GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension

GitHub disclosed on May 19-20, 2026, that attackers stole data from ~3,800 internal repositories after compromising an employee’s machine through a malicious Nx Console VS Code extension.

Attack Summary

On May 18, a fake maintainer uploaded poisoned version v18.95.0 of Nx Console (2.2M+ installs) to the VS Code Marketplace. The extension was live for about 18 minutes before removal. It stole GitHub tokens, npm credentials, AWS keys, SSH keys, and more.The attack stemmed from the earlier Mini Shai-Hulud campaign that compromised a legitimate Nx developer’s credentials via the TanStack package ecosystem. Threat group TeamPCP claimed responsibility and attempted to sell the stolen data.

Why This Matters for AI Security

AI development heavily relies on VS Code, monorepos, and open-source tools, exactly the attack surface exploited here. With sensitive assets like model weights, training data, and GPU cluster credentials at stake, supply chain attacks on developer tooling pose outsized risk to AI organizations.This incident follows similar compromises targeting AI companies through the same vectors in 2024-2025. Attackers are increasingly using AI to accelerate malware creation and social engineering, while defenders struggle with the pace of tool dependencies.

Key Takeaways

  • Audit and restrict VS Code extensions, even popular ones can be compromised.
  • Rotate all secrets immediately (GitHub, cloud providers, credential managers).
  • Enforce multi-approval for package/extension publishing.
  • Treat developer workstation and supply chain security as core parts of AI threat models.

Organizations building AI systems should treat this as a loud warning: the next breach could expose proprietary models or training infrastructure. GitHub and Nx have both improved controls, but vigilance across the ecosystem is essential.

OpenAI Wins on Technicality as Jury Rules Musk’s Lawsuit Came Too Late

In a swift verdict delivered on May 18, 2026, a federal jury in Oakland, California, sided with OpenAI and CEO Sam Altman in the closely watched lawsuit filed by Elon Musk. The case centered on Musk’s accusations that OpenAI had abandoned its original nonprofit mission to benefit humanity. However, the jury’s unanimous decision rested solely on a timing issue and did not address the substance of those claims.

Verdict Turns on Statute of Limitations

After deliberating for less than two hours, the nine-member jury determined that Musk’s claims were barred by California’s three-year statute of limitations. U.S. District Judge Yvonne Gonzalez Rogers accepted the jury’s advisory verdict and dismissed the entire case.Musk, who co-founded OpenAI in 2015 and contributed tens of millions before leaving in 2018, had alleged that Altman, Greg Brockman, and the company betrayed the founding agreement by shifting toward a for-profit structure backed by massive Microsoft investments. He famously called the move “stealing a charity,” arguing it violated OpenAI’s original charter to develop artificial general intelligence (AGI) for the benefit of humanity rather than private shareholders.Importantly, the jury did not rule on whether OpenAI had actually deviated from its mission or “stolen a charity from humanity.” The decision was purely procedural: evidence showed Musk was aware of OpenAI’s structural changes as early as 2019, meaning his later lawsuit came too late under the law.

Trial Highlights

The multi-week trial included testimony from Musk, Altman, Microsoft CEO Satya Nadella, and others. Musk’s team presented evidence of alleged betrayal, while OpenAI’s defense highlighted the competitive realities of the AI industry and noted that Musk himself had previously considered for-profit options for the organization.The proceedings raised broader questions about AI governance and the tension between nonprofit ideals and the enormous capital required to build advanced AI systems. However, because of the statute of limitations ruling, those deeper issues were never formally decided by the jury.

Reactions and What’s Next

OpenAI described the outcome as a complete victory, removing a significant legal overhang as the company moves toward a potential IPO. Sam Altman and the team reaffirmed their commitment to developing safe and beneficial AI.Musk reacted critically on X, calling the result a “terrible precedent” and indicating plans to appeal. The ruling allows him to focus fully on his competing AI venture, xAI.

