Cybersecurity

When the internet’s plumbing catches fire

GitHub Confirms 3,800 Internal Repos Were Stolen via a Poisoned VS Code Extension — The Platform That Hosts the World’s Code Just Got Owned by a Marketplace Plugin

🤚 The Open-Palm Incident Report On May 19, 2026, a single GitHub employee installed a Visual Studio Code extension. By the time the company detected…

Read more

Grafana’s Entire Source Code Was Stolen via a Single GitHub Token — Your CI/CD Pipeline Has More Access Than Your CEO and Less Security Than Your Wi-Fi

🤚 The Open-Palm Disclosure Grafana Labs — the company whose dashboards are plastered across every DevOps team’s second monitor like motivational posters made of metrics…

Read more

Microsoft ‘Fixed’ a Windows Zero-Day in 2020 — A Researcher Just Proved It Still Works in 2026, and Published the Exploit on GitHub as a Resignation Letter to the Bug Bounty Program

🤚 The Open-Palm Patch That Wasn’t In September 2020, a Google Project Zero researcher named James Forshaw discovered a privilege escalation vulnerability in the Windows…

Read more

Russia’s Secret Blizzard Upgrades Kazuar Backdoor Into a Peer-to-Peer Botnet — Your Government’s Network Now Has Better Mesh Connectivity Than Your Wi-Fi

Secret Blizzard — the Russian state-sponsored threat group also tracked as Turla, one of the most sophisticated cyber-espionage outfits on the planet — has upgraded…

Read more

Pwn2Own Berlin Researchers Collect $908,750 for 39 Zero-Days in Two Days — Your Enterprise Software Just Got a Very Public Performance Review

🤚 The Open-Palm Exploit Buffet The second day of Pwn2Own Berlin 2026 concluded on May 15 with security researchers collecting $385,750 in prize money after…

Read more

OpenAI Confirms Two Employee Devices Were Compromised in the Shai Hulud Supply Chain Attack — The AI That Writes Code Just Got Owned by the Code Supply Chain

Two days ago, we reported that the Shai Hulud supply chain worm had compromised hundreds of signed npm and PyPI packages, including TanStack, Mistral AI,…

Read more

Foxconn Gets Ransomwared for the Fourth Time Since 2020 — 8 Terabytes of Apple, Intel, and Nvidia Secrets Are Now a Dark Web Tasting Menu

🤚 The Open-Palm Inventory of Stolen Goods In news that will surprise absolutely no one who has been paying attention to the state of industrial…

Read more

Shai Hulud Supply Chain Attack Compromises Hundreds of Signed npm and PyPI Packages — Your Cryptographic Verification Just Verified the Malware

🤚 The Open-Palm Dissection If you thought the software supply chain had reached peak absurdity when a fake OpenAI privacy filter hit 244,000 downloads on…

Read more

Checkmarx’s Jenkins Security Plugin Was Backdoored Using Credentials Checkmarx Failed to Rotate — The Hackers Even Left a Thank-You Note

🤚 The Open-Palm Incident Report The TeamPCP hacking group has successfully backdoored the official Checkmarx Jenkins Application Security Testing (AST) plugin, turning one of the…

Read more

A Fake OpenAI ‘Privacy Filter’ Hit Number One on Hugging Face With 244,000 Downloads — It Was a Rust-Based Infostealer Wearing a Lab Coat

🤚 The Open-Palm Trending Page A malicious repository called Open-OSS/privacy-filter spent enough time at the #1 trending spot on Hugging Face to accumulate 244,000 downloads…

Read more