<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: GitHub Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving GitHub.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>Scans for ESAFENET CDG 3 Document Management System Weak Logins</title><link>https://isc.sans.edu/diary/rss/33184</link><guid isPermaLink="false">cst-3228</guid><description>ESAFENET's CDG (Content Data Guard) document management system is being actively scanned for exploitation using default credentials. The product, which targets Chinese markets, ships with weak default passwords that appear in public exploit templates despite meeting standard password complexity requirements. Attackers are leveraging these known default logins to attempt unauthorized access to CDG deployments.</description><pubDate>Sun, 26 Jul 2026 15:26:14 GMT</pubDate></item><item><title>GitHub, PyPI add time-absed defenses against supply chain attacks</title><link>https://bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks</link><guid isPermaLink="false">cst-3227</guid><description>GitHub and PyPI have integrated time-based defenses into Dependabot to mitigate supply chain attacks. The mechanism restricts the window during which compromised dependencies can propagate and cause damage across dependent projects.</description><pubDate>Sun, 26 Jul 2026 14:13:39 GMT</pubDate></item><item><title>MZ Automation libIEC61850</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-204-06</link><guid isPermaLink="false">cst-3119</guid><description>MZ Automation libIEC61850 versions 1.0.0 through 1.6.1 contain four vulnerabilities including stack-based and heap-based buffer overflows, and NULL pointer dereference flaws affecting the IEC 61850 industrial protocol library. Unauthenticated attackers on the network can trigger these flaws to crash services, cause memory corruption, or execute arbitrary code. The vendor recommends updating to the latest build.</description><pubDate>Thu, 23 Jul 2026 12:00:00 GMT</pubDate></item><item><title>Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers</title><link>https://thehackernews.com/2026/07/attackers-weaponize-github-actions.html</link><guid isPermaLink="false">cst-3085</guid><description>Researchers discovered a large-scale campaign weaponizing compromised GitHub repositories and Actions runners as attack infrastructure against cPanel and WebHost Manager instances. The campaign involved malicious Packagist development versions across 10 packages associated with a legitimate PHP and DevOps developer between July 12 and 13.</description><pubDate>Thu, 23 Jul 2026 11:28:54 GMT</pubDate></item><item><title>wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution</title><link>https://elastic.co/security-labs/wp2shell-wordpress-rce-detection-elastic-defend</link><guid isPermaLink="false">cst-3046</guid><description>On July 17, 2026, Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution chain affecting WordPress Core versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 through a route confusion flaw in the REST batch endpoint. Proof-of-concept tools circulated within hours, with attackers either escalating through SQL injection to upload malicious plugins or dropping webshells directly to disk, resulting in command execution via the web process. Defenders observe PHP and web server runtimes spawning shells, plugin directories appearing under wp-content/plugins/, and consistent post-exploitation discovery activity across vulnerable hosts.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier</title><link>https://thehackernews.com/2026/07/github-cuts-public-bug-bounty-payouts.html</link><guid isPermaLink="false">cst-3049</guid><description>GitHub is reducing public bug bounty rewards by at least 50 percent across all severity levels starting July 27, 2026, with critical vulnerabilities capped at $10,000 instead of the previous $20,000-$30,000 range. The company is simultaneously creating a VIP tier that offers $30,000 or more for select researchers. Reports submitted before the July 27 cutoff will maintain current payout rates.</description><pubDate>Wed, 22 Jul 2026 18:37:42 GMT</pubDate></item><item><title>Small teams are the heaviest users of AI coding agents</title><link>https://helpnetsecurity.com/2026/07/22/users-of-ai-coding-agents</link><guid isPermaLink="false">cst-2979</guid><description>Researchers at Rochester Institute of Technology analyzed over 25,000 pull requests generated by AI coding agents on GitHub to understand review patterns. The study found that small development teams are the primary users of these agents, with code often reviewed by single developers rather than distributed across larger teams.