⤷ Title: Poisoned Pipeline in Google’s Gemini-CLI: workflow_run PPE
════════════════════════
𐀪 Author: Rajat shukla
════════════════════════
ⴵ Time: Sat, 20 Jun 2026 16:55:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #github_actions #google #supply_chain_security
════════════════════════
𐀪 Author: Rajat shukla
════════════════════════
ⴵ Time: Sat, 20 Jun 2026 16:55:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #github_actions #google #supply_chain_security
Medium
Poisoned Pipeline in Google’s Gemini-CLI: workflow_run PPE
How attacker-controlled artifact data flows into a privileged GitHub Actions context and exposes GEMINI_API_KEY — found via Google OSS VRP.
⤷ Title: Atdork
════════════════════════
𐀪 Author: Dzone
════════════════════════
ⴵ Time: Sun, 21 Jun 2026 00:45:05 GMT
════════════════════════
⌗ Tags: #python #google_dork #github #ethical_hacking #google_dorking
════════════════════════
𐀪 Author: Dzone
════════════════════════
ⴵ Time: Sun, 21 Jun 2026 00:45:05 GMT
════════════════════════
⌗ Tags: #python #google_dork #github #ethical_hacking #google_dorking
Medium
Atdork
Atdork: OSINT Dorking Tool dengan Resilience Engine untuk Penetration Testing dan Security Research
⤷ Title: Novo Nordisk Breach: How a Leaked GitHub Token Exposed the Exact Ozempic Formula
════════════════════════
𐀪 Author: Pentesty
════════════════════════
ⴵ Time: Sun, 21 Jun 2026 02:23:36 GMT
════════════════════════
⌗ Tags: #pentesting #hacking #ozempic #github #pentesty
════════════════════════
𐀪 Author: Pentesty
════════════════════════
ⴵ Time: Sun, 21 Jun 2026 02:23:36 GMT
════════════════════════
⌗ Tags: #pentesting #hacking #ozempic #github #pentesty
Medium
Novo Nordisk Breach: How a Leaked GitHub Token Exposed the Exact Ozempic Formula
Published by Pentesty · Data Breach · Pharma · Source Code Leak
⤷ Title: Introducing PenTest Toolkit v2.0.0: A Modern AI-Powered Penetration Testing Framework
════════════════════════
𐀪 Author: Mohammed Muneef
════════════════════════
ⴵ Time: Mon, 22 Jun 2026 07:05:41 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #cybersecurity #github #medium
════════════════════════
𐀪 Author: Mohammed Muneef
════════════════════════
ⴵ Time: Mon, 22 Jun 2026 07:05:41 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #cybersecurity #github #medium
Medium
Introducing PenTest Toolkit v2.0.0: A Modern AI-Powered Penetration Testing Framework
Introduction
⤷ Title: 10,000 Fake GitHub Repositories Spread Trojan Malware
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 22 Jun 2026 08:32:30 +0000
════════════════════════
⌗ Tags: #Malware #Github #Infostealer #malware #SmartLoader #StealC #supply chain attack
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 22 Jun 2026 08:32:30 +0000
════════════════════════
⌗ Tags: #Malware #Github #Infostealer #malware #SmartLoader #StealC #supply chain attack
Information Security News
10,000 Fake GitHub Repositories Spread Trojan Malware
GitHub has filled up with fake repositories. They disguise themselves as ordinary developer projects. In reality, they push Trojans through links to ZIP archives. A developer using the alias Orchi…
⤷ Title: Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 22 Jun 2026 12:47:25 +0000
════════════════════════
⌗ Tags: #Security #Malware #Check Point #Clipper #Crypto #Cyber Attack #Cybersecurity #GitHub #Scam #VirusTotal
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 22 Jun 2026 12:47:25 +0000
════════════════════════
⌗ Tags: #Security #Malware #Check Point #Clipper #Crypto #Cyber Attack #Cybersecurity #GitHub #Scam #VirusTotal
Hackread
Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper
A multi-platform malware campaign abuses fake trust signals to infect Windows and Mac users with a crypto clipper packed with 15,500 attacker wallets.
⤷ Title: GitBait Phishing Campaign Targets 12 Mexican Banks via GitHub Pages
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 09:22:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credential Harvesting #Financial Sector #GitBait #GitHub Pages #Mexican banks #phishing #SheetBest #Telegram bot
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 09:22:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credential Harvesting #Financial Sector #GitBait #GitHub Pages #Mexican banks #phishing #SheetBest #Telegram bot
Daily CyberSecurity
GitBait Phishing Campaign Targets 12 Mexican Banks via GitHub Pages
The GitBait phishing campaign abuses GitHub Pages and the SheetBest API to steal banking credentials from at least 12 Mexican financial institutions.
⤷ Title: ‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 16:31:16 +0000
════════════════════════
⌗ Tags: #Security #CI/CD #Cordyceps #Cybersecurity #GitHub #Novee #Supply Chain #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 16:31:16 +0000
════════════════════════
⌗ Tags: #Security #CI/CD #Cordyceps #Cybersecurity #GitHub #Novee #Supply Chain #Vulnerability
Hackread
‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking
Novee Security reveals Cordyceps, a CI/CD vulnerability in GitHub Actions workflows that let anonymous users poison builds and expose tokens across major projects today.
⤷ Title: 8 GitHub Repositories That Make Google Dorking Ridiculously Powerful
════════════════════════
𐀪 Author: Devansh Patel
════════════════════════
ⴵ Time: Sun, 28 Jun 2026 14:07:34 GMT
════════════════════════
⌗ Tags: #google #github #ethical_hacking #cybersecurity #cyber_security_awareness
════════════════════════
𐀪 Author: Devansh Patel
════════════════════════
ⴵ Time: Sun, 28 Jun 2026 14:07:34 GMT
════════════════════════
⌗ Tags: #google #github #ethical_hacking #cybersecurity #cyber_security_awareness
Medium
8 GitHub Repositories That Make Google Dorking Ridiculously Powerful
Most people think Google is just a search engine.
⤷ Title: Gemini CLI Vulnerability Hits Maximum CVSS 10 Score
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 01:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12537 #Gemini CLI #GitHub Actions #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 01:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12537 #Gemini CLI #GitHub Actions #Vulnerability
Daily CyberSecurity
Gemini CLI Vulnerability Hits Maximum CVSS 10 Score
A critical Gemini CLI vulnerability (CVE-2026-12537) exposes developer workflows to maximum severity attacks. Google disclosed this CVSS 10 rating flaw recently. TL;DR A critical Gemini CLI vulner…