A vulnerability dubbed GitLost leaks private data from GitHub Agentic Workflows. An unauthenticated attacker can craft a public GitHub Issue to silently exfiltrate data from private repositories.

A newly identified vulnerability, named GitLost, has been discovered that allows for the exfiltration of private data from GitHub's Agentic Workflows. The flaw enables an unauthenticated attacker to exploit a public GitHub Issue to silently steal information from private repositories.
The exploit leverages a specific mechanism within GitHub Agentic Workflows. These workflows are designed to automate tasks and can be configured to access and process data from repositories. The GitLost vulnerability exploits how these workflows handle certain types of input or commands, particularly when interacting with external resources or generating output.
By creating a specially crafted public GitHub Issue, an attacker can trigger a workflow in a targeted private repository. This crafted issue contains malicious payloads that, when processed by the workflow, instruct it to send sensitive data back to an attacker-controlled endpoint. The exfiltration occurs silently, meaning the user or administrator of the private repository would not receive any immediate notification of the data leak.
The nature of the data that can be exfiltrated is not explicitly detailed, but it is understood to be any information accessible by the Agentic Workflow within the private repository. This could include source code, configuration files, sensitive credentials inadvertently stored in the repository, or any other data the workflow is permitted to access.
The vulnerability specifically targets GitHub Agentic Workflows, which are a feature designed to enhance automation and integrate with various tools and services. The attack vector relies on the workflow's execution context and its ability to interact with external systems or generate output that can be intercepted.
The fact that the attacker does not need to be authenticated to the target repository is a significant aspect of this vulnerability. This means that anyone who can create a public GitHub Issue could potentially attempt to exploit this flaw against private repositories they do not have legitimate access to.
While the specific technical details of the payload and the exact workflow configurations that are vulnerable are not fully disclosed, the core mechanism involves tricking the workflow into processing malicious input disguised as a legitimate issue comment or creation. This input then causes the workflow to inadvertently leak data.
As a general security measure, organizations using GitHub Agentic Workflows should review their workflow configurations and ensure that they are not inadvertently exposing sensitive information. Best practices include minimizing the scope of permissions granted to workflows, avoiding the storage of sensitive secrets directly within repositories, and regularly auditing workflow activity for any unusual patterns. Further guidance from GitHub on mitigating this specific vulnerability is expected.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.