GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension

GitHub disclosed on May 19-20, 2026, that attackers stole data from ~3,800 internal repositories after compromising an employee’s machine through a malicious Nx Console VS Code extension.

Attack Summary

On May 18, a fake maintainer uploaded poisoned version v18.95.0 of Nx Console (2.2M+ installs) to the VS Code Marketplace. The extension was live for about 18 minutes before removal. It stole GitHub tokens, npm credentials, AWS keys, SSH keys, and more.The attack stemmed from the earlier Mini Shai-Hulud campaign that compromised a legitimate Nx developer’s credentials via the TanStack package ecosystem. Threat group TeamPCP claimed responsibility and attempted to sell the stolen data.

Why This Matters for AI Security

AI development heavily relies on VS Code, monorepos, and open-source tools, exactly the attack surface exploited here. With sensitive assets like model weights, training data, and GPU cluster credentials at stake, supply chain attacks on developer tooling pose outsized risk to AI organizations.This incident follows similar compromises targeting AI companies through the same vectors in 2024-2025. Attackers are increasingly using AI to accelerate malware creation and social engineering, while defenders struggle with the pace of tool dependencies.

Key Takeaways

  • Audit and restrict VS Code extensions, even popular ones can be compromised.
  • Rotate all secrets immediately (GitHub, cloud providers, credential managers).
  • Enforce multi-approval for package/extension publishing.
  • Treat developer workstation and supply chain security as core parts of AI threat models.

Organizations building AI systems should treat this as a loud warning: the next breach could expose proprietary models or training infrastructure. GitHub and Nx have both improved controls, but vigilance across the ecosystem is essential.

OpenAI Wins on Technicality as Jury Rules Musk’s Lawsuit Came Too Late

In a swift verdict delivered on May 18, 2026, a federal jury in Oakland, California, sided with OpenAI and CEO Sam Altman in the closely watched lawsuit filed by Elon Musk. The case centered on Musk’s accusations that OpenAI had abandoned its original nonprofit mission to benefit humanity. However, the jury’s unanimous decision rested solely on a timing issue and did not address the substance of those claims.

Verdict Turns on Statute of Limitations

After deliberating for less than two hours, the nine-member jury determined that Musk’s claims were barred by California’s three-year statute of limitations. U.S. District Judge Yvonne Gonzalez Rogers accepted the jury’s advisory verdict and dismissed the entire case.Musk, who co-founded OpenAI in 2015 and contributed tens of millions before leaving in 2018, had alleged that Altman, Greg Brockman, and the company betrayed the founding agreement by shifting toward a for-profit structure backed by massive Microsoft investments. He famously called the move “stealing a charity,” arguing it violated OpenAI’s original charter to develop artificial general intelligence (AGI) for the benefit of humanity rather than private shareholders.Importantly, the jury did not rule on whether OpenAI had actually deviated from its mission or “stolen a charity from humanity.” The decision was purely procedural: evidence showed Musk was aware of OpenAI’s structural changes as early as 2019, meaning his later lawsuit came too late under the law.

Trial Highlights

The multi-week trial included testimony from Musk, Altman, Microsoft CEO Satya Nadella, and others. Musk’s team presented evidence of alleged betrayal, while OpenAI’s defense highlighted the competitive realities of the AI industry and noted that Musk himself had previously considered for-profit options for the organization.The proceedings raised broader questions about AI governance and the tension between nonprofit ideals and the enormous capital required to build advanced AI systems. However, because of the statute of limitations ruling, those deeper issues were never formally decided by the jury.

Reactions and What’s Next

OpenAI described the outcome as a complete victory, removing a significant legal overhang as the company moves toward a potential IPO. Sam Altman and the team reaffirmed their commitment to developing safe and beneficial AI.Musk reacted critically on X, calling the result a “terrible precedent” and indicating plans to appeal. The ruling allows him to focus fully on his competing AI venture, xAI.

