Secnora INC

Secnora INC InfoSec Consulting + IT Security Training+Pe*******on Testing + Computer Forensics

๐Ÿ›ก๏ธ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ถ๐—บ๐—ฝ๐—ฟ๐—ผ๐˜ƒ๐—ฒ๐—บ๐—ฒ๐—ป๐˜ ๐—ถ๐˜€ ๐—ผ๐—ป๐—ฒ ๐—ผ๐—ณ ๐˜๐—ต๐—ฒ ๐—ต๐—ฎ๐—ฟ๐—ฑ๐—ฒ๐˜€๐˜ ๐˜๐—ต๐—ถ๐—ป๐—ด๐˜€ ๐˜๐—ผ ๐—บ๐—ฎ๐—ธ๐—ฒ ๐˜ƒ๐—ถ๐˜€๐—ถ๐—ฏ๐—น๐—ฒNot because it is not happening but because the stro...
05/27/2026

๐Ÿ›ก๏ธ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ถ๐—บ๐—ฝ๐—ฟ๐—ผ๐˜ƒ๐—ฒ๐—บ๐—ฒ๐—ป๐˜ ๐—ถ๐˜€ ๐—ผ๐—ป๐—ฒ ๐—ผ๐—ณ ๐˜๐—ต๐—ฒ ๐—ต๐—ฎ๐—ฟ๐—ฑ๐—ฒ๐˜€๐˜ ๐˜๐—ต๐—ถ๐—ป๐—ด๐˜€ ๐˜๐—ผ ๐—บ๐—ฎ๐—ธ๐—ฒ ๐˜ƒ๐—ถ๐˜€๐—ถ๐—ฏ๐—น๐—ฒ

Not because it is not happening but because the strongest evidence of progress in security is often the absence of something, the incident that never occurred, the access that was stopped before it was abused, the vulnerability that was remediated before someone else found it.

That makes conversations around security progress genuinely difficult.

Leadership teams want to see progress, Security leaders need to demonstrate it. Yet many of the numbers commonly reported in security programmes, such as vulnerabilities identified, patches applied and controls marked compliant, say little about how much harder the organisation is to compromise.

The more important question is "Is the organisation systematically becoming harder to compromise over time?"

In many organisations, the early warning signs are subtle at first.

Remediation backlogs begin growing faster than teams can close them. Incidents are identified externally before internal teams detect them. Access reviews happen once a year or sometimes less. Incident response plans exist on paper but have never been tested under real pressure. Third-party risk assessments are completed during onboarding and quietly forgotten afterward.

Security reporting continues upward but very little of it influences operational decisions on the ground. Over time, programmes that begin gaining traction start to look noticeably different.

๐Ÿ“ˆ Mean time to remediate trends downward across consecutive quarters
๐Ÿ” Incidents are detected earlier in the attack chain by internal teams
๐Ÿ”„ Access reviews run on a defined cycle with documented outcomes
๐Ÿงช Tabletop exercises expose gaps that are actually addressed afterward
๐Ÿค Third-party risk gets reassessed during renewals and scope changes
๐Ÿ“Š Security data starts driving decisions instead of simply satisfying reporting requirements

The shift between those two states is rarely dramatic. It does not come from a single engagement, tool deployment or investment. It comes from consistent, structured improvement and from measuring what matters rather than what is easiest to report.

Over time, the real indicator of progress is not the number of findings reported, it is whether attackers have fewer opportunities, less room to move and a harder time succeeding than they did six months earlier.

That kind of improvement is not always obvious while it is happening but when organisations begin detecting threats earlier, reducing remediation delays and turning security insights into action, the difference becomes visible, not just in reports or audits but in how resilient the environment becomes under real conditions.

๐ŸŽฏ The gap between security effort and visible progress is often smaller than it seems but harder to measure clearly.

๐Ÿ” ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐—ถ๐—ฒ๐˜€ ๐—ฆ๐—ฐ๐—ฎ๐—ป๐—ป๐—ฒ๐—ฑ ๐˜ƒ๐˜€ ๐—ฅ๐—ฒ๐—บ๐—ฒ๐—ฑ๐—ถ๐—ฎ๐˜๐—ฒ๐—ฑ: ๐—ช๐—ต๐˜† ๐—™๐—ถ๐—ป๐—ฑ๐—ถ๐—ป๐—ด ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐—ถ๐—ฒ๐˜€ ๐—œ๐˜€ ๐—ป๐—ผ๐˜ ๐—ฆ๐—ฎ๐˜ƒ๐—ถ๐—ป๐—ด ๐—ฌ๐—ผ๐˜‚๐—ฟ ๐—ก๐—ฒ๐˜๐˜„๐—ผ๐—ฟ๐—ธThe volume of publicly di...
05/25/2026

๐Ÿ” ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐—ถ๐—ฒ๐˜€ ๐—ฆ๐—ฐ๐—ฎ๐—ป๐—ป๐—ฒ๐—ฑ ๐˜ƒ๐˜€ ๐—ฅ๐—ฒ๐—บ๐—ฒ๐—ฑ๐—ถ๐—ฎ๐˜๐—ฒ๐—ฑ: ๐—ช๐—ต๐˜† ๐—™๐—ถ๐—ป๐—ฑ๐—ถ๐—ป๐—ด ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐—ถ๐—ฒ๐˜€ ๐—œ๐˜€ ๐—ป๐—ผ๐˜ ๐—ฆ๐—ฎ๐˜ƒ๐—ถ๐—ป๐—ด ๐—ฌ๐—ผ๐˜‚๐—ฟ ๐—ก๐—ฒ๐˜๐˜„๐—ผ๐—ฟ๐—ธ

The volume of publicly disclosed vulnerabilities continues to rise at a rapid pace. The public CVE ecosystem cataloged a record number of new vulnerabilities in 2025, a roughly 21% year-over-year jump. Yet many security teams still place strong emphasis on scan completion but in reality, scanning is only a diagnostic step. The real measure of security posture is the remediation gap, the time between detecting a flaw and actually patching it.

