
GitHub Actions Supply Chain Attack Hijacks actions-cool Tags
Attackers hijacked two actions-cool GitHub Actions workflows via imposter commits, stealing CI/CD credentials from all pipelines that ran them by

Attackers hijacked two actions-cool GitHub Actions workflows via imposter commits, stealing CI/CD credentials from all pipelines that ran them by

Security researcher depthfirst disclosed CVE-2026-42945, an 18-year heap overflow in NGINX’s rewrite module enabling unauthenticated RCE. CVSS 9.2 critical.

Bitdefender researchers documented three consecutive FamousSparrow intrusions against an Azerbaijani oil and gas firm between December 2025 and February 2026.

Two unpatched Windows zero-days, YellowKey and GreenPlasma, were publicly dropped after researchers expressed dissatisfaction with Microsoft’s handling.

Socket identified GemStuffer, a campaign abusing 150+ RubyGems packages to scrape UK government council portals and publish collected data as

SAP’s May 2026 Security Patch Day fixes CVE-2026-34260, a CVSS 9.6 SQL injection in S/4HANA Enterprise Search that lets authenticated

PHP patched CVE-2026-6722, a use-after-free RCE in the SOAP extension, across all active branches (8.2, 8.3, 8.4, 8.5) — exposing

cPanel released a second emergency patch in ten days — CVE-2026-29202 and CVE-2026-29203 enable code execution — as Sorry ransomware

TeamPCP backdoored the Checkmarx Jenkins AST scanner plugin in a third supply chain wave, following March Trivy and April KICS

Socket discovered five NuGet packages typosquatting Chinese .NET UI libraries — IR.DantUI, IR.OscarUI, and three more — amassing 65,000 downloads
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.