GeistHaus
log in · sign up

hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far - StepSecurity

stepsecurity.io

A week-long automated attack campaign targeted CI/CD pipelines across major open source repositories, achieving remote code execution in at least 4 out of 5 targets. The attacker, an autonomous bot called hackerbot-claw, used 5 different exploitation techniques and successfully exfiltrated a GitHub token with write permissions from one of the most popular repositories on GitHub. This post breaks down each attack, shows the evidence, and explains what you can do to protect your workflows.

10 pages link to this URL
Quarterly Threat Report: First Quarter, 2026

The first quarter of 2026 started with a lull and ended with a bang. Early seasonal slowdowns across ransomware deployments, infostealer downloads, and other observed cybercriminal activity gave way to high-profile announcements, politically linked cyberattacks, and AI developments that shaped the cyber threat landscape this quarter.

An AI Agent Just Pwned Trivy's 32K-Star Repo via GitHub Actions

An autonomous agent powered by Claude Opus 4.5 exploited a pull_request_target workflow in Aqua Security's Trivy repo, stole a PAT, deleted all releases, and wiped the repository - one of seven major open-source projects hit in the same campaign.

1 inbound link article en News SecuritySupply Chain AttackGitHubVulnerability ScanningAI AgentsDevOpsOpen Source
‘CanisterWorm’ Springs Wiper Attack Targeting Iran

A financially motivated data theft and extortion group is attempting to inject itself into the Iran war, unleashing a worm that spreads through poorly secured cloud services and wipes data on infected systems that use Iran's time zone or have…

1 inbound link en A Little SunshineLatest WarningsNeer-Do-Well NewsRansomwareThe Coming Storm AikidoAqua SecurityAssaf MoragCanisterWormCatalin CimpanuCharlie EriksenFlareICPInternet Computer ProtocolTeamPCPTrivyWiz