๐ŸŽฏ ๐—”๐˜๐˜๐—ฎ๐—ฐ๐—ธ๐—ฒ๐—ฟ๐˜€ ๐—ข๐˜‚๐˜๐—ฝ๐—ฎ๐—ฐ๐—ฒ ๐—–๐—ต๐—ฎ๐—ป๐—ด๐—ฒ ๐— ๐—ฎ๐—ป๐—ฎ๐—ด๐—ฒ๐—บ๐—ฒ๐—ป๐˜
For years, defenders operated with the assumption that they had weeks to deploy a patch. That reality has changed. Threat intelligence shows the median time for attackers to exploit a newly disclosed vulnerability has dropped significantly. Many critical flaws are now weaponized in the wild before an official patch is even finalized. While teams route requests through rigid change management processes, automated botnets can deploy exploits within hours.

๐Ÿ”ฎ ๐—ง๐—ต๐—ฒ ๐—œ๐—น๐—น๐˜‚๐˜€๐—ถ๐—ผ๐—ป ๐—ผ๐—ณ ๐—–๐—ผ๐—บ๐—ฝ๐—น๐—ถ๐—ฎ๐—ป๐—ฐ๐—ฒ
Organizations often highlight automated scans with dashboards tracking discovered CVEs and exposures. But visibility alone does not reduce risk. Identifying vulnerabilities is important, yet it only marks the start of the process. Many enterprises still face delays in remediating high-severity vulnerabilities, leaving exposure windows open longer than intended. Frequent scanning without fast remediation creates a gap between awareness and actual risk reduction.

๐Ÿ“ฅ ๐—ฃ๐—ฟ๐—ถ๐—ผ๐—ฟ๐—ถ๐˜๐˜† ๐—™๐—ฎ๐˜๐—ถ๐—ด๐˜‚๐—ฒ ๐—ฎ๐—ป๐—ฑ ๐—”๐—น๐—ฒ๐—ฟ๐˜ ๐—ข๐˜ƒ๐—ฒ๐—ฟ๐—น๐—ผ๐—ฎ๐—ฑ
The remediation gap is often less about effort and more about prioritization. When a single scan generates thousands of "critical" alerts, engineering teams can quickly experience alert fatigue. Treating every issue as equally urgent makes it harder to focus on vulnerabilities with the highest real-world risk. Without proper context around exploitability, exposure and business impact, remediation queues grow, priorities blur and MTTR increases.

๐Ÿ› ๏ธ ๐—–๐—น๐—ผ๐˜€๐—ถ๐—ป๐—ด ๐˜๐—ต๐—ฒ ๐—š๐—ฎ๐—ฝ: ๐—™๐—ฟ๐—ผ๐—บ ๐—œ๐—ป๐—ด๐—ฒ๐˜€๐˜๐—ถ๐—ผ๐—ป ๐˜๐—ผ ๐—”๐—ฐ๐˜๐—ถ๐—ผ๐—ป
To shrink the risk window, organizations must shift focus from scan frequency to operational ex*****on:
โ€ข Risk-Based Prioritization: Cross-reference scan results with real-world threat intel to fix what is actively being weaponized first.
โ€ข Validate Reachability: Verify if the vulnerable component is actually exposed to the network before demanding downtime.
โ€ข Align KPIs: Security and IT teams should share a unified metric tied directly to MTTR for critical systems.

โš ๏ธ Finding vulnerabilities is not enough, reducing risk depends on how quickly issues are fixed, not how much is scanned.

๐Ÿšจ ๐—ง๐—ต๐—ฒ ๐—œ๐—ป๐˜€๐˜๐—ฟ๐˜‚๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ'๐˜€ ๐—–๐—ฎ๐—ป๐˜ƒ๐—ฎ๐˜€ ๐—Ÿ๐— ๐—ฆ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—œ๐—ป๐—ฐ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜When a centralized cloud platform experiences a security incident, the r...
05/22/2026

๐Ÿšจ ๐—ง๐—ต๐—ฒ ๐—œ๐—ป๐˜€๐˜๐—ฟ๐˜‚๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ'๐˜€ ๐—–๐—ฎ๐—ป๐˜ƒ๐—ฎ๐˜€ ๐—Ÿ๐— ๐—ฆ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—œ๐—ป๐—ฐ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜

When a centralized cloud platform experiences a security incident, the ripple effects can impact many organizations that rely on it. A recent security event involving Instructure's Canvas LMS where the threat actor group ShinyHunters claimed to have accessed ~3.65 terabytes of system data across ~8,809 institutional domains, highlights why managing third-party platform risk is so important for modern organizations.

๐ŸŒ ๐—ง๐—ต๐—ฒ ๐—ฅ๐—ฒ๐—ฎ๐—น "๐—•๐—น๐—ฎ๐˜€๐˜ ๐—ฅ๐—ฎ๐—ฑ๐—ถ๐˜‚๐˜€" ๐—ผ๐—ณ ๐— ๐—ฒ๐˜๐—ฎ๐—ฑ๐—ฎ๐˜๐—ฎ
While Instructure confirmed that high-risk fields like passwords and financial data were untouched, unauthorized access targeted a massive footprint of system logs. Exposed fields included usernames, email addresses, course names, student IDs and internal platform user messages. Exposing private communications creates a long-tail risk for targeted phishing and downstream social engineering against users.

