GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

2026-07-23T07:24:22Z40259dfa44f4d3d68b595165008a6e5e6e91cd0052734a2633ac8f9053fc0187
active-exploitationadobeencforgefakegit','hollowgraph','microsoft-365','azure-devops','prompt-inkratoslocal-privilege-escalationmalwarenugetpalo-altopan-ospath-traversalphishingqilinransomwarerceservicenowsharepointsmartloadersnap-confinesupply-chaintrojanvulnerabilitywindmillwordpresszimbra

What happened

A batch of high-impact security stories from The Hacker News: multiple disclosed and actively exploited vulnerabilities (notably SharePoint RCE CVE-2026-50522 and ServiceNow sandbox escape CVE-2026-6875) alongside critical flaws and exploit chains affecting default Ubuntu Desktop snap-confine (CVE-2026-8933), Adobe Acrobat Chrome extension (HermeticReader, CVE-2026-48294), Windmill path traversal (CVE-2026-29059), and WordPress wp2shell (CVE-2026-63030, CVE-2026-60137). Threat activity includes Qilin ransomware leveraging PAN-OS auth bypass (CVE-2026-0257), new ENCFORGE ransomware targeting AI

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
40259dfa44f4d3d68b595165008a6e5e6e91cd0052734a2633ac8f9053fc0187
Enrichment time
2026-07-23T07:24:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.