⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos
A weekly security roundup covers a GitHub supply-chain breach, active Defender and Drupal exploitation, a nine-year Linux flaw, and other major fixes.
Intelligence analysis by GPT-5.4 Mini
The recap stitches together a bad week for software security: a supply-chain compromise at GitHub, active exploitation in Defender and Drupal, a long-hidden Linux kernel flaw, and other urgent fixes across major products.
This story is like a city where several locks all fail at the same time. Some problems came from bad tools, some were old bugs that never got fixed in time, and some were already being used by thieves.
One big example is a broken helper tool that helped attackers sneak into GitHub-related systems. Another is a hidden flaw in Linux that had been sitting there for years, waiting for someone to use it.
The lesson is simple: when many important machines and programs are connected, one weak spot can spread trouble fast, like a cracked pipe making water leak into many rooms.
Analysis
Threat and supply-chain pressure
The lead story is GitHub's confirmation that its internal repository breach came from a compromised employee device tied to a poisoned Nx Console VS Code extension. GitHub said the incident led to the exfiltration of about 3,800 repositories and that it has rotated critical secrets while monitoring for follow-on activity. The article also connects the event to the earlier TanStack supply-chain attack and says the downstream fallout is still spreading.
Active exploitation across major products
The week's top news is dominated by flaws already being used in the wild. Microsoft said two Defender bugs are under active exploitation, one for privilege escalation and one for denial of service. Drupal Core is also under attack shortly after disclosure of CVE-2026-9082, with Imperva reporting more than 15,000 attack attempts against nearly 6,000 sites across 65 countries. Cisco, meanwhile, patched a CVSS 10.0 Secure Workload flaw that could expose sensitive data and let an attacker make configuration changes across tenant boundaries.
Long-tail risk and broader trend lines
The recap also highlights a nine-year-old Linux kernel flaw, CVE-2026-46333, that can let a local user disclose sensitive files and run commands as root on default installations of several major distributions. Elsewhere, Microsoft moved on Fox Tempest, a group described as an upstream enabler for ransomware and malware campaigns, while RondoDox started using an old ASUS router flaw in the wild. Anthropic's Project Glasswing is presented as a large-scale vulnerability-finding effort that has already surfaced more than 10,000 high- or critical-severity candidates, with thousands still under review. The overall message is straightforward: old bugs, supply-chain compromise, and fast-moving exploitation are all colliding at once.
Key points
- GitHub said an employee-device compromise involving a poisoned Nx Console extension led to the theft of about 3,800 repositories.
- Microsoft said two Defender vulnerabilities, one for privilege escalation and one for denial of service, are being actively exploited.
- Drupal Core exploit attempts were detected soon after disclosure, with Imperva reporting attacks against thousands of sites worldwide.
- A Linux kernel flaw introduced in November 2016 could let a local user read sensitive files and execute commands as root.
- The roundup also highlights Fox Tempest, RondoDox router exploitation, and Anthropic's large-scale vulnerability discovery effort.



