April 29, 2026 tech news: GitHub's Critical RCE Flaw; SAP Supply Chain Attack; Hashimoto Quits GitHub; Zed Editor Hits 1.0; Rust's Safety Limits Exposed; Linux 7.0 PostgreSQL Regression; Maryland Bans Surveillance Pricing.
GitHub’s Critical RCE Flaw A critical vulnerability in GitHub’s internal git infrastructure allowed attackers to execute remote code on backend servers. On GitHub.com, this granted access to millions of public and private repositories on shared storage nodes; on GitHub Enterprise Server, it allowed full server compromise. The flaw was discovered using AI-augmented reverse engineering. https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854 SAP Supply Chain Attack Attackers compromised SAP-affiliated npm accounts to distribute credential-stealing malware via core SAP Cloud Application Programming Model packages. The payload harvests GitHub, AWS, Azure, and GCP tokens and poisons victim repositories with a malicious VS Code tasks.json to establish persistent CI/CD footholds. ...