# GitHub Breach Exposes 3,800 Repos | Microsoft Kills SMS Authentication | Proton Fights Canada Bill Page: https://stenobird.com/podcast/cybersecurity-today-65508/github-breach-exposes-3-800-repos-microsoft-kills-sms-authentication-proton-fights-canada-bill Text version: https://stenobird.com/podcast/cybersecurity-today-65508/github-breach-exposes-3-800-repos-microsoft-kills-sms-authentication-proton-fights-canada-bill.md Podcast: [Cybersecurity Today](https://stenobird.com/podcast/cybersecurity-today-65508) Published: 2026-05-22T00:10:00+00:00 Episode link: https://cybersecuritytoday.libsyn.com/github-breach-exposes-3800-repos-microsoft-kills-sms-authentication-proton-fights-canada-bill Audio file: https://traffic.libsyn.com/secure/cybersecuritytoday/CST_Fri_May_22_2026.mp3?dest-id=679928 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/github-breach-exposes-3-800-repos-microsoft-kills-sms-authentication-proton-fights-canada-bill Duration seconds: 559 ## Resource GitHub confirms a major supply chain breach after a malicious Visual Studio Code extension reportedly gave attackers linked to TeamPCP access to roughly 3,800 internal repositories. The bigger issue: developer workstations now hold some of the most sensitive secrets in modern software organizations. Also today: Microsoft begins phasing out SMS-based authentication for personal accounts, calling text-message authentication a growing fraud risk as it shifts toward phishing-resistant passkeys. Researchers also disclose a nine-year-old Linux privilege escalation flaw, CVE-2026-46333, nicknamed SSH-Keysign-Pwn, which can allow root-level access with local machine access. And Proton publicly threatens to leave Canada rather than comply with proposed surveillance legislation it says would undermine its no-logs privacy promise. Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security. If cybersecurity, privacy, and digital infrastructure matter to your business, this is the daily briefing you need. Timestamps: 00:00 Top Stories Rundown 00:24 GitHub Supply Chain Breach 01:09 Developer Workstations at Risk 02:31 Microsoft Ditches SMS MFA 04:15 Linux Root Escalation Flaw 06:11 Proton vs Canada Surveillance Bill 08:03 Wrap Up and Sign Off #cybersecurity #github #microsoft #linux #protonvpn #privacy #databreach #supplychainattack #infosec #cybernews ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/github-breach-exposes-3-800-repos-microsoft-kills-sms-authentication-proton-fights-canada-bill/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cybersecurity-today-65508/github-breach-exposes-3-800-repos-microsoft-kills-sms-authentication-proton-fights-canada-bill.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.