Cybersecurity researchers at Wiz have disclosed a GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository. The flaw, present in the…
Snowflake, a leading cloud data platform, patched a GitHub Actions workflow injection vulnerability in its public snowflake-connector-net repository. The flaw could allow…
Cybersecurity researchers have uncovered a large-scale campaign that weaponizes compromised GitHub repositories to target cPanel and WebHost Manager (WHM) instances. The activity…
Cybersecurity researchers have uncovered a sophisticated software supply chain attack dubbed 'SleeperGem' targeting the Ruby ecosystem. Three malicious gems were published to…
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security,…
New research from Carnegie Mellon University PhD student Jacob Ginesin, also a cryptographic auditor at Cure53, reveals that GitHub's 'Verified' commit badge…
GitHub has announced a critical security update to its official actions/checkout action, effective June 18, 2026, designed to block common pwn request…
GitHub had previously documented the risk of expanding untrusted issue data in workflow run blocks. The Snowflake incident underscores the importance of…