CVE-2026-12537: Critical OS Command Injection in Gemini CLI
CVE-2026-12537 is a critical OS command injection vulnerability in Google's Gemini CLI container launcher. It allows an unprivileged attacker to execute arbitrary…
CVE-2026-12537 is a critical OS command injection vulnerability in Google's Gemini CLI container launcher. It allows an unprivileged attacker to execute arbitrary…
TeamCity is a CI/CD server by JetBrains. On-premise versions are affected by CVE-2026-63077, a critical RCE vulnerability actively exploited in the wild.
GitLab Community Edition is the open-source version of GitLab, offering core features including repository management, issue tracking, and CI/CD. It is affected…
Cybersecurity researchers have uncovered a sophisticated software supply chain attack dubbed 'SleeperGem' targeting the Ruby ecosystem. Three malicious gems were published to…
CircleCI is a CI/CD platform. The SleeperGem malware checks for CircleCI environment variables to avoid running on CI runners.
Travis CI is a CI/CD platform. The SleeperGem malware checks for Travis environment variables to avoid running on CI runners.
Jenkins is an open-source automation server. The SleeperGem malware checks for Jenkins environment variables to avoid running on CI runners.
GitLab is a DevOps platform. The SleeperGem malware checks for GitLab environment variables to avoid running on CI runners.
Cybersecurity researchers at Huntress have identified an intrusion where an unknown threat actor used a suspected AI-generated PowerShell script to enumerate Active…
Cybersecurity researchers have flagged a new evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family,…