Threat Briefing: October 2, 2026

Threat Briefing Cybersecurity

October 2, 2026

Threat Intel Update

Threat Intel Update

This week’s threats exposed persistent gaps across credentials, cloud, identity, user-targeted scams, and the software supply chain. Researchers found more than 543,000 active credentials in public GitHub repositories, many valid for years, while the JadePuffer actor abused compromised Azure service principals to harvest credentials and destroy cloud resources.

A large tech support scam campaign used Google Ads and fake security alerts to lure victims, and Microsoft’s SSPR portal was found to potentially expose data that could let attackers enumerate valid accounts, recovery methods, and administrator accounts.

The previously disrupted Mini Shai-Hulud supply chain campaign also resurfaced when compromised GitHub Actions repositories became accessible again, allowing affected workflows to resume executing credential-harvesting malware. Together, these events underscore the need for strong credential hygiene, proactive cloud monitoring, identity protection, supply chain risk management, and ongoing security awareness training.

Cybersecurity News

  • Over 543,000 Valid Credentials Found in Public GitHub Repos – Truffle Security scanned 224 million repositories and more than 58 billion files, identifying 543,699 unique valid credentials exposed as of July. Credentials stayed publicly accessible for a median of 784 days, and the oldest dated to 2009. BleepingComputer
  • JadePuffer Attacks Wipe Out Azure Resources – In two June attacks, Microsoft observed the actor Storm-3168 use compromised Azure service principals to map cloud resources and collect storage account keys. It then deleted more than 100 storage accounts, along with Key Vaults, Function Apps, VMs, and App Services, in a seven-minute destructive stage. The operator later returned and retrieved storage account keys through more than 30 additional requests. BleepingComputer
  • Google Ads Used to Push Fake Browser Lockout Alerts – Netskope Threat Labs documented a tech support scam kit that uses paid Google Ads to serve fake security alerts that make browsers appear locked. Between August 31 and September 14, 2026, the campaign reached at least 619 organizations through legitimate publisher sites. Hack Read
  • Microsoft Password Reset Portal Leaks Account Details – LevelBlue SpiderLabs found that Microsoft’s Self-Service Password Reset portal returns distinct responses that let unauthenticated attackers confirm valid accounts, view registered recovery methods (SMS or alternate email), and identify likely administrators. Researchers built a Python tool, ResetSpy, that automates this enumeration across large email lists. Hack Read
  • Hijacked GitHub Actions Briefly Revive Mini Shai-Hulud – Two GitHub Actions repositories compromised in May 2026 became accessible again on September 16, 2026. Workflows referencing them by version tag resumed downloading and executing malicious code until GitHub disabled both repositories a second time for terms of service violations. The Hacker News

Sign Up

To receive Threat Briefings by email.

Sign Up Now

Share

About the Author
CampusGuard Logo

CampusGuard Threat Intel Team