GitHub Breach: How a Malicious VS Code Extension Exposed 3,800 Internal Repositories

breached - A padlock rests on a computer keyboard.

GitHub confirmed on May 20, 2026 that a malicious VS Code extension on an employee device led to the exfiltration of roughly 3,800 internal repositories. The breach reveals less about one compromised endpoint than about the structural costs of platform centralization.

BitLocker Bypass Shows Encryption Without Architecture Fails

encryption - red padlock on black computer keyboard

On May 12, 2026, a researcher published YellowKey, a Windows Recovery Environment bypass allowing physical-access attackers to unlock BitLocker-protected drives on Windows 11 systems. The vulnerability exposes the difference between cryptographic strength and systemic trust architecture.

The End of Optional Encryption: What Meta and TikTok Just Told Us

The End of Optional Encryption: What Meta and TikTok Just Told Us

Meta ended optional end-to-end encryption on Instagram DMs on May 8, 2026. TikTok confirmed in March it will never offer it. The Take It Down Act takes effect May 19. These three facts are connected, and the connection matters more than any single one of them. What just happened On May 8, 2026, Meta removed … Read more

Post-Quantum Cryptography: We’ve Already Put It in Your Hands

Post-Quantum Cryptography: We've Already Put It in Your Hands

Why we’re talking about ML-KEM and ML-DSA only now, when our PQCServer platform has been live and open source for two months. The context On May 5, 2026, Proton Mail announced support for post-quantum cryptography for emails between Proton users. It’s an important move and deserves recognition: the email industry needed to see a mainstream … Read more