⤷ Title: AI Agent Finds GitHub Actions Bug, Reaches Snowflake’s Internal Jira
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 14:02:24 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI security #Credential Exposure #GitHub Actions #GitHub Copilot #Shell Injection #Snowflake #Wiz
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 14:02:24 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI security #Credential Exposure #GitHub Actions #GitHub Copilot #Shell Injection #Snowflake #Wiz
Information Security News
AI Agent Finds GitHub Actions Bug, Reaches Snowflake’s Internal Jira
An AI agent designed to hunt for vulnerabilities independently discovered a flaw within a public Snowflake repository and used it to gain access to the company’s internal Jira system. The vu…
⤷ Title: Operation RepoGhost: Russian-Linked Malware Hiding in GitHub Repositories
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 04 Sep 2026 12:30:32 +0000
════════════════════════
⌗ Tags: #Malware #Avyukt Security #CountLoader #GitHub malware #Go infostealer #Infostealer #NovaStealer #Operation RepoGhost #Supply Chain
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 04 Sep 2026 12:30:32 +0000
════════════════════════
⌗ Tags: #Malware #Avyukt Security #CountLoader #GitHub malware #Go infostealer #Infostealer #NovaStealer #Operation RepoGhost #Supply Chain
Information Security News
Operation RepoGhost: Russian-Linked Malware Hiding in GitHub Repositories
GitHub has been turned into a shop window for malware, and the victim need neither open a suspicious archive nor visit a counterfeit website. Researchers at Avyukt Security have uncovered Operatio…
⤷ Title: Vibe-Coded Apps Are the New Bug Bounty Goldmine: Complete Recon Workflow for AI-Built Applications
════════════════════════
𐀪 Author: Deepanshu Deep
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 06:25:59 GMT
════════════════════════
⌗ Tags: #github #bug_bounty #vibe_coding #coding
════════════════════════
𐀪 Author: Deepanshu Deep
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 06:25:59 GMT
════════════════════════
⌗ Tags: #github #bug_bounty #vibe_coding #coding
Medium
Vibe-Coded Apps Are the New Bug Bounty Goldmine: Complete Recon Workflow for AI-Built Applications
Every few months, a new development trend changes how applications are built. In 2026, that trend is vibe coding. Someone can have an idea…
⤷ Title: Secret Scanning Is Becoming a Merge Gate. That’s a Better Place to Stop Leaks.
════════════════════════
𐀪 Author: Puja Maheshvari
════════════════════════
ⴵ Time: Sun, 13 Sep 2026 03:36:43 GMT
════════════════════════
⌗ Tags: #application_security #github_actions #devops #devsecops #ci_cd_pipeline
════════════════════════
𐀪 Author: Puja Maheshvari
════════════════════════
ⴵ Time: Sun, 13 Sep 2026 03:36:43 GMT
════════════════════════
⌗ Tags: #application_security #github_actions #devops #devsecops #ci_cd_pipeline
Medium
Secret Scanning Is Becoming a Merge Gate. That’s a Better Place to Stop Leaks.
A secret committed to a branch is already a problem. A secret merged into the default branch is usually a much bigger one.
⤷ Title: FuzzingLocalBot v3.4 — A Web Fuzzer with Enhanced Detection & Reporting
════════════════════════
𐀪 Author: E-xX
════════════════════════
ⴵ Time: Sun, 13 Sep 2026 07:24:22 GMT
════════════════════════
⌗ Tags: #red_team_tools #fuzzing #cybersecurity #github #bug_bounty
════════════════════════
𐀪 Author: E-xX
════════════════════════
ⴵ Time: Sun, 13 Sep 2026 07:24:22 GMT
════════════════════════
⌗ Tags: #red_team_tools #fuzzing #cybersecurity #github #bug_bounty
Medium
FuzzingLocalBot v3.4 — A Web Fuzzer with Enhanced Detection & Reporting
What is FuzzingLocalBot?
⤷ Title: I built an open-source personal web memory for coding agents
════════════════════════
𐀪 Author: Jojo Mensah
════════════════════════
ⴵ Time: Sun, 13 Sep 2026 08:08:43 GMT
════════════════════════
⌗ Tags: #xs #github #reddit #social_bookmarking #bookmarks
════════════════════════
𐀪 Author: Jojo Mensah
════════════════════════
ⴵ Time: Sun, 13 Sep 2026 08:08:43 GMT
════════════════════════
⌗ Tags: #xs #github #reddit #social_bookmarking #bookmarks
Medium
I built an open-source personal web memory for coding agents
I kept saving things I knew I would need later: a GitHub repository, a Reddit answer, a post on X, a useful article, a small code pattern…
⤷ Title: GitHub’s $100,000 Security Bounty Highlights the Hidden Risks Inside Software Development Pipelines
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Mon, 14 Sep 2026 11:03:22 GMT
════════════════════════
⌗ Tags: #software_supply_chain #github #rce #software_security #secure_coding
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Mon, 14 Sep 2026 11:03:22 GMT
════════════════════════
⌗ Tags: #software_supply_chain #github #rce #software_security #secure_coding
Medium
GitHub’s $100,000 Security Bounty Highlights the Hidden Risks Inside Software Development Pipelines
Modern software development depends heavily on platforms that developers trust every day.
