TL;DR
This week’s security news covers a Microsoft GitHub supply chain incident, a TP-Link domain issue, new OpenSSL vulnerabilities, and the return of a prominent researcher. Confirmed incidents highlight ongoing risks and industry responses.
Microsoft’s open source Azure repositories were automatically disabled by GitHub after being compromised by the Miasma worm, affecting over 70 repositories and highlighting ongoing supply chain risks.
OpenSourceMalware reports that 73 Microsoft-related repositories were flagged and taken offline within minutes by GitHub’s automated security systems. The infection centered around the Microsoft Durabletask package, previously compromised in May, which was used to distribute infected packages via PyPi. The compromised repositories included over 400,000 downloads per month, and the incident underscores the persistent threat of supply chain attacks.
Separately, Microsoft patched a critical bug in GitHub’s embedded web-based VSCode editor that could allow attackers to exfiltrate user authentication tokens. Discovered by Ammar Askar, the flaw involved manipulating the sandboxed environment to install malicious extensions, risking account compromise.
In the hardware domain, researcher Julian B identified an unregistered domain in TP-Link firmware, which devices checked in with, raising concerns about potential security risks. After reporting the issue, Julian registered the domain, preventing further misuse.
OpenSSL disclosed new vulnerabilities, including a high-severity use-after-free flaw in PKCS7 handling that could enable arbitrary code execution. While most applications are unlikely to be affected, the advisory urges prompt updates.
Finally, the researcher known as NightmareEclipse, now returning as MSNightmare, released new exploits for Windows Defender and BitLocker bypasses, despite Microsoft’s previous threats of criminal investigation. These disclosures come during Patch Tuesday, with fixes expected in upcoming updates.
Ongoing Supply Chain and Security Risks Highlighted
This week’s incidents demonstrate the persistent vulnerabilities in software supply chains, the importance of timely patching, and the challenges in managing hardware and software security. The Microsoft GitHub incident illustrates how automated systems can quickly contain breaches but also disrupt development workflows. The OpenSSL flaws remind organizations to stay vigilant and update critical libraries promptly. The return of a controversial researcher underscores the evolving landscape of vulnerability disclosure and the importance of responsible reporting.

Code Until Burnout Patch – Funny Programmer Embroidered Iron-On Badge – Retro PC on Fire – Hacker, Coder, IT Humor Patch, 3.3 x 3.9 Inches
- Bold Retro Design: Computer on fire with slogan
- Premium Embroidery: Vivid colors and durability
- Easy to Apply: Iron-on or sew for durability
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Recent Security Incidents and Industry Trends
Supply chain attacks have been a growing concern, with recent incidents involving major companies like Microsoft exposing vulnerabilities in open source repositories. The May compromise of the Durabletask package led to widespread infection, illustrating the risks of dependencies in modern software development. Meanwhile, bug bounty programs and responsible disclosure have become standard, though recent actions by Microsoft suggest tensions remain regarding researcher engagement. The vulnerabilities in OpenSSL and hardware devices like TP-Link routers reflect ongoing challenges in securing foundational infrastructure components.
“The infection resulted in 73 repositories being flagged and taken offline in just over a minute, highlighting the speed and severity of supply chain attacks.”
— OpenSourceMalware

TP-Link BE6500 Dual-Band WiFi 7 Router (BE400) – Dual 2.5Gbps Ports, USB 3.0, Covers up to 2,400 sq. ft., 90 Devices, Quad-Core CPU, HomeShield, Private IoT, Free Expert Support
- Wi-Fi 7 Technology: Supports Multi-Link Operation and 4K-QAM
- High-Speed Dual-Band: Up to 5764 Mbps on 5GHz, 688 Mbps on 2.4GHz
- Wide Coverage: Covers up to 2,400 sq. ft. for 90 devices
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Unresolved Questions in Ongoing Security Incidents
It is not yet clear what specific long-term impact the Microsoft supply chain incident will have on broader software development practices. The full scope of the TP-Link domain issue and its potential security implications remains uncertain. Additionally, the severity and exploitability of the newly disclosed OpenSSL vulnerabilities depend on specific application contexts, which are still being analyzed. The future response of Microsoft to researcher disclosures and whether more vulnerabilities will be released or patched during upcoming updates also remains to be seen.
Microsoft Azure open source repositories
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Expected Developments and Industry Responses
Microsoft is expected to release security patches addressing the GitHub token bug and other vulnerabilities in the upcoming Patch Tuesday cycle. Organizations should review their dependency management policies following the supply chain incident and consider increasing monitoring of open source repositories. The security community will likely scrutinize the OpenSSL vulnerabilities and prepare updates accordingly. Regarding researcher disclosures, Microsoft may adjust its stance, but the ongoing tension suggests that responsible disclosure practices will continue to evolve. Additionally, device manufacturers like TP-Link are expected to improve firmware security and domain management practices.
hardware security domain registration
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
How serious is the GitHub token vulnerability?
The vulnerability could allow attackers to exfiltrate GitHub authentication tokens via the embedded web-based VSCode editor, potentially leading to full account compromise if exploited. Microsoft has patched the issue, but users should update immediately.
What are the risks of unregistered domains in device firmware?
Unregistered domains referenced in firmware can be hijacked or misused, potentially enabling remote attacks or data interception. In this case, the researcher registered the domain to prevent misuse, but the underlying risk persists if domains are overlooked.
Should organizations update OpenSSL now?
Yes. The vulnerabilities include high-severity use-after-free bugs that could enable remote code execution. Organizations should apply the latest patches as soon as they are available.
Will Microsoft change its approach to vulnerability disclosures?
It remains uncertain. The company previously threatened criminal investigations against researchers but may adjust its stance following industry feedback. The ongoing disclosures suggest a complex balancing act between security and researcher engagement.
What steps should organizations take after these incidents?
Organizations should review their supply chain security, patch affected systems promptly, monitor open source dependencies, and maintain strict domain and firmware management practices to mitigate similar risks.
Source: Hackaday