๐จ Microsoft warns two Defender vulnerabilities are being actively exploited in the wild.
https://t.co/z92odj1gF0
๐ธ CVE-2026-41091 could allow attackers to gain SYSTEM privileges locally.
๐ธ CVE-2026-45498 is a denial-of-service flaw impacting Defender.
CISA added both to KEV with a June 3, 2026 patch deadline.
๐จ GitHub Hacked - Internal Source Code Repositories Compromised via Employee Device
Source: https://t.co/5gc68A17Q7
GitHub has confirmed unauthorized access to its internal repositories after detecting a compromised employee device infected through a malicious Visual Studio Code extension, the company disclosed in a series of official statements on May 20, 2026.
GitHub's investigation indicates the attacker successfully exfiltrated data from GitHub-internal repositories only, with no confirmed impact on public or customer-hosted repositories at this stage.
A notorious threat actor operating under the alias TeamPCP has claimed responsibility for the breach, alleging the exfiltration of proprietary organization data and source code.
#cybersecuritynews