GITHUB ACTIONS RE-ENABLED WITH ACTIVE MALWARE
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
Two compromised GitHub Actions were restored by their maintainer while still hosting malicious code, remaining publicly accessible for over a week as part of the Mini Shai-Hulud campaign.
■ MORE FROM THE SECURITY DESK
AI agents operating through human credentials are exposing blind spots in SOC 2 compliance frameworks, as existing controls struggle to distinguish automated actions from legitimate user activity.
Traditional credit card fraud delivered through the postal system remains a significant security risk, even as cybercriminals increasingly turn to AI-powered attacks. Experts warn that old-school tactics continue to catch unsuspecting victims.
A Florida woman spent 13 days in jail after license plate reader data from Flock Security incorrectly linked her vehicle to a fatal hit-and-run. The misidentification highlights growing concerns about the accuracy and use of automated surveillance technology in criminal investigations.
A $357 million hack of crypto exchange Bitget on Thursday is attributed to North Korean hackers, pushing the nation-state's digital-asset thefts past $1 billion this year, according to analytics firm Elliptic Enterprises.