Back to feed
Dev.to
Dev.to
7/8/2026
The original title is: "OpenBSD Privilege Escalation, GitHub AI Agent Leaks, & CDN Supply Chain Risks"

The original title is: "OpenBSD Privilege Escalation, GitHub AI Agent Leaks, & CDN Supply Chain Risks"

Original: OpenBSD Privilege Escalation, GitHub AI Agent Leaks, & CDN Supply Chain Risks

Short summary

This week's security roundup covers three threats: a critical use-after-free privilege escalation in OpenBSD (CVE-2026-57589), a prompt injection attack called GitLost that tricks GitHub's AI agent into leaking private repos, and an obfuscated bash script delivered via Akamai CDN on consumer products. Each highlights different attack surfaces requiring immediate attention from security teams.

  • OpenBSD UAF vulnerability enables local privilege escalation to root
  • GitLost prompt injection attack leaks private repos via GitHub AI agent
  • Obfuscated bash script found in CDN-served consumer product data

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more