Implications for the AI Industry

  • For OpenAI: The dismissal clears a major hurdle, strengthening its position for future funding and growth.
  • For Musk/xAI: The legal chapter closes (at least for now), shifting the rivalry back entirely to technological and market competition.
  • Broader Context: While the case ended on a technicality, it spotlighted ongoing debates about corporate governance in AI, mission drift, and how best to balance rapid innovation with public benefit. Those questions remain unresolved by the court and will likely continue to shape industry discussions.

This high-profile clash between two AI powerhouses underscores the intense competition and philosophical divides driving the field forward. The battle for AGI supremacy continues, now firmly in the labs and boardrooms rather than the courtroom.

Anthropic Anthropic Ends the Compute Arbitrage Era — and Developers Are Furious

Anthropic is restructuring how compute gets distributed across its products, and the developer community is pushing back hard enough that the company’s own announcement got Community-Noted on X within hours of going live.

On May 13, via the official @ClaudeDevs account, Anthropic announced that Agent SDK and claude -p usage will draw from a new dedicated credit pool starting June 15, separate from subscription interactive usage limits. The tools moving to the new pool include the Claude -p non-interactive command, Claude Code GitHub Actions, and third-party apps that authenticate through the subscription via the Agent SDK. Interactive Claude Code, Cowork, and chat stay on existing subscription limits untouched.

The new credit tiers:

Pro gets $20/month. Max 5x gets $100. Max 20x gets $200. Team accounts get $100 per seat, Enterprise $200 per seat. Credits are metered at standard API list rates, reset monthly, and do not roll over.

Why Anthropic did it — and why developers aren’t buying the framing:

Some subscribers were paying $20 to $200 per month while consuming hundreds, even thousands of dollars in token value through third-party automation. Boris Cherny, head of Claude Code at Anthropic, described it bluntly: third-party tools operating outside the cache system are “really hard to do sustainably.”

Anthropic framed the change as a “free credit” added to subscriptions. The community framed it as a 25x effective price cut to programmatic usage, and Anthropic’s Lydia Hallie got Community-Noted on X within hours. Peer correction of company framing. That’s the headline.

The math backs the criticism. A Pro user running OpenClaw could previously extract roughly $236 of API-equivalent value per month from a $20 subscription — a 12x subsidy ratio. For Max 20x heavy users, the effective ratio ranged from 29x to 35x. In extreme cases, that number climbed to 175x.

The developer reaction:

T3 Code creator Theo Browne replied that his community’s effective cost just went up 25 times and cancelled within hours. Developer Yadesh Salvi noted that “the monthly limit you are providing won’t even last a day of serious work.” Browne went further, calling it “an attack on open-source tooling that repudiates months of explicit promises from Anthropic’s developer relations team.”

On X, users noted that power users running real automation would burn through the new cap within days, while those with dynamic monthly usage could find credits completely wasted in lighter months and exhausted in heavier ones. One user put it plainly: “For everyone running real automation, this is a downgrade dressed up as a feature.”

The competitive opening:

OpenAI moved quickly, rolling out an aggressive response offering two months of free Codex access for enterprise users migrating away from Anthropic. A direct play for the developers most likely to feel burned by the credit cap.

What Anthropic did to soften the blow:

On May 13, Anthropic raised Claude Code’s weekly limits by 50% through July 13 for Pro, Max, Team, and seat-based Enterprise users on the heels of a May 6 announcement that doubled five-hour rate limits and stripped out peak-hour throttling for Pro and Max accounts. All of it traces back to expanded compute capacity through a SpaceX deal for the Colossus 1 data center in Memphis.

Credits must be manually claimed via email notifications sent June 8, and reset monthly with no rollover. If credits run out, SDK calls return rate-limit errors unless extra usage has been manually enabled, which is off by default and billed at full API list price with no subscription discount.