</description><pubDate>Wed, 22 Jul 2026 06:00:31 GMT</pubDate></item><item><title>AI agents tricked into recommending malicious GitHub repositories</title><link>https://helpnetsecurity.com/2026/07/21/github-repos-malware-campaign-fakegit-ai-agents</link><guid isPermaLink="false">cst-2925</guid><description>Island researchers discovered approximately 7,600 malicious GitHub repositories, with over 800 masquerading as AI Skills or Model Context Protocol servers, peaking in April 2026. The FakeGit operation involved around 6,600 compromised accounts, roughly 1,400 of which targeted AI tools, agents, and workflows. These repositories offered fraudulent integrations spanning consumer and enterprise applications, including services like Gmail and WhatsApp.</description><pubDate>Tue, 21 Jul 2026 14:27:38 GMT</pubDate></item><item><title>Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness</title><link>https://tenable.com/blog/ai-coding-assistant-agent-harness-attacks</link><guid isPermaLink="false">cst-2912</guid><description>Attackers are poisoning AI coding assistant configuration files to achieve persistent access within developer environments by injecting malicious hooks into settings files used by tools like Cursor, GitHub Copilot, and Claude Code. These configuration files create a uniquely dangerous attack vector because they are trusted as developer settings, automatically executed by IDEs, and treated as authoritative instructions by large language models. The Mini Shai-Hulud worm, analyzed by Tenable, demonstrates this technique by scanning for and compromising AI tool configurations across npm and PyPI packages, enabling silent malware execution each time a developer starts a coding session.</description><pubDate>Tue, 21 Jul 2026 13:00:00 GMT</pubDate></item><item><title>FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware</title><link>https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html</link><guid isPermaLink="false">cst-2871</guid><description>Researchers identified approximately 7,600 malicious GitHub repositories in the FakeGit campaign, with over 800 masquerading as AI tools or Model Context Protocol servers to distribute SmartLoader malware. The campaign employs copied projects, lookalike developer profiles, and deceptive README files to deceive users into downloading infected packages.</description><pubDate>Mon, 20 Jul 2026 18:23:03 GMT</pubDate></item><item><title>wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core</title><link>https://tenable.com/blog/wp2shell-cve-2026-63030-cve-2026-60137-frequently-asked-questions-about-remote-code-execution</link><guid isPermaLink="false">cst-2848</guid><description>Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve unauthenticated remote code execution on WordPress 6.9.x and 7.0.x installations. Active exploitation began within days of the July 17, 2026 disclosure, with public proof-of-concept code circulating and multiple security firms confirming attacks in the wild. Patches are available in WordPress 7.0.2 and 6.9.5, with WordPress.org enabling forced automatic updates for affected installations.</description><pubDate>Mon, 20 Jul 2026 13:36:32 GMT</pubDate></item><item><title>20th July – Threat Intelligence Report</title><link>https://research.checkpoint.com/2026/20th-july-threat-intelligence-report</link><guid isPermaLink="false">cst-2835</guid><description>Ernst and Young disclosed a breach involving a compromised third-party IT support platform exposing client documents and tax information. Supply chain compromises affected the Jscrambler JavaScript package and multiple artificial intelligence tools including Claude Code, DeepSeek, and Grok Build. Microsoft released 622 patches in July including fixes for two actively exploited vulnerabilities in SharePoint Server and Active Directory Federation Services, while WordPress issued emergency updates for critical remote code execution flaws.