โš ๏ธ ๐—ข๐—ฝ๐—ฒ๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐—ฎ๐—น ๐—ฃ๐—ฎ๐—ฟ๐—ฎ๐—น๐˜†๐˜€๐—ถ๐˜€ ๐——๐˜‚๐—ฟ๐—ถ๐—ป๐—ด ๐—–๐—ฟ๐—ถ๐˜๐—ถ๐—ฐ๐—ฎ๐—น ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€
To contain the incident, Instructure temporarily placed the platform into maintenance mode. Occurring during a busy academic window, this required local IT teams to quickly rotate system integrations, single sign-on (SSO) connectors and API keys to secure their local networks. This period of transition also highlighted the importance of user vigilance against potential follow-up phishing attempts impersonating school administrators.

๐Ÿค ๐—ง๐—ต๐—ฒ ๐—ฅ๐—ฒ๐—ฎ๐—น๐—ถ๐˜๐˜† ๐—ผ๐—ณ "๐—ฅ๐—ฒ๐˜€๐—ผ๐—น๐˜‚๐˜๐—ถ๐—ผ๐—ป ๐—”๐—ด๐—ฟ๐—ฒ๐—ฒ๐—บ๐—ฒ๐—ป๐˜๐˜€"
To resolve the incident, Instructure reached a system-wide agreement with the threat actor, receiving digital "shred logs" to confirm the data's deletion. While this unified approach helps shield individual institutions from secondary extortion, relying on a threat actor's assurances naturally introduces a long tail of residual compliance and verification risk for risk leaders to navigate.

๐Ÿ” ๐—ฅ๐—ฒ๐—ฐ๐—ผ๐—บ๐—บ๐—ฒ๐—ป๐—ฑ๐—ฒ๐—ฑ ๐—ฃ๐—ฟ๐—ฒ๐—ฐ๐—ฎ๐˜‚๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐—ณ๐—ผ๐—ฟ ๐—–๐—ฎ๐—ป๐˜ƒ๐—ฎ๐˜€ ๐—จ๐˜€๐—ฒ๐—ฟ๐˜€
โ€ข Stay alert for phishing emails or fake messages impersonating Canvas or school staff.
โ€ข Reset your Canvas password and any accounts using the same credentials.
โ€ข Monitor accounts for suspicious activity or identity misuse.
โ€ข Access school platforms directly instead of clicking shared links.
โ€ข Report suspicious activity to your IT or security team immediately.

๐Ÿ›ก๏ธ ๐—ž๐—ฒ๐˜† ๐—ง๐—ฎ๐—ธ๐—ฒ๐—ฎ๐˜„๐—ฎ๐˜†๐˜€
โ€ข Audit whether free, trial or unmanaged user tiers are strictly isolated from enterprise production environments to prevent privilege escalation.
โ€ข Treat internal chat and message logs as Tier-1 high-risk data during vendor procurement.
โ€ข Always have a backup operational workflow for when a critical third-party system suddenly goes dark.

๐Ÿšจ ๐—š๐—ถ๐˜๐—›๐˜‚๐—ฏ ๐—–๐—ผ๐—ป๐—ณ๐—ถ๐—ฟ๐—บ๐˜€ ๐—•๐—ฟ๐—ฒ๐—ฎ๐—ฐ๐—ต: ~๐Ÿฏ,๐Ÿด๐Ÿฌ๐Ÿฌ ๐—œ๐—ป๐˜๐—ฒ๐—ฟ๐—ป๐—ฎ๐—น ๐—ฅ๐—ฒ๐—ฝ๐—ผ๐˜€๐—ถ๐˜๐—ผ๐—ฟ๐—ถ๐—ฒ๐˜€ ๐—•๐—ฟ๐—ฒ๐—ฎ๐—ฐ๐—ต๐—ฒ๐—ฑ ๐˜ƒ๐—ถ๐—ฎ ๐—ฃ๐—ผ๐—ถ๐˜€๐—ผ๐—ป๐—ฒ๐—ฑ ๐—ฉ๐—ฆ ๐—–๐—ผ๐—ฑ๐—ฒ ๐—˜๐˜…๐˜๐—ฒ๐—ป๐˜€๐—ถ๐—ผ๐—ปGitHub has officially conf...
05/21/2026

๐Ÿšจ ๐—š๐—ถ๐˜๐—›๐˜‚๐—ฏ ๐—–๐—ผ๐—ป๐—ณ๐—ถ๐—ฟ๐—บ๐˜€ ๐—•๐—ฟ๐—ฒ๐—ฎ๐—ฐ๐—ต: ~๐Ÿฏ,๐Ÿด๐Ÿฌ๐Ÿฌ ๐—œ๐—ป๐˜๐—ฒ๐—ฟ๐—ป๐—ฎ๐—น ๐—ฅ๐—ฒ๐—ฝ๐—ผ๐˜€๐—ถ๐˜๐—ผ๐—ฟ๐—ถ๐—ฒ๐˜€ ๐—•๐—ฟ๐—ฒ๐—ฎ๐—ฐ๐—ต๐—ฒ๐—ฑ ๐˜ƒ๐—ถ๐—ฎ ๐—ฃ๐—ผ๐—ถ๐˜€๐—ผ๐—ป๐—ฒ๐—ฑ ๐—ฉ๐—ฆ ๐—–๐—ผ๐—ฑ๐—ฒ ๐—˜๐˜…๐˜๐—ฒ๐—ป๐˜€๐—ถ๐—ผ๐—ป

GitHub has officially confirmed a major security breach resulting from a targeted cyberattack revealing that threat actors successfully exfiltrated data from approximately ~3,800 internal code repositories. The incident highlights an increasingly sophisticated trend of targeting developer environments to bypass robust corporate network defenses.

๐Ÿ” ๐—ช๐—ต๐—ฎ๐˜ ๐—›๐—ฎ๐—ฝ๐—ฝ๐—ฒ๐—ป๐—ฒ๐—ฑ
GitHub detected the breach on 19 May 2026 and went public a day later. Github said it "detected and contained a compromise of an employee device involving a poisoned VS Code extension", referring to a malicious plug-in for the popular Visual Studio Code editor, the entry point that gave attackers access to internal repos.

