CloudSec Wine
2.23K subscribers
1.02K photos
20 files
1.35K links
All about cloud security

Contacts:
@AMark0f
@dvyakimov

About DevSecOps:
@sec_devops
Download Telegram
👨‍💻 Widespread GitHub Campaign Uses Fake VS Code Security Alerts to Deliver Malware

A large-scale phishing campaign is targeting developers directly inside GitHub, using fake Visual Studio Code security alerts posted through Discussions to trick users into installing malicious software.

https://socket.dev/blog/widespread-github-campaign-uses-fake-vs-code-security-alerts-to-deliver-malware

#github
Please open Telegram to view this post
VIEW IN TELEGRAM
1👍1🔥1
👨‍💻 GitHub Actions Security Pt 1: Attacks & Defenses

Part one of a two-part series on GitHub Actions security, covering the core threat model, common misconfigurations, and real-world attack examples.

https://www.wiz.io/blog/github-actions-security-threat-model-and-defenses

#github
Please open Telegram to view this post
VIEW IN TELEGRAM
👍21🔥1
👨‍💻 GitHub RCE Vulnerability: CVE-2026-3854 Breakdown

Wiz Research discovered CVE-2026-3854 (CVSS 8.7): an unsanitized semicolon injection in GitHub's X-Stat internal header allows any authenticated user to override security fields via git push -o, achieving RCE on GitHub com and full GHES server compromise.

https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854

#github
Please open Telegram to view this post
VIEW IN TELEGRAM
👍31🔥1