Implications for the AI Industry

  • For OpenAI: The dismissal clears a major hurdle, strengthening its position for future funding and growth.
  • For Musk/xAI: The legal chapter closes (at least for now), shifting the rivalry back entirely to technological and market competition.
  • Broader Context: While the case ended on a technicality, it spotlighted ongoing debates about corporate governance in AI, mission drift, and how best to balance rapid innovation with public benefit. Those questions remain unresolved by the court and will likely continue to shape industry discussions.

This high-profile clash between two AI powerhouses underscores the intense competition and philosophical divides driving the field forward. The battle for AGI supremacy continues, now firmly in the labs and boardrooms rather than the courtroom.

Anthropic Anthropic Ends the Compute Arbitrage Era — and Developers Are Furious

Anthropic is restructuring how compute gets distributed across its products, and the developer community is pushing back hard enough that the company’s own announcement got Community-Noted on X within hours of going live.

On May 13, via the official @ClaudeDevs account, Anthropic announced that Agent SDK and claude -p usage will draw from a new dedicated credit pool starting June 15, separate from subscription interactive usage limits. The tools moving to the new pool include the Claude -p non-interactive command, Claude Code GitHub Actions, and third-party apps that authenticate through the subscription via the Agent SDK. Interactive Claude Code, Cowork, and chat stay on existing subscription limits untouched.

The new credit tiers:

Pro gets $20/month. Max 5x gets $100. Max 20x gets $200. Team accounts get $100 per seat, Enterprise $200 per seat. Credits are metered at standard API list rates, reset monthly, and do not roll over.

Why Anthropic did it — and why developers aren’t buying the framing:

Some subscribers were paying $20 to $200 per month while consuming hundreds, even thousands of dollars in token value through third-party automation. Boris Cherny, head of Claude Code at Anthropic, described it bluntly: third-party tools operating outside the cache system are “really hard to do sustainably.”

Anthropic framed the change as a “free credit” added to subscriptions. The community framed it as a 25x effective price cut to programmatic usage, and Anthropic’s Lydia Hallie got Community-Noted on X within hours. Peer correction of company framing. That’s the headline.

The math backs the criticism. A Pro user running OpenClaw could previously extract roughly $236 of API-equivalent value per month from a $20 subscription — a 12x subsidy ratio. For Max 20x heavy users, the effective ratio ranged from 29x to 35x. In extreme cases, that number climbed to 175x.

The developer reaction:

T3 Code creator Theo Browne replied that his community’s effective cost just went up 25 times and cancelled within hours. Developer Yadesh Salvi noted that “the monthly limit you are providing won’t even last a day of serious work.” Browne went further, calling it “an attack on open-source tooling that repudiates months of explicit promises from Anthropic’s developer relations team.”

On X, users noted that power users running real automation would burn through the new cap within days, while those with dynamic monthly usage could find credits completely wasted in lighter months and exhausted in heavier ones. One user put it plainly: “For everyone running real automation, this is a downgrade dressed up as a feature.”

The competitive opening:

OpenAI moved quickly, rolling out an aggressive response offering two months of free Codex access for enterprise users migrating away from Anthropic. A direct play for the developers most likely to feel burned by the credit cap.

What Anthropic did to soften the blow:

On May 13, Anthropic raised Claude Code’s weekly limits by 50% through July 13 for Pro, Max, Team, and seat-based Enterprise users on the heels of a May 6 announcement that doubled five-hour rate limits and stripped out peak-hour throttling for Pro and Max accounts. All of it traces back to expanded compute capacity through a SpaceX deal for the Colossus 1 data center in Memphis.

Credits must be manually claimed via email notifications sent June 8, and reset monthly with no rollover. If credits run out, SDK calls return rate-limit errors unless extra usage has been manually enabled, which is off by default and billed at full API list price with no subscription discount.

