The brief

Wednesday, May 20, 2026

GitHub suffered a breach of 3,800 internal repositories via malicious VS Code extension; separately, CISA and contractor credentials exposed in public repos. Simultaneously, 600+ malicious npm packages targeted @antv ecosystem in Shai-Hulud supply chain attack.

12 stories · 3 podcasts · get this by email each weekday

Today's stories

Worth a listen

  • Marc Andreessen on AI, California, and the Future of America | Joe Rogan

  • Eviltokens: A Conversation with Huntress on an AI‑Enabled Device Code Phishing Campaign

  • Risky Business #838 -- GitHub investigates possible breach

← All editions