GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
2026-07-23T01:24:12Z•fbe1c4ce41e429777020a50a1bf669d1bd9b5e01c616e45fdd0e1e4b9957906d
active-exploitationai-agentsai-securityauthentication-bypasscloud-securitycommand-injectioncritical-vulnerabilitiescross-site-scriptingdeserializationgithub-malwareincident-responseintel-brieflocal-privilege-escalationnugetpatchingpath-traversalphishing-kitprompt-injectionransomwarercesandbox-escapesupply-chain-malwaretyposquatzero-day-trends
What happened
A batch of high- and critical-severity security incidents and disclosures across cloud, enterprise, open-source, and AI ecosystems. Notable active-exploitation and high-impact issues include a critical SharePoint RCE (CVE-2026-50522) and a ServiceNow AI sandbox escape (CVE-2026-6875); WordPress wp2shell RCEs (CVE-2026-63030, CVE-2026-60137) driving mass compromise; an Ubuntu snap-confine local root LPE (CVE-2026-8933) affecting default Desktop installs; an Adobe Acrobat Chrome-extension chain that exposed WhatsApp Web data (CVE-2026-48294); and Windmill path traversal leading to unauth'd file-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- fbe1c4ce41e429777020a50a1bf669d1bd9b5e01c616e45fdd0e1e4b9957906d
- Enrichment time
- 2026-07-23T01:24:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.