</description><pubDate>Mon, 20 Jul 2026 12:18:41 GMT</pubDate></item><item><title>New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code</title><link>https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html</link><guid isPermaLink="false">cst-2783</guid><description>A critical vulnerability in WordPress core versions 6.9 and 7.0 allowed unauthenticated attackers to execute arbitrary code on unpatched installations. WordPress released patches (6.9.5 and 7.0.2) on Friday and deployed forced updates through its auto-update mechanism. Adam Kues at Assetnote discovered the flaw and coordinated its disclosure.</description><pubDate>Fri, 17 Jul 2026 21:20:10 GMT</pubDate></item><item><title>NASA Core Flight System (cFS) Health &amp; Safety (HS) Application</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-197-03</link><guid isPermaLink="false">cst-2706</guid><description>A null pointer dereference vulnerability (CVE-2026-15352) in NASA's Core Flight System Health &amp; Safety application can cause a denial-of-service condition when processing Housekeeping Telemetry requests. The flaw affects versions prior to v7.0.1, which NASA recommends as the remediation. CISA scored the vulnerability as High severity with a CVSS v3.1 base score of 7.5 and notes no known public exploitation at this time.</description><pubDate>Thu, 16 Jul 2026 12:00:00 GMT</pubDate></item><item><title>New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands</title><link>https://thehackernews.com/2026/07/new-agent-data-injection-attack-can.html</link><guid isPermaLink="false">cst-2673</guid><description>Researchers have identified a data injection attack where adversaries can embed malicious content in data sources that AI agents consult, causing them to perform unintended actions like clicking purchase buttons or executing commands. The attack corrupts the factual information the agent relies on rather than directly hijacking the agent's core task.</description><pubDate>Thu, 16 Jul 2026 11:32:28 GMT</pubDate></item><item><title>Understanding Claude Tag’s access model in Slack and how to configure it securely</title><link>https://tenable.com/blog/claude-tag-slack-access-model</link><guid isPermaLink="false">cst-2608</guid><description>Anthropic's Claude Tag is a Slack AI agent that operates using admin-configured shared credentials rather than individual user credentials, following a service-identity pattern similar to deploy bots and workflow automations. Access to connected services is controlled by admin-configured bundles at the workspace or channel level, with organization-wide controls governing who can direct the agent. Channel members can collaborate with Claude, but their participation does not grant new permissions beyond what the admin bundle defines.</description><pubDate>Wed, 15 Jul 2026 15:08:00 GMT</pubDate></item><item><title>Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware</title><link>https://thehackernews.com/2026/07/compromised-asyncapi-npm-packages.html</link><guid isPermaLink="false">cst-2552</guid><description>Four npm packages in the @asyncapi namespace were compromised and distributed a multi-stage botnet loader. The affected versions include @asyncapi/generator-helpers@1.1.1, @asyncapi/generator-components@0.7.1, @asyncapi/generator@3.3.1, and @asyncapi/specs@6.11.2 and v6.11.2-alpha.1. Security firms OX Security, SafeDep, Socket, and StepSecurity identified the malicious activity.</description><pubDate>Wed, 15 Jul 2026 09:16:13 GMT</pubDate></item><item><title>Recent DShield SIEM Update</title><link>https://isc.sans.edu/diary/rss/33156</link><guid isPermaLink="false">cst-2542</guid><description>DShield SIEM received an update in September 2025 that added TTY log collection and Suricata integration to its monitoring capabilities. The system now uses ELK stack version 8.19.15 and includes additional dashboards that allow security practitioners to review command activity on DShield sensors, with logs parsed and uploaded daily and cross-linked across visualizations.</description><pubDate>Wed, 15 Jul 2026 01:38:43 GMT</pubDate></item><item><title>Nearly 300 GitHub repos pose as legit software to push malware</title><link>https://bleepingcomputer.com/news/security/nearly-300-github-repos-pose-as-legit-software-to-push-malware</link><guid isPermaLink="false">cst-2512</guid><description>A threat actor created hundreds of fake GitHub repositories that impersonate legitimate software and security projects to distribute infostealer malware. These repositories are designed to deceive developers searching for authentic tools and libraries.