๐Ÿ‘ฅ ๐—ช๐—ต๐—ผ ๐—–๐—น๐—ฎ๐—ถ๐—บ๐—ฒ๐—ฑ ๐—œ๐˜
TeamPCP, a financially motivated cybercrime group tracked by Google Threat Intelligence as UNC6780 has claimed responsibility. The group listed GitHub's stolen source code and internal organisation data for sale on a cybercrime forum with an initial asking price of over ~$95,000, specifying this is a direct data sale rather than a traditional ransomware extortion scheme.

๐Ÿ›ก๏ธ ๐—š๐—ถ๐˜๐—›๐˜‚๐—ฏ'๐˜€ ๐—ฅ๐—ฒ๐˜€๐—ฝ๐—ผ๐—ป๐˜€๐—ฒ
GitHub immediately removed the malicious extension version, isolated the affected device and activated its incident response procedures. The platform also spent the night rotating high-impact credentials and cryptographic keys to revoke the threat actors' access. GitHub said it has "no evidence of impact to customer information stored outside of GitHub's internal repositories", though the investigation is ongoing.

๐Ÿ“ˆ ๐—ง๐—ต๐—ฒ ๐—•๐—ถ๐—ด๐—ด๐—ฒ๐—ฟ ๐—ฃ๐—ถ๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ
TeamPCP has compromised Trivy, Checkmarx, Bitwarden CLI, TanStack and now GitHub, all in 2026, all through developer tooling. The pattern is clear, attackers are targeting developer workstations as the path of least resistance into supply chains.

๐Ÿ’ก ๐—ง๐—ต๐—ฒ ๐—ง๐—ฎ๐—ธ๐—ฒ๐—ฎ๐˜„๐—ฎ๐˜†
โ€ข The Single Point of Failure: A single malicious VS Code extension installed on just one employee's workstation was all it took for threat actors to compromise internal GitHub repositories.
โ€ข The Reality of Modern Dev Workflows: Almost every engineering team heavily relies on IDE extensions to boost productivity, making this a widespread, systemic vulnerability across the industry.
โ€ข Audit and Inventory: It is critical to immediately audit all installed extensions across your development team to identify unauthorized, outdated or unverified tools.
โ€ข Restrict and Whitelist: Establish a strict security policy that limits installations exclusively to vetted, trusted publishers within official marketplaces.
โ€ข Secure the Workstation: Developer endpoints are critical assets, securing local environments is now as important as securing production infrastructure.

๐ŸŒ Europe came to Dallas - Culture, Connection and Collaboration, all in one unforgettable evening!Last week, we had the ...
05/20/2026

๐ŸŒ Europe came to Dallas - Culture, Connection and Collaboration, all in one unforgettable evening!

Last week, we had the pleasure of celebrating Europe Day at Experience EUROPE 2026 in Dallas and it was truly an evening to remember. Hosted at the stunning Marie Gabrielle Restaurant and Gardens in the Harwood District, the event brought together business leaders, entrepreneurs and cultural enthusiasts from across the Atlantic for a night that felt both inspiring and deeply meaningful.

The atmosphere was electric. From authentic European cuisine and premium wines to vibrant country booths, live entertainment and thought-provoking conversations, every corner of the evening reflected the richness of European culture and the strength of transatlantic relationships.

Building meaningful connections across borders, bridging European expertise with American opportunity and being part of a community that believes in the power of collaboration. That is exactly what made this event so meaningful. We connected with incredible people from across industries and countries, had conversations that sparked new ideas and were reminded of the immense potential that comes when Europe and America come together

A heartfelt thank you to the European American Chamber of Commerce Texas for curating such a memorable experience and for championing the European community in Dallas. โœจ

๐Ÿšจ ๐—ง๐—ต๐—ฒ "๐— ๐—ถ๐—ป๐—ถ ๐—ฆ๐—ต๐—ฎ๐—ถ-๐—›๐˜‚๐—น๐˜‚๐—ฑ" ๐—ช๐—ผ๐—ฟ๐—บ ๐—ฆ๐˜๐—ฟ๐—ถ๐—ธ๐—ฒ๐˜€ ๐—”๐—ด๐—ฎ๐—ถ๐—ป, ๐—œ๐—บ๐—ฝ๐—ฎ๐—ฐ๐˜๐—ถ๐—ป๐—ด ๐—ง๐—ฎ๐—ป๐—ฆ๐˜๐—ฎ๐—ฐ๐—ธ, ๐—จ๐—ถ๐—ฃ๐—ฎ๐˜๐—ต & ๐— ๐—ถ๐˜€๐˜๐—ฟ๐—ฎ๐—น ๐—”๐—œ ๐—˜๐—ฐ๐—ผ๐˜€๐˜†๐˜€๐˜๐—ฒ๐—บ๐˜€If your organization relie...
05/19/2026

๐Ÿšจ ๐—ง๐—ต๐—ฒ "๐— ๐—ถ๐—ป๐—ถ ๐—ฆ๐—ต๐—ฎ๐—ถ-๐—›๐˜‚๐—น๐˜‚๐—ฑ" ๐—ช๐—ผ๐—ฟ๐—บ ๐—ฆ๐˜๐—ฟ๐—ถ๐—ธ๐—ฒ๐˜€ ๐—”๐—ด๐—ฎ๐—ถ๐—ป, ๐—œ๐—บ๐—ฝ๐—ฎ๐—ฐ๐˜๐—ถ๐—ป๐—ด ๐—ง๐—ฎ๐—ป๐—ฆ๐˜๐—ฎ๐—ฐ๐—ธ, ๐—จ๐—ถ๐—ฃ๐—ฎ๐˜๐—ต & ๐— ๐—ถ๐˜€๐˜๐—ฟ๐—ฎ๐—น ๐—”๐—œ ๐—˜๐—ฐ๐—ผ๐˜€๐˜†๐˜€๐˜๐—ฒ๐—บ๐˜€

If your organization relies on TanStack, UiPath or Mistral AI, this incident highlights how modern supply chain attacks can quickly evolve beyond a developer-level issue into a broader enterprise security concern. Recent activity linked to TeamPCP demonstrates how attackers are targeting npm ecosystems and CI/CD infrastructure to distribute self-propagating malicious packages through trusted software pipelines.

