
GitLost Prompt Injection Leaks Private GitHub Repos via Public Issues
Noma Security’s GitLost technique tricks GitHub Agentic Workflows into leaking private repository contents via public issue comments, with no patch

Noma Security’s GitLost technique tricks GitHub Agentic Workflows into leaking private repository contents via public issue comments, with no patch

Sand Security found a one-click session isolation flaw in Writer AI letting attackers access any enterprise tenant’s private models, credentials,

Tokyo police arrested a 15-year-old who used ChatGPT to generate attack code that canceled 46,812 Bandai Channel streaming accounts in

BeyondTrust patched a CVSS 9.2 auth bypass in Remote Support and PRA for SaaS users months ago but withheld notice

CERT/CC disclosed CVE-2026-11405, a hidden backdoor in Tenda router firmware granting unauthenticated full admin access. No vendor patch is available.

Adobe ColdFusion CVE-2026-48282 (CVSS 10) moved from PoC release to confirmed in-the-wild exploitation in under two hours, according to KEVIntel

Unit 42 exposed an active campaign using fake Microsoft Teams IT support calls to install EtherRAT, a Node.js RAT whose

Proofpoint named UNK_MassTraction, a China-aligned group using Roundcube CVE-2024-42009 to steal credentials and 2FA tokens from university physics departments.

Attackers posing as 30-plus major brand recruiters use fake job interviews to steal Google credentials from marketing professionals who manage

North Korea’s PolinRider campaign used stolen maintainer credentials to push malicious updates to 108 packages across npm, Packagist, Go, and
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.