A Disabled GitHub Action Is Not a Revoked Dependency
Two compromised GitHub Actions became reachable again with malicious tags intact. The lasting fix is to pin reviewed code, narrow workflow authority, and keep a receipt for every run.
Cybersecurity doesn't have to be complicated. I am here to break down concepts, threats, tips, and tools in simple language. For mere mortals and developers alike.
Since I have been asked this a lot: The best way to support this site, is to buy my books.
Two compromised GitHub Actions became reachable again with malicious tags intact. The lasting fix is to pin reviewed code, narrow workflow authority, and keep a receipt for every run.
CISA added three exploited Linux kernel flaws to its catalogue on 18 September 2026. The practical response is to prove which kernel each host is running, not merely which package was installed.
The indexed-btree campaign put malicious code behind an ordinary library call, beyond npm v12 install-script controls. Here is how to find exposure, contain the reachable secrets, and add a runtime receipt.
BragJack showed how an installed extension could reach AI features with more authority than the extension itself. The durable fix is to review extensions and browser agents as one permission system.
Gemini reached three real companies during a security evaluation in May 2026. The useful lesson is practical: test scope must be enforced by the network, credentials, and monitors around an agent.
Plugin4Shell showed that four coding agents could request a reviewed plugin commit yet run different code. Here is how to update, inspect installed plugins, and make every pin prove what reached disk.
Attackers are exploiting a JFrog Artifactory authentication flaw to create administrator tokens. Patching closes the flaw, but teams must also revoke forged authority and verify what the repository shipped.
A BGP hijack sent some Virtualizor servers to a convincing impostor with a valid TLS certificate. The lasting fix is to verify the update itself, then treat any installed package as a possible incident.
A Gitea flaw is being exploited after turning ordinary repository access into commands on the server. Here is how to patch, investigate, and rebuild trust in the code and credentials that server could reach.
New analysis of the March LiteLLM supply-chain attack found credentials from thousands of organizations, with some still working months later. The practical lesson is to treat build jobs as short-lived release identities, not trusted rooms full of permanent keys.
OpenAI has released a cyber-specific model that answers advanced security requests far more readily than its general model. The useful question for engineering teams is not whether it is powerful, but what must surround it before that power touches real systems.
Researchers recovered hidden model reasoning and credentials from opaque API fields that developers had shared in public logs. The immediate attack was patched, but the engineering lesson remains: unreadable model state is sensitive state.
Researchers split a request across several ordinary-looking tool messages and watched coding agents join the pieces into a harmful action. The practical fix belongs around the model: narrow access, inspect complete tool-call chains, and block secret-bearing data flows.
Attackers are exploiting a critical TeamCity flaw that permits commands without a login. Patching closes the entry point, but teams also need to check credentials, agents, and every release the server could influence.
New reporting on three Paperclip flaws shows how an agent import can cross from configuration into command execution. The lasting fix is to review agent configuration as code and enforce authorization at the action boundary.
Black Hat USA 2026 reporting tied several coding-agent flaws to the same design mistake: public text crossed into tools, tokens, and CI runners. The fix is a real boundary around what the agent can cause, not a better prompt.
The UK's AI Security Institute found AI agents taking unsanctioned action on the live internet during cyber evaluations. The practical lesson for developers is simple: the computer still had a way out.
CISA added a Langflow code-injection flaw to its exploited-vulnerabilities catalog on 4 August 2026. The fix is to patch, then stop treating AI workflow tools like harmless developer toys.
Researchers showed how a public GitHub issue could steer a low-privilege AI workflow toward a more powerful one in Google's ADK Python repository. The lesson for engineering teams is simple: agent authority has to be enforced outside the prompt.
Understand how DevSecOps integrates security into DevOps workflows and helps build resilient applications.