๐Ÿ—๏ธ ๐—ง๐—ต๐—ฒ ๐—ข๐—ฟ๐—ด๐—ฎ๐—ป๐—ถ๐˜‡๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐—ฎ๐—น ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜: ๐—–๐—œ/๐—–๐—— ๐—œ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐˜๐˜† ๐—ง๐—ต๐—ฒ๐—ณ๐˜
The breach bypassed MFA and traditional password theft by targeting the build environment identity layer. A triple-vulnerability chain in GitHub Actions enabled a malicious pull request, cache poisoning via a compromised pnpm store and OIDC token exposure from runner process memory. Using these tokens, malicious package versions were published to npm without compromising account passwords or additional authentication controls.

๐Ÿ› ๐—ง๐—ต๐—ฒ ๐—ฃ๐—ฎ๐˜†๐—น๐—ผ๐—ฎ๐—ฑ: ๐—˜๐—ฐ๐—ผ๐˜€๐˜†๐˜€๐˜๐—ฒ๐—บ ๐—–๐—ผ๐—ป๐˜๐—ฎ๐—ด๐—ถ๐—ผ๐—ป
โ€ข Credential Siphoning: It targets AWS IMDSv2, GCP, Azure cloud metadata, Kubernetes service accounts, HashiCorp Vault secrets and CI/CD tokens such as GitHub Actions, GitLab or CircleCI.
โ€ข Self-Propagation: It uses stolen corporate tokens to access other writable registries and repositories and automatically publish poisoned updates to spread further.
โ€ข Evasive C2: Exfiltration uses a "Triple C2" setup involving git-tanstack[.]com, Session messenger network getsession[.]org and GitHub API dead drops.

๐Ÿ’ฃ ๐—ง๐—ต๐—ฒ ๐—ฅ๐—ฎ๐—ป๐˜€๐—ผ๐—บ๐˜„๐—ฎ๐—ฟ๐—ฒ-๐—ฆ๐˜๐˜†๐—น๐—ฒ ๐—ฅ๐—ฒ๐˜๐—ฎ๐—น๐—ถ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ง๐—ฟ๐—ถ๐—ด๐—ด๐—ฒ๐—ฟ
The malware establishes persistence on developer endpoints through a hidden gh-token-monitor background service that continuously validates GitHub tokens. Revoking a compromised token before removing the service may trigger a destructive rm -rf ~/ routine capable of wiping the userโ€™s home directory.

๐Ÿ› ๏ธ ๐—ฆ๐˜๐—ฒ๐—ฝ-๐—ฏ๐˜†-๐—ฆ๐˜๐—ฒ๐—ฝ ๐— ๐—ถ๐˜๐—ถ๐—ด๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ฃ๐—ฟ๐—ผ๐˜๐—ผ๐—ฐ๐—ผ๐—น
To help neutralize this threat across the organization, engineering teams should follow these steps:
โ€ข Neutralize Persistence First: Scan systems for the hidden gh-token-monitor background service in macOS LaunchAgents or Linux systemd user services and remove it before revoking GitHub tokens.
โ€ข Audit Lockfiles & IDE Directories: Search lockfiles and CI logs for affected package versions. Inspect .claude/ and .vscode/directories for persistence artifacts like 'router_runtime.js' or 'setup.mjs' which may remain after npm uninstall.
โ€ข Block Network Exfiltration: Block traffic to git-tanstack[.]com and getsession[.]org at corporate DNS/proxy level.
โ€ข Purge & Rotate: Once the local environment is verified clean, revoke and rotate all affected cloud credentials, npm tokens and GitHub secrets.

Four years in a row as a CREST-accredited firm and for SECNORA, that is more than a badge. It means our methodologies, g...
05/18/2026

Four years in a row as a CREST-accredited firm and for SECNORA, that is more than a badge. It means our methodologies, governance, technical capabilities and ethics are independently reviewed and re-validated every year, not claimed once and left unchecked.

Grateful to the team that puts in the work behind the scenes and to the clients who keep pushing us to raise the bar.

SECNORAยฎ continues to maintain CREST accreditation across:
๐Ÿ” Pe*******on Testing
๐Ÿ“ฑ CREST OVS Mobile Applications
๐ŸŒ CREST OVS Web Applications
๐Ÿ”Ž Vulnerability Assessment

For the organisations we work with, this means engagements backed by independently assessed methodologies, validated technical standards, and consistent delivery quality.

This recognition reflects our long-term focus on practical, high-quality cybersecurity services that help organisations strengthen security, manage risk, and build resilience with confidence.

โžก๏ธ Swipe through to see what CREST accreditation means and why it matters.

*******onTesting

Episode 10 of Secure by Design, published by SECNORAยฎ is here. ๐ŸŽ™๏ธAnd this one feels like a true milestone.Daniel Kulig, ...
05/15/2026

Episode 10 of Secure by Design, published by SECNORAยฎ is here. ๐ŸŽ™๏ธ
And this one feels like a true milestone.

Daniel Kulig, the host of Secure by Design, had the privilege of speaking with Winn Schwartau - one of the original voices in cybersecurity, information warfare, and cyber risk thinking.

