The Hacker News·16h ago highCompromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware#github-actions#supply-chain#mini-shai-hulud 2 sources in the wild 3 min
GBHackers·1d ago highGitLab Email Token Lets Attackers Push Code to Main and Execute CI/CD Jobs#gitlab#email-token#ci-cd 6 sources 4 min
Cyber Security News·1d ago highCritical GitLab Bugs Let Attackers Execute Code Through Malicious CI/CD Regex#gitlab#rce#ci-cd 2 sources 3 min2
Google Threat Intelligence·2d agoProactive Defense: Hardening Code Pipelines and CI/CD Infrastructure#google#ci-cd#supply-chain in the wild 15 min
CSO Online·3d ago highGitHub App keys can still enable takeovers long after they are forgotten#github#github-apps#leaked-keys 2 sources 4 min
Lobsters · security·4d agoGitHub Actions leaking secrets when Miri output is cached#rust#miri#github-actions 4 min
Jenkins Security Advisories·10d agoJenkins Security Advisory 2026-09-16#advisory#ci-cd#jenkinsAdvisory1
CSO Online·12d ago criticalA maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure trove#ci-cd#cisa-kev#cve-2026-85706 in the wild 4 min
The Hacker News·15d ago highGitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure#arbitrary-file-read#ci-cd#cve-2026-85706 in the wild 2 min1
GBHackers·15d ago criticalHackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access#artifactory#authentication-bypass#backdoor in the wild 5 min2
Web discovery (articles for new exploits & KEV entries)·18d ago highCritical Security Issue Affecting TeamCity On-Premises (CVE-2026-63077 ...#authentication-bypass#ci-cd#cve-2026-63077 4 min
Help Net Security·19d agoProduct showcase: Doppler secures secrets for humans, pipelines, and AI agents#ai-agents#ci-cd#credential-management 4 min
Canadian Centre for Cyber Security·23d agoJenkins security advisory (AV26-877)#advisory#ci-cd#jenkins
The Hacker News·23d agoShai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means#ci-cd#credential-harvesting#infostealer in the wild 11 min1
The Register · Security·24d ago highAI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit#agentic-attacks#ai-agents#ci-cd in the wild 2 min1
Infosecurity Magazine·Aug 25, 2026 criticalAustralia Warns of Active Exploitation of Critical TeamCity Server Flaw#active-exploitation#australia#ci-cdExploit / PoC in the wild1
Palo Alto Unit 42·Aug 21, 2026Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain#ci-cd#devsecops#sdlc in the wild1
Infosecurity Magazine·Aug 18, 2026 highWiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed#ci-cd#github-actions#snowflakeVulnerability
The Hacker News·Aug 17, 2026Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection#ci-cd#command-injection#github-actions 3 min1