Spring til indhold
GitHub bans vindictive security researcher - 2026-05-26 - Talkin' Bout [Infosec] News

GitHub bans vindictive security researcher - 2026-05-26

Talkin' Bout [Infosec] News · Black Hills Information Security

30. maj 2026 1t 2m
0:00 1t 2m

Beskrivelse

This episode covers a CISA contractor’s accidental exposure of AWS GovCloud credentials and internal system details on GitHub, the FBI’s efforts to patch vulnerable routers, and a critical NGINX vulnerability with public proof-of-concept code. The team also discusses Microsoft’s handling of a disputed Azure Backup security finding, the challenges of vulnerability disclosure and CVE assignment, and GitHub’s ban of security researcher Nightmare Eclipse following the publication of unpatched Windows vulnerability research. Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis 🔴live-chat Chapters (00:00) - PreShow Banter™ — Getting to Chili's (05:45) - GitHub bans vindictive security researcher - 2026-05-26 (07:09) - Story # 1: CISA Admin Leaked AWS GovCloud Keys on Github (10:45) - Story # 2 - PoC Code Published for Critical NGINX Vulnerability (12:53) - Story # 3 - Anthropic’s restricted Claude Mythos model may be coming to Claude Code (16:16) - Story # 4 - The FBI just remotely reset thousands of home and small office routers – and your TP-Link could be on the hitlist (22:37) - Story # 5 - Drupal to Release Emergency Core Security Updates Amid Fears of Rapid Exploitation (25:52) - Story # 6 - Microsoft rejects critical Azure vulnerability report, no CVE issued (28:09) - Story # 7 - GitHub bans vindictive security researcher dropping Windows zero-days: “I will make sure your bones are shattered” (30:41) - Story # 8a - A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale (32:16) - Story # 8b - TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension (35:21) - Story # 10 - Ubiquiti patches three max severity UniFi OS vulnerabilities (37:51) - Story # 11 - Pizza Hut's AI system caused 'cascading' problems and $100M in damages, franchisee alleges in new suit (43:55) - Story # 12 - Data Leak at German Hospital (45:00) - Story # 13 - Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware (47:50) - Story # 14 - Chicken News (50:07) - Story # 15 - New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released (51:04) - Story # 15b - Might someone pass along that Crowdstrike and Nessus are having a moment? Links Story # 1 - CISA Admin Leaked AWS GovCloud Keys on Github Story # 2 - PoC Code Published for Critical NGINX Vulnerability Story # 3 - Anthropic’s restricted Claude Mythos model may be coming to Claude Code Story # 4 - The FBI just remotely reset thousands of home and small office routers – and your TP-Link could be on the hitlist Story # 5 - Drupal to Release Emergency Core Security Updates Amid Fears of Rapid Exploitation Story # 6 - Microsoft rejects critical Azure vulnerability report, no CVE issued Story # 7 - GitHub bans vindictive security researcher dropping Windows zero-days: “I will make sure your bones are shattered” Story # 8a - A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale Story # 8b - TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension Story # 10 - Ubiquiti patches three max severity UniFi OS vulnerabilities Story # 11 - Pizza Hut’s AI system caused ‘cascading’ problems and $100M in damages, franchisee alleges in new suit Story # 12 - Data Leak at German Hospital Story # 13 - Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware Story # 14 - Chicken News Story # 15 - New Windows ‘MiniPlasma’ zero-day exploit gives SYSTEM access, PoC released Story # 15b - Might someone pass along that Crowdstrike and Nessus are having a moment?Creators & Guests Alethe Denis - Guest Corey Ham - Host Wade Wells - Host Bronwen Aker - Host Meagan Bentley - Producer Hayden Covington - Host Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits  https://poweredbybhis.com Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com

Andre episoder fra Talkin' Bout [Infosec] News Se alle episoder →