Aikido Security found GitLab's per-user issue email doubles as a non-expiring token that can commit code as the account owner.
Over 2,000 corporate applications built by non developer employees using AI platforms were found exposed on the open internet with…
The attacker exfiltrated source code and proprietary information from multiple GitHub repositories, prompting an ongoing investigation with law enforcement.