Floating servers depicting AI malware and intelligence credential theft.

Daily Cybersecurity News - June 28, 2026

Clean GitHub Repo Tricks AI Coding Agents Into Running Malware

Attackers are poisoning GitHub repos to make AI coding agents run malware during normal setup tasks.

They hide the payload inside scripts that look clean to scanners and humans, then let the agent clone and execute the repo as part of routine work.

The angle here is the abuse of agentic workflows rather than traditional social engineering or direct exploits. It reuses old repo poisoning tricks but targets new automation layers.

The report describes a proof-of-concept attack path, not confirmed real-world compromises.

Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials

Russian intelligence ran a years-long phishing campaign against Ukrainian government officials, military staff, politicians, and activists.

They sent SMS messages pretending to come from messaging app support teams, tricking targets into handing over credentials for accounts on Signal, Telegram, and Viber. The operation targeted high-value Ukrainian users specifically.

The technique is basic but effective because it exploits trust in app support channels instead of relying on malware or complex exploits.

SSU and the FBI worked the case together and confirmed the Russian intelligence link through shared infrastructure patterns.