<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Wiz got RCE on the cloud version of Github.com and access to every customer environment.]]></title><description><![CDATA[<p>Wiz got RCE on the cloud version of Github.com and access to every customer environment.</p><p>To do this they just reversed the on prem version and found a simple vuln.</p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">

<div class="card-body">
<h5 class="card-title">
<a href="https://xcancel.com/sagitz_/status/2049153195243372569">
 X Cancelled | Verifying your request
</a>
</h5>
<p class="card-text line-clamp-3"></p>
</div>
<a href="https://xcancel.com/sagitz_/status/2049153195243372569" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://xcancel.com/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(xcancel.com)</span></p>
</a>
</div><p></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://cyberplace.social/system/media_attachments/files/116/483/853/960/061/521/original/979f93f63799ec6a.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/ab39f166-f9d2-4d27-8b72-0f91d1e08f4f/wiz-got-rce-on-the-cloud-version-of-github.com-and-access-to-every-customer-environment.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 01 May 2026 12:57:14 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/ab39f166-f9d2-4d27-8b72-0f91d1e08f4f.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 28 Apr 2026 18:56:22 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Wiz got RCE on the cloud version of Github.com and access to every customer environment. on Wed, 29 Apr 2026 08:48:21 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> this is massive, have Github made a public response?</p>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/users/stemeerkat/statuses/116487127151312844</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/users/stemeerkat/statuses/116487127151312844</guid><dc:creator><![CDATA[stemeerkat@cyberplace.social]]></dc:creator><pubDate>Wed, 29 Apr 2026 08:48:21 GMT</pubDate></item><item><title><![CDATA[Reply to Wiz got RCE on the cloud version of Github.com and access to every customer environment. on Wed, 29 Apr 2026 06:35:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> They explicitly say so in their blog post, so ... ?</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/OmegaPolice/statuses/116486602974790691</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/OmegaPolice/statuses/116486602974790691</guid><dc:creator><![CDATA[omegapolice@hachyderm.io]]></dc:creator><pubDate>Wed, 29 Apr 2026 06:35:03 GMT</pubDate></item><item><title><![CDATA[Reply to Wiz got RCE on the cloud version of Github.com and access to every customer environment. on Wed, 29 Apr 2026 04:29:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> It’s a very Bill Clinton “depends on the meaning of the word ‘is’” approach to truth.</p>]]></description><link>https://board.circlewithadot.net/post/https://fosstodon.org/users/PeterUpfold/statuses/116486110239580430</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fosstodon.org/users/PeterUpfold/statuses/116486110239580430</guid><dc:creator><![CDATA[peterupfold@fosstodon.org]]></dc:creator><pubDate>Wed, 29 Apr 2026 04:29:44 GMT</pubDate></item><item><title><![CDATA[Reply to Wiz got RCE on the cloud version of Github.com and access to every customer environment. on Tue, 28 Apr 2026 20:27:53 GMT]]></title><description><![CDATA[<p><span><a href="https://social.chinwag.org/@xconde">@<span>xconde</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> as long as they also check for abuse of the exploit and Inform you about it. Which would be handy to have a cve number attached to the report.<br />So, they should still fix and then notify but can't just say "cloud is not affected" if they mean, "cloud is no longer vulnerable"</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/ketumbra/statuses/116484215535156107</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/ketumbra/statuses/116484215535156107</guid><dc:creator><![CDATA[ketumbra@infosec.exchange]]></dc:creator><pubDate>Tue, 28 Apr 2026 20:27:53 GMT</pubDate></item><item><title><![CDATA[Reply to Wiz got RCE on the cloud version of Github.com and access to every customer environment. on Tue, 28 Apr 2026 19:57:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> at least while I’m in charge of issuing CVEs, we won’t do this.</p>]]></description><link>https://board.circlewithadot.net/post/https://social.securitytheater.net/users/spaceinvader/statuses/116484097352228217</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.securitytheater.net/users/spaceinvader/statuses/116484097352228217</guid><dc:creator><![CDATA[spaceinvader@social.securitytheater.net]]></dc:creator><pubDate>Tue, 28 Apr 2026 19:57:50 GMT</pubDate></item><item><title><![CDATA[Reply to Wiz got RCE on the cloud version of Github.com and access to every customer environment. on Tue, 28 Apr 2026 19:34:24 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> Oh, phew. I thought this was an RCE impacting Wiz lightbulbs.