The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Sourcing
1source

via The Verge

The Verge · track record
71Stories
100%Verified
2630d
All sources →
Home/Tech/GitHub patches critical RCE vuln in under 6 hours
VERIFIEDBy Xavier Rivera· ·1.5 min read

GitHub patches critical RCE vuln in under 6 hours

Wiz Research surfaced a critical remote code execution flaw in GitHub’s internal git systems with AI assistance. The company validated the bug bounty report, shipped a patch, and verified no exploitation occurred, all within six hours.

Source:The Verge
Post
GitHub patches critical RCE vuln in under 6 hours
TL;DRAI · 60 sec read

Wiz Research discovers critical RCE vulnerability in GitHub's internal git infrastructure using AI, which could allow attackers to access millions of public and private repositories. GitHub reproduces it in 40 minutes, identifies root cause, and deploys fix to GitHub.com and Enterprise Server in under two hours, with no exploitation found. It earns top bug bounty reward and marks first such AI-discovered flaw in closed-source binaries.

Last month GitHub resolved a serious remote code execution flaw in its internal git systems roughly six hours after receiving a bug bounty submission from Wiz Research. The security firm relied on AI tools to surface the issue, which reportedly could have let malicious actors reach millions of both public and private repositories.

GitHub’s Response

Alexis Wales, GitHub’s chief information security officer, said the company’s security team “immediately began validating the bug bounty report” and reproduced the problem internally within 40 minutes. Engineering staff then built and rolled out a patch just over an hour after pinpointing the root cause, shielding both GitHub.com and GitHub Enterprise Server instances. Wales added that “in less than two hours we had validated the finding, deployed a fix to github.com, and begun a forensic investigation that concluded there was no exploitation.”

Discovery Method
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →

Wiz noted the flaw was found “using AI.” Security researcher Sagi Tzadik called it “one of the first critical vulnerabilities discovered in closed-source binaries using AI,” pointing to an emerging approach for spotting such defects. Although the precise model remains undisclosed, the firm described the vulnerability as “remarkably easy to exploit” despite the complexity of GitHub’s architecture.

Wales said the report qualified for one of the highest payouts in the company’s bug bounty program because of its potential impact.
The episode follows a string of service disruptions at GitHub, including an outage last month that unexpectedly reverted merged commits for some users and additional incidents the same week. The Verge reported last week on internal worries about the platform’s stability, including one employee’s claim that “the company is collapsing, both in outages that are reallllly bad and have torched the company reputation… and in an exodus of leadership.”

EXPERT TAKE

GitHub's sub-six-hour response time sets a benchmark for enterprise cloud security incident handling.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →

Reader-supported · Daily Brief

Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.

HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
GitHubSecurityVulnerability
More fromThe Verge
  • Trump administration asks OpenAI to stagger GPT-5.6 rollout

    Tech · 17h
  • Meta revives Creator Studio as AI companion app

    Tech · 1d
  • DeepMind partners with A24 on AI film tools after Google invests $75 million

    Tech · 3d
More inTech
  • Italy launches probe into Microsoft 365 price increases linked to AI

    Tech · 1h
  • Tesla quietly resolves suit tied to first known pedestrian death in Full Self-Driving mode

    Tech · 1h
  • ON Semiconductor Strikes $7 Billion All-Stock Deal for Synaptics

    Tech · 16h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
SubscribeCircuitry Brief

Daily brief at 7 AM ET. Top tech stories, every morning.

MORE IN TECH

Italy launches probe into Microsoft 365 price increases linked to AI

Italy's AGCM is investigating Microsoft over claims that fragmented notices left Microsoft 365 subscribers automatically moved to costlier plans once Copilot and Designer features were added without clear explanation of the changes.

Tesla quietly resolves suit tied to first known pedestrian death in Full Self-Driving mode

Tesla reached an undisclosed settlement with the family of a pedestrian killed by a Model Y operating in Full Self-Driving mode. The 2023 collision, the first known pedestrian fatality linked to FSD, also launched a federal probe targeting 3.2 million vehicles.

ON Semiconductor Strikes $7 Billion All-Stock Deal for Synaptics

ON Semiconductor agreed to acquire Synaptics in a nearly $7 billion all-stock transaction that accelerates its physical AI expansion and lifts its total addressable market to $243 billion by 2030. The deal, the company's largest to date, is slated to close in mid-2027 amid a surge in AI-related buyouts industrywide.