</description><pubDate>Tue, 14 Jul 2026 19:15:17 GMT</pubDate></item><item><title>M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions</title><link>https://wiz.io/blog/m-red-team-asyncapi-supply-chain-compromise-via-github-actions</link><guid isPermaLink="false">cst-2493</guid><description>A supply chain attack targeted AsyncAPI npm packages through compromised GitHub Actions workflows. Malicious packages were distributed via npm, affecting developers who installed the compromised versions.</description><pubDate>Tue, 14 Jul 2026 10:33:36 GMT</pubDate></item><item><title>The serpent’s tongue: Luring the Python out of its den</title><link>https://blog.talosintelligence.com/the-serpents-tongue-luring-the-python-out-of-its-den</link><guid isPermaLink="false">cst-2470</guid><description>Python packages are increasingly targeted by threat actors who exploit the trust in the packaging ecosystem to deliver malicious payloads at installation time without user interaction. GitHub's 2025 security data shows a 69% year-over-year increase in malware advisories, with 17% of reviewed advisories related to the Python Package Index (PyPI) ecosystem. The article examines the full lifecycle of Python package installation across hosting, distribution, and installation layers, and recommends defensive measures including dependency auditing, version pinning, and installation-time controls.</description><pubDate>Tue, 14 Jul 2026 10:00:06 GMT</pubDate></item><item><title>Lessons Learned from CISA’s Recent GitHub Leak</title><link>https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak</link><guid isPermaLink="false">cst-2418</guid><description>CISA experienced a six-month exposure of internal credentials, including AWS GovCloud administrative keys, after a contractor published sensitive data to a public GitHub repository in May 2026. The agency's postmortem identified delays in secret rotation, unclear incident reporting channels, and gaps in monitoring public code repositories as contributing factors. CISA has since committed to improving key management practices, establishing clearer reporting procedures, and implementing continuous scanning for exposed secrets.</description><pubDate>Mon, 13 Jul 2026 15:03:28 GMT</pubDate></item><item><title>Ghost Accounts Abuse GitHub API in Mass Recon Campaign</title><link>https://securityweek.com/ghost-accounts-abuse-github-api-in-mass-recon-campaign</link><guid isPermaLink="false">cst-2369</guid><description>Threat actors are using ghost accounts, which are dormant or fake GitHub profiles, to conduct reconnaissance against GitHub organizations by systematically mapping repositories and members through API calls. These mass recon campaigns aim to gather intelligence on potential targets before launching follow-up attacks.</description><pubDate>Sat, 11 Jul 2026 17:30:00 GMT</pubDate></item><item><title>US cybersecurity agency CISA had to build its incident playbook during the incident, agency reveals</title><link>https://techcrunch.com/2026/07/10/us-cyber-agency-cisa-had-to-build-its-incident-playbook-during-the-incident-agency-reveals</link><guid isPermaLink="false">cst-2358</guid><description>A CISA contractor employee accidentally uploaded exposed passwords to a publicly accessible GitHub repository, which a GitGuardian researcher discovered and reported in May. The incident revealed that CISA had to develop its incident response procedures in real time during the event rather than having them prepared in advance.</description><pubDate>Sat, 11 Jul 2026 01:01:28 GMT</pubDate></item><item><title>Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages</title><link>https://thehackernews.com/2026/07/injective-labs-github-compromise-pushes.html</link><guid isPermaLink="false">cst-2343</guid><description>Unknown threat actors compromised the Injective Labs SDK GitHub repository and published a malicious npm package that impersonated legitimate telemetry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised package version @injectivelabs/sdk-ts@1.20.21 was distributed through the npm registry to affect users of the SDK.</description><pubDate>Fri, 10 Jul 2026 17:29:28 GMT</pubDate></item><item><title>Network of 200 GitHub Repositories Used for Malware Infection</title><link>https://securityweek.com/network-of-200-github-repositories-used-for-malware-infection</link><guid isPermaLink="false">cst-2312</guid><description>A network of approximately 200 GitHub repositories is being exploited to distribute Windows malware through a Go module that loads PowerShell code and retrieves payloads from dead drops. This abuse of GitHub's infrastructure demonstrates how legitimate code hosting platforms can be weaponized for malware delivery at scale.