Advertisement

HIGH
Supply Chain
Developer Workstations: The New Front in Software Supply Chain Attacks
A surge in attacks targeting npm, PyPI, and Docker Hub highlights a shift toward stealing developer credentials and API keys from workstations and CI/CD pipelines.
Runtime Rebel Intel
4 min read·May 18, 2026

CRITICAL
Vulnerabilities
Gemini CLI Critical RCE Fix: Patching the @google/gemini-cli Flaw
Google patches a CVSS 10.0 flaw in Gemini CLI tools that allowed unprivileged attackers to execute commands in CI/CD environments via malicious configurations.
Runtime Rebel Intel
3 min read·Apr 30, 2026