The bottom line: The compute arbitrage era is over. The era when a $20 plan could quietly pretend to be a $1,000 one is done. Anthropic is converging its subscription and API products, interactive use stays subsidized, programmatic use gets priced like the API it always effectively was. Whether that’s a reasonable business correction or a betrayal of the developer community that helped build Claude’s momentum is a question Anthropic still hasn’t answered cleanly and the backlash suggests it may not get the chance to frame it on its own terms.

The AI Patch Revolution: How Microsoft’s MDASH Is About to Redefine Software Security—and What Vendors Must Do to Survive

OpEd by Steve

The days of quarterly Patch Tuesdays feeling like a manageable fire drill are ending. Microsoft’s new multi-model agentic scanning harness – codenamed MDASH – just demonstrated that AI can systematically unearth complex, exploitable vulnerabilities at a scale and speed that outpaces traditional human-led auditing. In the May 2026 Patch Tuesday alone, MDASH helped discover 16 vulnerabilities in Windows networking and authentication components, including four critical remote code execution (RCE) flaws. 

This isn’t another incremental AI scanner hyped in a lab. MDASH is a production-grade, agentic system orchestrating more than 100 specialized AI agents across an ensemble of frontier and distilled models. It handles end-to-end workflows: preparing codebases, scanning for candidates, debating exploitability, deduplicating findings, and even proving bugs with triggering inputs. On internal tests, it achieved near-perfect recall on historical vulnerabilities in components like tcpip.sys and clfs.sys, zero false positives on a deliberately bugged private driver, and topped the CyberGym benchmark at 88.45%. 

From Reactive Patching to Continuous Discovery

Traditional vulnerability management has long been a cat-and-mouse game. Vendors ship code, researchers (or attackers) find flaws, patches follow, often months later. MDASH flips this dynamic. By treating vulnerability discovery as an automated, scalable engineering process rather than sporadic human heroism, it compresses the time between introduction of a bug and its detection from months or years to weeks or days.

For Microsoft’s own ecosystem, this means larger, more proactive Patch Tuesdays. The company itself has signaled that releases will grow structurally as AI-driven findings accelerate. 
For the broader industry, it signals the end of “good enough” security hygiene. If one vendor can deploy agentic systems that approximate professional offensive researchers on massive, proprietary codebases, customers and regulators will soon demand comparable rigor everywhere.

he patching landscape will change in several profound ways:

  • Speed becomes table stakes. Vulnerabilities won’t wait for the next scheduled release cycle. Organizations will expect rapid, automated remediation pipelines, potentially shifting toward continuous security updates or virtual patching layers for high-risk components.
  • Depth of analysis increases. Agentic systems excel at reasoning through complex interactions (kernel invariants, lock ordering, trust boundaries) that static analyzers or simple fuzzers miss. Shallow bugs will vanish quickly; the remaining ones will be subtler, architectural, or logic-based.
  • Proof and validation raise the bar. MDASH doesn’t just flag potential issues -it debates them internally and generates proofs. This reduces noise and builds confidence, but it also means vendors can no longer dismiss reports with “not exploitable” hand-waving without strong evidence.
  • Attack surface scrutiny intensifies. Third-party libraries, drivers, and dependencies -long the weak links—will face the same relentless scanning. Supply chain security moves from SBOM checklists to live, AI-audited verification.

What Software Vendors Must Do to Stay Current

Staying competitive in this new era won’t be optional for vendors who want enterprise trust (and contracts). Here’s what’s required:

  1. Invest in AI-Native Security Pipelines: Adopt or build agentic scanning harnesses tailored to your codebases. Relying solely on open-source scanners or occasional manual audits will leave you exposed. Integrate multi-model ensembles with domain-specific plugins for your architectures.
  2. Embrace Continuous Scanning and Remediation: Shift from release-gated security to always-on discovery. This demands mature DevSecOps practices, automated patch generation/validation, and rapid deployment mechanisms. Your CI/CD must include AI auditors as first-class citizens.
  3. Prioritize Code Provenance and Modularity: Complex, monolithic codebases are harder to scan effectively. Favor modular designs with clear boundaries, which AI agents can reason about more reliably. Maintain high-quality indices, threat models, and historical commit data to feed these systems.
  4. Collaborate and Share Intelligence: Microsoft is offering limited private previews of MDASH. Engage early. Broader industry efforts-shared benchmarks, standardized agent plugins, collaborative datasets of historical CVEs will accelerate everyone’s capabilities while raising the baseline.
  5. Prepare for Transparency and Accountability: As AI findings become routine, expect greater scrutiny. Customers and regulators will ask: “What AI tools did you use to validate this release?” Be ready with metrics on recall, false positive rates, and remediation velocity.
  6. Upskill Teams for Human-AI Collaboration: The best outcomes come from offensive researchers guiding and extending AI agents, not replacing them. Invest in talent that can craft effective prompts, domain plugins, and validation oracles.

The Bigger Picture: Defense at AI Speed

MDASH underscores a critical truth: in the AI era, the advantage belongs to the system, not any single model. A lone frontier LLM might hallucinate or miss context; a well-orchestrated harness of specialized agents, debate cycles, and proof engines delivers production results.

For security practitioners, this is exhilarating. We move closer to finding and fixing bugs before adversaries exploit them. For vendors, it’s a wake-up call. Those who treat security as a checkbox will fall behind. Those who integrate agentic AI into their core development and response processes will build more resilient products, and earn greater customer confidence. The patching treadmill isn’t slowing down; it’s accelerating into a continuous, intelligent race. Microsoft has set a new pace with MDASH. The question for the industry is simple: will you keep up, or watch your vulnerabilities pile up? The era of AI-augmented defense is here. Adapt or become the next headline.

Google Connects the Dots: This Cyberattack Started With AI

For the first time, Google’s Threat Intelligence Group has confirmed a real-world case of hackers using AI to discover and weaponize a zero-day vulnerability — catching the attack before it could be used to bypass two-factor authentication on a widely deployed web management tool.

What tipped them off:

  • The attack was designed to let an unauthorized user skip past two-factor authentication entirely. Google worked directly with the affected company to neutralize it before damage was done.
  • Investigators flagged the exploit based on tells that human-written attack code rarely shows: unusually clean, polished structure, extensive explanatory notes, and a fabricated severity score — a calling card that pointed squarely to AI authorship.
  • GTIG’s John Hultquist described the discovery as just the surface of a much deeper problem. Anthropic’s Rob Bair framed the window defenders have left even more starkly — warning the advantage is measured in months, not years.
  • Google’s broader threat report catalogued additional AI-assisted attacks, including tools that allow AI to remotely commandeer devices, and AI-generated malicious code and prompt injections traced to operators in North Korea and Russia.

Why it is important: We’ve seen glimpses of what AI can do on the defensive side of cybersecurity. The problem is that offensive capabilities are closing the gap faster than most institutions are prepared for. The next wave of AI model releases won’t just push the frontier for researchers and enterprises — it’ll hand a meaningful upgrade to attackers too. For the vast majority of systems still operating without modern security infrastructure, that’s not a distant risk. It’s an incoming one.

Canvas Is Down — and So Are Thousands of Classrooms

For many teachers, Canvas isn’t just a platform — it’s where an entire year’s worth of lesson plans lives. Assignments, curricula, discussion threads, grade books. All of it. Which makes what happened this week particularly devastating: a cybercrime group held one of American education’s most critical platforms hostage, and thousands of schools found out mid-semester that their digital backbone was gone.

Canvas parent company Instructure is reeling from an ongoing data extortion attack that disrupted classes and coursework at school districts and universities across the country, after the cybercrime group ShinyHunters defaced the platform’s login page with a ransom demand threatening to leak data on 275 million students and faculty across nearly 9,000 institutions. Instructure’s response was to take Canvas offline entirely.

