<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ - Security Vulnerabilities</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ Security Vulnerabilities feed</description>
    <item>
      <title>GitHub Introduces Default "Cooldown" Policy for Dependabot Version Updates</title>
      <link>https://www.infoq.com/news/2026/07/github-dependabot-cooldown/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security+Vulnerabilities</link>
      <description>&lt;img src="https://www.infoq.com/styles/static/images/logo/logo_bigger.jpg"/&gt;&lt;p&gt;Instead of immediately opening pull requests when newer dependency versions are released, Dependabot now waits three days before suggesting upgrades, thus increasing the likelihood that malicious releases are identified and removed before they can be integrated.&lt;/p&gt; &lt;i&gt;By Sergio De Simone&lt;/i&gt;</description>
      <category>Software Supply Chain</category>
      <category>github</category>
      <category>Security Vulnerabilities</category>
      <category>Dependency Management</category>
      <category>Development</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Tue, 28 Jul 2026 19:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/07/github-dependabot-cooldown/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security+Vulnerabilities</guid>
      <dc:creator>Sergio De Simone</dc:creator>
      <dc:date>2026-07-28T19:00:00Z</dc:date>
      <dc:identifier>/news/2026/07/github-dependabot-cooldown/en</dc:identifier>
    </item>
    <item>
      <title>AI-Enabled Security Researchers Discover How a Crafted Video Can Provide Attackers Access to Your PC</title>
      <link>https://www.infoq.com/news/2026/07/pixelsmash-vulnerability/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security+Vulnerabilities</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/07/pixelsmash-vulnerability/en/headerimage/generatedHeaderImage-1785042241189.jpg"/&gt;&lt;p&gt;JFrog Security Research revealed "PixelSmash," a vulnerability in the FFmpeg media framework, allowing for Remote Code Execution and Denial of Service attacks. Present for sixteen years, it affects numerous applications using the MagicYUV decoder. Exploitation requires only a crafted media file. Users are advised to check for the vulnerability and apply patches or disable the decoder if necessary.&lt;/p&gt; &lt;i&gt;By Olimpiu Pop&lt;/i&gt;</description>
      <category>Streaming Video</category>
      <category>Video Codec</category>
      <category>FFmpeg Video Codec</category>
      <category>Security Vulnerabilities</category>
      <category>Security</category>
      <category>Development</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Sun, 26 Jul 2026 09:09:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/07/pixelsmash-vulnerability/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security+Vulnerabilities</guid>
      <dc:creator>Olimpiu Pop</dc:creator>
      <dc:date>2026-07-26T09:09:00Z</dc:date>
      <dc:identifier>/news/2026/07/pixelsmash-vulnerability/en</dc:identifier>
    </item>
    <item>
      <title>Indirect Prompt Injection Exploits GitHub's AI Agent to Leak Private Repository Data</title>
      <link>https://www.infoq.com/news/2026/07/gitlost-github-prompt-injection/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security+Vulnerabilities</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/07/gitlost-github-prompt-injection/en/headerimage/gitlost-vulnerability-1784835323320.jpeg"/&gt;&lt;p&gt;GitLost is a prompt-injection exploit discovered by Noma Security that tricks GitHub's new Agentic Workflows into leaking private data. By embedding concealed instructions within public GitHub issues, attackers can circumvent security safeguards and induce AI agents to reveal confidential information in public comments.&lt;/p&gt; &lt;i&gt;By Sergio De Simone&lt;/i&gt;</description>
      <category>Large language models</category>
      <category>Agents</category>
      <category>github</category>
      <category>Security Vulnerabilities</category>
      <category>Prompt Engineering</category>
      <category>Development</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Thu, 23 Jul 2026 20:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/07/gitlost-github-prompt-injection/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security+Vulnerabilities</guid>
      <dc:creator>Sergio De Simone</dc:creator>
      <dc:date>2026-07-23T20:00:00Z</dc:date>
      <dc:identifier>/news/2026/07/gitlost-github-prompt-injection/en</dc:identifier>
    </item>
  </channel>
</rss>
