⤷ Title: Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
Daily CyberSecurity
Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
Composer CVE-2026-45793 leaks GitHub tokens into CI/CD logs due to a validation error. Update to version 2.9.8 now and audit your GitHub Action logs.
⤷ Title: Mini Shai-Hulud Alert: TeamPCP Hijacks @tanstack and PyPI to Poison 12 Million Weekly Downloads
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 08:12:28 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack #GitHub Actions #InfoSec 2026 #Mini Shai_Hulud #npm security #OIDC #PyPI malware #supply chain attack #tanstack_runner.js #TeamPCP #Trusted Publishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 08:12:28 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack #GitHub Actions #InfoSec 2026 #Mini Shai_Hulud #npm security #OIDC #PyPI malware #supply chain attack #tanstack_runner.js #TeamPCP #Trusted Publishing
Penetration Testing Tools
Mini Shai-Hulud Alert: TeamPCP Hijacks @tanstack and PyPI to Poison 12 Million Weekly Downloads
The Mini Shai-Hulud incursion has once again laid siege to the software supply chain. While the initial offensive
⤷ Title: The Trojan PR: Achieving Code Execution in GitHub Actions via Pipeline Poisoning
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:18:45 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #bug_bounty #github_actions #ci_cd_pipeline
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:18:45 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #bug_bounty #github_actions #ci_cd_pipeline
Medium
The Trojan PR: Achieving Code Execution in GitHub Actions via Pipeline Poisoning
Introduction
⤷ Title: The Trojan PR: Achieving Code Execution in GitHub Actions via Pipeline Poisoning
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Mon, 18 May 2026 10:19:33 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #bug_bounty #github_actions #ci_cd_pipeline
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Mon, 18 May 2026 10:19:33 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #bug_bounty #github_actions #ci_cd_pipeline
Medium
The Trojan PR: Achieving Code Execution in GitHub Actions via Pipeline Poisoning
Introduction
⤷ Title: Shai-Hulud Returns: Massive npm Supply Chain Attack Hijacks AntV Ecosystem to Scrape GitHub Runner Memory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:52:05 +0000
════════════════════════
⌗ Tags: #Malware #AntV Ecosystem #atool #Claude Code Hijack #Cyber Security #GitHub Actions #infosec #Mini Shai_Hulud #npm Worm #Runner Memory Scraper #supply chain attack #timeago.js
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:52:05 +0000
════════════════════════
⌗ Tags: #Malware #AntV Ecosystem #atool #Claude Code Hijack #Cyber Security #GitHub Actions #infosec #Mini Shai_Hulud #npm Worm #Runner Memory Scraper #supply chain attack #timeago.js
Daily CyberSecurity
Shai-Hulud Returns: Massive npm Supply Chain Attack Hijacks AntV Ecosystem to Scrape GitHub Runner Memory
The Mini Shai-Hulud npm worm has hijacked the atool account, poisoning AntV & timeago.js to scrape GitHub runner memory. Execute a full reset now!
⤷ Title: Ecosystem Poisoned: Mini Shai-Hulud Worm Hijacks @antv npm Packages to Target CI/CD Pipelines
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 02:59:48 +0000
════════════════════════
⌗ Tags: #Malware #AntV Ecosystem #CI/CD Pipeline Security #Cyber Security #echarts_for_react #GitHub Actions Memory Scraping #infosec #Mini Shai_Hulud #npm Supply Chain Attack #Sigstore Forgery #TeamPCP #Token Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 02:59:48 +0000
════════════════════════
⌗ Tags: #Malware #AntV Ecosystem #CI/CD Pipeline Security #Cyber Security #echarts_for_react #GitHub Actions Memory Scraping #infosec #Mini Shai_Hulud #npm Supply Chain Attack #Sigstore Forgery #TeamPCP #Token Theft
Daily CyberSecurity
Ecosystem Poisoned: Mini Shai-Hulud Worm Hijacks @antv npm Packages to Target CI/CD Pipelines
Microsoft warns of an aggressive Mini Shai-Hulud worm attack targeting the @antv npm ecosystem and stealing secrets from cloud-connected CI/CD pipelines.
⤷ Title: Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
Daily CyberSecurity
Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
Socket exposes a clever cross-ecosystem supply chain attack targeting PHP packages by hiding a malicious JS postinstall backdoor inside package.json.
