vulnerability
In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug
Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug appeared first on SecurityWeek.
snowflakehigh
Snowflake GitHub Actions Flaw Allows Command Injection
Researchers have identified a vulnerability in Snowflake's GitHub Actions workflows, specifically within the snowflakedb/snowflake-connector-net repository. A specially crafted GitHub issue could exploit this flaw to execute commands within a workflow, potentially exposing internal Jira credentials.
malware
GitHub Dependabot malware alerts now cover eight ecosystems
GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. GitHub’s Advisory Database now ingests malware reports from OpenSSF’s malicious-packages repository, a public feed in OSV format that launch
CVE-2026-12537critical
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
Researchers discovered vulnerabilities in Anthropic's Claude Code and Google's Gemini CLI that allowed unprivileged attackers to execute code on CI runners. The flaws, which have been patched and assigned CVEs, involved issues with command validation and container launching. A separate finding related to OpenAI's Codex also allowed for the hijacking of agent runs, though OpenAI considers its sandbox to have behaved as documented.