Home

GitLab AI Agent Flaw Could Expose CI Pipelines

GitLab has released security updates for a high-severity vulnerability in its Duo Claude AI agent that could allow authenticated developers to run unauthorized commands inside CI pipeline environments. Tracked as [...]

Patch Now: Critical Next.js Flaw Enables RCE

Two critical security issues in Next.js could allow attackers to execute code remotely on vulnerable applications without logging in. The first vulnerability, CVE-2026-75604, affects applications using the Image Optimization API [...]

npm Packages Exploited for ClickFix Phishing

Security researchers have uncovered a campaign involving 24 malicious npm packages that use legitimate package-mirroring services to deliver phishing content. The attackers are not primarily interested in getting developers to [...]

Subscribe to our newsletter to receive security tips everday!