meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Thursday, May 21st, 2026: GitHub Breach; Agentic Threat Intel Feed; NGINX Vuln; YellowKey Fix; Incomplete SonicWall Patch

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 21 May 2026

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Thursday, May 21st, 2026: GitHub Breach; Agentic Threat Intel Feed; NGINX Vuln; YellowKey Fix; Incomplete SonicWall Patch

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, May 21st, 2006 edition of the Sands Internet Storms Centers Stormcast.

0:12.3

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:16.5

And this episode is brought you by the Sands.edu credit certificate program in cyber defense

0:23.1

operations.

0:25.0

Well, today can't help it, but to continue to talk about supply chain issues.

0:30.3

And first one here is a breach of GitHub.

0:33.4

I usually don't talk about breaches, as I mentioned before, but this has sort of an important impact to, of course, everybody using GitHub.

0:41.2

And, well, that's pretty much everybody probably listening to this podcast.

0:46.1

Even if you're not personally a user of GitHub, pretty much large percentage.

0:51.6

I have no idea what percentage, but it's very large of open source software

0:56.2

is maintained via GitHub. Now, while these, of course, are often public GitHub repositories,

1:02.5

any modifications, of course, these repositories would be devastating. At this point,

1:07.3

there is no indication that anything other than GitHub's own internal repositories leaked,

1:14.4

they're talking about something like 3,800 different repositories, which sounds about right for a company the size of GitHub.

1:24.3

Of course, the second question is, what leaked with all of those repositories?

1:28.5

What kind of secrets?

1:29.8

What kind of source code?

1:31.7

What kind of, you know, maybe issues talking about bugs and security vulnerabilities have leaked here?

1:37.5

GitHub promised more details as the investigation evolves.

1:42.5

But at this point, it appears that the root cause was, well,

1:46.5

an individual developer using a malicious Visual Studio Code extension.

1:51.8

And Nostig, a company that focuses on securing Agendic AI, has open-sourced their own database

...

Transcript will be available on the free plan in 13 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.