SecurityHorrors

Stories you never want to feel on your own skin

New 22 May 2026

Megalodon: 5,561 Repos Swallowed in Six Hours

TLDR and details on the Megalodon supply chain attack mass-backdooring GitHub repositories via malicious CI/CD workflow commits.

20 May 2026

GitHub: The Extension That Opened the Vault

TLDR and impact summary for the GitHub internal repository breach caused by a malicious VS Code extension installed by a GitHub developer.