Click any tag below to further narrow down your results
Links
Novee found a pattern of CI/CD vulnerabilities in GitHub Actions workflows that let any unauthenticated user hijack build pipelines, steal credentials, or push malicious code. They scanned 30,000 repositories and confirmed over 300 fully exploitable cases at Microsoft, Google, Apache, Cloudflare, and others. AI coding agents are accelerating the spread of these insecure YAML patterns, putting millions of projects at risk.
This daily roundup covers Fortinet’s FortiBleed campaign exposing 86,000 device credentials, a Texas hunting-license vendor breach affecting 3 million records, and an unpatchable BootROM exploit on Apple A12/A13 chips. It also highlights GitHub’s context-aware secret scanning, the Novo Nordisk code leak via a stolen GitHub token, and other emerging tools and vulnerabilities.
CISA warns that a Russian-speaking threat actor has harvested 86,644 valid logins from internet-facing FortiGate firewalls and VPNs using SSL VPN interception, GPU-powered hash cracking, and brute-force attacks. Major government entities and critical infrastructure providers are affected. CISA advises resetting credentials, enforcing PBKDF2 for admin logins, enabling phishing-resistant MFA, and tightening management access.
In 2025, infostealer malware infected over 11 million devices and exposed 3.3 billion credentials, browser artifacts, session tokens, and system metadata. Sold as malware-as-a-service for as little as $60 a month, strains like Vidar and Lumma use sandbox detection and obfuscation to evade defenses, harvesting passwords, cookies, crypto keys, and more. Attackers then resell the data or use the stolen credentials to gain undetected access and deploy ransomware.