Cybersecurity Daily: News & Threats · 22 May 2026 · 4 min

Bug Bounty Collapse, FIRESCALE C2 & Double Extortion Dominates

A poisoned VS Code extension exposed 3,800 GitHub repositories while TeamPCP's FIRESCALE malware hides C2 instructions in public commit messages. Plus: HackerOne slashes bug bounty payouts 75%, Linus Torvalds warns of a Linux maintainer crisis, and New Jersey's breach law redraws liability.

Cybersecurity Daily: News & Threats
Now Playing
Bug Bounty Collapse, FIRESCALE C2 & Double Extortion Dominates

Audio is available on Spreaker — see link below.

What's covered

GitHub Breached via VS Code Extension

A poisoned VS Code extension just handed attackers the keys to GitHub's internal codebase. That's not a theoretical supply chain risk.

Listen now →

FIRESCALE C2 and Mini Shai-Hulud Worm

TeamPCP isn't new to this. They've previously compromised tools like Trivy, LiteLLM, and TanStack.

Listen now →

Bug Bounty Economics Collapse

Now for a story that's been building quietly and just became operational. HackerOne has cut bug bounty payouts by seventy-five percent.

Listen now →

Linus Torvalds Declares Maintainer Crisis

The same pressure is hitting open-source directly. Linus Torvalds has described the Linux kernel security mailing list as unmanageable due to AI-generated duplicate reports.

Listen now →

Ransomware and New Jersey Breach Law

Two more items worth tracking. On ransomware, double extortion is now the dominant playbook.

Listen now →

Key Watchpoints

The two things worth watching closely are the downstream scope of the GitHub PyPI compromise, and whether the full extent of the Copilot and CodeQL internals exposure becomes clearer. Both carry second-order risk that hasn't fully materialized yet.

Listen now →

Chapter summary auto-generated from the verified script. Listen to the full episode for the complete content.

More episodes

From Cybersecurity Daily: News & Threats