🚨‼️ RANSOMWARE ALERT
On 25th May 2026, ransomware group, "DragonForce" has added 12 companies to their victim list affecting 5 countries:
1. Business Record 🇺🇸
2. Goldklang Group CPAs 🇺🇸
3. VegFresh 🇺🇸
4. Saver 🇳🇱
5. Global X ETFs 🇩🇪
6. Alliance Adjustment Group 🇺🇸
🛡️ We suggest users should use websites such as https://t.co/uJeyHUZCuW to mask your IP address when clicking suspicious links and using https://t.co/BRcIuHV81Q to scan suspicious files for malware.
On 26th August 2024, a threat actor on a dark web forum, "Knox," has allegedly posted a thread containing Discord usernames, Discord IDs, and IP addresses.
Mylon Intelligence has identified that the data leak contains more than 100K+ users spanning over 192 countries.
🛡️ There's currently insufficient evidence that this data leak originated from Discord itself. Users should be aware when clicking links, downloading files and authorizing applications.
‼️🇦🇹 AUSTRIA RANSOMWARE ALERT
Ransomware group, "Lamashtu" has added Roth-Technik Austria to their page. Leaked data may contain confidential documents.
- 📦120GB (150K files)
- ⏰Date Added: 18/5/2026
- ⏳Date Leak: 26/5/2026 (8 days)
🛡️ It's currently unclear what type of data was leaked. We suggest everyone should be aware of any suspicious phone calls and phishing links sent via email or a text message.
🚨‼️DATA BREACH ALERT
Threat actor, "ShinyHunters" (UNC6040/UNC6240) has allegedly breached 2 organizations:
- 🇺🇸 Baker Distributing Company — 📦260K records
- 🇺🇸 Charter Communications, Inc — 📦42M records
All ransomware demands are made within 4 days before it's made public.
Hello 👋
Today I've reverse engineered the new variant of the Mini Shai-Hulud worm affecting PyPI module durabletask. It's quite similar to the mistralai worm a few days back.
The domain used in the attack, git-service[.]com is currently deactivated.
https://t.co/Xb1AcZEkyl
🚨CYBERSECURITY INCIDENT
The Mini Shai-Hulud worm strikes again!
The following PyPI packages have been affected by the Mini Shai-Hulud worm and yanked from PyPI:
- durabletask==1.4.1
- durabletask==1.4.2
- durabletask==1.4.3
🛡️The domain used in the attack to download the malicious payload, git-service[.]com has been suspended.
Developers that installed the affected modules are advised to uninstall the affected packages immediately and rotate all credentials.
📰 NEWS
Operation Saffron, a joint operation involving 15 law enforcement agencies and bodies, brought down the First VPN Service that was used by cybercriminals.
A press release is yet to be published.
‼️CYBERSECURITY INCIDENT
GitHub Pull Request (PR) #3139 was made regarding the removal of NX Console from the VS Code Marketplace on 18/5/2026.
The VS Code extension was compromised, and it contains an infostealer.
Microsoft has since removed it from the VS Code marketplace.
🛡️ We recommend any developer that has installed this VS Code extension to remove it immediately and rotate all credentials.
Check files for compromise:
- ~/.local/share/kitty/cat.py
- ~/Library/LaunchAgents/com.user.kitty-monitor.plist
- /tmp/kitty-*
- /var/tmp/.gh_update_state
🗞️ Mylon Intelligence Threat Report — "GitHub Compromise of over ~3.8k Repositories via Malicious VS Code Extension"
Mylon Intelligence has published it's findings regarding the security incident involving unauthorized access to GitHub's internal source code.
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
‼️🚨 CYBERSECURITY INCIDENT — A threat actor on a hacker forum, "TeamPCP" is allegedly selling GitHub source code.
Mylon Intelligence has identified that there was no user data involved which aligns with GitHub investigative reports.
🛡️ There is currently no cause for alarm for GitHub users. GitHub has since contained the security incident that involved compromising an employee's device via a malicious VS Code extension.
Mylon Intelligence would monitor the situation closely & will publish a threat report.
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
‼️GitHub claims to be investigating unauthorized access to GitHub's internal repositories through a poisoned VS Code extension that led to the compromise of an employee's device.
A threat actor on a hacker forum, "TeamPCP" claims to be selling GitHub's internal source code.
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.