GITHUB ACTIONS SECURITY CONCERNS PROMPT MAJOR EXODUS
■ AI-SUMMARIZED FROM 2 SOURCES BELOW
Security vulnerabilities in GitHub Actions have sparked significant developer concern, with high-profile projects including Ghostty announcing their departure from the platform.
■ MORE FROM THE SECURITY DESK
The U.S. Commerce Department last week ordered multiple chip equipment manufacturers to stop certain shipments to Hua Hong, China's second-largest chipmaker. The action represents another escalation in U.S. restrictions targeting China's semiconductor capabilities.
Attackers are actively exploiting a critical SQL injection vulnerability in LiteLLM, an open-source LLM gateway, to access sensitive data. The flaw, tracked as CVE-2026-42208, requires no authentication to exploit.
Security researchers have identified a critical flaw in VECT 2.0 ransomware that permanently wipes large files rather than encrypting them. The vulnerability stems from improper handling of encryption nonces.
Vimeo has disclosed that customer and user data was accessed without authorization following a breach at Anodot, a data anomaly detection company. The incident exposed information from an unspecified number of Vimeo users.