A public-code secret hunt found exposed n8n API tokens that could open live instances and, in some deployments, reach sensitive data and downstream credentials without a software exploit.
A reported malleability issue in Git commit signing can produce byte-different commits with the same content, forcing teams to rethink what a green badge actually proves.
A burst of suspicious commits across thousands of repositories shows how trusted automation can be turned into a delivery channel for backdoored workflows.
A fast-moving GitHub Actions campaign highlights how CI/CD automation can turn into a high-volume path toward secrets, cloud access, and source-code risk.