TL;DR
Attackers planted credential-stealing GitHub Actions workflows in 340+ open-source repositories by compromising two high-profile maintainer accounts. FBI continues dismantling ShinyHunters extortion group with additional arrests. AhsayCBS backup platform flaws remain unpatched and are being exploited to deploy webshells and cryptominers in the wild.
Executive Summary
- Cybersecurity researchers disclosed an ongoing credential-theft campaign targeting GitHub developers via compromised maintainer accounts and malicious Actions workflows reaching 340+ repositories [#1].
- The FBI arrested a third ShinyHunters member and confirmed the group extorted a Boeing spin-off prior to arrests; detention of the suspected group leader from Amman, Jordan, occurred following coordination with law enforcement [#11, #12].
- Two unpatched critical and medium-severity vulnerabilities in AhsayCBS backup management platform (CVE-2026-105133, CVE-2026-105134) are actively exploited in the wild to deploy webshells and cryptocurrency miners [#7, #29].
- CISA added five additional CVEs to its Known Exploited Vulnerabilities catalog on 2026-10-08, including Apache Struts command injection and ISC BIND DoS flaws, with federal remediation due 2026-10-11 [#31–35].
- Firmware-preinstalled malware (Midnight Mimosa campaign) targets budget Android devices across 150+ countries via low-cost device manufacturers [#30].
Top Threats Today
1. Malicious GitHub Actions Deployed Across 340+ Repositories
Severity: HIGH Affected: Technology
Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that exploited two high-profile open-source maintainer accounts to inject malicious GitHub Actions workflows into over 340 repositories [1]. The compromised accounts included Takashi Kitao, author of the 18,400-star game engine pyxel ⚠[1]. The malicious workflows are designed to steal credentials from developers who use affected repositories, creating a supply-chain risk that extends from open-source projects into enterprise environments that depend on them [1].
Sources:[1] The Hacker News
Recommended Action
- Audit your organization’s open-source dependencies for presence of affected GitHub Actions workflows; cross-reference against the 340+ compromised repositories
- Enable GitHub token expiration, rotate any tokens that may have been exposed, and enforce short-lived ephemeral credentials for CI/CD pipelines
- Implement code review and approval workflows for all GitHub Actions to detect anomalous workflow definitions
- Monitor repository activity logs for unauthorized workflow modifications or suspicious Actions execution
2. FBI Escalates Arrests in ShinyHunters Extortion Campaign
Severity: HIGH Affected: Government
The FBI arrested a third suspected co-conspirator of ShinyHunters in connection with the group’s extortion and data theft operations ⚠[1]. A teenager from Amman, Jordan, who uses the hacker handle "Rey" and is suspected of leading the ShinyHunters group, was detained and is reportedly cooperating with the FBI to identify other members [2]. Prior to arrests, ShinyHunters extorted a Boeing spin-off, demonstrating the group’s capability to target aerospace and defense contractors alongside its September ⚠ 2026 breach of the FBI’s jobs portal, which compromised sensitive data on nearly all FBI agents and exposed job applicants [#2, #12].
Sources:[1] Krebs on Security[2] Krebs on Security
Recommended Action
- Review CISA and FBI alerts regarding ShinyHunters indicators of compromise (IOCs) and network signatures; block identified command-and-control infrastructure
- Audit access logs for any unauthorized access or data exfiltration tied to the group’s known TTPs (data theft, credential harvesting, extortion threats)
- If your organization received extortion demands or communications from ShinyHunters, report immediately to FBI Cyber Division and coordinate evidence preservation
- Strengthen data access controls and segmentation to limit lateral movement in the event of credential compromise
3. Unpatched AhsayCBS Flaws Exploited for Webshell and Cryptomining Deployments
Severity: HIGH Affected: Technology
Threat actors are actively exploiting two unpatched vulnerabilities in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners [7, #29]. The flaws, CVE-2026-105133 (critical) and CVE-2026-105134 (medium-severity), allow attackers to bypass authentication and inject arbitrary OS commands [#29]. Organizations running AhsayCBS are exposed to remote code execution and persistent compromise, with active exploitation occurring in the wild [#7].
