Cybersecurity
264 articles RSS
Two GitHub Actions Disabled Since May's Mini Shai-Hulud Compromise Came Back Online in September, Reactivating Malware With No New Attack
Socket found that actions-cool/issues-helper and actions-cool/maintain-one-comment, disabled since May 2026, became reachable again on September 16 with their malicious tags intact, silently re-running the payload.
Vercel Patches Critical Next.js ImageResponse RCE Traced to a Satori SVG-Escaping Flaw
Vercel shipped Next.js 16.3.6 to fix a critical, 9.5-rated remote code execution flaw in ImageResponse rooted in a Satori SVG-escaping bug, CVE-2026-94545.
Cloudflare Discloses Cross-Tenant Disk Data Leak in Containers and Sandboxes, Finds No Evidence of Exploitation
A bug-bounty researcher showed a paying Cloudflare Containers customer could recover up to 60 KB of leftover disk data from other customers' deleted containers; Cloudflare says it found no evidence of exploitation.
Critical Bifrost AI Gateway Flaw Let Attackers Run Commands Without Credentials
CVE-2026-90898 lets unauthenticated attackers execute arbitrary commands on Bifrost AI gateway servers via a single HTTP request; fixed in transports/v2.1.0.
Plugin4Shell Flaw Lets Repository Owners Swap Pinned Plugin Code in Claude Code, Codex, and Copilot
Security firm Air Security found a zero-click flaw letting a plugin repository owner bypass commit-hash pinning in four AI coding agents.
AWS Confirms Data in War-Damaged Middle East Availability Zones Is Permanently Unrecoverable
AWS says data held only in Bahrain's me-south-1 region and the UAE's mec1-az2 zone, hit by Iranian strikes in March, cannot be restored.
Rust Security Team Fixes Miri Bug That Let GitHub Actions Caches Leak Secrets to Pull Requests
The Rust Security Response Team disclosed and patched a Miri flaw that stored all environment variables in target/, letting cached CI output expose secrets to pull requests.
Malicious npm Package Bypasses Install-Script Defenses, Hides Malware Inside Runtime Code
The indexed-btree npm package evades npm v12's install-script blocking by hiding its malware loader inside a runtime method instead, Checkmarx reports.
PolinRider Campaign Hits Packagist, Planting Malware in a 700,000-Download Laravel Nova Package
Socket found malicious code in dev branches of a 700,000-download Laravel Nova package on Packagist, tying the compromise to its ongoing PolinRider campaign.
Rust Security Team Warns of Targeted Social-Engineering Campaign Against Prominent Developers
The Rust security response working group and crates.io team warn that rust-lang members and popular crate owners are being lured into fake video calls to compromise their devices and accounts.
GemStuffer Campaign Exploited RubyGems' Documentation-Build Pipeline for RCE and a CVSS 7.3 CDN Caching Flaw
A research report ties a May 2026 RubyGems package-flooding campaign to OpenAI agents that abused a documentation-build RCE and probed a since-patched CDN key-leak bug.
GitHub Security Lab Finds Same-Second Race Condition in JupyterLab CI Action That Enables Code Execution
A TOCTOU race in JupyterLab's update-snapshots-checkout GitHub Action let a same-second commit push bypass its authorization check and reach attacker-controlled code execution, GitHub Security Lab found.