threat-intel Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent Google removed three AI agent workflows from its ADK Python repository after a public GitHub issue allowed a malicious bot to trigger a privileged code-fixing agent, leading to potential code execution and credential exposure. The vulnerability stemmed from a misconfigured workflow that granted excessive permissions to… The Hacker News · Aug 4, 2026 High botcredential exposuregit
vulnerability n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process N8n, a workflow automation platform, had a high-severity expression-sandbox escape that could allow authenticated workflow editors to execute operating system commands on the server. The vulnerability stemmed from a flaw… The Hacker News · Jul 27, 2026 High CVE-2026-27577expression-sandboxworkflowjavascript
threat-intel How Pentera Turns AI Security Workflows into Validation Engines Pentera has introduced a new protocol, MCP, to integrate its security validation platform directly into existing AI security workflows. Traditionally, AI security tools relied on fragmented risk signals, leading to guess… The Hacker News · Jul 14, 2026 High aivalidationattack-path
threat-intel New Enterprise-Ready MCP Specification Brings New Security Challenges The Model Context Protocol (MCP) is evolving from a single-user AI tool to an enterprise-ready platform designed for cloud-native AI usage, with a major update slated for July 28, 2026. This transition introduces new sec… SecurityWeek · Jun 26, 2026 High aistatelesssecurity
supply-chain Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking A new vulnerability, dubbed ‘Cordyceps,’ has been identified within CI/CD workflows across numerous open-source projects, allowing unauthorized access and control over developer repositories. The flaws, primarily found i… SecurityWeek · Jun 24, 2026 High ci/cdsupply chaingithub actions
supply-chain GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns GitHub is implementing a security update to its "actions/checkout" action to mitigate a common supply chain attack vector. The update, effective June 18, 2026, will block the execution of malicious code from untrusted fo… The Hacker News · Jun 23, 2026 High supply-chaingithubactions
threat-intel Anthropic rolls out Claude Fable 5, but it's available for a limited time Anthropic has released a new AI model, Claude Fable 5, built on the Mythos model, but with enhanced safeguards to mitigate potential misuse by malicious actors. Initially limited to cybersecurity experts and trusted part… BleepingComputer · Jun 10, 2026 High aicybersecuritymodel
threat-intel The Hidden Security Risk in Modern Networks: The Work Between Tools This article highlights a critical operational challenge facing modern network security teams: the ‘work between tools.’ Despite advancements in technology and AI, organizations struggle with fragmented workflows when re… The Hacker News · Jun 9, 2026 Medium workflowautomationalerting
threat-intel Only 10% of SOCs Say They’re Getting Excellent Value From AI. Here’s What the Second Wave Has to Deliver This Hacker News article analyzes the underwhelming adoption of AI within Security Operations Centers (SOCs) based on the SOC-CMM 2026 Maturity Report. Despite significant investment in AI-powered security tools, only a… The Hacker News · Jun 5, 2026 Medium aisocmaturity
supply-chain Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos A six-hour malware campaign, dubbed 'Megalodon,' targeted over 5,500 GitHub repositories, injecting malicious commits containing credential-stealing payloads. The campaign, orchestrated by an unknown threat actor potenti… Dark Reading · May 26, 2026 High githubsupply-chainmalware
supply-chain Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack A sophisticated supply chain attack, dubbed Megalodon, has infected over 5,500 GitHub repositories by injecting malicious code into automated workflows. The attack leverages compromised versions of the Tiledesk package t… SecurityWeek · May 25, 2026 High supply chaingithubmalware
threat-intel Security Bosses Are All in on AI: Here's Why This Dark Reading Confidential episode explores the growing adoption of Artificial Intelligence (AI) within cybersecurity organizations, particularly focusing on Large Language Models (LLMs). CISO Fredrick Lee of Reddit… Dark Reading · Apr 2, 2026 Medium aillmautomation