
wiz.io
April 28, 2026
7 min read
66/100
Summary
Wiz Research identified a critical vulnerability (CVE-2026-3854) in GitHub's internal git infrastructure that allows authenticated users to execute arbitrary commands on backend servers with a single git push command. This vulnerability is notable as one of the first critical flaws found in closed-source binaries using AI.
Key Takeaways
Community Sentiment
Positives
Concerns

GitLost: We Tricked GitHub's AI Agent into Leaking Private Repos
Jul 8, 2026

An Update on GitHub Availability
Apr 28, 2026

Exploit brokers pay $500k for WordPress RCEs. I found one with GPT5.6 and $25
Jul 20, 2026

NIST gives up enriching most CVEs
Apr 17, 2026

Google API keys weren't secrets, but then Gemini changed the rules
Feb 25, 2026