How we got here:

  • ShinyHunters first claimed a breach on May 1. Instructure’s Chief Information Security Officer declared the incident contained the very next day. It wasn’t.
  • By May 6, Instructure acknowledged stolen data that included names, email addresses, student ID numbers, and messages between users — though the company said no passwords, dates of birth, government IDs, or financial information were compromised.
  • On May 7, students and faculty across dozens of schools logged in to find a ransom demand where the Canvas homepage used to be. ShinyHunters claims the haul includes several billion private messages between students and teachers. Instructure pulled the plug and replaced the login portal with a message calling it “scheduled maintenance” — a characterization that drew immediate criticism from security researchers.
  • The ransom deadline started at May 6, was pushed to May 12, and the extortion message directed affected schools to negotiate their own payments directly with the hackers — independent of whatever Instructure decides to do.

The pattern security experts are pointing to: This wasn’t a one-off. Cloudskope CEO Dipan Mann says this is at least the third time in eight months that ShinyHunters has breached Instructure’s environment. In September 2025, thousands of internal University of Pennsylvania files — donor records, internal memos, confidential materials — leaked through what investigators later determined was partly a Canvas-mediated access path. Penn was named as the victim; Instructure was framed as a bystander. Mann argues that framing was wrong then and looks catastrophically wrong now.

“The September 2025 Penn breach was the proof of concept,” Mann wrote. “The May 1 incident was the production run. The May 7 recompromise was ShinyHunters demonstrating publicly that the May 2 ‘containment’ did not happen.”

A source close to the investigation confirmed that several universities have already approached the group about paying. Notably, ShinyHunters quietly removed Instructure from its public leak site — a move these groups typically only make after receiving payment or entering active negotiations.

The timing couldn’t be worse. Countless schools are in the middle of final exams. ShinyHunters is not a single-target operation — Google-owned Mandiant’s CTO Charles Carmakal confirmed that “multiple concurrent and discrete ShinyHunters intrusion and extortion campaigns” are active right now. Recent victims include ADT, Medtronic, Rockstar Games, McGraw Hill, 7-Eleven, and Carnival.

Canvas is back online as of May 8, with Instructure saying hackers exploited a vulnerability tied to Free-for-Teacher accounts — the same entry point used in the prior week’s breach. The company has temporarily shut down those accounts while it works to resolve the underlying issue, and says it is directly contacting affected organizations.

For the teachers who built an entire school year inside Canvas, “we’re working on it” is a hard thing to hear in May.

Canvas stores an enormous amount of sensitive behavioral and academic data — exactly the kind of structured, large-scale dataset that makes education platforms an increasingly attractive target for threat actors looking to train or fine-tune AI models on real human interaction patterns.

OpenAI accelerates “AI agent phone”

OpenAI is reportedly moving up its AI phone timeline by a full year, now targeting mass production in the first half of 2027 — a significant acceleration that supply chain analyst Ming-Chi Kuo attributes to IPO pressure and an increasingly crowded AI hardware market.

What we know:

  • Kuo believes the faster timeline is driven by two forces: OpenAI’s desire to show investors a compelling hardware story ahead of a public offering, and mounting competition in the AI phone space.
  • MediaTek is expected to be the sole chip supplier, with the phone running two AI processors in parallel to handle vision and language tasks simultaneously.
  • The device’s headline feature won’t be raw processing power — it’ll be the image signal processor, equipped with an enhanced HDR pipeline designed to sharpen AI agents’ ability to interpret the physical world in real time.
  • If development stays on track, Kuo estimates OpenAI’s combined 2027–28 shipments could reach 30 million units.

Owning both the hardware and the OS is increasingly looking like the endgame for anyone serious about building a true agentic experience — and OpenAI clearly doesn’t want to cede that ground. But the accelerated timeline raises an awkward question: what does this mean for the device OpenAI is building with Jony Ive’s io? The acquisition came with considerable fanfare around going “beyond screens,” yet has produced little beyond a handful of rumors. If the AI phone is now the priority, io’s vision may be getting quietly sidelined — or the two products are on a collision course with each other.