The episode title asks a powerful question:

"Are We Still Defending Systems, or Are We Now Defending Reality?"

Because cybersecurity is no longer only about networks, endpoints, firewalls, passwords, and compliance checklists.

It is also about trust.
What people believe.
What organizations accept as true.
How AI, misinformation, manipulation, immersive technologies, and cognitive attacks are changing the battlefield.

This conversation goes deeper than traditional cybersecurity.
It asks whether we are still protecting technology - or whether we are now also protecting human perception, decision-making, and reality itself.

This episode is worth listening to not only for CISOs and cybersecurity professionals, but also for founders, executives, board members, investors, and anyone leading in the AI era.

Letโ€™s make commotion around conversations that matter. ๐Ÿ”

Secure by Design Podcast
Publisher: SECNORAยฎ
Host: Daniel Kulig
Guest: Winn Schwartau
Episode 10: Are We Still Defending Systems, or Are We Now Defending Reality?

๐ŸŽง Watch/listen here: https://open.spotify.com/episode/75HGp4z0Aa2Msc1YyENJqo?si=gFYRmBE8RtC6VNxbUs9hIQ&nd=1&dlsi=b613034040e24c4d

๐Ÿ›ก๏ธ ๐—™๐—ฟ๐—ผ๐—บ ๐—ข๐—ป๐—ฒ ๐—Ÿ๐—ผ๐—ด๐—ถ๐—ป ๐˜๐—ผ ๐—™๐˜‚๐—น๐—น ๐—–๐—ผ๐—บ๐—ฝ๐—ฟ๐—ผ๐—บ๐—ถ๐˜€๐—ฒ: ๐—›๐—ผ๐˜„ ๐—”๐˜€๐˜€๐˜‚๐—บ๐—ฒ๐—ฑ ๐—ง๐—ฟ๐˜‚๐˜€๐˜ ๐—ง๐˜‚๐—ฟ๐—ป๐˜€ ๐—œ๐—ป๐˜๐—ผ ๐—ฎ ๐—•๐—ฟ๐—ฒ๐—ฎ๐—ฐ๐—ตMost breaches do not begin with malware or br...
05/13/2026

๐Ÿ›ก๏ธ ๐—™๐—ฟ๐—ผ๐—บ ๐—ข๐—ป๐—ฒ ๐—Ÿ๐—ผ๐—ด๐—ถ๐—ป ๐˜๐—ผ ๐—™๐˜‚๐—น๐—น ๐—–๐—ผ๐—บ๐—ฝ๐—ฟ๐—ผ๐—บ๐—ถ๐˜€๐—ฒ: ๐—›๐—ผ๐˜„ ๐—”๐˜€๐˜€๐˜‚๐—บ๐—ฒ๐—ฑ ๐—ง๐—ฟ๐˜‚๐˜€๐˜ ๐—ง๐˜‚๐—ฟ๐—ป๐˜€ ๐—œ๐—ป๐˜๐—ผ ๐—ฎ ๐—•๐—ฟ๐—ฒ๐—ฎ๐—ฐ๐—ต

Most breaches do not begin with malware or brute force. They begin with a valid login. Stolen credentials, Adversary-in-the-Middle (AiTM) phishing and session token theft allow attackers to inherit the trust of legitimate users and operate as insiders.

Once that trust is established, the path to a full breach can unfold quickly. A single compromised account can move from initial access to organization-wide impact before defenders recognize what is happening.

1๏ธโƒฃ ๐—œ๐—ป๐—ถ๐˜๐—ถ๐—ฎ๐—น ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€: ๐—Ÿ๐—ผ๐—ด๐—ด๐—ถ๐—ป๐—ด ๐—œ๐—ป, ๐—ก๐—ผ๐˜ ๐—•๐—ฟ๐—ฒ๐—ฎ๐—ธ๐—ถ๐—ป๐—ด ๐—œ๐—ป
Attackers bypass MFA through AiTM phishing, token theft or session hijacking. Instead of exploiting vulnerabilities, they simply authenticate with a valid session and immediately gain the same access and trust as the legitimate user.

2๏ธโƒฃ ๐—ฆ๐—ถ๐—น๐—ฒ๐—ป๐˜ ๐—ฅ๐—ฒ๐—ฐ๐—ผ๐—ป๐—ป๐—ฎ๐—ถ๐˜€๐˜€๐—ฎ๐—ป๐—ฐ๐—ฒ: ๐— ๐—ฎ๐—ฝ๐—ฝ๐—ถ๐—ป๐—ด ๐˜๐—ต๐—ฒ ๐—˜๐—ป๐˜ƒ๐—ถ๐—ฟ๐—ผ๐—ป๐—บ๐—ฒ๐—ป๐˜
Using tools such as Burp Suite Proxy, Nmap, LinPEAS/ WinPEAS, PowerShell, WMI and RDP, attackers enumerate users, systems, group memberships, permissions and sensitive data stores while blending into normal administrative activity.

3๏ธโƒฃ ๐—ฃ๐—ฟ๐—ถ๐˜ƒ๐—ถ๐—น๐—ฒ๐—ด๐—ฒ ๐—˜๐˜€๐—ฐ๐—ฎ๐—น๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ฎ๐—ป๐—ฑ ๐—Ÿ๐—ฎ๐˜๐—ฒ๐—ฟ๐—ฎ๐—น ๐— ๐—ผ๐˜ƒ๐—ฒ๐—บ๐—ฒ๐—ป๐˜
Misconfigured permissions, cached credentials and over-privileged service accounts allow attackers to escalate privileges, move across systems and establish persistence beyond the initially compromised account.

