OIDC
-
SimpleHelp bug lets attackers create rogue technician accounts
A critical SimpleHelp flaw lets unauthenticated attackers create privileged technician accounts on OIDC-enabled servers. The bug affects version 5.5.15 and older, along with 6.0 pre-release builds, and was fixed on June 9.
-
UNC6426 used stolen npm keys to gain AWS administrator access in under 72 hours
UNC6426 leveraged keys from an August 2025 nx npm supply chain compromise to obtain a GitHub token and escalate to AWS administrator permissions in under 72 hours, leading to S3 data exfiltration and production resource destruction.


