Dev.to
7/8/2026

The original title is: "OpenBSD Privilege Escalation, GitHub AI Agent Leaks, & CDN Supply Chain Risks"
Original: OpenBSD Privilege Escalation, GitHub AI Agent Leaks, & CDN Supply Chain Risks
Short summary
This week's security roundup covers three threats: a critical use-after-free privilege escalation in OpenBSD (CVE-2026-57589), a prompt injection attack called GitLost that tricks GitHub's AI agent into leaking private repos, and an obfuscated bash script delivered via Akamai CDN on consumer products. Each highlights different attack surfaces requiring immediate attention from security teams.
- •OpenBSD UAF vulnerability enables local privilege escalation to root
- •GitLost prompt injection attack leaks private repos via GitHub AI agent
- •Obfuscated bash script found in CDN-served consumer product data
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



