Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Medium
medium.com > @Aacle > top-43-ai-skills-mcp-servers-github-repos-every-bug-hunter-needs-259a2528eb45

Top 43 AI Security Skills, MCP Servers & GitHub Repos Every Bug Hunter Needs

13+ hour, 18+ min ago   (35+ words) Top 43 AI Skills, MCP Servers & GitHub Repos Every Bug Hunter Needs The AI-security corner of GitHub is moving too fast for its own good. Half the tools worth using didn’t exist eighteen months …...

Medium
medium.com > @thedevnotebook > github-actions-cache-mode-ci-cache-poisoning-6be2c3020015

Your CI Cache Can Carry Malicious Code. GitHub Just Added New Controls.

1+ day, 7+ hour ago   (20+ words) GitHub Actions now supports cache-mode for least-privilege cache access. Learn how read, write, write-only, and none reduce CI cache-poisoning risk....

Forkast
forkast.news > one-http-request-every-file-on-the-server-gitlabs-cvss-10-commits-api-flaw-hits-active-exploitation-within-hours

One HTTP Request, Every File on the Server: GitLab’s CVSS 10 Commits-API Flaw Hits Active Exploitation Within Hours

2+ day, 12+ hour ago   (170+ words) A single HTTP POST to the commits API bypasses all security controls and reads arbitrary files from a GitLab server. CISA gave agencies until September 14 to patch. watchTowr saw exploitation attempts starting six hours after disclosure. The vulnerability was reported…...

DEV Community
dev.to > anoymask > gitlab-cve-2026-85706-active-scanning-targeting-pre-authentication-file-read-591b

GitLab CVE-2026-85706: Active Scanning Targeting Pre-Authentication File Read

2+ day, 13+ hour ago   (1465+ words) 1. Basic Information Original Title: GitLab urges users to patch max severity path traversal flaw Source: BleepingComputer, GitLab Publication Date: 2026-09-11 Severity: Critical Reason for Severity: It allows unauthenticated network-based reading of credentials and sensitive information on GitLab servers, and attack attempts…...

DEV Community
dev.to > bpsmartdesign > two-and-a-half-months-with-an-intruder-in-our-repositories-4a69

Two and a half months with an intruder in our repositories

3+ day, 14+ hour ago   (592+ words) On 6 September 2026, an antivirus quarantined a 32 KB "font file" in one of our projects. That file... Tagged with security, github, polinrider, th1nkdev....

DEV Community
dev.to > omarmohelal > i-pointed-my-own-security-tool-at-my-own-github-action-it-found-two-bugs-4dia

I pointed my own security tool at my own GitHub Action. It found two bugs.

5+ day, 2+ hour ago   (864+ words) I write an application-security tool called SecHelix. Last week I added a GitHub Action to it. Before merging, I pointed the tool at its own new Action. It found two real defects. Neither would have failed a test. Both were…...

SecurityWeek
securityweek.com > north-korean-hackers-deploy-new-linux-espionage-toolkit

North Korean Hackers Deploy New Linux Espionage Toolkit

1+ week, 3+ hour ago   (735+ words) The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. North Korea-aligned threat actors have been using a new Linux toolkit in attacks targeting automotive and media organizations in South…...

SC Media
scworld.com > brief > coder-platform-targeted-by-attackers-delivering-malicious-terraform-modules

Coder platform targeted by attackers delivering malicious Terraform modules

1+ week, 2+ day ago   (83+ words) SC Media Coder platform targeted by attackers delivering malicious Terraform modules Ping YOUniverse: The next stage of human authentication Student thwarted real-world supply chain attack by rogue Mythos 5 agent Hackers compromise Rust crate arrayref to inject malware The AI you…...

DEV Community
dev.to > kalemi > the-2026-github-actions-reset-cheaper-runners-stricter-security-and-smarter-pipelines-1mh6

The 2026 GitHub Actions Reset: Cheaper Runners, Stricter Security, and Smarter Pipelines

1+ week, 3+ day ago   (477+ words) Here is a grounded read of what happened, with sources, and an honest account of where Latchkey fits. Alongside the cuts, GitHub introduced a $0.002 per-minute Actions cloud platform charge that applies to all Actions workflows. For GitHub-hosted runners, that charge…...

CSO Online
csoonline.com > article > 4218075 > counterfeit-installers-turn-routine-software-downloads-into-enterprise-breaches.html

Counterfeit installers turn routine software downloads into enterprise breaches

1+ week, 4+ day ago   (589+ words) The attackers are using a network of spoofed websites mimicking legitimate vendors, from browsers and security tools to utilities such as Baidu Netdisk, draw.io, and Sejda PDF, to trick users into downloading malicious installers, the blog added. Microsoft said…...