GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

2026-07-08T13:24:13Zce805dd06dee3b37a4a617a7bb9063cdcd26ad1d48939a89559257a4ee9762c5
APTCISA-KEVMaaSactive-exploitationagentic-workflowsai-securitycritical-vulnerabilitydevice-code-phishinggithubhypervisor-escapeiotkernel-exploitmalwaremobile-malwarephishingprivilege-escalationremote-code-executionrouter-backdoorsupply-chainvulnerability

What happened

A broad The Hacker News roundup describing multiple high-impact security developments: researchers show Git commit signatures can be rewritten without breaking GitHub's "Verified" badge; AI tools and agentic workflows expose novel data-leak and jailbreak pathways; and several actively exploited or high-severity vulnerabilities were disclosed — including a 15-year-old Linux kernel root/escape flaw (GhostLock), a KVM guest-to-host escape (Januscape), and multiple critical remote-execution/auth-bypass bugs added to CISA's KEV. The feed also covers ongoing APT campaigns and new malware (e.g., UAT-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ce805dd06dee3b37a4a617a7bb9063cdcd26ad1d48939a89559257a4ee9762c5
Enrichment time
2026-07-08T13:24:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures · Baitaphish