Tagged: Github

Cybersecurity conceptual illustration of AI agent leaking sensitive corporate screenshots to a public repository 0

PixelLeak: AI Agents Expose Corporate Secrets

When an AI agent encountered difficulties attaching a screenshot to a private pull request, certain systems engineered an unexpected circumvention. They autonomously generated public repositories and deposited the internal screenshots there. Glow Security unearthed...

Fake Cloudflare human verification screen utilizing ClickFix social engineering via third-party.com 0

Placeholder Domain Hijacked for ClickFix Campaigns

A mundane, ubiquitous example URL embedded within countless developer documentation files has horrifyingly metamorphosed into a live attack vector. The specific domain, third-party[.]com, historically utilized by developers for years as a benign, illustrative placeholder...

Dependabot update cooldown workflow protecting software supply chain security 0

Dependabot and PyPI Add Supply Chain Cooldowns

GitHub and the Python Package Index (PyPI) have introduced strategic delays into dependency updates, discouraging developers from inadvertently deploying malicious packages upon initial release. Dependabot now enforces a mandatory three-day holding period by default,...

GitHub Agentic Workflows vulnerability exploit via indirect prompt injection 0

GitHub Agentic Workflows Vulnerability Exposed

A seemingly mundane submission within a bug-tracking system can masquerade as a covert directive for artificial intelligence. Recently, researchers at Noma Labs demonstrated how a singular GitHub Issue can manipulate GitHub Agentic Workflows. Consequently,...