⤷ Title: The Shai-Hulud Infiltration: Red Hat Exploited in Sovereign Supply Chain Breach
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 04:35:11 +0000
════════════════════════
⌗ Tags: #Malware #credential harvesting malware #GitHub Actions OIDC bypass #Mini Shai_Hulud worm #Red Hat NPM attack #supply chain compromise #trusted publishing vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 04:35:11 +0000
════════════════════════
⌗ Tags: #Malware #credential harvesting malware #GitHub Actions OIDC bypass #Mini Shai_Hulud worm #Red Hat NPM attack #supply chain compromise #trusted publishing vulnerability
Daily CyberSecurity
The Shai-Hulud Infiltration: Red Hat Exploited in Sovereign Supply Chain Breach
Recently, several prominent cybersecurity corporations simultaneously intercepted a series of malicious software repositories. Specifically, an adversary uploaded these corrupted packages directly…
⤷ Title: Shift Security Left: Detecting Code Vulnerabilities Early with CodeQL in GitHub Actions
════════════════════════
𐀪 Author: SwayamOps
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 05:36:39 GMT
════════════════════════
⌗ Tags: #shift_left_security #github_actions #application_security #codeql #devsecops
════════════════════════
𐀪 Author: SwayamOps
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 05:36:39 GMT
════════════════════════
⌗ Tags: #shift_left_security #github_actions #application_security #codeql #devsecops
Medium
Shift Security Left: Detecting Code Vulnerabilities Early with CodeQL in GitHub Actions
Most CI pipelines are great at answering one question:
⤷ Title: Building a Parallel Security Gate in CI: Combining Secret Scanning, Dependency Audits, and SAST…
════════════════════════
𐀪 Author: SwayamOps
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 05:58:28 GMT
════════════════════════
⌗ Tags: #cicd #application_security #github_actions #shift_left_security #devsecops
════════════════════════
𐀪 Author: SwayamOps
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 05:58:28 GMT
════════════════════════
⌗ Tags: #cicd #application_security #github_actions #shift_left_security #devsecops
Medium
Building a Parallel Security Gate in CI: Combining Secret Scanning, Dependency Audits, and SAST…
One of the biggest challenges in DevSecOps isn’t convincing teams that security matters.
❤1
⤷ Title: Poisoned Pipeline in Google’s Gemini-CLI: workflow_run PPE
════════════════════════
𐀪 Author: Rajat shukla
════════════════════════
ⴵ Time: Sat, 20 Jun 2026 16:55:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #github_actions #google #supply_chain_security
════════════════════════
𐀪 Author: Rajat shukla
════════════════════════
ⴵ Time: Sat, 20 Jun 2026 16:55:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #github_actions #google #supply_chain_security
Medium
Poisoned Pipeline in Google’s Gemini-CLI: workflow_run PPE
How attacker-controlled artifact data flows into a privileged GitHub Actions context and exposes GEMINI_API_KEY — found via Google OSS VRP.
⤷ Title: Gemini CLI Vulnerability Hits Maximum CVSS 10 Score
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 01:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12537 #Gemini CLI #GitHub Actions #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 01:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12537 #Gemini CLI #GitHub Actions #Vulnerability
Daily CyberSecurity
Gemini CLI Vulnerability Hits Maximum CVSS 10 Score
A critical Gemini CLI vulnerability (CVE-2026-12537) exposes developer workflows to maximum severity attacks. Google disclosed this CVSS 10 rating flaw recently. TL;DR A critical Gemini CLI vulner…
⤷ Title: GitLost: GitHub’s AI Agent Tricked Into Leaking Private Repository Data
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 13:00:20 +0000
════════════════════════
⌗ Tags: #Security #Agentic AI #Cybersecurity #GitHub #GitHub Actions #GitLost #Privacy #Repository #Vulnerability
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 13:00:20 +0000
════════════════════════
⌗ Tags: #Security #Agentic AI #Cybersecurity #GitHub #GitHub Actions #GitLost #Privacy #Repository #Vulnerability
Hackread
GitLost: GitHub’s AI Agent Tricked Into Leaking Private Repository Data
Noma Labs details GitLost, a prompt injection flaw that made GitHub's AI agent expose private repo data through a crafted public issue and guardrail failures.