4๏ธโƒฃ ๐——๐—ฎ๐˜๐—ฎ ๐—˜๐˜…๐—ณ๐—ถ๐—น๐˜๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ผ๐—ฟ ๐—ฅ๐—ฎ๐—ป๐˜€๐—ผ๐—บ๐˜„๐—ฎ๐—ฟ๐—ฒ ๐——๐—ฒ๐—ฝ๐—น๐—ผ๐˜†๐—บ๐—ฒ๐—ป๐˜
With elevated access, attackers stage sensitive data for exfiltration or deploy ransomware against critical systems, often disabling logs and security controls to delay detection and response.

5๏ธโƒฃ ๐—™๐˜‚๐—น๐—น ๐—–๐—ผ๐—บ๐—ฝ๐—ฟ๐—ผ๐—บ๐—ถ๐˜€๐—ฒ: ๐—ข๐—ฝ๐—ฒ๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐—ฎ๐—น ๐—ฎ๐—ป๐—ฑ ๐—•๐˜‚๐˜€๐—ถ๐—ป๐—ฒ๐˜€๐˜€ ๐—œ๐—บ๐—ฝ๐—ฎ๐—ฐ๐˜
What began as a single hijacked session can evolve into a company-wide incident involving operational disruption, financial loss, regulatory scrutiny and long-term reputational damage.

โš ๏ธ ๐—ช๐—ต๐˜† ๐—ง๐—ฟ๐—ฎ๐—ฑ๐—ถ๐˜๐—ถ๐—ผ๐—ป๐—ฎ๐—น ๐——๐—ฒ๐—ณ๐—ฒ๐—ป๐˜€๐—ฒ๐˜€ ๐—™๐—ฎ๐—น๐—น ๐—ฆ๐—ต๐—ผ๐—ฟ๐˜
Most defenses were built for a different threat:
โ€ข Firewalls stop unknown traffic, not authenticated sessions.
โ€ข MFA stops password theft, not token theft or AiTM.
โ€ข SIEMs flag anomalies but living-off-the-land looks normal.
โ€ข Least privilege is policy but over-provisioning is reality.

๐Ÿ” ๐—›๐—ผ๐˜„ ๐˜๐—ผ ๐—•๐—ฟ๐—ฒ๐—ฎ๐—ธ ๐˜๐—ต๐—ฒ ๐—–๐—ต๐—ฎ๐—ถ๐—ป
โ€ข Implement Zero Trust and continuously verify every access request.
โ€ข Deploy phishing-resistant MFA such as FIDO2 for privileged accounts.
โ€ข Enforce least privilege and review standing access regularly.
โ€ข Monitor for anomalous behavior, impossible travel and bulk downloads.
โ€ข Use Identity Threat Detection and Response (ITDR) to identify account abuse.

๐ŸŽฏ The question is no longer "Can attackers get in?" but "How far can they laterally move within the network?โ€

๐Ÿšจ ๐—ฃ๐—ฎ๐˜๐—ฐ๐—ต๐—ถ๐—ป๐—ด ๐—–๐—ฉ๐—˜๐˜€ ๐—ถ๐˜€ ๐—ป๐—ผ๐˜ ๐˜๐—ต๐—ฒ ๐˜€๐—ฎ๐—บ๐—ฒ ๐—ฎ๐˜€ ๐—ฐ๐—น๐—ผ๐˜€๐—ถ๐—ป๐—ด ๐—ฒ๐˜…๐—ฝ๐—ผ๐˜€๐˜‚๐—ฟ๐—ฒ๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—ฎ ๐—ณ๐˜‚๐—น๐—น๐˜† ๐—ฝ๐—ฎ๐˜๐—ฐ๐—ต๐—ฒ๐—ฑ ๐—ฒ๐—ป๐˜ƒ๐—ถ๐—ฟ๐—ผ๐—ป๐—บ๐—ฒ๐—ป๐˜ ๐—ฐ๐—ฎ๐—ป ๐˜€๐˜๐—ถ๐—น๐—น ๐—ฏ๐—ฒ ๐—ต๐—ถ๐—ด๐—ต๐—น๐˜† ๐—ฒ๐˜…๐—ฝ๐—น๐—ผ๐—ถ๐˜๐—ฎ๐—ฏ๐—น๐—ฒ.Tha...
05/11/2026

๐Ÿšจ ๐—ฃ๐—ฎ๐˜๐—ฐ๐—ต๐—ถ๐—ป๐—ด ๐—–๐—ฉ๐—˜๐˜€ ๐—ถ๐˜€ ๐—ป๐—ผ๐˜ ๐˜๐—ต๐—ฒ ๐˜€๐—ฎ๐—บ๐—ฒ ๐—ฎ๐˜€ ๐—ฐ๐—น๐—ผ๐˜€๐—ถ๐—ป๐—ด ๐—ฒ๐˜…๐—ฝ๐—ผ๐˜€๐˜‚๐—ฟ๐—ฒ๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—ฎ ๐—ณ๐˜‚๐—น๐—น๐˜† ๐—ฝ๐—ฎ๐˜๐—ฐ๐—ต๐—ฒ๐—ฑ ๐—ฒ๐—ป๐˜ƒ๐—ถ๐—ฟ๐—ผ๐—ป๐—บ๐—ฒ๐—ป๐˜ ๐—ฐ๐—ฎ๐—ป ๐˜€๐˜๐—ถ๐—น๐—น ๐—ฏ๐—ฒ ๐—ต๐—ถ๐—ด๐—ต๐—น๐˜† ๐—ฒ๐˜…๐—ฝ๐—น๐—ผ๐—ถ๐˜๐—ฎ๐—ฏ๐—น๐—ฒ.

That blind spot is exactly where modern attacks accelerate, not through unpatched systems but through reachable paths security programs never measured.

Security leaders often see positive indicators across the board. Critical systems patched. Compliance targets met. Dashboards showing steady progress. Yet in many environments, an attacker can still compromise an internet-facing service and move toward critical internal systems within minutes.

