Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > CI/CD security
#CI/CD security

Unauthenticated RCE Flaw in JetBrains TeamCity Puts Software Supply Chains at Risk

1 August 2026  |  dark6  |  Vulnerability

JetBrains has patched a critical, unauthenticated remote code execution flaw (CVE-2026-63077) in TeamCity On-Premises that could let attackers hijack build servers and tamper with software releases. Administrators are...

>> read more

Microsoft Warns: Claude Code GitHub Action Exploitable via Prompt Injection to Leak CI/CD Secrets

8 June 2026  |  dark6  |  Vulnerability

Microsoft Threat Intelligence disclosed a prompt injection flaw in the Claude Code GitHub Action that allowed attackers to access /proc/self/environ and steal API keys from CI/CD runners. Anthropic...

>> read more