⤷ Title: Think Like an Attacker: CI/CD Security in the AI Era
════════════════════════
𐀪 Author: Hideaki Takahashi
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 14:06:14 GMT
════════════════════════
⌗ Tags: #github_actions #continuous_integration #ai_agent #hacking #information_security
════════════════════════
𐀪 Author: Hideaki Takahashi
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 14:06:14 GMT
════════════════════════
⌗ Tags: #github_actions #continuous_integration #ai_agent #hacking #information_security
Medium
Think Like an Attacker: CI/CD Security in the AI Era
How to turn a working exploit into a repeatable GitHub Actions test with h5i
⤷ Title: GitHub Copilot Runtime Migrated to Rust
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 13:15:49 +0000
════════════════════════
⌗ Tags: #Technology #Artificial intelligence #GitHub Copilot #Rust #Software Engineering
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 13:15:49 +0000
════════════════════════
⌗ Tags: #Technology #Artificial intelligence #GitHub Copilot #Rust #Software Engineering
Information Security News
GitHub Copilot Runtime Migrated to Rust
GitHub has successfully rewritten the entire Copilot runtime environment, transitioning from TypeScript to Rust. Astonishingly, Copilot’s own artificial intelligence agents generated the vas…
⤷ Title: Leaked GitHub App Private Keys Expose Critical Infrastructure
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 12:22:27 +0000
════════════════════════
⌗ Tags: #Data Leak #Data Exposure #GitGuardian #GitHub App private keys #leaked GitHub App private keys #Supply Chain Security
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 12:22:27 +0000
════════════════════════
⌗ Tags: #Data Leak #Data Exposure #GitGuardian #GitHub App private keys #leaked GitHub App private keys #Supply Chain Security
Daily CyberSecurity
Leaked GitHub App Private Keys Expose Critical Infrastructure
At a Glance Attribute Details Organization Multiple entities (including the US CDC, BuildBuddy, and Civica) Data Exposed GitHub App RSA private keys, repository access, administrative permissions …
⤷ Title: Critical GitHub Enterprise Server Vulnerabilities Addressed
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 24 Sep 2026 00:40:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_77987 #cybersecurity #github #Remote Code Execution #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 24 Sep 2026 00:40:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_77987 #cybersecurity #github #Remote Code Execution #Vulnerability
Daily CyberSecurity
Critical GitHub Enterprise Server Vulnerabilities Addressed
TL;DR GitHub released security updates addressing several GitHub Enterprise Server vulnerabilities. These critical flaws could permit remote code execution and unauthorized access to internal serv…
⤷ Title: Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sat, 26 Sep 2026 19:02:54 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #Scams and Fraud #AI Agents #AI Tools #BBC #Cyber Crime #Cybersecurity #Fraud #GitHub #macOS #Manifold #Placeholder Domains #Scam
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sat, 26 Sep 2026 19:02:54 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #Scams and Fraud #AI Agents #AI Tools #BBC #Cyber Crime #Cybersecurity #Fraud #GitHub #macOS #Manifold #Placeholder Domains #Scam
Hackread
Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams
Manifold Security found placeholder domains cited in 359,000 GitHub files and 349 AI agent skills serving cloaked scam redirects observed on macOS.
⤷ Title: GitHub Blocks New Outlook and Hotmail Sign-Ups
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 28 Sep 2026 03:44:49 +0000
════════════════════════
⌗ Tags: #Technology #cybersecurity #Email Security #github #Microsoft
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 28 Sep 2026 03:44:49 +0000
════════════════════════
⌗ Tags: #Technology #cybersecurity #Email Security #github #Microsoft
Daily CyberSecurity
GitHub Blocks New Outlook and Hotmail Sign-Ups
GitHub, the premier code-hosting platform owned by Microsoft, has discreetly implemented a ban preventing the creation of new accounts utilizing Microsoft’s own Outlook and Hotmail email add…
⤷ Title: Some experiments and fun with SAST, DAST and CI/CD tools. And Juice Shop.
