GitHub users are being targeted in a phishing and extortion campaign which tricks victims into granting external access to their accounts and repositories. The scam uses GitHub’s email notification system and a malicious OAuth app. Once permission is gained, the attacker wipes user repos and demands a ransom via Telegram for the recovery of their data. GitHub has advised not to click links in suspicious messages and warned users to be wary of authorising OAuth apps.

HashiCorp Nomad Vulnerability Allows Privilege Escalation via ACL Policy Lookup Exploit
A critical vulnerability (CVE-2025-4922) in HashiCorp Nomad allows privilege escalation via improper Access Control List (ACL) policy lookups. Affected versions (1.4.0-1.10.1) can let attackers create