GitHub Slashes Public Bug Bounty Payouts by Half, Launches VIP Tier for Top Researchers
Beginning July 27, 2026, GitHub will reduce public bug bounty payouts by at least 50% across all severity levels, moving top rewards…
Beginning July 27, 2026, GitHub will reduce public bug bounty payouts by at least 50% across all severity levels, moving top rewards…
A critical vulnerability in AWS Kiro, an agentic coding IDE, allowed a poisoned web page to rewrite its configuration file and execute…
Google's DeepMind has announced the release of Gemini 3.5 Flash Cyber, a specialized AI model designed to discover, validate, and patch software…
F5 has patched a critical heap buffer overflow vulnerability in NGINX, tracked as CVE-2026-42533, which can crash worker processes and may allow…
OpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery to fix issues before tools…
Security researcher cereblab discovered that xAI's Grok Build coding CLI (version 0.2.93) was uploading entire Git repositories—including full commit history—to a Google…
GitHub has officially released npm version 12, introducing significant security changes to reduce software supply chain risks. The most notable change is…
Researchers at the AI Now Institute have published a proof-of-concept attack called 'Friendly Fire' that exploits AI coding agents designed to catch…
Researchers Abhishek Kumar and Carsten Maple have discovered a novel workflow-level jailbreak method that bypasses safety guardrails in GitHub Copilot. The study,…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability affecting PTC Windchill PDMlink and PTC…