vulnerability Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git A researcher, depthfirst, has published a proof-of-concept exploit targeting GitLab 18.11.3 and earlier, allowing authenticated users to execute arbitrary commands as the ‘git’ user. The vulnerability stems from flaws wi… The Hacker News · Jul 25, 2026 High rcejupyterjson
threat-intel ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories This week's "ThreatsDay" bulletin highlights a diverse range of security threats, from malware targeting PLCs with Iranian involvement to AI-generated vulnerabilities and deceptive apps. Key concerns include a GitHub sup… The Hacker News · Jul 23, 2026 High IRmalwarethreat intelligencesupply-chain
threat-intel Attackers Are Learning to Live Off the AI Toolchain Attackers are increasingly leveraging AI coding assistants and CI/CD pipelines to hide malicious activity, a trend exemplified by the Sandworm_Mode worm. This ‘living off the AI toolchain’ approach makes detection incred… Dark Reading · Jul 22, 2026 High aimalwaresupply-chain
threat-intel GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier GitHub is significantly altering its public bug bounty program, reducing payouts and moving top rewards to a private, invite-only VIP tier. Public payouts will be fixed, with a maximum of $10,000 for critical findings, d… The Hacker News · Jul 22, 2026 High bug bountyvulnerabilityai
threat-intel FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware A sophisticated campaign dubbed FakeGit has leveraged nearly 7,600 malicious GitHub repositories to spread SmartLoader malware, utilizing AI agents to discover these fake repositories and execute the attack. The campaign… The Hacker News · Jul 20, 2026 High aigithubmalware
supply-chain SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines A sophisticated supply chain attack, dubbed SleeperGem, has been targeting Ruby developers through three previously dormant malicious RubyGems packages. These packages, including a fake Git Credential Manager, were updat… The Hacker News · Jul 20, 2026 High rubysupply chainmalware
threat-intel ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories This week’s security news is a mixed bag, encompassing a range of threats from sophisticated ransomware attacks to deceptive software distribution and widespread surveillance techniques. A new ransomware family, Spirals,… The Hacker News · Jul 16, 2026 High CVE-2026-46817CVE-2023-4346CVE-2026-35273NESPPOransomwareinfostealerbrandjacking
supply-chain The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) The npm ecosystem experienced a critical inflection point in September 2025 with the emergence of the Shai-Hulud worm, marking a shift from nuisance attacks to a high-consequence threat landscape. Since then, Unit 42 has… Palo Alto Unit 42 · Jul 15, 2026 High NLsupply chainnpmgithub
vulnerability Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution A vulnerability in Cursor, a Git repository hosting platform for Windows, allows malicious cloned repositories to execute arbitrary code on the user's system. The flaw stems from Cursor's tendency to run a `git.exe` file… The Hacker News · Jul 15, 2026 High CVE-2026-26268CVE-2026-10591CVE-2020-26233gitwindowscode execution
supply-chain Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware A sophisticated supply-chain attack leveraging compromised npm packages has delivered a multi-stage botnet loader, Miasma, to numerous developers. The attacker exploited a GitHub Actions release pipeline to inject malici… The Hacker News · Jul 15, 2026 High supply chainnpmgithub actions
threat-intel Lessons Learned from CISA’s Recent GitHub Leak A CISA contractor inadvertently published a massive trove of sensitive credentials, including AWS GovCloud keys and plaintext passwords, in a public GitHub repository for nearly six months before CISA was notified. The a… Krebs on Security · Jul 13, 2026 High secretsgithubaws
threat-intel Ghost Accounts Abuse GitHub API in Mass Recon Campaign Threat actors are systematically abusing GitHub's public API using a network of dormant ghost accounts to map organizations, repositories, and user accounts – a reconnaissance tactic that occasionally leads to data exfil… SecurityWeek · Jul 11, 2026 Medium CHINreconnaissancegithubapi
threat-intel AI Coding: Do Security Risks Outweigh Productivity Gains? AI coding tools are rapidly increasing in popularity, with 91% of organizations using two or more and 54% using three or more. While developers report productivity gains and ROI, significant security risks are associated… Dark Reading · Jul 10, 2026 High aicodingsecurity
threat-intel ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism Researchers have discovered a new attack technique called ‘HalluSquatting’ that leverages AI assistants’ tendency to fabricate information to create scalable botnets. Attackers register fake repository names, and when us… SecurityWeek · Jul 10, 2026 High aiprompt injectionhallucination
supply-chain Network of 200 GitHub Repositories Used for Malware Infection A threat actor, linked to previous activity associated with the ‘ischhfd83’ email address, has created a network of over 200 GitHub repositories delivering Windows malware through a Go module disguised as a DNS scanning… SecurityWeek · Jul 10, 2026 High supply chaingithubmalware
threat-intel AI Agents Are a New Kind of Identity & Most Organizations Aren't Ready This article discusses the growing risk posed by AI agents in software development environments and highlights that most organizations are unprepared to manage this new type of identity. Unlike traditional service accoun… Dark Reading · Jul 9, 2026 High aiidentitygovernance
threat-intel Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs Datadog Security Labs has discovered a campaign where attackers are systematically mapping corporate GitHub organizations by leveraging dormant accounts and stolen credentials to gather extensive information about a comp… The Hacker News · Jul 9, 2026 Medium githubenumerationapi
vulnerability AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique AI coding assistants like Claude Code, Amazon Q Developer, and Cursor are vulnerable to a decades-old technique called GhostApproval, where attackers can trick the tools into accessing and modifying sensitive system file… SecurityWeek · Jul 9, 2026 High symlinkaicoding
threat-intel GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents Researchers at Wiz discovered a vulnerability (GhostApproval) in six AI coding assistants – Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity, and Windsurf – that allows malicious repositor… The Hacker News · Jul 9, 2026 High CVE-2026-12957symlinkaicode injection
threat-intel New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware Researchers at Tel Aviv University have identified a new attack method called ‘HalluSquatting’ that leverages AI coding assistants’ tendency to fabricate names. Attackers register fake software package names that AIs com… The Hacker News · Jul 8, 2026 Medium ISaihallucinationprompt injection