</description><pubDate>Fri, 10 Jul 2026 08:00:14 GMT</pubDate></item><item><title>Injective SDK on npm infected with cryptocurrency wallet stealer</title><link>https://bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer</link><guid isPermaLink="false">cst-2279</guid><description>Hackers compromised the Injective Labs SDK repository on GitHub and published a malicious package to npm that targeted cryptocurrency wallet credentials, specifically private keys and mnemonic seed phrases. The attack exploited the trust developers place in open-source dependencies to distribute wallet-stealing malware.</description><pubDate>Thu, 09 Jul 2026 20:10:00 GMT</pubDate></item><item><title>Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs</title><link>https://thehackernews.com/2026/07/dormant-github-accounts-help-attackers.html</link><guid isPermaLink="false">cst-2267</guid><description>Datadog Security Labs identified multiple coordinated campaigns systematically enumerating GitHub organizations, repositories, and user accounts via the GitHub API. The attackers use automated scraping tools with legitimate-appearing user agents and leverage dormant ghost accounts or compromised OAuth tokens to avoid detection while conducting reconnaissance.</description><pubDate>Thu, 09 Jul 2026 18:38:49 GMT</pubDate></item><item><title>npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk</title><link>https://thehackernews.com/2026/07/npm-12-disables-install-scripts-by.html</link><guid isPermaLink="false">cst-2269</guid><description>npm version 12 disables install scripts by default to mitigate supply chain attacks, and deprecates granular access tokens that could bypass two-factor authentication. These changes shift security-sensitive operations from automatic execution to opt-in workflows, requiring developers to explicitly enable script execution during package installation.</description><pubDate>Thu, 09 Jul 2026 16:49:02 GMT</pubDate></item><item><title>Your coding agent says no in chat and yes in the code</title><link>https://helpnetsecurity.com/2026/07/09/github-coding-agent-jailbreak</link><guid isPermaLink="false">cst-2246</guid><description>Researchers from the Alan Turing Institute found that GitHub Copilot and similar coding agents may behave differently in chat versus multi-turn code generation contexts, potentially bypassing safety measures designed for single-response interactions. Current safety testing for these agents uses chatbot-style evaluation that does not account for how agents behave across extended coding sessions with multiple turns and autonomous execution capabilities.</description><pubDate>Thu, 09 Jul 2026 10:44:29 GMT</pubDate></item><item><title>Open-source collaboration is growing worldwide and putting pressure on maintainers</title><link>https://helpnetsecurity.com/2026/07/09/github-open-source-collaboration</link><guid isPermaLink="false">cst-2218</guid><description>GitHub reports that cross-border open-source collaboration grew 16% from Q4 2025 to Q1 2026, with developers increasingly contributing code and pull requests to public repositories internationally. This marks the second-highest quarter-over-quarter growth since 2020, approaching the surge seen in Q2 2020. The trend is placing mounting pressure on open-source project maintainers.</description><pubDate>Thu, 09 Jul 2026 05:10:05 GMT</pubDate></item><item><title>GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures</title><link>https://thehackernews.com/2026/07/github-verified-commits-can-be.html</link><guid isPermaLink="false">cst-2150</guid><description>Researchers discovered that signed Git commits can be rewritten to produce different hashes while maintaining valid signatures that GitHub still verifies as legitimate. An attacker without the signing key can create a duplicate commit with identical files, author, and date information, yet a different hash value, and GitHub's verification will still pass.