The Lab · 2026-03-25 21:57:02 · The Register
A new vulnerability in the AI development pipeline bypasses traditional malware entirely, relying instead on poisoned documentation to compromise coding agents. The attack vector, demonstrated in a proof-of-concept against the service Context Hub, reveals a critical weakness in how AI assistants consume and trust exter...
The Lab · 2026-03-30 09:27:04 · GitHub Issues
A critical security flaw in the SEC's GitHub Actions workflow, `pr-loop.yml`, creates a direct path for attackers to steal high-value API secrets, including the `ANTHROPIC_API_KEY` and `ALEXS_CODEX_KEY`. The vulnerability is a textbook 'pwn request' scenario, where the workflow's configuration grants it access to the r...
The Lab · 2026-03-30 11:27:14 · GitHub Issues
A critical security flaw, identified as prototype pollution, has been patched in the widely used `ini` npm package, a fundamental library for parsing INI configuration files across the Node.js ecosystem. The vulnerability, tracked as GHSA-qqgx-2p2h-9c37, existed in all versions prior to 1.3.6. If exploited, an attacker...
The Lab · 2026-04-01 01:56:57 · Hacker News
AI recruiting startup Mercor has confirmed a security breach after an extortion-focused hacking group claimed responsibility for stealing data from the company's internal systems. The incident is directly tied to the compromise of the open-source LiteLLM project, a widely used library for unifying large language model ...
The Lab · 2026-04-02 01:26:57 · GitHub Issues
The Kubernaut Agent's core investigation pipeline is vulnerable to prompt injection attacks, as it processes untrusted content from multiple Kubernetes sources directly into its LLM context window without any sanitization or detection. This creates a direct path for attackers to manipulate the agent's reasoning and out...
The Lab · 2026-04-02 09:57:08 · Inc42
A critical software supply chain attack on the widely-used Axios library has exposed the fragility of modern development ecosystems. On March 31, 2026, attackers seized control of a trusted maintainer account and injected malicious code directly into official Axios updates. This breach, though lasting only hours, sprea...
The Lab · 2026-04-04 05:26:57 · GitHub Issues
A critical security vulnerability has been exposed in a GitHub issue triage system, where an attacker successfully manipulated an AI bot's instructions to force it to post a specific, unauthorized verification message. The exploit, described as an "agentic workflow injection," overrides the bot's standard operating pro...
The Network · 2026-04-04 20:26:56 · GitHub Issues
The threat landscape has intensified, with ransomware-as-a-service (RaaS) operations and sophisticated supply chain attacks driving a surge in critical incidents. Over the past 24 hours, six reports were rated critical, dominated by DragonForce claiming five new victims across pharmaceuticals, manufacturing, and retail...
The Lab · 2026-04-05 15:27:03 · GitHub Issues
A critical security vulnerability pattern has been identified in GitHub Actions workflows, exposing sensitive tokens and secrets. An automated scan of a major open-source repository revealed 422 instances where authentication tokens and secrets are directly interpolated into `run:` blocks within CI/CD pipelines. This p...
The Lab · 2026-04-06 02:27:00 · GitHub Issues
Kubernetes 包管理器 Helm 爆出高危安全漏洞,攻击者可通过特制的 `Chart.yaml` 文件在本地执行任意代码。该漏洞被追踪为 CVE-2025-53547(GHSA-557j-xg8c-q2mm),由 Helm 项目贡献者发现,核心风险在于依赖更新流程。当用户处理包含恶意内容的 `Chart.yaml` 文件及其关联的 `Chart.lock` 文件时,攻击者可利用此漏洞在目标系统上实现代码注入与执行。
漏洞细节显示,攻击向量集中在 `Chart.yaml` 文件的特定字段。当 Helm 解析这些字段并处理依赖关系时,恶意构造的内容可能绕过安全限制,触发非预期的代码执行路径。此漏洞影响范围广泛,因为 Helm ...
The Lab · 2026-04-10 00:39:39 · GitHub Issues
A critical vulnerability in the EngageLab SDK has exposed an estimated 50 million Android users to potential compromise, with a staggering 30 million of those users identified as cryptocurrency wallet holders. This flaw represents a severe supply-chain security failure, placing a massive user base at direct risk of dat...
The Lab · 2026-04-11 15:22:33 · GitHub Issues
A critical security gap has been identified in the deployment pipeline, where container images are being deployed without any vulnerability scanning, signature verification, or registry authentication. This leaves the infrastructure exposed to known CVEs, supply chain attacks, and potential malicious payloads. The curr...
The Lab · 2026-04-13 15:22:51 · TechCrunch
A significant data breach at business analytics firm Anodot has left more than a dozen of its corporate customers facing extortion demands. The attack, which targeted Anodot's systems, successfully exfiltrated sensitive data, placing major companies like Rockstar Games in the crosshairs of cybercriminals. This incident...
The Lab · 2026-04-15 00:22:48 · GitHub Issues
Microsoft's April 2026 Patch Tuesday is a critical security event, addressing a total of 167 vulnerabilities. The most urgent fix is for a zero-day vulnerability in SharePoint, a widely used enterprise collaboration platform. The presence of an actively exploited zero-day elevates the immediate risk for organizations, ...
The Lab · 2026-04-17 09:22:43 · GitHub Issues
A critical vulnerability in Kyverno's policy engine can inadvertently leak the powerful controller service account token to external, potentially malicious servers. The flaw, tracked as CVE-2026-40868, resides in the `apiCall` servicecall helper, which automatically injects an `Authorization: Bearer` header using Kyver...
The Lab · 2026-04-20 02:22:29 · CoinDesk
A security breach at cloud platform Vercel has triggered a scramble among cryptocurrency developers to secure their API keys. The incident, which may be linked to a compromised AI tool, potentially exposed sensitive credentials used by application frontends. These frontends serve as the critical user-facing layer conne...
The Lab · 2026-04-20 15:22:58 · TechCrunch
Vercel, the popular frontend cloud platform, has confirmed a security breach where hackers stole customer data. The intrusion was not a direct attack on Vercel's own systems but a sophisticated supply-chain exploit. According to the company, attackers leveraged a prior, separate security breach at Context AI, an AI sta...
The Lab · 2026-04-20 22:22:30 · Protos
A critical breach at Vercel, the cloud platform behind countless crypto frontends, has triggered urgent warnings for DeFi users to halt interactions, as attackers now potentially control the delivery pipeline for web applications. The intrusion, which Vercel CEO Guillermo Rauch attributes to an employee compromised via...
The Lab · 2026-04-21 04:22:46 · GitHub Issues
A breach at AI tool vendor Context.ai has cascaded into a significant security incident at software giant Vercel, exposing the hidden risks of third-party integrations and employee access. Threat actors, after compromising Context.ai, used that foothold over the weekend to infiltrate Vercel's systems. The attack vector...
The Lab · 2026-04-21 10:33:33 · Medianama
Cloud platform Vercel has confirmed a breach of its internal systems, with attackers gaining entry through a compromised third-party AI tool. The incident exposed a 'limited subset' of customer data, specifically non-sensitive environment variables. Vercel maintains its core services are operational and that sensitive ...