Security Feed
  1. Archives

Sep 26 2026 GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Source

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. [...]

Posted by Bill Toulas on Sat 26 September 2026 in BleepingComputer.

Tags: Security.

Categories

  1. Ars Technica
  2. AWS Security
  3. BleepingComputer
  4. Brian Krebs
  5. Bruce Schneier
  6. GCP Security
  7. Google Project Zero
  8. The Daily Swig
  9. The Guardian
  10. The Register
  11. Threatpost

Tag cloud

  • Security
  • Uncategorized
  • Security, Identity, & Compliance
  • Security Blog
  • Biz & IT
  • Microsoft
  • AI
  • Security & Identity
  • Artificial Intelligence
  • Announcements
  • CryptoCurrency
  • google
  • Foundational (100)
  • Legal
  • privacy
  • A Little Sunshine
  • Apple
  • Advanced (300)
  • LLM
  • Intermediate (200)
  • squid
  • Hacking
  • Technical How-to
  • Mobile
  • vulnerabilities

Security Feed. Powered by Pelican and m.css. Code is available on GitLab.