GitHub Actions stories
Browser verification can now be folded into development workflows, as teams face pressure to prove AI-generated code works before review.
A flaw in a Microsoft GitHub workflow could let attackers run unauthorised code and steal repository secrets, Tenable said.
A flaw in a widely watched Microsoft repository could have let attackers run code and steal secrets through GitHub Actions, Tenable said.
A critical flaw in a widely used Microsoft code-sample repository could have let attackers steal secrets and run code through GitHub issues.
Leaked AI credentials and unpatched dependencies are leaving production systems exposed across US and European organisations, Orca Security said.
The malicious packages could leave build systems and Kubernetes clusters exposed, prompting checks across CI/CD pipelines and AI frameworks.
Enterprises could spot compromised maintainers sooner, as the new tool maps open-source contributors, dependencies and policy breaches across builds.
Aqua Security's Trivy GitHub Action was hijacked to ship infostealer code via CI/CD pipelines, exposing secrets across downstream users.
1Password unveils Unified Access to secure AI agents and machine credentials, promising endpoint-to-agent visibility for security teams.
GitHub joins tech giants in a USD $12.5 million Alpha-Omega push, boosting AI-powered defences for critical open source software.
JFrog warns 13 GitHub CI/CD workflow flaws, mostly critical, could let attackers hijack pipelines and steal secrets at scale.
Datadog warns 87% of organisations run software with exploitable flaws as ageing code, fast releases and automation amplify DevSecOps risk.
GitHub debuts Agentic Workflows, using AI agents with strict guardrails to automate repo chores while keeping maintainers in control.
GitHub will cut Actions hosted runner prices by up to 39% from 2026 while adding a new USD $0.002-a-minute fee for self-hosted use.
Keeper Security named Overall Leader in non-human identity management, praised for securing machine identities across cloud-native and hybrid environments.
AppOmni has launched Heisenberg, an open source tool that detects and prevents risky software dependencies by inspecting changes in real time at pull requests.
GitHub launches Agents panel, enabling paid Copilot users to manage AI coding tasks across platforms like GitHub.com, VS Code, and JetBrains IDEs.
GitHub Copilot has surpassed 20 million users, with over 90% of the Fortune 100 adopting the AI tool, as demand for AI coding aids surges globally.
BeyondTrust named Overall Leader in the 2025 KuppingerCole Leadership Compass for Enterprise Secrets Management, praised for secure, scalable secrets solutions.
Attackers are now moving fast enough that patching delays, standing privilege and inherited trust leave organisations exposed within minutes.