AI-Assisted Research Uncovers Linux Kernel Zero-Day Enabling Root Privilege Escalation
Attackers compromised GitHub Actions to inject Miasma malware into legitimate AsyncAPI npm packages, putting development environments at risk. This supply chain attack bypassed standard security measures by leveraging trusted publishing workflows to distribute malicious code.