The patches were applied but the exposure remained.

Because a CVE is a flaw in a component. An exposure is something different entirely, it is a reachable condition inside your specific environment, shaped by network paths, trust relationships, identity privileges, segmentation gaps and blast radius. One exists in a scanner report and the other one exists in the architecture attackers actually operate against.

This is where most programs create their blind spots. ๐ŸŽฏ

CVSS scores measure severity in isolation, not real exploitability. A vulnerability having a CVSS score of 9.8 on an isolated system may get urgent attention, while one with a CVSS score of 6.2 on an internet-facing asset with weak segmentation and lateral movement stays open despite presenting a more realistic attack path.

Patch metrics improve but attackers do not operate against patch statistics, they operate against reachable attack paths.

The most effective security teams are shifting from patching velocity to attack path visibility by asking how attackers could realistically move through the environment and create impact:

๐Ÿ” Visibility into what is actually reachable matters more than raw vulnerability counts because not every finding exists on a surface an attacker can access.

๐Ÿงฉ Understanding what is realistically exploitable requires context beyond severity scores including environmental conditions, identity exposure and control gaps.

๐Ÿ›ฃ๏ธ Identifying what creates a viable path to impact is where real risk reduction happens especially through weak segmentation, trust relationships and lateral movement.

The environments that prove hardest to compromise are rarely the ones with the fewest vulnerabilities. They are the ones where exposure paths are constrained, lateral movement is limited and critical assets are difficult to reach even after initial access.

Real security maturity is not built through patch volume alone. It comes from understanding how attackers navigate the environment and systematically reducing the conditions that allow small weaknesses to become operational compromise.

โš ๏ธ If your program cannot clearly answer what an attacker can actually reach right now, the dashboard may be measuring compliance more than security.

๐Ÿ›ก๏ธ ๐—ฅ๐—ฒ๐—ฎ๐—น ๐—ฃ๐—ฎ๐˜๐˜๐—ฒ๐—ฟ๐—ป๐˜€ ๐—™๐—ฟ๐—ผ๐—บ ๐—ฅ๐—ฒ๐—ฎ๐—น ๐—˜๐—ป๐˜ƒ๐—ถ๐—ฟ๐—ผ๐—ป๐—บ๐—ฒ๐—ป๐˜๐˜€: ๐—ช๐—ต๐—ฒ๐—ฟ๐—ฒ ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ ๐——๐—ฒ๐—ณ๐—ฒ๐—ป๐—ฐ๐—ฒ ๐—”๐—ฐ๐˜๐˜‚๐—ฎ๐—น๐—น๐˜† ๐—•๐—ฟ๐—ฒ๐—ฎ๐—ธ๐˜€ ๐——๐—ผ๐˜„๐—ปMost organisations today have invested ...
05/08/2026

๐Ÿ›ก๏ธ ๐—ฅ๐—ฒ๐—ฎ๐—น ๐—ฃ๐—ฎ๐˜๐˜๐—ฒ๐—ฟ๐—ป๐˜€ ๐—™๐—ฟ๐—ผ๐—บ ๐—ฅ๐—ฒ๐—ฎ๐—น ๐—˜๐—ป๐˜ƒ๐—ถ๐—ฟ๐—ผ๐—ป๐—บ๐—ฒ๐—ป๐˜๐˜€: ๐—ช๐—ต๐—ฒ๐—ฟ๐—ฒ ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ ๐——๐—ฒ๐—ณ๐—ฒ๐—ป๐—ฐ๐—ฒ ๐—”๐—ฐ๐˜๐˜‚๐—ฎ๐—น๐—น๐˜† ๐—•๐—ฟ๐—ฒ๐—ฎ๐—ธ๐˜€ ๐——๐—ผ๐˜„๐—ป

Most organisations today have invested in tooling, governance, monitoring and response capabilities. Yet many security incidents still trace back to areas that were assumed to be functioning correctly.

The challenge is often not the absence of security controls. It is maintaining visibility into how those controls actually operate as the environment, teams, vendors and business priorities continue to evolve.

Some recurring patterns tend to surface during assessments and response engagements:

๐Ÿ”“ Visibility without context: Detection tools are running, logs are being collected and alerts are firing but there is limited understanding of what normal activity actually looks like within that environment. The alert may exist but the surrounding operational context is often missing.

๐Ÿšช Access that outlasted the person: Roles change. Vendors rotate out. Team members leave. In some cases, access remains active longer than intended because deprovisioning processes did not fully keep pace with operational changes.

๐Ÿ“‹ Incident response plans that were never exercised: Plans may be documented, approved and reviewed regularly. But practical exercises can still reveal outdated escalation paths, unclear ownership or decision-making processes that become difficult under pressure.

๐Ÿ”— Third-party exposure with limited ongoing oversight: Initial onboarding and assessments are often completed thoroughly. Ongoing reassessment, however, may become less consistent over time, especially as vendor scope or business dependencies evolve.

โš–๏ธ The gap between policy and practice: Policies are usually written with good intent, but organisations move quickly. Over time, operational reality can drift from documented governance as teams prioritise delivery, scale and speed.

In many cases, risk does not emerge from a single major failure.

It develops gradually through small gaps that remain unchecked for long periods of time. A permission that was never removed. A process that was never exercised. A trusted connection that quietly expanded beyond its original scope.

Individually, these issues may appear manageable. Together, they often create the conditions where incidents become far more difficult to detect, investigate and contain.

The gap between documented process and operational reality is where risk tends to grow quietly โš ๏ธ

Address

2451 West Grapevine Mills Circle, Suite 211
Grapevine, TX
76051

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm
Saturday 9am - 5pm

Telephone

+37259123819

Alerts

Be the first to know and let us send you an email when Secnora INC posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Secnora INC:

Share