actions-cool Came Back With the Old Tags actions-cool issues-helper and maintain-one-comment were live again from Sept. 16. May 18 tags were still malicious. Older SHA pins were spared. devops
Google Says Attackers Are Going After AI Coding Tools GTIG maps token theft from GitHub Actions runners and junk in hidden AI workspaces. What to change on Linux CI and laptops this week. security
The Ted Backdoor Was Built Into HAProxy. Verify the Binary. Rapid7 found a DPRK toolkit compiled into HAProxy 2.8.12, not exploited through it. Here is how to checksum your reverse proxy, catch /tmp pipes, and stop building load balancers on the edge box. server-config
How to Check if Your Linux Server Is Affected by the PAM Backdoor Discovered in 2026 A decade-long supply chain compromise in Linux PAM modules has been uncovered. Here's how to audit your servers, detect the backdoor, and secure your authentication stack. linux
Securing the AI-Powered DevOps Pipeline: A Practical Guide for 2026 As AI tools become integral to CI/CD workflows, the artifact supply chain has emerged as a new attack surface. Learn how to secure your DevOps pipeline against AI-specific threats. devops