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/ClickyMcTicker/statuses/116484005197071391</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/ClickyMcTicker/statuses/116484005197071391</guid><dc:creator><![CDATA[clickymcticker@hachyderm.io]]></dc:creator><pubDate>Tue, 28 Apr 2026 19:34:24 GMT</pubDate></item><item><title><![CDATA[Reply to Wiz got RCE on the cloud version of Github.com and access to every customer environment. on Tue, 28 Apr 2026 19:31:26 GMT]]></title><description><![CDATA[<p><span><a href="/user/henryk%40chaos.social">@<span>henryk</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> I was hoping for an exciting eyploit and was left rather disappointed <img class="not-responsive emoji" src="https://media.bsd.network/custom_emojis/images/000/044/185/original/016c7fb20085bb69.png" title=":flan_disappointed:" />​</p>]]></description><link>https://board.circlewithadot.net/post/https://bsd.network/users/stsp/statuses/116483993506983693</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://bsd.network/users/stsp/statuses/116483993506983693</guid><dc:creator><![CDATA[stsp@bsd.network]]></dc:creator><pubDate>Tue, 28 Apr 2026 19:31:26 GMT</pubDate></item><item><title><![CDATA[Reply to Wiz got RCE on the cloud version of Github.com and access to every customer environment. on Tue, 28 Apr 2026 19:05:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> Totally <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>]]></description><link>https://board.circlewithadot.net/post/https://fosstodon.org/users/laurento/statuses/116483893349203432</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fosstodon.org/users/laurento/statuses/116483893349203432</guid><dc:creator><![CDATA[laurento@fosstodon.org]]></dc:creator><pubDate>Tue, 28 Apr 2026 19:05:57 GMT</pubDate></item><item><title><![CDATA[Reply to Wiz got RCE on the cloud version of Github.com and access to every customer environment. on Tue, 28 Apr 2026 19:04:24 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> A header injection? In *this* economy?!</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/henryk/statuses/116483887228954820</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/henryk/statuses/116483887228954820</guid><dc:creator><![CDATA[henryk@chaos.social]]></dc:creator><pubDate>Tue, 28 Apr 2026 19:04:24 GMT</pubDate></item><item><title><![CDATA[Reply to Wiz got RCE on the cloud version of Github.com and access to every customer environment. on Tue, 28 Apr 2026 18:59:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> Can I quote you on that?</p>]]></description><link>https://board.circlewithadot.net/post/https://masto.hackers.town/users/drwho/statuses/116483869882219708</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://masto.hackers.town/users/drwho/statuses/116483869882219708</guid><dc:creator><![CDATA[drwho@masto.hackers.town]]></dc:creator><pubDate>Tue, 28 Apr 2026 18:59:59 GMT</pubDate></item><item><title><![CDATA[Reply to Wiz got RCE on the cloud version of Github.com and access to every customer environment. on Tue, 28 Apr 2026 18:59:08 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> Here's a non-Twitter link: <a href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854" rel="nofollow noopener"><span>https://www.</span><span>wiz.io/blog/github-rce-vulnera</span><span>bility-cve-2026-3854</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Xavier/statuses/116483866523507563</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Xavier/statuses/116483866523507563</guid><dc:creator><![CDATA[xavier@infosec.exchange]]></dc:creator><pubDate>Tue, 28 Apr 2026 18:59:08 GMT</pubDate></item><item><title><![CDATA[Reply to Wiz got RCE on the cloud version of Github.com and access to every customer environment. on Tue, 28 Apr 2026 18:58:56 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> You're describing the Microsoft method</p>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/users/systemadminihater/statuses/116483865724528470</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/users/systemadminihater/statuses/116483865724528470</guid><dc:creator><![CDATA[systemadminihater@cyberplace.social]]></dc:creator><pubDate>Tue, 28 Apr 2026 18:58:56 GMT</pubDate></item><item><title><![CDATA[Reply to Wiz got RCE on the cloud version of Github.com and access to every customer environment. on Tue, 28 Apr 2026 18:58:12 GMT]]></title><description><![CDATA[<p>Almost every time a SaaS supplier tells you a CVE in their product doesn't apply to their SaaS version.. it means they patched it before issuing the CVE.</p>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/users/GossiTheDog/statuses/116483862879721423</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/users/GossiTheDog/statuses/116483862879721423</guid><dc:creator><![CDATA[gossithedog@cyberplace.social]]></dc:creator><pubDate>Tue, 28 Apr 2026 18:58:12 GMT</pubDate></item></channel></rss>