The bottom line: The compute arbitrage era is over. The era when a $20 plan could quietly pretend to be a $1,000 one is done. Anthropic is converging its subscription and API products, interactive use stays subsidized, programmatic use gets priced like the API it always effectively was. Whether that’s a reasonable business correction or a betrayal of the developer community that helped build Claude’s momentum is a question Anthropic still hasn’t answered cleanly and the backlash suggests it may not get the chance to frame it on its own terms.

The AI Patch Revolution: How Microsoft’s MDASH Is About to Redefine Software Security—and What Vendors Must Do to Survive

OpEd by Steve

The days of quarterly Patch Tuesdays feeling like a manageable fire drill are ending. Microsoft’s new multi-model agentic scanning harness – codenamed MDASH – just demonstrated that AI can systematically unearth complex, exploitable vulnerabilities at a scale and speed that outpaces traditional human-led auditing. In the May 2026 Patch Tuesday alone, MDASH helped discover 16 vulnerabilities in Windows networking and authentication components, including four critical remote code execution (RCE) flaws. 

This isn’t another incremental AI scanner hyped in a lab. MDASH is a production-grade, agentic system orchestrating more than 100 specialized AI agents across an ensemble of frontier and distilled models. It handles end-to-end workflows: preparing codebases, scanning for candidates, debating exploitability, deduplicating findings, and even proving bugs with triggering inputs. On internal tests, it achieved near-perfect recall on historical vulnerabilities in components like tcpip.sys and clfs.sys, zero false positives on a deliberately bugged private driver, and topped the CyberGym benchmark at 88.45%. 

From Reactive Patching to Continuous Discovery

Traditional vulnerability management has long been a cat-and-mouse game. Vendors ship code, researchers (or attackers) find flaws, patches follow, often months later. MDASH flips this dynamic. By treating vulnerability discovery as an automated, scalable engineering process rather than sporadic human heroism, it compresses the time between introduction of a bug and its detection from months or years to weeks or days.

For Microsoft’s own ecosystem, this means larger, more proactive Patch Tuesdays. The company itself has signaled that releases will grow structurally as AI-driven findings accelerate. 
For the broader industry, it signals the end of “good enough” security hygiene. If one vendor can deploy agentic systems that approximate professional offensive researchers on massive, proprietary codebases, customers and regulators will soon demand comparable rigor everywhere.

he patching landscape will change in several profound ways:

  • Speed becomes table stakes. Vulnerabilities won’t wait for the next scheduled release cycle. Organizations will expect rapid, automated remediation pipelines, potentially shifting toward continuous security updates or virtual patching layers for high-risk components.
  • Depth of analysis increases. Agentic systems excel at reasoning through complex interactions (kernel invariants, lock ordering, trust boundaries) that static analyzers or simple fuzzers miss. Shallow bugs will vanish quickly; the remaining ones will be subtler, architectural, or logic-based.
  • Proof and validation raise the bar. MDASH doesn’t just flag potential issues -it debates them internally and generates proofs. This reduces noise and builds confidence, but it also means vendors can no longer dismiss reports with “not exploitable” hand-waving without strong evidence.
  • Attack surface scrutiny intensifies. Third-party libraries, drivers, and dependencies -long the weak links—will face the same relentless scanning. Supply chain security moves from SBOM checklists to live, AI-audited verification.

What Software Vendors Must Do to Stay Current

Staying competitive in this new era won’t be optional for vendors who want enterprise trust (and contracts). Here’s what’s required:

  1. Invest in AI-Native Security Pipelines: Adopt or build agentic scanning harnesses tailored to your codebases. Relying solely on open-source scanners or occasional manual audits will leave you exposed. Integrate multi-model ensembles with domain-specific plugins for your architectures.
  2. Embrace Continuous Scanning and Remediation: Shift from release-gated security to always-on discovery. This demands mature DevSecOps practices, automated patch generation/validation, and rapid deployment mechanisms. Your CI/CD must include AI auditors as first-class citizens.
  3. Prioritize Code Provenance and Modularity: Complex, monolithic codebases are harder to scan effectively. Favor modular designs with clear boundaries, which AI agents can reason about more reliably. Maintain high-quality indices, threat models, and historical commit data to feed these systems.
  4. Collaborate and Share Intelligence: Microsoft is offering limited private previews of MDASH. Engage early. Broader industry efforts-shared benchmarks, standardized agent plugins, collaborative datasets of historical CVEs will accelerate everyone’s capabilities while raising the baseline.
  5. Prepare for Transparency and Accountability: As AI findings become routine, expect greater scrutiny. Customers and regulators will ask: “What AI tools did you use to validate this release?” Be ready with metrics on recall, false positive rates, and remediation velocity.
  6. Upskill Teams for Human-AI Collaboration: The best outcomes come from offensive researchers guiding and extending AI agents, not replacing them. Invest in talent that can craft effective prompts, domain plugins, and validation oracles.

The Bigger Picture: Defense at AI Speed

MDASH underscores a critical truth: in the AI era, the advantage belongs to the system, not any single model. A lone frontier LLM might hallucinate or miss context; a well-orchestrated harness of specialized agents, debate cycles, and proof engines delivers production results.

For security practitioners, this is exhilarating. We move closer to finding and fixing bugs before adversaries exploit them. For vendors, it’s a wake-up call. Those who treat security as a checkbox will fall behind. Those who integrate agentic AI into their core development and response processes will build more resilient products, and earn greater customer confidence. The patching treadmill isn’t slowing down; it’s accelerating into a continuous, intelligent race. Microsoft has set a new pace with MDASH. The question for the industry is simple: will you keep up, or watch your vulnerabilities pile up? The era of AI-augmented defense is here. Adapt or become the next headline.

Google Connects the Dots: This Cyberattack Started With AI

For the first time, Google’s Threat Intelligence Group has confirmed a real-world case of hackers using AI to discover and weaponize a zero-day vulnerability — catching the attack before it could be used to bypass two-factor authentication on a widely deployed web management tool.

What tipped them off:

  • The attack was designed to let an unauthorized user skip past two-factor authentication entirely. Google worked directly with the affected company to neutralize it before damage was done.
  • Investigators flagged the exploit based on tells that human-written attack code rarely shows: unusually clean, polished structure, extensive explanatory notes, and a fabricated severity score — a calling card that pointed squarely to AI authorship.
  • GTIG’s John Hultquist described the discovery as just the surface of a much deeper problem. Anthropic’s Rob Bair framed the window defenders have left even more starkly — warning the advantage is measured in months, not years.
  • Google’s broader threat report catalogued additional AI-assisted attacks, including tools that allow AI to remotely commandeer devices, and AI-generated malicious code and prompt injections traced to operators in North Korea and Russia.

Why it is important: We’ve seen glimpses of what AI can do on the defensive side of cybersecurity. The problem is that offensive capabilities are closing the gap faster than most institutions are prepared for. The next wave of AI model releases won’t just push the frontier for researchers and enterprises — it’ll hand a meaningful upgrade to attackers too. For the vast majority of systems still operating without modern security infrastructure, that’s not a distant risk. It’s an incoming one.

Canvas Is Down — and So Are Thousands of Classrooms

For many teachers, Canvas isn’t just a platform — it’s where an entire year’s worth of lesson plans lives. Assignments, curricula, discussion threads, grade books. All of it. Which makes what happened this week particularly devastating: a cybercrime group held one of American education’s most critical platforms hostage, and thousands of schools found out mid-semester that their digital backbone was gone.

Canvas parent company Instructure is reeling from an ongoing data extortion attack that disrupted classes and coursework at school districts and universities across the country, after the cybercrime group ShinyHunters defaced the platform’s login page with a ransom demand threatening to leak data on 275 million students and faculty across nearly 9,000 institutions. Instructure’s response was to take Canvas offline entirely.