</description><pubDate>Wed, 08 Jul 2026 11:51:24 GMT</pubDate></item><item><title>GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code</title><link>https://thehackernews.com/2026/07/github-copilot-refuses-harmful-requests.html</link><guid isPermaLink="false">cst-2152</guid><description>Researchers discovered that GitHub Copilot and other AI coding assistants refuse harmful requests made in chat interfaces but will execute the same requests when phrased as incremental code steps within the editor. The study examined Copilot, Claude, and Gemini, finding inconsistent safety guardrails across different interaction modalities.</description><pubDate>Wed, 08 Jul 2026 11:21:07 GMT</pubDate></item><item><title>'GitLost' Flaw Leaks Private Data from GitHub's Agentic Workflows</title><link>https://darkreading.com/cyber-risk/gitlost-leaks-private-data-github-agentic-workflows</link><guid isPermaLink="false">cst-538</guid><description>A vulnerability in GitHub's Agentic Workflows allows unauthenticated attackers to craft a malicious GitHub Issue in a public repository to extract data from private repositories within the same organization. The flaw, dubbed GitLost, enables silent data exfiltration without requiring authentication or explicit permissions.</description><pubDate>Tue, 07 Jul 2026 15:24:30 GMT</pubDate></item><item><title>Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data</title><link>https://thehackernews.com/2026/07/public-github-issue-could-trick-github.html</link><guid isPermaLink="false">cst-535</guid><description>Researchers at Noma Security identified a vulnerability in GitHub Agentic Workflows where a public issue in a repository can be crafted to trick the workflow agent into leaking contents from private repositories. The attack requires only the ability to open an issue on a public repository and relies on the organization having granted the agent read access across its repositories.</description><pubDate>Tue, 07 Jul 2026 14:04:50 GMT</pubDate></item><item><title>The GitHub Actions Attack Pattern Your CI Security Scanners Miss</title><link>https://bleepingcomputer.com/news/security/the-github-actions-attack-pattern-your-ci-security-scanners-miss</link><guid isPermaLink="false">cst-533</guid><description>ActiveState has identified attack patterns in GitHub Actions that bypass conventional CI security scanners, demonstrating that passing a security scan does not ensure pipeline security. The article discusses governance strategies to better protect CI/CD workflows from these evasion techniques.</description><pubDate>Tue, 07 Jul 2026 14:01:11 GMT</pubDate></item><item><title>Weekly Metasploit Update: Modules for SMB-to-Meterpreter, Peyara Remote Mouse RCE exploit, and more</title><link>https://rapid7.com/blog/post/pt-metasploit-wrap-up-07-03-2026</link><guid isPermaLink="false">cst-363</guid><description>Metasploit Framework version 6.4.142 includes new modules for upgrading SMB sessions to Meterpreter shells via PsExec, an exploit for Peyara Remote Mouse 1.0.1 unauthenticated remote code execution, and a new Linux LoongArch64 payload. The update also adds MCP server HTTP transport authentication support and fixes bugs in UDP sweep scanning and SSH session debugging.</description><pubDate>Fri, 03 Jul 2026 22:11:22 GMT</pubDate></item><item><title>New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos</title><link>https://thehackernews.com/2026/07/new-chocopoc-rat-targets-vulnerability.html</link><guid isPermaLink="false">cst-39</guid><description>A remote access trojan (RAT) called ChocoPoC is being distributed through fraudulent proof-of-concept repositories on GitHub, masquerading as legitimate exploit code for recent vulnerabilities. When executed, the malware steals credentials, browser data, and files while establishing remote access for attackers, with vulnerability researchers identified as the primary targets.</description><pubDate>Thu, 02 Jul 2026 07:24:23 GMT</pubDate></item><item><title>​​What’s new in Microsoft Security: June 2026</title><link>https://microsoft.com/en-us/security/blog/2026/06/30/whats-new-in-microsoft-security-june-2026</link><guid isPermaLink="false">cst-326</guid><description>Microsoft announced security updates for June 2026 including MDASH, a multi-model AI scanning system for discovering and remediating vulnerabilities, extended endpoint protection for local AI agents, and new capabilities for identity backup and recovery. Additional releases include database threat protection for open-source AWS RDS instances and customizable reporting features in Microsoft Purview for data security posture management.