CloudSec Wine
2.25K subscribers
1.07K photos
24 files
1.39K links
All about cloud security

Contacts:
@AMark0f
@dvyakimov

About DevSecOps:
@sec_devops
Download Telegram
👨‍💻 Widespread GitHub Campaign Uses Fake VS Code Security Alerts to Deliver Malware

A large-scale phishing campaign is targeting developers directly inside GitHub, using fake Visual Studio Code security alerts posted through Discussions to trick users into installing malicious software.

https://socket.dev/blog/widespread-github-campaign-uses-fake-vs-code-security-alerts-to-deliver-malware

#github
Please open Telegram to view this post
VIEW IN TELEGRAM
1👍1🔥1
👨‍💻 GitHub Actions Security Pt 1: Attacks & Defenses

Part one of a two-part series on GitHub Actions security, covering the core threat model, common misconfigurations, and real-world attack examples.

https://www.wiz.io/blog/github-actions-security-threat-model-and-defenses

#github
Please open Telegram to view this post
VIEW IN TELEGRAM
👍21🔥1
👨‍💻 GitHub RCE Vulnerability: CVE-2026-3854 Breakdown

Wiz Research discovered CVE-2026-3854 (CVSS 8.7): an unsanitized semicolon injection in GitHub's X-Stat internal header allows any authenticated user to override security fields via git push -o, achieving RCE on GitHub com and full GHES server compromise.

https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854

#github
Please open Telegram to view this post
VIEW IN TELEGRAM
👍31🔥1
👨‍💻 Coordinated GitHub API enumeration and access token abuse

Datadog Security Research has tracked multiple coordinated campaigns enumerating GitHub organizations, repositories, and users through the public GitHub API, abusing leaked access tokens, and cloning private repositories.

https://securitylabs.datadoghq.com/articles/coordinated-github-api-enumeration

#github
Please open Telegram to view this post
VIEW IN TELEGRAM
1👍1🔥1