Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization’s private repositories, researchers at Noma Security have shown.

The attacker needs only to open a normal-looking issue on a public repository, with no stolen credentials and no access to the organization. If that organization has given the agent read access across its repositories, private ones

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Show HN: I trained a 125M model to autocomplete piano on-device

Show HN: I trained a 125M model to autocomplete piano on-device Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 17.08.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 668 requests (recent log) 216.73.216.144 — 276 requests (recent log) 20.119.58.187 — 190 requests (recent

Painting with Gaussians

Painting with Gaussians Source: Hacker News