Cybersecurity
264 articles RSS
Wiz Discloses GitHub Actions Workflow Injection in Snowflake Repo, Exposing a Live Jira API Token
Wiz's autonomous Red Agent found and exploited a GitHub Actions injection flaw in a Snowflake repo that GitHub's own scanner had missed, exfiltrating a live Jira token.
rsync 3.5.0 Fixes 33 CVEs, Including a Critical Proxy-Spoofing Flaw, as Outside Researchers Join the Project's Admin Team
rsync 3.5.0, released August 13, patches 33 CVEs found through an audit, fuzzing, and outside researchers, following the disruptive May 3.4.3 security release.
Gitea Patches Critical Unauthenticated File-Read Flaw CVE-2026-59774 Found by an Autonomous AI Pentesting System
A CVSS 9.8 Gitea flaw let unauthenticated users read server files via Org-mode markup; XBOW Security's autonomous system found it.
Security Researcher Publishes Windows Defender 'ShieldBreak' Zero-Day, Says Microsoft Threatened Legal Action
A researcher known as Nightmare Eclipse disclosed an unpatched Windows Defender privilege-escalation flaw, saying Microsoft's legal threats left public disclosure as the only option.
Mozilla Rotates Firefox and Thunderbird GPG Signing Key After Accidental GitHub Exposure
Mozilla revoked and replaced a GPG signing subkey after an unencrypted copy leaked into a private GitHub repo, finding no evidence of unauthorized use.
Varonis Discloses RovoBlast, a One-Click Prompt Injection Flaw in Atlassian's Rovo AI Assistant
A crafted link could seed attacker instructions into a user's Rovo session, letting the assistant's browsing agent exfiltrate Jira and Confluence data.
Novee Security Finds Zero-Privilege Flaws in Claude Code, Gemini CLI, and Codex Around Black Hat USA 2026
Researcher Elad Meged showed a privilege-less GitHub issue could reach CI secrets in Claude Code, Gemini CLI, and Codex; two flaws got CVEs, one didn't.
Unpatched GeoServer Zero-Day Sees Active Exploitation Within Hours of Public Disclosure
An unpatched SQL injection flaw in GeoServer's jsonArrayContains function is already being probed by attackers, watchTowr says, with no CVE or fix yet available.
Lazarus Group Exploited Windows Kernel Zero-Day via Fake Job Offers Before Microsoft's August Patch Tuesday Fix
Check Point traced CVE-2026-68820, a WinSock kernel flaw, to a North Korean campaign deploying the FudModule rootkit against defense contractors before Microsoft patched it.
OpenAI Open-Sources Codex Security CLI, Leaving the Scanner Behind a Gate
OpenAI released the command-line tool and SDK for Codex Security, formerly Aardvark, under Apache-2.0, while the underlying scanner stays limited-beta.
OpenSSH 10.5 Fixes ssh-agent Locking Bypass and Two Other Flaws, Citing AI-Assisted Bug Reports for a Faster Release Cadence
OpenSSH 10.5 patches a locking bypass in ssh-agent and two other flaws, and the project says a surge in AI-assisted vulnerability reports is pushing it toward faster, on-demand security releases.
Six npm Packages Compromised to Pull Malware Command-and-Control Addresses From Ethereum Transactions
Sonatype found six npm packages that decode malware C2 server IPs from Ethereum transaction bytes, using a technique tied to North Korea's Contagious Interview campaign.