The maintainers of the official Model Context Protocol Python SDK disclosed a flaw that lets a malicious MCP server trick an application built on the SDK into handing over the OAuth credentials it uses to log in to a real service. Affected versions sent the client secret, authorization code, and PKCE proof key to an attacker-controlled token endpoint, because the SDK did not always verify where the authorization server was. Cycode, which reported it, exchanged the stolen material for a valid access token carrying the app's permissions, and noted the long-lived client secret keeps working until rotated. Fixes are in versions 1.30.0 and 2.2.0.
Cryptocurrency exchange Bitget said the attacker who stole about 388 million dollars gained access through a vulnerability in a third-party security product the exchange used. The attacker exploited the flaw to obtain high-level internal credentials, then on September 24 used them to reach an internal management system and insert fraudulent withdrawal commands into wallet backend services, where they were treated as legitimate. The stolen funds came from Bitget's hot and warm wallets, while its offline cold wallets were unaffected. CEO Gracy Chen described the incident publicly, confirming the earlier statement that a critical wallet backend system had been compromised and used to spoof transaction data and trigger approvals.
Socket reported that two GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-comment, were disabled a second time after their repositories became accessible again on September 16, months after being compromised in the May Mini Shai-Hulud campaign. When the repositories returned, their release tags were not cleaned up and still pointed to the malicious content introduced on May 18, so any workflow referencing either action by a version tag resumed downloading and executing the payload on its next run. The original May 18 compromise ran code that harvested credentials from CI/CD pipelines and exfiltrated them, activity linked to the Mini Shai-Hulud cluster through a shared exfiltration domain. GitHub has again disabled both repositories.
ReversingLabs detailed a malicious npm package, tw-pkgprobe-7731, that masquerades as an authorized Twilio bug-bounty research probe while harvesting developer data. Uploaded in mid-August by an account that no longer exists, it shipped eleven versions within about 45 minutes. Comments inside describe it as an authorized HackerOne probe that runs only inside Twilio's serverless sandbox and takes no destructive action. On execution it first checks for a Twilio developer environment and exits otherwise, then collects environment variables plus system details like mounts and temporary folders and exfiltrates them through a webhook. Later versions specifically target developers using Twilio APIs by searching for folders tied to particular Twilio account identifiers, sharpening the credential theft.
Varonis Threat Labs detailed a post-compromise technique it calls TrustSink, in which an attacker holding a highly privileged Microsoft Entra account registers a rogue External Authentication Method as an external MFA provider. During normal sign-ins, Entra redirects users to the rogue provider to complete the second factor, and the attacker inserts a convincing Microsoft password prompt that captures the password in plaintext before returning a valid signed token, so the login completes with no error. In testing, every sign-in succeeded while the attacker server logged passwords with source IPs. Resetting a captured password does not remove the rogue provider, which persists in the configuration and works against any external provider model.
Researchers at GitGuardian found that a recent variant of the self-spreading Shai-Hulud npm worm has expanded its credential theft to scan 469 distinct locations on infected developer machines. The targets now span developer environments, continuous integration and deployment tooling, cloud configuration files, and even the configuration of AI tools. That breadth turns a single compromised package into a wide net for secrets, from cloud and registry credentials to keys held by developer and AI tooling. It reflects how supply-chain worms are industrializing secret collection, treating any credential a developer's machine can reach as fair game once malicious code runs during installation or use.
Researchers at Expel found a new malware toolkit, SynkLoader, spread through Microsoft Teams messages in which attackers pose as a company's IT help desk. Using their own Microsoft tenant and an onmicrosoft.com address for credibility, they talk an employee into installing a fake "PowerShell Cleaner" hosted on Microsoft's own Azure storage. Once installed, SynkLoader can load modules including a convincing full-screen fake Windows lock screen that captures the user's password, plus a reverse proxy, remote shell, and remote desktop control. Its focus on counting Active Directory systems suggests it is used by a ransomware group or access broker to size targets. The fake lock screen can be escaped with Alt+Tab or Ctrl+Alt+Delete.
Attackers began exploiting a critical unauthenticated flaw in MLflow, the popular open-source machine-learning platform, within hours of its disclosure. Tracked as CVE-2026-64849 and scored 9.3, the server-side request forgery bug lives in the model-registry webhook testing feature: an attacker hosts an endpoint that passes validation, then redirects MLflow to internal targets such as the cloud metadata service or loopback addresses, and MLflow returns their responses. That exposes cloud credentials, API tokens, and secrets. Because MLflow sits close to training data, artifacts, object storage, CI/CD, and inference pipelines, a compromise offers both credentials and a foothold for lateral movement. watchTowr's honeypots saw exploitation attempts almost immediately.
Researchers at Wiz found that a public Snowflake code repository could be hijacked through nothing more than a crafted GitHub issue title. A workflow that ran when issues were opened dropped the attacker-controlled title straight into a command, so an unauthenticated user could run code on the GitHub Actions runner and steal a Jira API token used by the automation. The notable twist is how the bug arrived: it was introduced days earlier by an AI tool meant to fix security issues, and an AI code reviewer approved the change. Snowflake fixed it by passing the title safely as an argument rather than expanding it into a command.
Novee Security showed at Black Hat that a GitHub issue opened by an account with no repository access could reach the CI runners behind major AI coding agents in their default configurations, tested against Claude Code, Gemini CLI, and Codex. The strongest, a Gemini CLI container-launcher command injection scored 10.0, runs code on the CI host before the sandbox starts. In Claude Code, a validator that stripped quoted text let a payload in a Git flag reach the runner, and a separate flaw leaked an API key through a download counter. Untrusted issue content reaching an agent that holds secrets and tools in the same runtime is the shared weakness.