๐จ ACTIVE EXPLOITATION
- fake-captcha-clickfix-mac-backdoor โ Cyber Security News
๐ ADVISORIES
- Permissive GitHub Actions workflows expose tokens and secrets to attackers
Attackers can abuse permissive GitHub Actions workflows to steal tokens and secrets.- GitHub Actions users and organizations are affected.
- Pull-request workflows, third-party actions, and runner environments can expose GITHUB_TOKEN credentials, secrets, or build outputs.
- Contributor-controlled code can run in a privileged workflow and access tokens or secrets.
- Compromised actions or runner environments can also read credentials and alter build artifacts.
๐ Coverage: clearpathsecurity.co.uk ยท ๐ via securityboulevard.com (discovered)
๐ CVEs & KEV
-
CVE-2026-78306 โ CVSS 8.5 โ DJI Drone Bluetooth Interface Unauthenticated DUML Command ExecutionDJI drone...
-
CVE-2026-78321 โ CVSS 6.0 โ DJI Drone HTTP Media Server Denial of Service via Connection Pool ExhaustionT...