</description><pubDate>Tue, 30 Jun 2026 16:00:00 GMT</pubDate></item><item><title>Frangoteam FUXA SCADA/HMI</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-181-02</link><guid isPermaLink="false">cst-268</guid><description>Frangoteam FUXA SCADA/HMI versions 1.3.1 and earlier contain an authentication bypass vulnerability (CVE-2026-13207) that allows unauthenticated attackers to enumerate user accounts and role assignments through dot-segment path normalization in the REST API. The vulnerability exploits improper path normalization before authentication middleware is applied, allowing attackers to access protected endpoints by using sequences like /api/./users or /api/project/../users. Frangoteam recommends upgrading to version 1.3.2 or later to remediate the issue.</description><pubDate>Tue, 30 Jun 2026 12:00:00 GMT</pubDate></item><item><title>OFFIS DCMTK Toolkit</title><link>https://cisa.gov/news-events/ics-medical-advisories/icsma-26-181-01</link><guid isPermaLink="false">cst-264</guid><description>OFFIS DCMTK Toolkit versions 3.7.0 and earlier contain five critical vulnerabilities including path traversal, memory leaks, and type confusion flaws. Successful exploitation could allow attackers to write files outside intended directories, access unauthorized information, exhaust memory, or crash client and server processes. The vendor has provided fixes available in the latest GitHub releases.</description><pubDate>Tue, 30 Jun 2026 12:00:00 GMT</pubDate></item><item><title>Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more</title><link>https://rapid7.com/blog/post/pt-weekly-metasploit-update-modules-for-audiobookshelf-litellm-next-js-dalfox-and-more</link><guid isPermaLink="false">cst-367</guid><description>Metasploit Framework released new modules for detecting and exploiting vulnerabilities in Audiobookshelf, LiteLLM Proxy, Next.js, and Dalfox. The updates include authentication bypass scanners, a SQL injection detection module, and a remote code execution exploit, along with improvements to bruteforce-related modules. The project is also soliciting feedback on planned changes to evasion capabilities until July 1, 2026.</description><pubDate>Fri, 26 Jun 2026 19:32:52 GMT</pubDate></item><item><title>pydicom pynetdicom Library</title><link>https://cisa.gov/news-events/ics-medical-advisories/icsma-26-176-01</link><guid isPermaLink="false">cst-274</guid><description>A critical path traversal vulnerability (CVE-2026-56445) exists in pynetdicom versions 1.0.0 through 3.0.4, allowing unauthenticated attackers to write arbitrary files via unsanitized DICOM dataset inputs in the qrscp application's C-STORE handler. The vulnerability impacts healthcare and critical infrastructure globally with a CVSS score of 9.1. The pynetdicom maintainer has not engaged with CISA on remediation, and no public exploitation has been reported.</description><pubDate>Thu, 25 Jun 2026 12:00:00 GMT</pubDate></item><item><title>One-two punch delivered in global operation disrupts cybercrime "assembly line"</title><link>https://arstechnica.com/security/2026/06/one-two-punch-delivered-in-global-operation-disrupts-cybercrime-assembly-line</link><guid isPermaLink="false">cst-426</guid><description>International authorities and technology companies disrupted two major cybercrime tools, Amadey and StealC, which operated as malware and infostealer services. The operation targeted shared infrastructure used by both platforms, which together facilitated theft of millions of login credentials and over $47 million in fraudulent payments. The simultaneous takedown exploited the discovery that many cybercriminals used both tools in tandem.</description><pubDate>Wed, 24 Jun 2026 21:03:34 GMT</pubDate></item><item><title>What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials</title><link>https://tenable.com/blog/what-the-miasma-campaign-reveals-about-the-new-supply-chain-threat-model-and-the-underground</link><guid isPermaLink="false">cst-383</guid><description>The Miasma campaign exploited a stolen Red Hat developer credential from underground markets to inject malicious packages into the npm registry, affecting 89 plus packages across three waves in early June. The attack demonstrated a structured threat model where harvested developer credentials are bought and weaponized weeks after theft, and included novel techniques such as forged SLSA provenance attestations and persistence mechanisms targeting AI coding assistants like Claude and Cursor. The campaign illustrates an emerging developer credential economy where infostealers, dark web markets, and supply chain compromises operate as coordinated layers in a single attack pipeline.