Aikido Security found GitLab's per-user issue email doubles as a non-expiring token that can commit code as the account owner.
CISA flags actively exploited TeamCity flaw CVE-2026-63077, giving federal agencies until August 8 to patch.
The attacker exploited a misconfigured GitHub Action called a Pwn Request vulnerability to steal privileged tokens and download the source…