
Sign up to save your podcasts
Or


Wiz researcher Sagi Tzadik joins us to break down how a single semicolon led to a critical Remote Code Execution (RCE) vulnerability in GitHub.
For two years, Sagi sat on a lead. Reverse engineering GitHub's microservices manually was too tedious to justify the time. Then, AI agents arrived. By hooking Claude directly into his reverse engineering software, he condensed months of grueling binary analysis into 48 hours. The result? A critical bug in how GitHub handles git push options that exposed both SaaS and Enterprise environments. We get into the weeds on how different microservices interpreting the same input differently creates massive attack surfaces, and why security by obscurity is officially dead in the age of AI.
What's Inside:
- How combining Claude with the IDA MCP server dramatically sped up the reverse engineering process
- The technical anatomy of the GitHub semicolon vulnerability.
- Why microservice communication breakdowns lead to critical RCEs.
- The massive difference in impact between GitHub.com and GitHub Enterprise Server.
- Why Enterprise users need to patch their instances immediately.
Resources:
- Learn more about the findings at: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
By Wiz4.8
2121 ratings
Wiz researcher Sagi Tzadik joins us to break down how a single semicolon led to a critical Remote Code Execution (RCE) vulnerability in GitHub.
For two years, Sagi sat on a lead. Reverse engineering GitHub's microservices manually was too tedious to justify the time. Then, AI agents arrived. By hooking Claude directly into his reverse engineering software, he condensed months of grueling binary analysis into 48 hours. The result? A critical bug in how GitHub handles git push options that exposed both SaaS and Enterprise environments. We get into the weeds on how different microservices interpreting the same input differently creates massive attack surfaces, and why security by obscurity is officially dead in the age of AI.
What's Inside:
- How combining Claude with the IDA MCP server dramatically sped up the reverse engineering process
- The technical anatomy of the GitHub semicolon vulnerability.
- Why microservice communication breakdowns lead to critical RCEs.
- The massive difference in impact between GitHub.com and GitHub Enterprise Server.
- Why Enterprise users need to patch their instances immediately.
Resources:
- Learn more about the findings at: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854

90,963 Listeners

43,594 Listeners

376 Listeners

649 Listeners

1,026 Listeners

112,191 Listeners

92 Listeners

314 Listeners

192 Listeners

213 Listeners

61 Listeners

45 Listeners

1,486 Listeners