GitHub Breach: How a Malicious VS Code Extension Exposed 3,800 Internal Repositories

breached - A padlock rests on a computer keyboard.

GitHub confirmed on May 20, 2026 that a malicious VS Code extension on an employee device led to the exfiltration of roughly 3,800 internal repositories. The breach reveals less about one compromised endpoint than about the structural costs of platform centralization.

The CISA GitHub Leak: What Six Months of Exposed Credentials Tell Us About Systemic Security Failures

leak - A padlock rests on a computer keyboard.

A contractor for the U.S. Cybersecurity and Infrastructure Security Agency maintained a public GitHub repository containing AWS GovCloud credentials, plaintext passwords, and DevSecOps files for six months before researchers intervened.

Emergency Data Requests and Law Enforcement Impersonation: Onion Mail’s Position

Emergency Data Requests and Law Enforcement Impersonation: Onion Mail's Position

In recent years, a new category of abuse has emerged in the cybersecurity landscape: the impersonation of law enforcement officers and government agencies by organized criminal groups, carried out through the use of compromised or look-alike government email domains. The objective of these attacks is to obtain user data from online service providers through what … Read more

BitLocker Bypass Shows Encryption Without Architecture Fails

encryption - red padlock on black computer keyboard

On May 12, 2026, a researcher published YellowKey, a Windows Recovery Environment bypass allowing physical-access attackers to unlock BitLocker-protected drives on Windows 11 systems. The vulnerability exposes the difference between cryptographic strength and systemic trust architecture.

Understanding Onion Email: Tor-Based Anonymous Email Explained

Understanding Onion Email: Tor-Based Anonymous Email Explained

Onion email services route communication through the Tor network using .onion addresses. This guide explains how they work, what they protect, and where they fit in the anonymous email landscape.

Onion Mail in 2026: What Changed, What Hasn’t, and How to Verify

Onion Mail in 2026: What Changed, What Hasn't, and How to Verify

Onion Mail has been criticized publicly over the years for login failures, Tor connection issues, mobile app problems, and concerns about security architecture. Most of those criticisms were written between 2015 and 2023. This article documents what has changed since then, what has not, and how the service operates today — with verification paths for … Read more