The GlassWorm supply-chain campaign has returned with a new, coordinated attack that targeted hundreds of packages, ...
AI-powered bot hackerbot-claw exploited GitHub Actions workflows across Microsoft, DataDog, and CNCF projects over 7 days using 5 attack techniques. Bot achieved RCE in 5 of 7 targets, stole GitHub ...
Because attacker-supplied flow data is used in public flows, the bug leads to unauthenticated remote code execution.
The attacks, which unfolded over several days starting in late February, involved the bot opening crafted pull requests that ...
GlassWorm campaign injects malware into GitHub Python repos using stolen tokens since March 8, 2026, exposing developers to ...
New release integrates automated security scanning, AI-powered remediation, and GitHub-native workflows for enterprise ...