The GhostAction supply-chain campaign has evolved to use lookalike domains my-github.com and my-gitlab.com alongside continued GitHub account compromises that inject malicious Actions workflows to steal CI/CD secrets and credentials. The newly registered domains resolve to attacker infrastructure and may signal a shift toward phishing and developer targeting. Responders must assume exposure of active secrets and invalidate all potentially compromised credentials.
guardrails-md is an open-source tool that intercepts commands from coding agents and scores them against a GUARDRAILS.md file using a decision model, blocking destructive, credential-exposing, or policy-violating commands within ~100ms. The system uses fixed scoring questions rather than full LLM generations, fails closed by default, and requires human approval via pull requests to change policies.
BasedApp disclosed a data breach exposing customer KYC data including names, dates of birth, addresses, and passport numbers. Unauthorized parties also gained administrator access to the company's AI-agent backend through Google Quick Login, compromising sensitive tokens and API keys.
MapRoulette discovered multiple security vulnerabilities in October 2026 that exposed user email addresses and OSM access tokens, potentially allowing attackers to impersonate users and edit OpenStreetMap. Maintainer Jake Low took the service offline, revoked compromised credentials, and deployed patches; server logs showed no evidence of exploitation, though the bugs existed for years.
Tensorlake's TypeScript SDK was compromised for 102 minutes with the Shai-Hulud worm, a malware designed to steal GitHub and AWS credentials. The attacker used stolen employee credentials to inject malicious code. The package was removed immediately, and Tensorlake implemented multiple security measures including hardware security keys, signed commits, and two-person approval for package publishing.
Zenity researchers discovered a critical vulnerability in AWS Bedrock AgentCore that allowed attackers to hijack all AI agents in an AWS account through a single prompt to one public agent. The flaw stemmed from improper isolation and overly broad default permissions, enabling access to credentials, source code, and private data. AWS has partially patched the issue but recommends companies implement stricter access controls.
A developer criticizes poorly designed APIs from established vendors, highlighting frustrations with gated documentation, missing OpenAPI specs, manual credential management, and account-tied credentials that create operational risks and integration delays.