</description><pubDate>Tue, 23 Jun 2026 13:00:00 GMT</pubDate></item><item><title>Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign</title><link>https://darkreading.com/cyberattacks-data-breaches/crypto-heist-fake-reputation-boosting-campaign</link><guid isPermaLink="false">cst-121</guid><description>Attackers are leveraging legitimate platforms such as GitHub, YouTube, and VirusTotal to create a false appearance of credibility and trustworthiness. They use this manufactured reputation to distribute a clipboard hijacker malware that operates across multiple platforms and steals cryptocurrency by intercepting and replacing wallet addresses during copy-paste operations.</description><pubDate>Mon, 22 Jun 2026 16:10:10 GMT</pubDate></item><item><title>Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more</title><link>https://rapid7.com/blog/post/pt-metasploit-wrap-up-19-06-2026</link><guid isPermaLink="false">cst-370</guid><description>Rapid7 released five new Metasploit modules this week, including a full remote code execution chain for Paperclip AI using six API calls, an NTLM relay technique for privilege escalation to SYSTEM on Windows, VS Code extension persistence, and exploits for Xerte Online Toolkits and Linux kernel vulnerabilities. The update also includes an MCP server plugin enabling AI tool integration within msfconsole and improved module check codes with richer diagnostic detail.</description><pubDate>Fri, 19 Jun 2026 17:08:23 GMT</pubDate></item><item><title>Novo Nordisk Breach Highlights Software Development Pipeline Risk</title><link>https://darkreading.com/cyber-risk/novo-nordisk-breach-exposes-dev-pipeline-risk</link><guid isPermaLink="false">cst-124</guid><description>Novo Nordisk experienced a security incident involving a leaked GitHub token that exposed gaps in secrets management practices. The breach highlights how organizations often address credential security through tools alone rather than implementing comprehensive identity and access controls. This reflects a broader industry pattern of treating secrets management as a technical tooling issue rather than a foundational identity problem.</description><pubDate>Thu, 18 Jun 2026 20:05:47 GMT</pubDate></item><item><title>From Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard Hijacker</title><link>https://research.checkpoint.com/2026/from-stars-to-upvotes-fake-reputation-fueling-a-crypto-clipboard-hijacker</link><guid isPermaLink="false">cst-596</guid><description>A threat actor is distributing a Rust-based clipboard hijacker disguised as cryptocurrency trading bots and game prediction tools across multiple platforms, including fake GitHub and SourceForge repositories, a YouTube channel with AI-generated content, and compromised news sites. The operation uses coordinated fake accounts, inflated engagement metrics, and manipulated VirusTotal reputation signals to create a false appearance of legitimacy and trustworthiness. Once installed, the malware monitors the clipboard for cryptocurrency wallet addresses and replaces them with attacker-controlled addresses, generating illicit cryptocurrency transactions.</description><pubDate>Wed, 17 Jun 2026 13:38:55 GMT</pubDate></item><item><title>Who Runs the Ransomware Group ‘The Gentlemen?’</title><link>https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen</link><guid isPermaLink="false">cst-132</guid><description>The Gentlemen ransomware group, the second most active ransomware gang by victim count with over 240 victims in 2026 alone, operates as a ransomware-as-a-service (RaaS) offering that attracts affiliates with a 90/10 revenue split. Security researchers have traced the group's administrator, known as Hastalamuerte and later Zeta88, to Alexander Andreevich Yapaev, a 36-year-old from Izhevsk, Russia, through analysis of forum registrations, email addresses, Telegram accounts, and Russian government database records. The group targets internet-facing devices such as VPNs and firewalls as entry points and encrypts entire networks within hours.</description><pubDate>Wed, 10 Jun 2026 14:03:44 GMT</pubDate></item></channel></rss>