Anthropic’s Washington Relationship Just Got Messy

The White House is pushing back on Anthropic’s bid to more than double private-sector access to its Mythos AI, citing compute constraints that could eat into the government’s own use — even as a national security memo quietly moves to defuse parts of the broader Pentagon standoff.

What’s going on:

  • Anthropic wanted Mythos access expanded from roughly 50 companies to nearly 120. U.S. officials balked, warning the wider rollout could strain compute resources the government depends on for its own operations.
  • A forthcoming White House AI memo is expected to push agencies toward multi-vendor AI adoption — and to address some of the underlying grievances that sparked Anthropic’s original feud with the Pentagon.
  • Axios reported the action would give agencies a workaround on the supply chain risk designation — even with the legal fight still ongoing.
  • GPT-5.5 has reached comparable cyber capabilities to Mythos, with former AI czar David Sacks predicting every frontier model will hit that bar within six months.

Summary: The White House’s posture toward Anthropic is shifting — but not cleanly. The administration clearly wants more of its own access to Mythos, which explains the sudden willingness to find middle ground. But with Secretary of Defense Pete Hegseth calling Anthropic “run by an ideological lunatic” just this week, the internal signals are pulling in opposite directions. It’s less a détente and more a tug-of-war between factions that want to bury the hatchet and those still looking for a fight.

Beijing stops Meta’s $2B Manus deal


China has blocked Meta’s $2 billion acquisition of Manus, ordering both companies to unwind the deal — and turning a Singapore-based AI startup with Chinese roots into a pointed message for any founder thinking about moving talent or technology beyond Beijing’s reach.

What happened:

  • Meta announced the deal in December. Chinese officials launched a probe in January examining export-control and foreign-investment regulations.
  • The National Development and Reform Commission formally stepped in, declaring the deal off-limits to foreign investment and directing both parties to reverse it.
  • By the time the order came down, the two organizations were already “deeply integrated” at Meta’s Singapore office — and Manus’s website had already been updated to read “now part of Meta.”
  • The ruling lands just weeks before Trump’s scheduled May summit with Xi in Beijing. Manus executives are reportedly barred from leaving China while the investigation continues.

Why is this important: Beijing just classified AI talent as a national security asset — applying the same export-control logic to people and startups that Washington uses on chips. The move raises a question that neither side has answered: with the companies already operationally merged and Meta maintaining the deal “complied fully with applicable law,” what does an actual unwind even look like? And more pointedly — will Meta comply? For founders eyeing exits to Western acquirers, Beijing just made the off-ramp a lot narrower.

DeepSeek’s Back, and It’s Bringing a Price War

Chinese AI lab DeepSeek has unveiled preview builds of its long-awaited V4, a new family of open-source models boasting 1M-token context windows, Huawei chip support, and pricing that puts serious pressure on U.S. competitors.

What’s in it:

  • Early third-party benchmarks rank V4 Pro near the top of the open-source field, and DeepSeek’s own evals put it in the same tier as GPT-5.4 and Gemini 3.1-Pro on reasoning tasks.
  • It leads Vals AI’s Vibe Code Bench, though it lands in the fourth tier on AA’s Intelligence Index, alongside Meta’s Muse Spark.
  • At $1.74/$3.48 per million input/output tokens, V4 Pro costs a fraction of GPT-5.5 ($5/$30) and Opus 4.7 ($5/$25) — a price gap that’s hard to ignore.
  • Huawei confirmed its Ascend chips can run V4, offering the clearest proof yet of a functional AI infrastructure stack built entirely outside of Nvidia.

DeepSeek is back — and while markets aren’t in freefall this time, V4 reframes the AI competition around cost as much as raw capability. The Huawei angle may ultimately be the bigger story, though. A domestic Chinese chip stack demonstrating real-world viability suggests that U.S. export restrictions, long seen as a hard ceiling on China’s AI ambitions, may be a more porous barrier than assumed.