The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Sourcing
1source

via The Verge

The Verge · track record
102Stories
100%Verified
1230d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/GitHub patches critical RCE vuln in under 6 hours
VERIFIEDBy Xavier Rivera· ·1.5 min read

GitHub patches critical RCE vuln in under 6 hours

Wiz Research surfaced a critical remote code execution flaw in GitHub’s internal git systems with AI assistance. The company validated the bug bounty report, shipped a patch, and verified no exploitation occurred, all within six hours.

Source:The Verge
Post
GitHub patches critical RCE vuln in under 6 hours
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

Wiz Research discovers critical RCE vulnerability in GitHub's internal git infrastructure using AI, which could allow attackers to access millions of public and private repositories. GitHub reproduces it in 40 minutes, identifies root cause, and deploys fix to GitHub.com and Enterprise Server in under two hours, with no exploitation found. It earns top bug bounty reward and marks first such AI-discovered flaw in closed-source binaries.

Last month GitHub resolved a serious remote code execution flaw in its internal git systems roughly six hours after receiving a bug bounty submission from Wiz Research. The security firm relied on AI tools to surface the issue, which reportedly could have let malicious actors reach millions of both public and private repositories.

GitHub’s Response

Alexis Wales, GitHub’s chief information security officer, said the company’s security team “immediately began validating the bug bounty report” and reproduced the problem internally within 40 minutes. Engineering staff then built and rolled out a patch just over an hour after pinpointing the root cause, shielding both GitHub.com and GitHub Enterprise Server instances. Wales added that “in less than two hours we had validated the finding, deployed a fix to github.com, and begun a forensic investigation that concluded there was no exploitation.”

Discovery Method
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →

Wiz noted the flaw was found “using AI.” Security researcher Sagi Tzadik called it “one of the first critical vulnerabilities discovered in closed-source binaries using AI,” pointing to an emerging approach for spotting such defects. Although the precise model remains undisclosed, the firm described the vulnerability as “remarkably easy to exploit” despite the complexity of GitHub’s architecture.

Wales said the report qualified for one of the highest payouts in the company’s bug bounty program because of its potential impact.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
The episode follows a string of service disruptions at GitHub, including an outage last month that unexpectedly reverted merged commits for some users and additional incidents the same week. The Verge reported last week on internal worries about the platform’s stability, including one employee’s claim that “the company is collapsing, both in outages that are reallllly bad and have torched the company reputation… and in an exodus of leadership.”

EXPERT TAKE

GitHub's sub-six-hour response time sets a benchmark for enterprise cloud security incident handling.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
GitHubSecurityVulnerability
More fromThe Verge
  • Meta shows VR glasses with 100g weight and pocket puck

    Tech · 3d
  • Meta Connect 2026 opens with AI and smart glasses focus

    Tech · 3d
  • California requires AI data centers to fund local grid and water upgrades

    Energy · 5d
More inTech
  • OpenAI pauses model training after AI agents breach sandbox again

    Tech · 12h
  • CISA Adds WordPress Core Flaw CVE-2026-87902 to KEV Catalog

    Tech · 1d
  • CISA Adds Microsoft SharePoint Code Injection Flaw CVE-2026-65660 to KEV

    Tech · 1d
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    High-Severity Flaw in D-Link DIR-895L Router Has a Public Exploit

    CVE-2026-100740 is an out-of-bounds write in the L2TP code of the D-Link DIR-895L router on firmware A1_102b07. It can be triggered remotely, scores 8.6 (high), and an exploit is public.

  • Tech· 

    IBM Discloses Two More Guardium Data Protection 12.2 Flaws, Including a CVSS 8.8 Bug

    NVD published two more high-severity CVE records for IBM Guardium Data Protection 12.2 on September 25: CVE-2026-85542 (CVSS 8.8), a command injection bug, and CVE-2026-85029 (CVSS 7.5), a path traversal flaw. IBM lists fix pack SqlGuard_12.0p233.

  • Tech· 

    Microsoft Outlook Flaw CVE-2026-100208 Could Allow Remote Code Execution

    Microsoft Office Outlook has an integer overflow flaw, CVE-2026-100208, that could let an unauthorized attacker run code over a network. Microsoft scores it 7.5 (High), and an attack needs user interaction.

  • Tech· 

    IBM Power Server Firmware Flaw CVE-2026-93306 Can Crash the ASMI Web Interface

    CVE-2026-93306, published by NVD on September 25, lets an unauthenticated attacker on the management network crash the ASMI web server in IBM server firmware with a malformed HTTPS request. IBM rates it 7.1 (High) and has released fixed firmware for Power11, Power10 and Power9 systems.

  • Tech· 

    IBM Patches Two High-Severity Flaws in Guardium Data Protection 12.2

    NVD published two high-severity CVE records for IBM Guardium Data Protection 12.2 on September 25. CVE-2026-84884 (CVSS 7.5) covers REST service-account passwords stored in a reversible format, and CVE-2026-84862 (CVSS 7.2) is an insecure deserialization flaw that could allow code execution. IBM points customers to fix pack SqlGuard_12.0p233.