CISA Warning: Nx Console / GitHub Supply Chain Compromise — Two CVEs on KEV, Megalodon Confirmed, Federal Deadline June 10
CISA issued a formal advisory on May 28 covering both the Nx Console VS Code extension breach and the parallel Megalodon GitHub Actions campaign. CVE-2026-48027 and CVE-2026-45321 are on the KEV catalog. TeamPCP open-sourced its attack framework — copycat groups are already active. Full forensic audit checklist and remediation guide inside.
Read Full Advisory →Threats & Attacks
CISA formally documented both the Nx Console breach and the parallel Megalodon GitHub Actions campaign. TeamPCP open-sourced its framework. Copycat groups already active. Full forensic checklist inside.
22,052 incidents. 12,195 confirmed breaches. Exploitation beats credentials for the first time. Ransomware in 44% of breaches. Supply chain attacks doubled. Median patch time: 43 days.
Directory traversal in Apex One on-premise server. Attacker injects malicious code that auto-deploys to every managed endpoint. CISA KEV. Federal deadline June 4, 2026.
Poisoned Nx Console auto-delivered to 2.2M installs. GitHub, OpenAI, Mistral AI, Grafana Labs all breached. 3,800 internal repos exfiltrated. TeamPCP at SolarWinds scale.
A crafted email triggers JavaScript inside an authenticated OWA session. No permanent patch. CISA KEV. Federal deadline May 29. Exchange Online is not affected.
Standard user in, SYSTEM shell out. Public PoC on GitHub. 6th zero-day in 6 weeks. First 3 confirmed used in real attacks.
Intelligence & Deep Dive
Further Coverage
No race condition. Public PoC. Container escape. Dirty Frag kernel patch does NOT protect you. Third Linux root exploit in two weeks.
Four DTLS packets. No credentials. Full admin access to the enterprise SD-WAN fabric. Nation-state-linked UAT-8616. CISA Emergency Directive 26-03.
VulnCheck confirms real-world attacks. CVSS 9.2. ~34% of all internet web servers exposed. Patch to NGINX 1.30.1 now.
One SMTP sequence. Heap corrupted. Shell opened. Autonomous AI built the full exploit in 7 days. Patch to Exim 4.99.3.
732 bytes of Python. Root on every major distro since 2017. No race condition. No disk trace. Container escape primitive.
The same TeamPCP campaign that breached GitHub started here on April 30. Malicious PyPI packages, credential-stealing worm, IDE persistence hooks.
The DataWater Intelligence Brief
Weekly CISO-level threat analysis — breaking vulnerabilities, technical depth, zero noise. Trusted by enterprise and government security leaders.
