BleepingComputer·17h ago highGitHub Actions re-enabled with Mini Shai-Hulud payload still active#github-actions#supply-chain#mini-shai-hulud 2 sources in the wild 2 min
Google Threat Intelligence·2d agoProactive Defense: Hardening Code Pipelines and CI/CD Infrastructure#google#ci-cd#supply-chain in the wild 15 min
The Hacker News·3d ago highCompromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI#credential-stealer#exfiltration#github-actions 4 sources in the wild 3 min1
Infosecurity Magazine·3d ago highHundreds of Leaked GitHub App Keys Still Authenticate#github#gitguardian#secrets 2 sources 2 min
Lobsters · security·4d agoGitHub Actions leaking secrets when Miri output is cached#rust#miri#github-actions 4 min
Infosecurity Magazine·4d ago highAttackers Abuse npm Trusted Publishing in GHAPPIER Campaign#ghappier#github-actions#loader 3 sources in the wild 2 min
The Register · Security·18d ago highExtortion crews have their eyes on high-value AI data, Google warns#agentic-ai#ai-data-theft#extortion 2 sources in the wild 3 min1
Infosecurity Magazine·Aug 18, 2026 highWiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed#ci-cd#github-actions#snowflakeVulnerability
The Hacker News·Aug 17, 2026Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection#ci-cd#command-injection#github-actions 3 min1
Wiz Blog·Aug 17, 2026Wiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Through a Flaw in a GitHub Copilot–Assisted PR#agentic-ai#agent-security#github-actions1