NVD has published CVE-2026-67308 for a shell injection vulnerability in Wazuh workflows before 44bf114. Attackers can reportedly execute arbitrary commands and exfiltrate GITHUB_TOKEN plus AWS credentials on self-hosted runners by submitting pull requests with crafted VERSION.json files. The record, received from VulnCheck on August 1 2026, carries a CVSS 3.1 score of 10.0 critical from the CNA.

Malicious actors reportedly can trigger arbitrary command execution by submitting pull requests that include specially crafted VERSION.json files.
The resulting behavior reportedly enables command execution together with exfiltration of secrets such as GITHUB_TOKEN and AWS credentials when self-hosted runners are in use.
Organizations running self-hosted GitHub runners for Wazuh CI/CD should update workflows to commit 44bf114 or later immediately to block pull-request-based secret exfiltration.
Tap a lens to see what this story means for you.
Reader-supported · The Brief
Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Microsoft AI released a draft Humanist AI Code of Conduct for MAI models on September 14, 2026, opening six weeks of public feedback. The company says the draft puts people first, keeps models interruptible and auditable, sets Absolute Constraints on weapons, offensive cyber, and mass manipulation, and will be revised later in 2026 to guide 2027 training — current models are not trained on it yet.
Google launched Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking on September 15, 2026: near real-time voice dialogue models with visual grounding, 97-language mid-conversation switching, and background tool use. Extended Thinking adds simultaneous reasoning and leads Google-cited speech and agentic benchmarks, with rollout across Gemini API, AI Studio, Search Live, Gemini Live, and Workspace Live surfaces.
CISA added CVE-2026-76461, a SQL injection flaw in the Cisco email security appliance, to its Known Exploited Vulnerabilities catalog on 2026-09-14. Federal agencies have until 2026-09-17 to apply vendor mitigations under BOD 26-04, with forensic triage required.