GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

2026-07-23T01:24:12Zfbe1c4ce41e429777020a50a1bf669d1bd9b5e01c616e45fdd0e1e4b9957906d
active-exploitationai-agentsai-securityauthentication-bypasscloud-securitycommand-injectioncritical-vulnerabilitiescross-site-scriptingdeserializationgithub-malwareincident-responseintel-brieflocal-privilege-escalationnugetpatchingpath-traversalphishing-kitprompt-injectionransomwarercesandbox-escapesupply-chain-malwaretyposquatzero-day-trends

What happened

A batch of high- and critical-severity security incidents and disclosures across cloud, enterprise, open-source, and AI ecosystems. Notable active-exploitation and high-impact issues include a critical SharePoint RCE (CVE-2026-50522) and a ServiceNow AI sandbox escape (CVE-2026-6875); WordPress wp2shell RCEs (CVE-2026-63030, CVE-2026-60137) driving mass compromise; an Ubuntu snap-confine local root LPE (CVE-2026-8933) affecting default Desktop installs; an Adobe Acrobat Chrome-extension chain that exposed WhatsApp Web data (CVE-2026-48294); and Windmill path traversal leading to unauth'd file-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
fbe1c4ce41e429777020a50a1bf669d1bd9b5e01c616e45fdd0e1e4b9957906d
Enrichment time
2026-07-23T01:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.