════════════════════════
𐀪 Author: Swapnil Deshpande
════════════════════════
ⴵ Time: Mon, 28 Sep 2026 05:10:33 GMT
════════════════════════
⌗ Tags: #devsecops #github_actions #application_security #ci_cd_pipeline #information_security
════════════════════════
𐀪 Author: Swapnil Deshpande
════════════════════════
ⴵ Time: Mon, 28 Sep 2026 05:10:33 GMT
════════════════════════
⌗ Tags: #devsecops #github_actions #application_security #ci_cd_pipeline #information_security
Medium
Some experiments and fun with SAST, DAST and CI/CD tools. And Juice Shop.
I took a look at setting up SAST and DAST tools on OWASP Juice Shop. SAST scanners look at the application code to find security issues and…
⤷ Title: Daily CyberSecurity Launches CVE Alerts, an Automated Vulnerability Intelligence Service for IT and Security Teams
════════════════════════
𐀪 Author: ddos-admin
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 01:05:24 +0000
════════════════════════
⌗ Tags: #Announcement #CISA KEV #CVE Alerts #CVE_Watch #EPSS #Exploit Intelligence #Free Trial #GitHub Issues #Microsoft Teams #patch management #Reserved CVE #Slack Integration #threat intelligence #vulnerability management
════════════════════════
𐀪 Author: ddos-admin
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 01:05:24 +0000
════════════════════════
⌗ Tags: #Announcement #CISA KEV #CVE Alerts #CVE_Watch #EPSS #Exploit Intelligence #Free Trial #GitHub Issues #Microsoft Teams #patch management #Reserved CVE #Slack Integration #threat intelligence #vulnerability management
Daily CyberSecurity
Daily CyberSecurity Launches CVE Alerts, an Automated Vulnerability Intelligence Service for IT and Security Teams
Daily CyberSecurity, the team behind the CVE-Watchtower vulnerability tracking platform on securityonline.info, today announced the general availability of CVE Alerts, a subscription service that …
⤷ Title: Placeholder Domain Hijacked for ClickFix Campaigns
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 13:11:40 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Github #malware #Social Engineering
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 13:11:40 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Github #malware #Social Engineering
Information Security News
Placeholder Domain Hijacked for ClickFix Campaigns
A mundane, ubiquitous example URL embedded within countless developer documentation files has horrifyingly metamorphosed into a live attack vector. The specific domain, third-party[.]com, historic…
⤷ Title: GeoServer Cloud Fixes CVSS 10 GitHub Actions Flaw That Exposed Repository Secrets
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 02:02:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #GeoServer #GeoServer Cloud #GeoServer Cloud vulnerability #GitHub Actions #pull_request_target #Supply Chain Security
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 02:02:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #GeoServer #GeoServer Cloud #GeoServer Cloud vulnerability #GitHub Actions #pull_request_target #Supply Chain Security
Daily CyberSecurity
GeoServer Cloud Fixes CVSS 10 GitHub Actions Flaw That Exposed Repository Secrets
TL;DR GeoServer maintainers disclosed a CVSS 10 GeoServer Cloud vulnerability in a GitHub Actions workflow. It could have let an outside contributor run code on the build runner and steal reposito…
⤷ Title: AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 08:21:06 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Agents #Data Exposure #DevSecOps #github #Glow Labs #PixelLeak #shadow AI
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 08:21:06 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Agents #Data Exposure #DevSecOps #github #Glow Labs #PixelLeak #shadow AI
Daily CyberSecurity
AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos
More than 13,000 internal screenshots sat in public GitHub repositories, open to anyone. Glow Labs says AI coding agents put them there. The firm calls this AI agent screenshot leak “PixelLe…
⤷ Title: PixelLeak: AI Agents Expose Corporate Secrets
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 12:37:29 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Agents #data breach #Github #PixelLeak
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 12:37:29 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Agents #data breach #Github #PixelLeak
Information Security News
PixelLeak: AI Agents Expose Corporate Secrets
When an AI agent encountered difficulties attaching a screenshot to a private pull request, certain systems engineered an unexpected circumvention. They autonomously generated public repositories …
⤷ Title: PixelLeak: AI Agents Expose Corporate Secrets
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 12:37:29 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Agents #data breach #Github #PixelLeak
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 12:37:29 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Agents #data breach #Github #PixelLeak
Information Security News
PixelLeak: AI Agents Expose Corporate Secrets
When an AI agent encountered difficulties attaching a screenshot to a private pull request, certain systems engineered an unexpected circumvention. They autonomously generated public repositories …