⤷ Title: Patching the CVSS 10 RCE Hole in Gemini CLI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 03:01:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #@google/gemini_cli #AI security #Automation #CI/CD security #CVSS 10 #Gemini CLI #GitHub Actions #infosec #Patch Alert #Prompt injection #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 03:01:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #@google/gemini_cli #AI security #Automation #CI/CD security #CVSS 10 #Gemini CLI #GitHub Actions #infosec #Patch Alert #Prompt injection #rce
⤷ Title: The Poisoned Pipeline: How a GitHub Actions Flaw Infiltrated the Popular “Elementary-Data” Library
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:30:10 +0000
════════════════════════
⌗ Tags: #Malware #2026 Tech News #cloud security #Credential Stealer #Data Engineering #dbt #Docker #Elementary_data #GitHub Actions #GITHUB_TOKEN #PyPI #Python Security #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:30:10 +0000
════════════════════════
⌗ Tags: #Malware #2026 Tech News #cloud security #Credential Stealer #Data Engineering #dbt #Docker #Elementary_data #GitHub Actions #GITHUB_TOKEN #PyPI #Python Security #supply chain attack
Penetration Testing Tools
The Poisoned Pipeline: How a GitHub Actions Flaw Infiltrated the Popular "Elementary-Data" Library
The ubiquitous Python library elementary-data has emerged as a conduit for the exfiltration of sensitive developer telemetry. The
⤷ Title: Desert Power in the Code: How the “Mini Shai-Hulud” Malware Burrows into SAP’s npm Supply Chain
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 07:44:09 +0000
════════════════════════
⌗ Tags: #Malware #@cap_js #CI/CD Security #CircleCI #cloud security #Credentials Theft #Cyber Security 2026 #GitHub Actions #malware #Mini Shai_Hulud #npm #SAP #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 07:44:09 +0000
════════════════════════
⌗ Tags: #Malware #@cap_js #CI/CD Security #CircleCI #cloud security #Credentials Theft #Cyber Security 2026 #GitHub Actions #malware #Mini Shai_Hulud #npm #SAP #supply chain attack
Information Security News
Desert Power in the Code: How the "Mini Shai-Hulud" Malware Burrows into SAP’s npm Supply Chain
Adversaries have once again targeted the npm supply chain, though this incursion pursued a surgical and perilous objective:
⤷ Title: Supply Chains in the Crosshairs: Scan and Simulate Multi-Stage Attacks with Trajan
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 08:24:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Azure DevOps #CI/CD Security #DevSecOps #GitHub Actions #GitLab CI #jenkins #JFrog #Pentesting Tools #supply chain attack #Taint Tracking #Trajan #WebAssembly
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 08:24:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Azure DevOps #CI/CD Security #DevSecOps #GitHub Actions #GitLab CI #jenkins #JFrog #Pentesting Tools #supply chain attack #Taint Tracking #Trajan #WebAssembly
Penetration Testing Tools
Supply Chains in the Crosshairs: Scan and Simulate Multi-Stage Attacks with Trajan
Trajan isn't just a scanner. It maps dependency graphs and uses built-in attack plugins to simulate real-world CI/CD supply chain compromises.
⤷ Title: Supply Chain Siege: 84 TanStack Packages Compromised to Steal GitHub Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:37:03 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack/react_router #CI/CD security #credential stealer #GitHub Actions #infosec #JavaScript Security #Malware Analysis #npm Security #Socket Threat Research #supply chain attack #TanStack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:37:03 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack/react_router #CI/CD security #credential stealer #GitHub Actions #infosec #JavaScript Security #Malware Analysis #npm Security #Socket Threat Research #supply chain attack #TanStack
Daily CyberSecurity
Supply Chain Siege: 84 TanStack Packages Compromised to Steal GitHub Secrets
Urgent: 84 TanStack npm packages hijacked to harvest GitHub Actions secrets. Over 12M weekly downloads impacted. Audit your CI/CD pipelines and rotate tokens.
⤷ Title: Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
Daily CyberSecurity
Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
Composer CVE-2026-45793 leaks GitHub tokens into CI/CD logs due to a validation error. Update to version 2.9.8 now and audit your GitHub Action logs.
⤷ Title: Mini Shai-Hulud Alert: TeamPCP Hijacks @tanstack and PyPI to Poison 12 Million Weekly Downloads
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 08:12:28 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack #GitHub Actions #InfoSec 2026 #Mini Shai_Hulud #npm security #OIDC #PyPI malware #supply chain attack #tanstack_runner.js #TeamPCP #Trusted Publishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 08:12:28 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack #GitHub Actions #InfoSec 2026 #Mini Shai_Hulud #npm security #OIDC #PyPI malware #supply chain attack #tanstack_runner.js #TeamPCP #Trusted Publishing
Penetration Testing Tools
Mini Shai-Hulud Alert: TeamPCP Hijacks @tanstack and PyPI to Poison 12 Million Weekly Downloads
The Mini Shai-Hulud incursion has once again laid siege to the software supply chain. While the initial offensive
⤷ Title: The Trojan PR: Achieving Code Execution in GitHub Actions via Pipeline Poisoning
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:18:45 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #bug_bounty #github_actions #ci_cd_pipeline
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:18:45 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #bug_bounty #github_actions #ci_cd_pipeline
Medium
The Trojan PR: Achieving Code Execution in GitHub Actions via Pipeline Poisoning
Introduction
⤷ Title: The Trojan PR: Achieving Code Execution in GitHub Actions via Pipeline Poisoning
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Mon, 18 May 2026 10:19:33 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #bug_bounty #github_actions #ci_cd_pipeline
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Mon, 18 May 2026 10:19:33 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #bug_bounty #github_actions #ci_cd_pipeline
Medium
The Trojan PR: Achieving Code Execution in GitHub Actions via Pipeline Poisoning
Introduction
⤷ Title: Shai-Hulud Returns: Massive npm Supply Chain Attack Hijacks AntV Ecosystem to Scrape GitHub Runner Memory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:52:05 +0000
════════════════════════
⌗ Tags: #Malware #AntV Ecosystem #atool #Claude Code Hijack #Cyber Security #GitHub Actions #infosec #Mini Shai_Hulud #npm Worm #Runner Memory Scraper #supply chain attack #timeago.js
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:52:05 +0000
════════════════════════
⌗ Tags: #Malware #AntV Ecosystem #atool #Claude Code Hijack #Cyber Security #GitHub Actions #infosec #Mini Shai_Hulud #npm Worm #Runner Memory Scraper #supply chain attack #timeago.js
Daily CyberSecurity
Shai-Hulud Returns: Massive npm Supply Chain Attack Hijacks AntV Ecosystem to Scrape GitHub Runner Memory
The Mini Shai-Hulud npm worm has hijacked the atool account, poisoning AntV & timeago.js to scrape GitHub runner memory. Execute a full reset now!