⤷ Title: GitHub Actions Abuse Powers a Distributed cPanel and WHM Attack Campaign
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 02:29:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cPanel and WHM exploitation #Credential Theft #CVE_2026_41940 #GitHub Actions abuse #Packagist #supply chain attack
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 02:29:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cPanel and WHM exploitation #Credential Theft #CVE_2026_41940 #GitHub Actions abuse #Packagist #supply chain attack
Daily CyberSecurity
GitHub Actions Abuse Powers a Distributed cPanel and WHM Attack Campaign
At a Glance Actor or group Unattributed threat actor; no group name published Activity type GitHub Actions abuse, internet scanning, credential theft Targets Internet-facing cPanel and WHM servers…
⤷ Title: Analyzing GitHub Actions workflows at scale
════════════════════════
𐀪 Author: Kulkan Security
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 13:44:03 GMT
════════════════════════
⌗ Tags: #prompt_injection_attack #penetration_testing #supply_chain_security #vulnerability #github_actions
════════════════════════
𐀪 Author: Kulkan Security
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 13:44:03 GMT
════════════════════════
⌗ Tags: #prompt_injection_attack #penetration_testing #supply_chain_security #vulnerability #github_actions
Medium
Analyzing GitHub Actions workflows at scale
This research project was born after reading many news articles about supply chain attacks and highly used packages being compromised to…
⤷ Title: AI Agent Finds GitHub Actions Bug, Reaches Snowflake’s Internal Jira
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 14:02:24 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI security #Credential Exposure #GitHub Actions #GitHub Copilot #Shell Injection #Snowflake #Wiz
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 14:02:24 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI security #Credential Exposure #GitHub Actions #GitHub Copilot #Shell Injection #Snowflake #Wiz
Information Security News
AI Agent Finds GitHub Actions Bug, Reaches Snowflake’s Internal Jira
An AI agent designed to hunt for vulnerabilities independently discovered a flaw within a public Snowflake repository and used it to gain access to the company’s internal Jira system. The vu…
⤷ Title: Secret Scanning Is Becoming a Merge Gate. That’s a Better Place to Stop Leaks.
════════════════════════
𐀪 Author: Puja Maheshvari
════════════════════════
ⴵ Time: Sun, 13 Sep 2026 03:36:43 GMT
════════════════════════
⌗ Tags: #application_security #github_actions #devops #devsecops #ci_cd_pipeline
════════════════════════
𐀪 Author: Puja Maheshvari
════════════════════════
ⴵ Time: Sun, 13 Sep 2026 03:36:43 GMT
════════════════════════
⌗ Tags: #application_security #github_actions #devops #devsecops #ci_cd_pipeline
Medium
Secret Scanning Is Becoming a Merge Gate. That’s a Better Place to Stop Leaks.
A secret committed to a branch is already a problem. A secret merged into the default branch is usually a much bigger one.
⤷ Title: Think Like an Attacker: CI/CD Security in the AI Era
════════════════════════
𐀪 Author: Hideaki Takahashi
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 14:06:14 GMT
════════════════════════
⌗ Tags: #github_actions #continuous_integration #ai_agent #hacking #information_security
════════════════════════
𐀪 Author: Hideaki Takahashi
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 14:06:14 GMT
════════════════════════
⌗ Tags: #github_actions #continuous_integration #ai_agent #hacking #information_security
Medium
Think Like an Attacker: CI/CD Security in the AI Era
How to turn a working exploit into a repeatable GitHub Actions test with h5i
⤷ Title: Some experiments and fun with SAST, DAST and CI/CD tools. And Juice Shop.
════════════════════════
𐀪 Author: Swapnil Deshpande
════════════════════════
ⴵ Time: Mon, 28 Sep 2026 05:10:33 GMT
════════════════════════
⌗ Tags: #devsecops #github_actions #application_security #ci_cd_pipeline #information_security
════════════════════════
𐀪 Author: Swapnil Deshpande
════════════════════════
ⴵ Time: Mon, 28 Sep 2026 05:10:33 GMT
════════════════════════
⌗ Tags: #devsecops #github_actions #application_security #ci_cd_pipeline #information_security
Medium
Some experiments and fun with SAST, DAST and CI/CD tools. And Juice Shop.
I took a look at setting up SAST and DAST tools on OWASP Juice Shop. SAST scanners look at the application code to find security issues and…
⤷ Title: GeoServer Cloud Fixes CVSS 10 GitHub Actions Flaw That Exposed Repository Secrets
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 02:02:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #GeoServer #GeoServer Cloud #GeoServer Cloud vulnerability #GitHub Actions #pull_request_target #Supply Chain Security
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 02:02:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #GeoServer #GeoServer Cloud #GeoServer Cloud vulnerability #GitHub Actions #pull_request_target #Supply Chain Security
Daily CyberSecurity
GeoServer Cloud Fixes CVSS 10 GitHub Actions Flaw That Exposed Repository Secrets
TL;DR GeoServer maintainers disclosed a CVSS 10 GeoServer Cloud vulnerability in a GitHub Actions workflow. It could have let an outside contributor run code on the build runner and steal reposito…