How we got here:

  • ShinyHunters first claimed a breach on May 1. Instructure’s Chief Information Security Officer declared the incident contained the very next day. It wasn’t.
  • By May 6, Instructure acknowledged stolen data that included names, email addresses, student ID numbers, and messages between users — though the company said no passwords, dates of birth, government IDs, or financial information were compromised.
  • On May 7, students and faculty across dozens of schools logged in to find a ransom demand where the Canvas homepage used to be. ShinyHunters claims the haul includes several billion private messages between students and teachers. Instructure pulled the plug and replaced the login portal with a message calling it “scheduled maintenance” — a characterization that drew immediate criticism from security researchers.
  • The ransom deadline started at May 6, was pushed to May 12, and the extortion message directed affected schools to negotiate their own payments directly with the hackers — independent of whatever Instructure decides to do.

The pattern security experts are pointing to: This wasn’t a one-off. Cloudskope CEO Dipan Mann says this is at least the third time in eight months that ShinyHunters has breached Instructure’s environment. In September 2025, thousands of internal University of Pennsylvania files — donor records, internal memos, confidential materials — leaked through what investigators later determined was partly a Canvas-mediated access path. Penn was named as the victim; Instructure was framed as a bystander. Mann argues that framing was wrong then and looks catastrophically wrong now.

“The September 2025 Penn breach was the proof of concept,” Mann wrote. “The May 1 incident was the production run. The May 7 recompromise was ShinyHunters demonstrating publicly that the May 2 ‘containment’ did not happen.”

A source close to the investigation confirmed that several universities have already approached the group about paying. Notably, ShinyHunters quietly removed Instructure from its public leak site — a move these groups typically only make after receiving payment or entering active negotiations.

The timing couldn’t be worse. Countless schools are in the middle of final exams. ShinyHunters is not a single-target operation — Google-owned Mandiant’s CTO Charles Carmakal confirmed that “multiple concurrent and discrete ShinyHunters intrusion and extortion campaigns” are active right now. Recent victims include ADT, Medtronic, Rockstar Games, McGraw Hill, 7-Eleven, and Carnival.

Canvas is back online as of May 8, with Instructure saying hackers exploited a vulnerability tied to Free-for-Teacher accounts — the same entry point used in the prior week’s breach. The company has temporarily shut down those accounts while it works to resolve the underlying issue, and says it is directly contacting affected organizations.

For the teachers who built an entire school year inside Canvas, “we’re working on it” is a hard thing to hear in May.

Canvas stores an enormous amount of sensitive behavioral and academic data — exactly the kind of structured, large-scale dataset that makes education platforms an increasingly attractive target for threat actors looking to train or fine-tune AI models on real human interaction patterns.

OpenAI accelerates “AI agent phone”

OpenAI is reportedly moving up its AI phone timeline by a full year, now targeting mass production in the first half of 2027 — a significant acceleration that supply chain analyst Ming-Chi Kuo attributes to IPO pressure and an increasingly crowded AI hardware market.

What we know:

  • Kuo believes the faster timeline is driven by two forces: OpenAI’s desire to show investors a compelling hardware story ahead of a public offering, and mounting competition in the AI phone space.
  • MediaTek is expected to be the sole chip supplier, with the phone running two AI processors in parallel to handle vision and language tasks simultaneously.
  • The device’s headline feature won’t be raw processing power — it’ll be the image signal processor, equipped with an enhanced HDR pipeline designed to sharpen AI agents’ ability to interpret the physical world in real time.
  • If development stays on track, Kuo estimates OpenAI’s combined 2027–28 shipments could reach 30 million units.

Owning both the hardware and the OS is increasingly looking like the endgame for anyone serious about building a true agentic experience — and OpenAI clearly doesn’t want to cede that ground. But the accelerated timeline raises an awkward question: what does this mean for the device OpenAI is building with Jony Ive’s io? The acquisition came with considerable fanfare around going “beyond screens,” yet has produced little beyond a handful of rumors. If the AI phone is now the priority, io’s vision may be getting quietly sidelined — or the two products are on a collision course with each other.