Sources:[1] BleepingComputer[2] SecurityWeek
Recommended Action
- Immediately isolate AhsayCBS instances from production networks or disable them until a patch is released by the vendor
- Monitor backup infrastructure for signs of unauthorized access or resource consumption (CPU spikes, outbound traffic anomalies indicating cryptomining)
- Review backup and restore logs for any evidence of data exfiltration or malware injection
- Contact AhsayCBS vendor to confirm patch release timeline and apply updates as soon as available
- Implement network segmentation to restrict AhsayCBS communication to trusted administrative systems only
4. Five CVEs Added to CISA Known Exploited Vulnerabilities Catalog
Severity: HIGH Affected: Technology
CISA added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on 2026-10-08 with federal remediation due 2026-10-11 [#31–35]. The additions include CVE-2015-5477 (ISC BIND data processing error causing remote DoS via TKEY queries) [#31], CVE-2016-3081 (Apache Struts command injection via Dynamic Method Invocation enabling remote code execution) [#32], CVE-2023-22894 (Strapi cleartext storage of sensitive information, chainable with CVE-2023-22621 for remote code execution) [#33], CVE-2021-3199 (ONLYOFFICE Docs path traversal via JWT misconfiguration enabling remote code execution) [#34], and CVE-2015-3306 (ProFTPD improper access control allowing arbitrary file read/write via site cpfr and site cpto commands) [#35]. These additions indicate active exploitation in government and critical infrastructure environments.
Sources:[1] CISA KEV[2] CISA KEV[3] CISA KEV[4] CISA KEV[5] CISA KEV
Recommended Action
- Prioritize scanning your infrastructure for ISC BIND, Apache Struts, Strapi, ONLYOFFICE Docs, and ProFTPD instances
- Apply patches or implement vendor mitigations for all five CVEs before the 2026-10-11 federal deadline
- For Strapi, discontinue use of impacted end-of-life versions and transition to supported releases; review admin panel logs for exploitation evidence
- Monitor network traffic for exploitation signatures or TKEY queries (BIND), Dynamic Method Invocation patterns (Struts), or FTP directory traversal commands (ProFTPD)
5. Android Firmware Malware Campaign Spans 150+ Countries
Severity: MEDIUM Affected: Technology
SecurityWeek reports that a malware campaign dubbed “Midnight Mimosa” is primarily running preinstalled on low-cost Android devices, affecting users across 150+ countries [#30]. The malware is embedded in device firmware by manufacturers rather than delivered post-installation, creating persistence and bypass challenges for traditional mobile threat detection [#30]. Users of budget Android handsets are at heightened risk, particularly in regions where device prices are lower and manufacturer security practices may be inconsistent [#30].
Sources:[1] SecurityWeek
Recommended Action
- If your organization distributes or manages budget Android devices, coordinate with device manufacturers to identify affected models and obtain firmware updates
- Deploy mobile device management (MDM) solutions to monitor and remediate preinstalled malware on enrolled devices
- Educate users of budget devices to avoid sideloading applications, enable restricted app installation, and monitor battery and data usage for anomalies
- Monitor carrier and OEM advisories for patches; enforce updated security policies for BYOD programs involving lower-cost Android devices
Today’s Action Checklist
- ☐ URGENT: Audit GitHub repositories your organization depends on against the 340+ compromised repositories; rotate any exposed CI/CD tokens
- ☐ URGENT: Isolate or disable AhsayCBS instances pending patch release; monitor backup infrastructure for signs of cryptomining or unauthorized access
- ☐ URGENT: Apply patches for CVE-2026-105133, CVE-2026-105134 as soon as vendor releases them
- ☐ HIGH: Scan for and patch ISC BIND, Apache Struts, Strapi, ONLYOFFICE Docs, and ProFTPD by 2026-10-11 (CISA federal deadline)
- ☐ HIGH: Review ShinyHunters IOCs and FBI alerts; audit logs for unauthorized access, exfiltration, or extortion communications
- ☐ MEDIUM: If your organization manages or distributes budget Android devices, coordinate with manufacturers for Midnight Mimosa firmware patches