Ghostcommit Prompt Injection Attack Steals Secrets via AI Code Review Blind Spot
July 11, 2026 Researchers from the University of Missouri Kansas City’s ASSET Research Group have disclosed a new supply-chain attack called Ghostcommit. This technique hides malicious prompt-injection instructions inside a PNG image embedded in an…
Polymarket Supply-Chain Attack Drains Million in Crypto via Frontend Compromise
June 28, 2026 Polymarket, a $9 billion cryptocurrency-based prediction market platform, disclosed on June 26, 2026, that attackers stole approximately $3 million from customers through a frontend supply-chain attack. Consequently, the breach exploited a…
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
June 24, 2026 Cybersecurity researchers at Novee Security have disclosed a critical new class of CI/CD workflow vulnerabilities called Cordyceps. This flaw allows unauthenticated attackers to hijack GitHub Actions workflows and seize full control of…