
KEDB #001 — Nx Console Supply Chain Attack: Four Lessons for CISO Teams
In May 2026, the VS Code extension Nx Console 18.95.0 was compromised and stole developer credentials en masse via auto-update; this KEDB entry draws four lessons for CISO teams: uncontrolled extension trust chains, auto-update as a double-edged sword, token hygiene, and build pipeline isolation — with concrete action
CISA Administrator Exposed AWS GovCloud Keys on GitHub
A CISA contractor stored highly sensitive credentials for AWS GovCloud accounts and internal systems in a public GitHub repository, containing cloud keys, plaintext passwords, and administrative data—rated by security firm GitGuardian as the most severe government data leak of their career.









