Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to…
You work in your company's human resources department and use HR software to check employee information, benefits, and payroll. So, when you see a downloadable Windows version promising a faster…
We discovered an undocumented remote-access Trojan (RAT) called Kothamine Agent. It supports more than 30 commands and it gives attackers control of an infected Windows computer: they can run…
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud…
If you’re new to fuzzing and want to learn the fundamentals first, check out our Fuzzing 101 course at gh.io/fuzzing101. Continuous fuzzing is not a magic solution that solves all your problems…
Introduction The landscape of software supply chain security has undergone a significant shift. Recent campaigns demonstrate that sophisticated threat actors are systematically targeting the…
Google has jumped on the AI-defense-for-critical-systems train with its Scan for Good initiative, and says that its threat-hunting models have already autonomously uncovered critical security issues…
arXiv:2609.26900v1 Announce Type: new Abstract: A language model agent acts through the tools it is given. The data it reads while working on a task can redirect what it does with those tools. A…
arXiv:2609.27542v1 Announce Type: new Abstract: The safety of a tool-using language model agent is usually treated as a property of the model alone. We give controlled, full-precision evidence that…
Serial Number: AV26-956 Date: September 23, 2026 As of September 22, 2026, GitHub is affected by vulnerabilities in the following product: Enterprise Server 3.17.0 Prior to 3.17.21 3.18.0 Prior to…
Posted by Rostislav on Sep 23 Hello oss-security, Multiple vulnerabilities have been discovered in ntfs-3g (https://github.com/tuxera/ntfs-3g). The vulnerabilities have been fixed in version…
Academic publishing giant Elsevier confirmed a compromise this week after students found its platform redirecting users to a cybercriminal crew's leak page. One Reddit user, a self-described nursing…
Attackers spoofed LastPass on GitHub, used a Microsoft-signed driver to disable 145 security products, then deployed an infostealer. Someone impersonated LastPass on GitHub, got users to download a…
Posted by Simon McVittie on Sep 22 We've eventually been able to obtain CVE IDs for most of these (two are still pending). I requested CVE IDs from Github before we unembargoed, but we haven't…
Threat actors stole 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool…
Chinese AI giant Z.ai has apologized after developers caught it pulling a Grok, packaging up and uploading user workspaces to cloud storage. In a case that’s highly reminiscent of the issues over…
Serial Number: AV26-948 Date: September 22, 2026 As of September 22, 2026, Erlang is affected by vulnerabilities in the following product: OTP 17.0 Prior to 27.3.4.18 21b8a1b Prior to afec515…