Researcher Jatin Banga reported the issue in October 2025; Meta silently patched it days later but denied the bug’s validity, closing the report as “Not Applicable” without confirming the root cause.
Source: https://t.co/Zm7vctGo0w
Pro-Russia hacktivist groups are targeting virtual network computing connected human-machine interface devices to conduct opportunistic attacks on global critical infrastructure. Follow the advice in this new joint CSA to protect your organization. https://t.co/acoyL8IXgg
🚨Cyber Alert‼️
🇺🇸USA - JPMorgan, Citi, Morgan Stanley client data may be exposed by vendor's hack
SitusAMC suffered a cyberattack on November 12, 2025, exposing accounting documents and legal contracts tied to major clients, including JPMorgan Chase, Citi, and Morgan Stanley.
The company confirmed the breach, alerted law enforcement and the FBI, and reported no impact on banking operations.
Status Confirmed
Article source: https://t.co/eMMYxQy0pX
SitusAMC statement:
https://t.co/6LBYPfmpJp
The FBI and our partners successfully dismantled an infostealer, remote access trojan, and botnet as part of Operation Endgame. This marks the third large-scale action in this ongoing initiative, which was launched to combat criminal infrastructure used for ransomware attacks worldwide.
This operation is a joint effort with partners from Australia, Belgium, Canada, Denmark, France, Germany, Greece, Lithuania, the Netherlands, and the UK. We took down 1,025 servers, seized 20 domains, and arrested one suspect in Greece. The dismantled infrastructure, including the Rhadamanthys infostealer, VenomRAT, and Elysium botnet, was crucial to cybercriminal activities. By working with international partners, we are defending the homeland by shutting down the key services that cybercriminals depend on.
💣️ 𝗘𝗫𝗖𝗟𝗨𝗦𝗜𝗩𝗘 𝗜𝗡𝗧𝗘𝗥𝗩𝗜𝗘𝗪 𝗪𝗜𝗧𝗛 𝗟𝗢𝗖𝗞𝗕𝗜𝗧 𝟱.𝟬!
Declared dismantled by law enforcement earlier this year, 𝗟𝗼𝗰𝗸𝗕𝗶𝘁 𝗵𝗮𝘀 𝗿𝗲-𝗲𝗺𝗲𝗿𝗴𝗲𝗱 under the name 𝗟𝗼𝗰𝗸𝗕𝗶𝘁 𝟱.𝟬 — and now speaks exclusively to Hackmanac.
In this unprecedented interview, conducted via anonymous channels, for the first time the group explains 𝗵𝗼𝘄 𝗶𝘁 𝗿𝗲𝗯𝘂𝗶𝗹𝘁, 𝗵𝗼𝘄 𝗮𝗳𝗳𝗶𝗹𝗶𝗮𝘁𝗲𝘀 𝗼𝗽𝗲𝗿𝗮𝘁𝗲, and 𝘄𝗵𝘆 𝘁𝗵𝗲𝘆 𝗰𝗼𝗻𝘀𝗶𝗱𝗲𝗿 𝗿𝗮𝗻𝘀𝗼𝗺𝘄𝗮𝗿𝗲 𝗮𝗻 “𝙚𝙣𝙙𝙡𝙚𝙨𝙨 𝙗𝙪𝙨𝙞𝙣𝙚𝙨𝙨 𝙢𝙤𝙙𝙚𝙡.”
A rare look inside the world’s most notorious cyber-extortion network.
🔗 Read the full interview: https://t.co/dSIUJRrWZL